NIST SP 800-53 Rev 5
PS - Personnel Security

NIST SP 800-53 Rev 5 NIST800-PS-6: PS-6 Access Agreements

a. Develop and document access agreements for organizational systems; b. Review and update the access agreements [Assignment: organization-defined frequency]; and c. Verify that individuals requiring access to organizational information and systems: 1. Sign appropriate access agreements prior to being granted access; and 2. Re-sign access agreements to maintain access to organizational systems when access agreements have been updated or [Assignment: organization-defined frequency].

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 39 controls across 22 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 7 controls

  • 6.4.1 Prior to employment
  • 6.4.2 During employment
  • 6.6.3 User responsibilities
  • 7.2.6 Contracts with PII processors
  • 8.2.1 Customer agreement
  • 8.2.5 Customer obligations
  • 8.5.7 Engagement of a subcontractor to process PII

C5 (Germany) · 3 controls

  • C5-AM-05 Commitment to Permissible Use, Safe Handling and Return of Assets
  • C5-HR-02 Employment terms and conditions
  • C5-HR-06 Confidentiality agreements

ISO 27001:2022 · 3 controls

  • 5.20 Addressing information security within supplier agreements
  • 6.2 Terms and conditions of employment
  • 6.6 Confidentiality or non-disclosure agreements

FedRAMP High · 2 controls

  • IR-9(4) Information Spillage Response | Exposure to Unauthorized Personnel (IR-9(4))
  • PS-6 Access Agreements

FedRAMP Moderate · 2 controls

  • IR-9(4) Information Spillage Response | Exposure to Unauthorized Personnel (IR-9(4))
  • PS-6 Access Agreements

HIPAA Security Rule · 2 controls

ISO 27002:2022 · 2 controls

  • 6.2 Terms and conditions of employment
  • 6.6 Confidentiality or non-disclosure agreements

SOC 2 · 2 controls

  • SOC2-CC1.1 CC1.1 Commitment to integrity and ethical values (COSO principle 1)
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials

APPI · 1 control

  • AUCDR-IS-6 Information security training and awareness program

GDPR · 1 control

  • GDPR-Art.29 Processing under the authority of the controller or processor
  • PS-6 PS-6 Access Agreements
  • PS-6 PS-6 Access Agreements
  • PS-6 PS-6 Access Agreements

PCI DSS 4.0 · 1 control

  • 3.7.8 3.7.8 Key custodians formally acknowledge responsibilities
  • 0120 0120 Assurance of suitability and agreement to comply with protective policies

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PS - Personnel Security

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-PS-6 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 39 it maps to, and the evidence behind each claim, over MCP and REST.