NIST 800-171 Controls · Access Control
AC.2.009 — Provide Privacy and Security Notices
Provide privacy and security notices consistent with CUI rules.
What AC.2.009 means in plain English
When someone logs into your computer systems, they should see a short warning message that tells them the system is for authorized use only and that their activity may be monitored. You've probably seen a similar banner when logging into government websites — you need to do the same thing. It's a simple text box that pops up before login.
The assessment question
“Do your computer systems display a logon banner or warning message before login that informs users the system is for authorized use only and that activities are subject to monitoring?”
How to implement AC.2.009
- Set a Windows logon banner via Local Security Policy: open secpol.msc > Local Policies > Security Options. Set "Interactive logon: Message title for users attempting to log on" to "AUTHORIZED USE ONLY" and "Interactive logon: Message text..." to the standard notice below.
- Use this standard notice text (copy it exactly): "This system is the property of [Your Company Name]. It is for authorized use only. Users (authorized or unauthorized) have no explicit or implicit expectation of privacy. Any or all uses of this system and all files on this system may be intercepted, monitored, recorded, copied, audited, inspected, and disclosed to authorized site and law enforcement personnel. By using this system, the user consents to such monitoring. Unauthorized or improper use of this system may result in disciplinary action and civil and criminal penalties."
- For Microsoft 365, add a Terms of Use policy in Microsoft Entra ID: Azure Portal > Microsoft Entra ID > Security > Conditional Access > Terms of Use. Users will be required to accept it before accessing company resources.
- For any VPN or remote access portals, configure the pre-login banner in the VPN client or portal settings — check vendor documentation for the specific setting name.
- Take a screenshot of the banner on each system type and retain it as evidence.
Evidence your assessor will ask for
- Screenshot of Windows logon banner message as it appears to users
- Screenshot of Local Security Policy settings showing banner text configured
- Microsoft Entra Terms of Use policy screenshot (if using M365)
- VPN pre-login banner screenshot (if applicable)
- Written policy referencing the use of system-use notices
Does AI prompt monitoring help with this control? Honestly, no.
AC.2.009 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.
Full mapping: which 800-171 controls AI prompt monitoring evidences →
More Access Control controls
Score yourself against all 110 controls
The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.