Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

PS-6 — Access Agreements

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

3Enhancements
2Parameters
4Baseline memberships
3Assessment methods

PS — Personnel Security · NIST SP 800-53 Release 5.2.0

LowModerateHighPrivacy
Official NIST control content

Control statement

  1. a.Develop and document access agreements for organizational systems;
  2. b.Review and update the access agreements [Organization-defined: frequency] ; and
  3. c.Verify that individuals requiring access to organizational information and systems:
    1. 1.Sign appropriate access agreements prior to being granted access; and
    2. 2.Re-sign access agreements to maintain access to organizational systems when access agreements have been updated or [Organization-defined: frequency].
Official NIST discussion

Discussion

Access agreements include nondisclosure agreements, acceptable use agreements, rules of behavior, and conflict-of-interest agreements. Signed access agreements include an acknowledgement that individuals have read, understand, and agree to abide by the constraints associated with organizational systems to which access is authorized. Organizations can use electronic signatures to acknowledge access agreements unless specifically prohibited by organizational policy.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

frequencythe frequency at which to review and update access agreements is defined;
frequencythe frequency at which to re-sign access agreements to maintain access to organizational information is defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Access Agreements as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to personnel risk, screening, agreements, transfer, termination, and access consequences.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • screening and suitability records
  • access agreements
  • transfer and termination checklists
  • role change and offboarding evidence

Common failure patterns

  • access persists after transfer or separation
  • contractor lifecycle handled outside normal controls
  • sensitive-role screening not risk based
  • termination actions cannot be shown to occur promptly

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. PS-06a.access agreements are developed and documented for organizational systems;
  2. PS-06b.the access agreements are reviewed and updated [Organization-defined: frequency];
  3. PS-06c.
    1. PS-06c.01individuals requiring access to organizational information and systems sign appropriate access agreements prior to being granted access;
    2. PS-06c.02individuals requiring access to organizational information and systems re-sign access agreements to maintain access to organizational systems when access agreements have been updated or [Organization-defined: frequency].

Examine

  • Personnel security policy
  • personnel security procedures
  • procedures addressing access agreements for organizational information and systems
  • access control policy
  • access control procedures
  • access agreements (including non-disclosure agreements, acceptable use agreements, rules of behavior, and conflict-of-interest agreements)
  • documentation of access agreement reviews, updates, and re-signing
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with personnel security responsibilities
  • organizational personnel who have signed/resigned access agreements
  • organizational personnel with information security and privacy responsibilities

Test

  • Organizational processes for reviewing, updating, and re-signing access agreements
  • mechanisms supporting the reviewing, updating, and re-signing of access agreements
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

PS-6(1) — Information Requiring Special Protection

Withdrawn

This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.

Official NIST control enhancement

PS-6(2) — Classified Information Requiring Special Protection

Verify that access to classified information requiring special protection is granted only to individuals who:

  1. (a)Have a valid access authorization that is demonstrated by assigned official government duties;
  2. (b)Satisfy associated personnel security criteria; and
  3. (c)Have read, understood, and signed a nondisclosure agreement.
Official discussion

Classified information that requires special protection includes collateral information, Special Access Program (SAP) information, and Sensitive Compartmented Information (SCI). Personnel security criteria reflect applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

Assessment objectives and methods
  1. PS-06(02)(a)access to classified information requiring special protection is granted only to individuals who have a valid access authorization that is demonstrated by assigned official government duties;
  2. PS-06(02)(b)access to classified information requiring special protection is granted only to individuals who satisfy associated personnel security criteria;
  3. PS-06(02)(c)access to classified information requiring special protection is granted only to individuals who have read, understood, and signed a non-disclosure agreement.

Examine

  • Personnel security policy
  • procedures addressing access agreements for organizational information and systems
  • access agreements
  • access authorizations
  • personnel security criteria
  • signed non-disclosure agreements
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with personnel security responsibilities
  • organizational personnel who have signed non-disclosure agreements
  • organizational personnel with information security responsibilities

Test

  • Organizational processes for access to classified information requiring special protection
Official NIST control enhancement

PS-6(3) — Post-employment Requirements

  1. (a)Notify individuals of applicable, legally binding post-employment requirements for protection of organizational information; and
  2. (b)Require individuals to sign an acknowledgment of these requirements, if applicable, as part of granting initial access to covered information.
Official discussion

Organizations consult with the Office of the General Counsel regarding matters of post-employment requirements on terminated individuals.

Assessment objectives and methods
  1. PS-06(03)(a)individuals are notified of applicable, legally binding post-employment requirements for the protection of organizational information;
  2. PS-06(03)(b)individuals are required to sign an acknowledgement of applicable, legally binding post-employment requirements as part of being granted initial access to covered information.

Examine

  • Personnel security policy
  • procedures addressing access agreements for organizational information and systems
  • signed post-employment acknowledgement forms
  • access agreements
  • list of applicable, legally binding post-employment requirements
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with personnel security responsibilities
  • organizational personnel who have signed access agreements that include post-employment requirements
  • organizational personnel with information security responsibilities

Test

  • Organizational processes for post-employment requirements
  • mechanisms supporting notifications and individual acknowledgements of post-employment requirements
Related controls
Source record

Authoritative sources