Rules of Behavior PL-4
Planning · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds PL-4 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Planning family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
PL-4 (Rules of Behavior) is about telling the people who use a system, in plain terms, what is expected of them — how to use it safely and protect information and privacy — and getting a documented acknowledgment before they are granted access. It is a Planning control at the Low baseline.
What good looks like
- Write rules of behavior that describe how people may use the system and handle information.
- Cover security and privacy expectations — acceptable use, protecting data, and reporting problems.
- Get a documented acknowledgment (signed or click-through) before an account is granted access.
- Review and update the rules on a set schedule.
- Have people re-acknowledge when the rules change, or on a set schedule.
Framework mapping
How to move it toward Implemented
- Write a short rules-of-behavior document for the lab server: acceptable use, data handling, and who to tell when something looks wrong.
- Collect a signed acknowledgment from each person before their account is created, and file it with a date.
- Show a use notice at login — put the text in
/etc/issue.netand setBanner /etc/issue.netin/etc/ssh/sshd_config(and/etc/motdfor the local console). - Review the rules on a schedule and have people re-acknowledge when they change.
- Attach the rules and the signed acknowledgments as hardening evidence on the asset, naming
PL-4in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.