PS-6: Access Agreements

PS-06 requires organizations to create, maintain, and enforce signed access agreements before granting anyone access to information systems.

Quick-reference card

FieldValue
Control IDPS-06
Control NameAccess Agreements
FrameworkNIST SP 800-53 Revision 5
Control FamilyPersonnel Security
BaselinesLOW MODERATE HIGH PRIVACY
RelevanceOrganization (First Party and Third Party)
Risk SeverityMedium

What this control requires

PS-06 requires organizations to create, maintain, and enforce signed access agreements before granting anyone access to information systems. Every person who touches organizational data, whether an employee, contractor, or external partner, must acknowledge the rules governing that access in writing before they receive credentials.

In practice, this control means you need a documented set of agreements covering nondisclosure, acceptable use, rules of behavior, and conflict-of-interest obligations. These agreements aren’t one-time paperwork. You must review and update them on a defined schedule, and anyone with existing access must re-sign whenever terms change. Electronic signatures satisfy this requirement unless your organization’s policy specifically prohibits them.

The intent behind PS-06 is accountability. Without a signed agreement tying each individual to specific access constraints, your organization has no enforceable baseline for user behavior. Auditors look for evidence that every active user has a current, signed agreement on file. Gaps in this documentation create compliance findings that are difficult to remediate retroactively, especially across the Personnel Security family of controls.

Why it matters

Most organizations treat access agreements as onboarding paperwork and then forget about them. That gap between signing and re-signing is where compliance risk accumulates. When agreements go stale, your organization loses the documented proof that users understand and accept current access constraints.

Failure to maintain this control introduces audit risk and may result in certification withdrawal or regulatory findings. Assessors evaluating your NIST SP 800-53 implementation will flag any user who holds active credentials without a current, signed agreement. The remediation burden grows with every month agreements remain unreviewed.

This control also affects your privacy posture. PS-06 appears in the PRIVACY baseline because access agreements are a primary mechanism for communicating data handling obligations to individuals. Without documented acknowledgment, you can’t demonstrate that users understood their responsibilities before accessing sensitive information.

Beyond audit exposure, stale or missing agreements weaken your ability to enforce personnel sanctions. If an employee violates an acceptable use policy they never signed, your legal and HR teams lose a critical enforcement tool.

What attackers exploit

  • Absent or outdated nondisclosure agreements that leave organizations unable to pursue legal action after insider data theft
  • Missing acceptable use agreements that allow users to claim ignorance of prohibited activities, such as unauthorized data transfers or shadow IT usage
  • Lapsed conflict-of-interest disclosures that obscure relationships between personnel and external entities seeking access to proprietary data
  • Unsigned rules of behavior that remove the documented basis for revoking access after policy violations
  • Incomplete re-signing processes that leave former contractors with credentials tied to outdated terms

How to implement

For your organization

The most common failure mode is treating access agreements as a single HR form rather than a living document system with review cycles and re-signing triggers. Organizations that bundle all agreement types into one generic form miss the specificity auditors expect.

Step 1 — Inventory your agreement types. Map each required agreement type to the roles and access levels in your organization. At minimum, you need nondisclosure agreements, acceptable use agreements, rules of behavior, and conflict-of-interest agreements. Some roles may require additional agreements based on the sensitivity of the data they access.

Step 2 — Draft agreements with specific constraints. Each agreement must reference the organizational systems it covers and the specific constraints users are acknowledging. Generic boilerplate won’t satisfy assessment objectives. Rules of behavior agreements, for example, should reference the rules of behavior expectations your organization enforces, not abstract principles.

Step 3 — Establish a review cadence. Define how frequently you’ll review and update each agreement type. Link this cadence to your broader policy review cycle so updates to your personnel security policy automatically trigger agreement reviews.

Step 4 — Build a re-signing workflow. When agreements change, every individual with active access must re-sign. Your workflow needs to track who has signed, who hasn’t, and escalate non-compliance. Set a grace period after which unsigned users lose access.

Step 5 — Centralize signature records. Maintain a single repository linking each user to their signed agreements, signature dates, and agreement versions. This repository is what auditors request during assessments. Electronic signature platforms work well here, provided your policy permits them.

Step 6 — Connect to onboarding and offboarding. Access agreements must be part of your provisioning workflow. No credentials should be issued before all required agreements are signed. Integrate agreement status checks into your access control procedures so provisioning systems verify signature status before granting access.

For your vendors

The most common failure mode in vendor environments is accepting a vendor’s internal policies as proof of PS-06 compliance without verifying that individual vendor personnel have actually signed access agreements specific to your systems and data.

Step 1 — Include access agreement requirements in contracts. Your vendor agreements should mandate that all vendor personnel with access to your systems sign access agreements covering nondisclosure, acceptable use, and rules of behavior before receiving credentials.

Step 2 — Request evidence of agreement processes. Ask vendors to provide their access agreement templates and their procedures for tracking signatures. Look for specificity in the agreements, including references to your data and systems, not just the vendor’s internal policies.

