# PS-06 Access Agreements

NIST SP 800-53 control. Family: PS Personnel Security. Function: preventative. Baselines: low, moderate, high, privacy. Mapping licence: CC BY-SA 4.0.

Statement: a. Develop and document access agreements for organizational systems; b. Review and update the access agreements [Assignment: organization-defined frequency]; and c. Verify that individuals requiring access to organizational information and systems: 1. Sign appropriate access agreements prior to being granted access; and 2. Re-sign access agreements to maintain access to organizational systems when access agreements have been updated or [Assignment: organization-defined frequency].
Guidance: Access agreements include nondisclosure agreements, acceptable use agreements, rules of behavior, and conflict-of-interest agreements. Signed access agreements include an acknowledgement that individuals have read, understand, and agree to abide by the constraints associated with organizational systems to which access is authorized. Organizations can use electronic signatures to acknowledge access agreements unless specifically prohibited by organizational policy.

## Enhancements (2)
- PS-06(02) Classified Information Requiring Special Protection
- PS-06(03) Post-employment Requirements
Withdrawn by NIST: PS-06(01) (now in PS-03).
Each enhancement's statement: /api/v1/controls/PS-06?fields=enhancements

## Patterns that use it (9)
- Critical (1): SP-014 Awareness and Training Pattern
- Important (5): SP-011 Cloud Computing Pattern; SP-024 iPhone Pattern; SP-035 Offensive Security Testing; SP-048 Offensive AI and Deepfake Defence (draft); SP-051 Tokenised Asset Security Architecture (draft)
- Standard (3): SP-001 Client Module; SP-045 AI Governance and Responsible AI; SP-049 AI in Security Operations (draft)

## Clauses by framework (62 frameworks)
- iso_27001_2022: A.5.4, A.5.14, A.6.2, A.6.6
- iso_27002_2022: 6.2, 6.5, 6.6
- cobit_2019: APO07
- nist_csf_2: GV.RR-04. OSA's own, not in NIST's crosswalk: GV.RR-04
- soc2_tsc: CC1.5
- iso_42001_2023: A.9.2
- nis2: Art. 21(2)(i)
- bsi_grundschutz: ORP.2
- anssi: Hygiene.7, SecNumCloud.8.2
- osfi_b13: B-13.1.1
- finma_circular: IV.B.a(48), IV.B.d(59)
- gdpr: Art.29, Art.32(4)
- dora: Art.5(4)
- bio2: 6.2, 6.5, 6.6
- rbi_csf: Annex1.8
- fisc: FISC.O8
- lgpd_bcb: LGPD.Art.47
- mlps_2: 8.1.8.1
- dnb_good_practice: DNB.8.4
- swift_cscf: SWIFT.5.3A
- nca_ecc: 1-9
- qatar_nia: HR
- sama_csf: 1.7
- uae_ia: T5
- bog_cisd: CISD-XV
- bom_ctrm: 1.2, 3.8
- cbe_csf: CD-1, GOV-2
- cbn_csf: Part1.2, Part9
- popia: s19
- sa_js2: JS2-8.6
- bot_cyber: Ch7.2
- cpmi_pfmi: CG.GOV
- ecb_croe: CROE.2.1.2, CROE.2.3.2
- ffiec_is: II.C.7, II.C.7(a), II.C.7(d)
- hipaa_sr: §164.308(a)(1)(ii)(C), §164.308(a)(3)(i), §164.308(a)(3)(ii)(B), §164.308(a)(4)(ii)(B)
- iosco_cyber: GOV-4
- nydfs_500: 500.10
- sebi_cscrf: GV.RR
- cmmc_2: PS
- nerc_cip: CIP-004-7
- nrc_73_54: RG5.71-C-PS
- doe_c2m2: WORKFORCE
- api_1164: Sec 13
- awia: AWWA Sec 8
- iaea_nss: Sec 9
- pci_pts: H
- pci_hsm: 1, 5, 6
- common_criteria: CC Part 2 — FMT
- fca_sysc_13: SYSC 13.6.1
- fda_21_cfr_11: §11.10(j)
- hitrust_csf: 01.a, 02.a, 02.b
- iso_27799: 7.1, 7.2
- naic_ds: 4-personnel, 4B
- nhs_dspt: NDG-2.3
- pra_ss1_23: P2.4
- solvency_ii: Art.42
- csa_ccm_v4: HRS-07, HRS-08, HRS-10, HRS-13
- csa_aicm: HRS-07, HRS-08, HRS-10, HRS-13
- mica: Art.36(1), Art.65(1), Art.73(1), Art.86(1), Art.92(1)
- basel_sco60: SCO60.55, SCO60.60, SCO60.62
- bssc: GSP-04
- sec_custody_digital: SEC-CD-19
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/PS-06
- Clauses only: /api/v1/controls/PS-06?fields=mappings
- Page for people: /controls/ps-06/
