NIST 800-53 Rev 5, AC-8 requires the display of the following System Use Notification:
In proceeding and accessing U.S. Government information and information systems, you acknowledge that you fully understand and consent to all of the following: 1) You are accessing U.S. Government information and information systems that are provided for official U.S. Government purposes only; 2) Unauthorized access to or unauthorized use of U.S. Government information or information systems is subject to criminal, civil, administrative, or other lawful action; 3) The term U.S. Government information system includes systems operated on behalf of the U.S. Government; 4) You have no reasonable expectation of privacy regarding any communications or information used, transmitted, or stored on U.S. Government information systems; 5) At any time, the U.S. Government may for any lawful government purpose, without notice, monitor, intercept, search, and seize any authorized or unauthorized communication to or from U.S. Government information systems or information used or stored on U.S. Government information systems; 6) At any time, the U.S. Government may for any lawful government purpose, search and seize any authorized or unauthorized device, to include non-U.S. Government owned devices, that stores U.S. Government information; 7) Any communications or information used, transmitted, or stored on U.S. Government information systems may be used or disclosed for any lawful government purpose, including but not limited to, administrative purposes, penetration testing, communication security monitoring, personnel misconduct measures, law enforcement, and counterintelligence inquiries; and 8) You may not process or store classified national security information on this computer system._
This notification message or banner must be displayed on the screen until users acknowledge the usage conditions and take explicit actions to log on to or further access the system.
Implementation Notes:
Remove the dialog that appears below the "What's New" box. Only retain the "Log in" button that appears in the menu bar. When a user clicks the login button, display a dialog with the above text. The dialog should have a button for "Cancel" and "Continue". The "Cancel" button closes the dialog. The "Continue" button proceeds with the login flow.
Verified that dialog box appears when the Log In button is pressed on dev. Should the dialog box have a header? Per 6/7/2024 standup, header text not required
NIST 800-53 Rev 5, AC-8 requires the display of the following System Use Notification:
This notification message or banner must be displayed on the screen until users acknowledge the usage conditions and take explicit actions to log on to or further access the system.
Implementation Notes:
Remove the dialog that appears below the "What's New" box. Only retain the "Log in" button that appears in the menu bar. When a user clicks the login button, display a dialog with the above text. The dialog should have a button for "Cancel" and "Continue". The "Cancel" button closes the dialog. The "Continue" button proceeds with the login flow.