Mapped to NIST 800-171 Requirement: 3.5.9
CMMC Assessment Objective: IA.L2-3.5.7[c]
What This Objective Means
This control verifies that users not only see the system use notice but are also required to acknowledge it before access is granted. This acknowledgment can be implicit (e.g., pressing “OK” to continue) or explicit (e.g., checkbox or click-to-accept message).
This control applies to:
• Operating system login screens
• VPN and remote access gateways
• Web portals or cloud login pages
• Application-specific logins with system access
Why It Matters
A system use banner with no acknowledgment:
• Can be bypassed or ignored
• May not satisfy legal or compliance requirements
• Reduces user awareness of acceptable use rules
• Limits your ability to enforce accountability
Acknowledgment ties user behavior to intent—and intent to responsibility.
How to Implement It
1. Configure Acknowledgment Requirements
• Require users to click “OK,” “Accept,” or press a key to continue past the notice
• If possible, require a checkbox (e.g., “I agree”) before login fields are revealed
2. Apply to All Access Points
• Local machines (e.g., via Windows GPO or Linux PAM)
• Remote desktops or VPNs
• Cloud-based apps and admin consoles
3. Make It Inescapable
• Prevent login attempts or credential entry until acknowledgment is made
4. Log Acknowledgment If Supported
• Some platforms allow event logging of user interactions with the login banner
• Capture timestamps if technically feasible
5. Train Users
• Include explanation of the login banner and why it must be accepted during onboarding
Evidence the Assessor Will Look For
• Screenshots showing acknowledgment options (e.g., OK button, checkbox)
• Configuration settings enforcing acknowledgment before login
• Logs or policies that reflect user acknowledgment
• Test results showing access is blocked until the notice is accepted
Common Gaps
• Banners are shown but don’t require acknowledgment
• Users can skip or bypass the notification
• Systems display banners inconsistently across platforms
• No documentation or evidence showing acknowledgment is required
How Cuick Trac Helps
Cuick Trac supports this control by:
• Displaying mandatory acknowledgment banners across local and remote systems
• Enforcing user interaction with login notices before access is allowed
• Blocking credential input until the notice is accepted
• Providing banner interaction logs where supported
• Ensuring consistent user experience across all system entry points
With Cuick Trac, acceptable use isn’t just posted—it’s acknowledged.
Final CTA
Compliance starts with consent.
Schedule a Cuick Trac demo to ensure every user sees—and accepts—your system use terms before logging in.