Law / Frameworks / CIS Controls / 8
CIS Controls, 88.2
Turning on and gathering logs from the enterprise's systems. Our summary; Center for Internet Security's text is not ours to print.
We read each law below as bearing on this Safeguard. That does not mean the Safeguard, done well, meets the law: what each law asks is on its own page. Law library as of .
The kinds of duty that reach it: governance, retention.
- 59
- laws
- 54
- places
- 0
- with court rulings behind them
- 4
- not yet in force
- 1
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 1.1 Legal and regulatory requirements involving AI are understood, managed, and documented.
- NIST AI RMFGOVERN 1.4 The risk management process and its outcomes are established through transparent...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-07 Human-AI Configuration
- OWASP LLM Top 10LLM03:2026 Excessive Agency
- OWASP Agentic Top 10ASI09 Human-Agent Trust Exploitation
- MIT mitigations4.1 System Documentation
- MIT mitigations1.1 Board Structure & Oversight
- NIST Privacy FrameworkGV.PO-P1 Organizational privacy values and policies (e.g., conditions on data processing such...
- NIST Privacy FrameworkCT.DM-P8 Audit/log records are determined, documented, implemented, and reviewed in accordance...
- NIST CSF 2.0ID.AM-07 Inventories of data and corresponding metadata for designated data types are maintained
- NIST CSF 2.0PR.PS-04 Log records are generated and made available for continuous monitoring
- FINOS AIGFAIR-DET-004 AI System Observability
- FINOS AIGFAIR-DET-021 Agent Decision Audit and Explainability
A law in force is unmarked; the rest wear their state: not yet in force proposed
Sector security regimes
41 laws, 39 placesShow the other 31 laws
Security baseline statutes
16 laws, 16 placesShow the other 6 laws
| Law on Information Security, General Security Measures |
Through its governance duty. What it requires |
|
| Cybersecurity Law, General Security Requirements for the Public Administration and the Private Sector |
Through its governance duty. What it requires |
|
| Identity Theft Protection Act, destruction of personal information records |
Through its retention duty. What it requires |
|
| Proyecto de Ley 9906/2024-CR, Ley de Seguridad Digital o Ciberseguridad proposed |
Through its governance duty. What it requires |
|
| Document Safe Destruction Act, safe destruction of records containing personal information |
Through its retention duty. What it requires |
|
| Cybersecurity Law, Information System Classification and Protection Measures |
Through its governance duty. What it requires |
Product security requirements
2 laws, 2 places| Place | Law | How it reaches this Safeguard |
|---|---|---|
| Security Standards for Smart Devices |
Through its governance duty. What it requires |
|
| Cybersecurity Law, Network Product and Service Security Duties |
Through its governance duty. What it requires |
CIS Critical Security Controls® (CIS Controls®) v8.1 © Center for Internet Security, Inc. Safeguard numbers are used under a CIS Controls Supporter License; the one-line descriptions beside them are our own, not CIS text. Every Safeguard of the framework.
