Law / Frameworks / CIS Controls / 3
CIS Controls, 33.2
A maintained catalogue of the sensitive data the enterprise holds and where it sits. Our summary; Center for Internet Security's text is not ours to print.
We read each law below as bearing on this Safeguard. That does not mean the Safeguard, done well, meets the law: what each law asks is on its own page. Law library as of .
The kinds of duty that reach it: governance.
- 51
- laws
- 46
- places
- 0
- with court rulings behind them
- 4
- not yet in force
- 1
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 1.1 Legal and regulatory requirements involving AI are understood, managed, and documented.
- NIST AI RMFGOVERN 1.4 The risk management process and its outcomes are established through transparent...
- NIST AI 600-1GAI-RISK-07 Human-AI Configuration
- OWASP LLM Top 10LLM03:2026 Excessive Agency
- OWASP Agentic Top 10ASI09 Human-Agent Trust Exploitation
- MIT mitigations1.1 Board Structure & Oversight
- MIT mitigations1.2 Risk Management
- NIST Privacy FrameworkID.IM-P4 Data actions of the systems/products/services are inventoried.
- NIST Privacy FrameworkGV.PO-P1 Organizational privacy values and policies (e.g., conditions on data processing such...
- NIST CSF 2.0GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including...
- NIST CSF 2.0GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and...
- FINOS AIGFAIR-PREV-005 System Acceptance Testing
- FINOS AIGFAIR-PREV-006 Data Quality & Classification/Sensitivity
A law in force is unmarked; the rest wear their state: not yet in force proposed
Sector security regimes
40 laws, 38 placesShow the other 30 laws
Security baseline statutes
9 laws, 9 placesProduct security requirements
2 laws, 2 places| Place | Law | How it reaches this Safeguard |
|---|---|---|
| Security Standards for Smart Devices |
Through its governance duty. What it requires |
|
| Cybersecurity Law, Network Product and Service Security Duties |
Through its governance duty. What it requires |
CIS Critical Security Controls® (CIS Controls®) v8.1 © Center for Internet Security, Inc. Safeguard numbers are used under a CIS Controls Supporter License; the one-line descriptions beside them are our own, not CIS text. Every Safeguard of the framework.
