Rules of Behavior describe security controls associated with user responsibilities and certain expectations of behavior for following security policies, standards, and procedures. Public Code of Conduct describes certain expectation of public appearance for the company employees.
Company employees who have access to the company Information System or Information must sign Rules of Behavior and Public Code of Conduct. Rules of Behavior and Public Code of Conduct may be signed on paper or electronically upon joining the Agency. Either way, the organization must retain artifacts to enable an independent assessor to verify that Rules of Behavior have been signed for all employees.