Control statement
- a.Display [Organization-defined: system use notification] to users before granting access to the system that provides privacy and security notices consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines and state that:
- 1.Users are accessing a U.S. Government system;
- 2.System usage may be monitored, recorded, and subject to audit;
- 3.Unauthorized use of the system is prohibited and subject to criminal and civil penalties; and
- 4.Use of the system indicates consent to monitoring and recording;
- b.Retain the notification message or banner on the screen until users acknowledge the usage conditions and take explicit actions to log on to or further access the system; and
- c.For publicly accessible systems:
- 1.Display system use information [Organization-defined: conditions] , before granting further access to the publicly accessible system;
- 2.Display references, if any, to monitoring, recording, or auditing that are consistent with privacy accommodations for such systems that generally prohibit those activities; and
- 3.Include a description of the authorized uses of the system.
Discussion
System use notifications can be implemented using messages or warning banners displayed before individuals log in to systems. System use notifications are used only for access via logon interfaces with human users. Notifications are not required when human interfaces do not exist. Based on an assessment of risk, organizations consider whether or not a secondary system use notification is needed to access applications or other system resources after the initial network logon. Organizations consider system use notification messages or banners displayed in multiple languages based on organizational needs and the demographics of system users. Organizations consult with the privacy office for input regarding privacy messaging and the Office of the General Counsel or organizational equivalent for legal review and approval of warning banner content.
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use System Use Notification as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to identity, authorization, least privilege, session boundaries, and access lifecycle governance.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- access approvals and entitlement records
- role and group configuration exports
- periodic access review results
- authentication and authorization logs
Common failure patterns
- standing privileges that outlive business need
- shared or orphaned accounts
- access rules implemented differently across systems
- approvals that cannot be traced to actual permissions
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- AC-08a.[Organization-defined: system use notification] is displayed to users before granting access to the system that provides privacy and security notices consistent with applicable laws, Executive Orders, directives, regulations, policies, standards, and guidelines;
- AC-08a.01the system use notification states that users are accessing a U.S. Government system;
- AC-08a.02the system use notification states that system usage may be monitored, recorded, and subject to audit;
- AC-08a.03the system use notification states that unauthorized use of the system is prohibited and subject to criminal and civil penalties; and
- AC-08a.04the system use notification states that use of the system indicates consent to monitoring and recording;
- AC-08b.the notification message or banner is retained on the screen until users acknowledge the usage conditions and take explicit actions to log on to or further access the system;
- AC-08c.
- AC-08c.01for publicly accessible systems, system use information [Organization-defined: conditions] is displayed before granting further access to the publicly accessible system;
- AC-08c.02for publicly accessible systems, any references to monitoring, recording, or auditing that are consistent with privacy accommodations for such systems that generally prohibit those activities are displayed;
- AC-08c.03for publicly accessible systems, a description of the authorized uses of the system is included.
Examine
- Access control policy
- privacy and security policies, procedures addressing system use notification
- documented approval of system use notification messages or banners
- system audit records
- user acknowledgements of notification message or banner
- system design documentation
- system configuration settings and associated documentation
- system use notification messages
- system security plan
- privacy plan
- privacy impact assessment
- privacy assessment report
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security and privacy responsibilities
- legal counsel
- system developers
Test
- Mechanisms implementing system use notification
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.