Step 3 — Verify re-signing procedures. Confirm that the vendor has a defined process for updating access agreements and requiring re-signatures. Request documentation showing the most recent review date and any resulting updates.

Step 4 — Audit signature completeness. Request a list of all vendor personnel with access to your systems alongside confirmation that each person has a current, signed agreement on file. Cross-reference this list against your own access logs to identify anyone with credentials who lacks a signed agreement.

Step 5 — Watch for red flags. Vendors that can’t produce signed access agreements for specific individuals, rely solely on employment contracts as proof of acknowledgment, or have no defined review cadence for their agreements pose a compliance risk to your organization. These gaps often indicate broader weaknesses in the vendor’s personnel security practices.

Step 6 — Establish periodic verification. Don’t treat vendor access agreement verification as a one-time event. Build it into your ongoing vendor assessment cycle, requesting updated evidence at least annually.

Evidence examples

Evidence TypeExample Artifact
Access agreement templatesNondisclosure agreements, acceptable use agreements, rules of behavior, and conflict-of-interest agreements customized to organizational systems and data classifications
Signed agreement recordsRepository of signed access agreements for all active users, including signature dates, agreement versions, and the specific systems covered by each agreement
Agreement review documentationRecords of periodic reviews showing when access agreements were last evaluated, what changes were made, and the approval authority for updates
Re-signing tracking recordsLogs documenting re-signing events triggered by agreement updates, including completion dates, outstanding signatures, and escalation actions for non-compliance
Personnel security policyPolicy defining access agreement types, review frequency, re-signing triggers, and roles responsible for agreement administration
Access control proceduresProcedures linking agreement signature status to access provisioning workflows, ensuring credentials are not issued before agreements are signed
System security planPlan sections documenting how PS-06 is implemented, including the agreement types used, the review schedule, and the signature tracking mechanism
Privacy planPlan sections addressing how access agreements communicate data handling and privacy obligations to individuals accessing sensitive information

Cross-framework mapping

FrameworkControl(s)Coverage
ISO 27001:20225.14 Information transferPartial
ISO 27001:20225.4 Management responsibilitiesPartial
ISO 27001:20226.2 Terms and conditions of employmentPartial
ISO 27001:20226.6 Confidentiality or non-disclosure agreementsPartial
  • AC-17 — Remote Access: Defines the access requirements that remote users must acknowledge through signed agreements before connecting to organizational systems.
  • PE-02 — Physical Access Authorizations: Establishes the authorization process for physical access, which may require separate access agreements for facility entry.
  • PL-04 — Rules of Behavior: Specifies the behavioral expectations that form the content basis for the rules of behavior agreements required by PS-06.
  • PS-02 — Position Risk Designation: Determines the risk level of each position, which informs the scope and specificity of access agreements assigned to individuals in those roles.
  • PS-03 — Personnel Screening: Ensures individuals are vetted before being presented with access agreements, sequencing screening before agreement signing in the onboarding workflow.
  • PS-07 — External Personnel Security: Extends access agreement requirements to external personnel, including contractors and consultants who access organizational systems.
  • PS-08 — Personnel Sanctions: Defines the enforcement actions available when individuals violate the terms of their signed access agreements.
  • SA-21 — Developer Screening: Applies screening and agreement requirements to developers with access to system development environments and source code.
  • SI-12 — Information Management and Retention: Governs how signed access agreements and related records are retained, archived, and disposed of across their lifecycle.

Frequently asked questions

What is NIST SP 800-53 PS-06?

PS-06 is the NIST SP 800-53 control that requires organizations to develop, document, and enforce signed access agreements before granting individuals access to information systems. These agreements must cover nondisclosure terms, acceptable use rules, rules of behavior, and conflict-of-interest disclosures. Organizations must also define a review cadence for updating these agreements and require re-signing when terms change. The control applies across all four baselines, including LOW, MODERATE, HIGH, and PRIVACY.

What happens if PS-06 is not implemented?

Without PS-06 implementation, your organization lacks documented proof that individuals understand and accept the constraints governing their system access. Auditors will issue findings for any active user missing a current, signed access agreement, and repeated findings can jeopardize certification status. The absence of signed nondisclosure agreements and acceptable use agreements also weakens your legal standing if an insider incident occurs, since you can’t demonstrate the individual acknowledged prohibited activities.

How do you audit PS-06?

Auditing PS-06 starts with verifying that access agreement templates exist for each required type, including nondisclosure agreements, acceptable use agreements, rules of behavior, and conflict-of-interest agreements. Assessors then sample active users and check whether each person has a signed agreement on file that matches the current version. The audit also examines evidence of periodic agreement reviews and documentation showing that re-signing occurred after the most recent update to any agreement.

What types of agreements does PS-06 require?

PS-06 requires four categories of access agreements: nondisclosure agreements that restrict unauthorized disclosure of organizational information, acceptable use agreements that define permitted and prohibited system activities, rules of behavior that establish expected user conduct, and conflict-of-interest agreements that require individuals to disclose relationships that could compromise their objectivity. Each agreement type must be documented, reviewed on a defined schedule, and signed before access is granted.

Experience superior visibility and a simpler approach to cyber risk management