Law / Frameworks / CIS Controls / 3
CIS Controls, 33.5
Destroying data in a way that fits its sensitivity and storage type. Our summary; Center for Internet Security's text is not ours to print.
We read each law below as bearing on this Safeguard. That does not mean the Safeguard, done well, meets the law: what each law asks is on its own page. Law library as of .
The kinds of duty that reach it: retention.
- 9
- laws
- 9
- places
- 0
- with court rulings behind them
- 0
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI 600-1GAI-RISK-04 Data Privacy
- MIT mitigations3.2 Data Governance
- MIT mitigations4.1 System Documentation
- NIST Privacy FrameworkGV.PO-P1 Organizational privacy values and policies (e.g., conditions on data processing such...
- NIST Privacy FrameworkCT.PO-P2 Policies, processes, and procedures for enabling data review, transfer, sharing or...
- NIST CSF 2.0ID.AM-07 Inventories of data and corresponding metadata for designated data types are maintained
- NIST CSF 2.0ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles
- FINOS AIGFAIR-DET-004 AI System Observability
- FINOS AIGFAIR-DET-021 Agent Decision Audit and Explainability
Security baseline statutes
8 laws, 8 placesSector security regimes
1 law, 1 place| Place | Law | How it reaches this Safeguard |
|---|---|---|
| Loi n° 05-20 relative à la cybersécurité, Digital Service Provider and Platform Operator Security Duties |
Through its retention duty. What it requires |
CIS Critical Security Controls® (CIS Controls®) v8.1 © Center for Internet Security, Inc. Safeguard numbers are used under a CIS Controls Supporter License; the one-line descriptions beside them are our own, not CIS text. Every Safeguard of the framework.
