Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

AC-8 — System Use Notification

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

0Enhancements
2Parameters
3Baseline memberships
3Assessment methods

AC — Access Control · NIST SP 800-53 Release 5.2.0

LowModerateHigh
Official NIST control content

Control statement

  1. a.Display [Organization-defined: system use notification] to users before granting access to the system that provides privacy and security notices consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines and state that:
    1. 1.Users are accessing a U.S. Government system;
    2. 2.System usage may be monitored, recorded, and subject to audit;
    3. 3.Unauthorized use of the system is prohibited and subject to criminal and civil penalties; and
    4. 4.Use of the system indicates consent to monitoring and recording;
  2. b.Retain the notification message or banner on the screen until users acknowledge the usage conditions and take explicit actions to log on to or further access the system; and
  3. c.For publicly accessible systems:
    1. 1.Display system use information [Organization-defined: conditions] , before granting further access to the publicly accessible system;
    2. 2.Display references, if any, to monitoring, recording, or auditing that are consistent with privacy accommodations for such systems that generally prohibit those activities; and
    3. 3.Include a description of the authorized uses of the system.
Official NIST discussion

Discussion

System use notifications can be implemented using messages or warning banners displayed before individuals log in to systems. System use notifications are used only for access via logon interfaces with human users. Notifications are not required when human interfaces do not exist. Based on an assessment of risk, organizations consider whether or not a secondary system use notification is needed to access applications or other system resources after the initial network logon. Organizations consider system use notification messages or banners displayed in multiple languages based on organizational needs and the demographics of system users. Organizations consult with the privacy office for input regarding privacy messaging and the Office of the General Counsel or organizational equivalent for legal review and approval of warning banner content.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

system use notificationsystem use notification message or banner to be displayed by the system to users before granting access to the system is defined;
conditionsconditions for system use to be displayed by the system before granting further access are defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use System Use Notification as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to identity, authorization, least privilege, session boundaries, and access lifecycle governance.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • access approvals and entitlement records
  • role and group configuration exports
  • periodic access review results
  • authentication and authorization logs

Common failure patterns

  • standing privileges that outlive business need
  • shared or orphaned accounts
  • access rules implemented differently across systems
  • approvals that cannot be traced to actual permissions

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. AC-08a.[Organization-defined: system use notification] is displayed to users before granting access to the system that provides privacy and security notices consistent with applicable laws, Executive Orders, directives, regulations, policies, standards, and guidelines;
    1. AC-08a.01the system use notification states that users are accessing a U.S. Government system;
    2. AC-08a.02the system use notification states that system usage may be monitored, recorded, and subject to audit;
    3. AC-08a.03the system use notification states that unauthorized use of the system is prohibited and subject to criminal and civil penalties; and
    4. AC-08a.04the system use notification states that use of the system indicates consent to monitoring and recording;
  2. AC-08b.the notification message or banner is retained on the screen until users acknowledge the usage conditions and take explicit actions to log on to or further access the system;
  3. AC-08c.
    1. AC-08c.01for publicly accessible systems, system use information [Organization-defined: conditions] is displayed before granting further access to the publicly accessible system;
    2. AC-08c.02for publicly accessible systems, any references to monitoring, recording, or auditing that are consistent with privacy accommodations for such systems that generally prohibit those activities are displayed;
    3. AC-08c.03for publicly accessible systems, a description of the authorized uses of the system is included.

Examine

  • Access control policy
  • privacy and security policies, procedures addressing system use notification
  • documented approval of system use notification messages or banners
  • system audit records
  • user acknowledgements of notification message or banner
  • system design documentation
  • system configuration settings and associated documentation
  • system use notification messages
  • system security plan
  • privacy plan
  • privacy impact assessment
  • privacy assessment report
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security and privacy responsibilities
  • legal counsel
  • system developers

Test

  • Mechanisms implementing system use notification
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Source record

Authoritative sources