|
controlPL-4

Rules of Behavior (PL-4)

Establish and provide to individuals requiring access to the system, the rules that describe their responsibilities and expected behavior for information and system usage, security, and privacy; Receive a documented acknowledgment from such individuals, indicating that they have read, understand, and agree to abide by the rules of behavior, before authorizing access to information and the system; Review and update the rules of behavior [organization-defined] ; and Require individuals who have ac

Security Baselines

LOWMODERATEHIGH
planningsecurity-plan

Why These Connect

Maps To2

These are equivalent or closely aligned requirements in other frameworks.

Baselined In3

This control is included in the linked security baseline (LOW, MODERATE, or HIGH).

Supports35

These related controls work together — a change to one may affect the others.

Enhances1

These enhancements add specific capabilities or refinements to the base control.

Cross-Framework Mappings(2)

ISO 27001ISO/IEC 27001:20223 mappingsFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
HIPAAHIPAA Security Rule1 mappingFinal
NIST OLIR informative reference — HIPAA Security Rule to SP 800-53 Rev 5

Organization-Defined Parameters(3)

Assignmentorganization-defined frequency
SelectionSelection (one-or-more): {{ insert: param, pl-04_odp.03 }} / when the rules are revised or updated
Assignmentorganization-defined frequency

Control Enhancements(1)