Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-171 CUI Protection Center

03.15.03 — Rules of Behavior

Read the official CUI requirement and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect it to implementation, evidence, and sustained operation.

1Parameters
1Source controls
5Assessment objectives
3Assessment methods

03.15 — Planning · NIST SP 800-171 Revision 3

Active
Official NIST requirement content

Security requirement

  1. a.Establish rules that describe the responsibilities and expected behavior for system usage and protecting CUI.
  2. b.Provide rules to individuals who require access to the system.
  3. c.Receive a documented acknowledgement from individuals indicating that they have read, understand, and agree to abide by the rules of behavior before authorizing access to CUI and the system.
  4. d.Review and update the rules of behavior [Organization-defined: frequency].
Official NIST discussion

Discussion

Rules of behavior represent a type of access agreement for system users. Organizations consider rules of behavior for the handling of CUI based on individual user roles and responsibilities and differentiate between rules that apply to privileged users and rules that apply to general users.

Official organization-defined parameters

Tailoring decisions required

Resolve these values through the governing organization’s approved tailoring and risk-management process before declaring the requirement implemented.

frequencyorganization-defined frequencythe frequency at which the rules of behavior are reviewed and updated is defined.
Bare Metal Cyber interpretation

Implementation perspective

Treat Rules of Behavior as a CUI protection outcome that must be reflected in the system boundary, documented implementation, operational behavior, and assessment evidence. Pay particular attention to accurate plans, architecture, rules of behavior, system boundaries, and lifecycle alignment for CUI protection.

  1. Confirm the requirement is in scope for the CUI system components, services, users, and external connections being assessed.
  2. Resolve every organization-defined parameter through an approved governance and tailoring process.
  3. Map each clause of the requirement to an accountable owner, implementation mechanism, and evidence source.
  4. Verify that inherited and shared implementations are supported by current provider evidence and responsibility boundaries.
  5. Collect evidence during normal operation and review changes, exceptions, and deficiencies on a risk-based cadence.

Questions to ask

  • Which CUI assets, data flows, users, and services are protected by this requirement?
  • Which portions are implemented locally, inherited, shared, or not applicable, and what evidence supports that determination?
  • Do the system security plan, deployed configuration, operating process, and assessment evidence tell the same story?
  • What change, incident, or threshold should trigger reassessment?

Evidence and validation

  • system security plans
  • architecture and data-flow diagrams
  • rules-of-behavior acknowledgments
  • plan review and approval records

Common failure patterns

  • plans copied from templates without system specificity
  • diagrams that do not match deployed services
  • inherited protection claimed without provider evidence
  • plans updated only before assessment
Official NIST SP 800-171A content

Assessment objectives and methods

Assessment objectives (5)
  1. a.

    rules that describe responsibilities and expected behavior for system usage and protecting CUI are established.

  2. b.

    rules are provided to individuals who require access to the system.

  3. c.

    a documented acknowledgement from individuals indicating that they have read, understand, and agree to abide by the rules of behavior is received before authorizing access to CUI and the system.

  4. d.

    the rules of behavior are updated [Organization-defined: frequency] .

  5. d.

    the rules of behavior are reviewed [Organization-defined: frequency].

Examine

  • security planning policy and procedures
  • rules of behavior for system users
  • signed acknowledgements of rules of behavior
  • records for rules of behavior reviews and updates
  • system security plan
  • other relevant documents or records

Interview

  • personnel with rules of behavior establishment, review, and update responsibilities
  • personnel with literacy training and awareness responsibilities
  • personnel with role-based training responsibilities
  • authorized users of the system who have signed rules of behavior
  • personnel with information security responsibilities

Test

  • processes for establishing, reviewing, disseminating, and updating rules of behavior
  • mechanisms for supporting or implementing the establishment, dissemination, review, and update of rules of behavior
Official source-control relationships

Source NIST SP 800-53 controls

These controls are referenced by the official SP 800-171 Rev. 3 OSCAL record. Open the corresponding control pages for complete control text, enhancements, D3FEND mappings, and related learning.

Source record

Authoritative sources