The IT Law Wiki


Control system[]

An access agreement

is an agreement[] for control system access [signed] before access is granted. This requirement applies to all parties, including third parties and contractors, who require access to the control system. The organization reviews and updates access agreements periodically.[1]
include[s] nondisclosure agreements, acceptable use agreements, rules of behavior, and conflict-of-interest agreements.[2]


"Signed access agreements include an acknowledgment that individuals have read, understand, and agree to abide by the constraints associated with the control system to which access is authorized. Electronic signatures are acceptable for acknowledging access agreements unless specifically prohibited by organizational policy or applicable government regulations."[3]