AC.L2-3.1.9Privacy & Security Notices
Provide privacy and security notices consistent with applicable CUI rules.
[a]
privacy and security notices required by CUI-specified rules are identified, consistent, and associated with the specific CUI category; and[b]
privacy and security notices are displayed.
CUI rules banner before enclave session and on shared workstations
Implementation
AO coverage. Addresses both Privacy & Security Notices objectives for CUI rules.
Notices. Before first daily access to enclave apps, users accept an IdP Terms of Use stating CUI handling rules, monitoring, and no personal storage. Shared kiosks display a legal banner at logon covering the same points.
Consistency. Banner text is version-controlled with the CUI handling policy. Changes go through security review; acceptance is re-prompted when the version changes.
Maintenance. Annual review of notice text against contract and 32 CFR Part 2002 expectations used by the org. Spot-check that new enclave apps inherit the ToU grant.
Accepted gap. Mobile Intune App Protection cannot show the full desktop banner chrome. Users still hit the IdP ToU on first SSO; app-level privacy string is abbreviated.
What the evidence looks like
- IdP Terms of Use text and version history
- Screenshot of kiosk logon banner
- Change ticket for last notice revision
- Conditional Access / app assignment showing ToU required for enclave apps
Environment
Tools
Was this example useful?
Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.
Discussion(0)
No discussion on this example yet
Verdicts capture a conclusion. Use a thread when the interesting part is the argument.
Sign in to start a thread.