Privacy & Security Notices
Practice statement
Provide privacy and security notices consistent with applicable CUI rules.
Quoted verbatim from NIST SP 800-171 Rev. 2 §3.1.9.Source
The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.
Assessment Objectives(2)
An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.
- [a]
privacy and security notices required by CUI-specified rules are identified, consistent, and associated with the specific CUI category; and
1 example covers this
- [b]
privacy and security notices are displayed.
1 example covers this
Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.
Implementation examples(1)
Submit your own example- addresses
AC.L2-3.1.9Privacy & Security Notices
Provide privacy and security notices consistent with applicable CUI rules.
[a]
privacy and security notices required by CUI-specified rules are identified, consistent, and associated with the specific CUI category; and[b]
privacy and security notices are displayed.
CUI rules banner before enclave session and on shared workstations
ControlVerdict Corpus@cv-corpusOSCJul 31, 2026Community is just starting — add yours. No verdicts yet.Implementation
AO coverage. Addresses both Privacy & Security Notices objectives for CUI rules.
Notices. Before first daily access to enclave apps, users accept an IdP Terms of Use stating CUI handling rules, monitoring, and no personal storage. Shared kiosks display a legal banner at logon covering the same points.
Consistency. Banner text is version-controlled with the CUI handling policy. Changes go through security review; acceptance is re-prompted when the version changes.
Maintenance. Annual review of notice text against contract and 32 CFR Part 2002 expectations used by the org. Spot-check that new enclave apps inherit the ToU grant.
Accepted gap. Mobile Intune App Protection cannot show the full desktop banner chrome. Users still hit the IdP ToU on first SSO; app-level privacy string is abbreviated.
What the evidence looks like
- IdP Terms of Use text and version history
- Screenshot of kiosk logon banner
- Change ticket for last notice revision
- Conditional Access / app assignment showing ToU required for enclave apps
Environment
Hybrid; enclave SaaS + a few shared shop-floor kiosks.Tools
Discussion(0)
No discussion on this control yet
Edge cases, scoping questions, and “would this pass?” scenarios belong here.
Sign in to start a thread.