Law / Frameworks / CIS Controls / 3
CIS Controls, 33.11
Encryption of sensitive data where it is stored on servers and applications. Our summary; Center for Internet Security's text is not ours to print.
We read each law below as bearing on this Safeguard. That does not mean the Safeguard, done well, meets the law: what each law asks is on its own page. Law library as of .
The kinds of duty that reach it: security.
- 65
- laws
- 52
- places
- 0
- with court rulings behind them
- 7
- not yet in force
- 1
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFMEASURE 2.5 The AI system to be deployed is demonstrated to be valid and reliable. Limitations of...
- NIST AI RMFMEASURE 2.6 The AI system is evaluated regularly for safety risks – as identified in the MAP...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-09 Information Security
- OWASP LLM Top 10LLM01:2026 Prompt Injection
- OWASP LLM Top 10LLM02:2026 Sensitive Information Disclosure
- OWASP Agentic Top 10ASI01 Agent Goal Hijack
- OWASP Agentic Top 10ASI03 Identity and Privilege Abuse
- MIT mitigations2.1 Model & Infrastructure Security
- MIT mitigations2.3 Model Safety Engineering
- NIST Privacy FrameworkPR.PO-P7 Response plans (Incident Response and Business Continuity) and recovery plans...
- NIST Privacy FrameworkPR.PO-P10 A vulnerability management plan is developed and implemented.
- NIST CSF 2.0ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
- NIST CSF 2.0ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established
- FINOS AIGFAIR-PREV-007 Legal and Contractual Frameworks for AI Systems
- FINOS AIGFAIR-PREV-008 Quality of Service (QoS) and DDoS Prevention for AI Systems
A law in force is unmarked; the rest wear their state: not yet in force proposed
Security baseline statutes
33 laws, 31 placesShow the other 23 laws
Sector security regimes
16 laws, 16 placesShow the other 6 laws
| FSM Telecommunications Act of 2014, Security Safeguards for Customer Information |
Through its security duty. What it requires |
|
| Law on Information Security, ICT Systems of Special Importance and Security Measures |
Through its security duty. What it requires |
|
| Telecommunications Act 2009, Security Safeguards for Consumer Information |
Through its security duty. What it requires |
|
| Bank and Financial Holding Company Internal Control Rules, Dedicated Information Security Unit |
Through its security duty. What it requires |
|
| Cybersecurity Act 2025, Critical Infrastructure Operator Obligations from a date not yet set |
Through its security duty. What it requires |
|
| Law on Communications, network and subscriber-information protection duties |
Through its security duty. What it requires |
Product security requirements
8 laws, 8 placesVulnerability and incident reporting
8 laws, 8 placesCIS Critical Security Controls® (CIS Controls®) v8.1 © Center for Internet Security, Inc. Safeguard numbers are used under a CIS Controls Supporter License; the one-line descriptions beside them are our own, not CIS text. Every Safeguard of the framework.
