Law / Frameworks / CIS Controls / 8

CIS Controls, 88.2

Turning on and gathering logs from the enterprise's systems. Our summary; Center for Internet Security's text is not ours to print.

We read each law below as bearing on this Safeguard. That does not mean the Safeguard, done well, meets the law: what each law asks is on its own page. Law library as of .

The kinds of duty that reach it: governance, retention.

59
laws
54
places
0
with court rulings behind them
4
not yet in force
1
proposed, not law

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force proposed

  • Alabama
  • Albania
  • Andorra
  • Australia
  • Austria
  • Belgium
  • Bulgaria
  • Cameroon
  • China
  • Croatia
  • Cyprus
  • Czech Republic
  • Denmark
  • Estonia
  • Ethiopia
  • European Union
  • Finland
  • Florida
  • Gabon
  • Germany
  • Greece
  • Haiti
  • Hawaii
  • Hungary
  • Iceland
  • Italy
  • Kansas
  • Kiribati
  • Kuwait
  • Kyrgyzstan
  • Liechtenstein
  • Lithuania
  • Luxembourg
  • Malta
  • Marshall Islands
  • Michigan
  • Montenegro
  • Morocco
  • Mozambique
  • Netherlands
  • North Carolina
  • Peru
  • Portugal
  • Romania
  • Serbia
  • Sierra Leone
  • Slovakia
  • Slovenia
  • Spain
  • Sweden
  • Taiwan
  • Tonga
  • Vermont
  • Vietnam

Sector security regimes

41 laws, 39 places
PlaceLawHow it reaches this Safeguard
Albania Law No. 25/2024, On Cybersecurity

Through its governance duty. What it requires

Andorra Llei 22/2022, Cybersecurity Risk-Management Obligations

Through its governance duty. What it requires

Austria Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Cybersecurity Risk-Management Measures

Through its governance duty. What it requires

Belgium Loi du 26 avril 2024, Cybersecurity Risk-Management Measures and Governance

Through its governance duty. What it requires

Bulgaria Cybersecurity Act, Risk-Management Measures and Governance (Zakon za kibersigurnost, ZKS)

Through its governance duty. What it requires

Croatia Zakon o kibernetičkoj sigurnosti, Risk-Management Measures and Governance

Through its governance duty. What it requires

Cyprus Security of Networks and Information Systems Law, Cybersecurity Risk-Management Measures and Governance

Through its governance duty. What it requires

Czech Republic Cybersecurity Act (Zákon o kybernetické bezpečnosti), Risk-Management Security Measures

Through its governance duty. What it requires

Denmark NIS 2-loven, Cybersecurity Risk-Management Measures and Registration

Through its governance duty. What it requires

Estonia Küberturvalisuse seadus (KüTS), System Security Measures and Management-Body Duties

Through its governance duty. What it requires

Show the other 31 laws
Ethiopia Critical Infrastructure Cybersecurity Proclamation, Critical Infrastructure Owner Obligations from , in 9 months

Through its governance duty. What it requires

European Union NIS2 Directive, Cybersecurity Risk-Management Measures

Through its governance duty. What it requires

Finland Kyberturvallisuuslaki, Cybersecurity Risk-Management Measures and Governance

Through its governance duty. What it requires

Germany BSI-Gesetz (BSIG), Risk-Management Measures for Essential and Important Entities

Through its governance duty. What it requires

Greece Law 5160/2024, Cybersecurity Risk-Management Measures and Governance

Through its governance duty. What it requires

Haiti BRH Circulaire 126, Information Security Rules for Financial Institutions

Through its governance duty. What it requires

Hungary Cybersecurity Act, Risk-Management Measures

Through its governance duty. What it requires

Iceland Minimum Risk-Management and Preparedness Requirements for Critical Infrastructure

Through its governance duty. What it requires

Italy Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Risk-Management Measures

Through its governance duty. What it requires

Kiribati Cybersecurity Act 2026, Critical Infrastructure Operator Obligations from a date not yet set

Through its governance duty. What it requires

Liechtenstein Cyber-Sicherheitsgesetz (CSG), Risk-Management Measures for Essential and Important Entities

Through its governance duty. What it requires

Lithuania Kibernetinio saugumo įstatymas (Law on Cyber Security), Risk-Management Measures

Through its governance duty. What it requires

Luxembourg Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Risk-Management Measures for Essential and Important Entities

Through its governance duty. What it requires

Malta Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order, Risk-Management Measures for Essential and Important Entities

Through its governance duty. What it requires

Marshall Islands Cybersecurity Act 2025, Cybersecurity of Critical Information Infrastructure

Through its governance duty. What it requires

Montenegro Law on Information Security, Essential and Important Entities

Through its governance duty. What it requires

Morocco Loi n° 05-20 relative à la cybersécurité, Digital Service Provider and Platform Operator Security Duties

Through its retention duty. What it requires

Mozambique Cybersecurity Law, Sector-Specific Security Requirements for Critical Infrastructure, Essential Services and Digital Providers

Through its governance duty. What it requires

Netherlands Cyberbeveiligingswet, Cybersecurity Risk-Management Measures and Governance

Through its governance duty. What it requires

Portugal Regime Jurídico da Cibersegurança, Cybersecurity Risk-Management Measures and Governance

Through its governance duty. What it requires

Romania Ordonanța de urgență nr. 155/2024, Cybersecurity Risk-Management Measures

Through its governance duty. What it requires

Serbia Law on Information Security, ICT Systems of Special Importance and Security Measures

Through its governance duty. What it requires

Sierra Leone Cyber Security and Crime Act, 2021, Critical National Information Infrastructure

Through its governance duty. What it requires

Slovakia Zákon o kybernetickej bezpečnosti (Cybersecurity Act), Risk-Management Measures

Through its governance duty. What it requires

Slovenia Zakon o informacijski varnosti (ZInfV-1), Cybersecurity Risk-Management Measures and Governance from , in 2 months

Through its governance duty. What it requires

Spain Real Decreto-ley 12/2018, Security Obligations for Operators of Essential Services and Digital Service Providers

Through its governance duty. What it requires

Sweden Cybersäkerhetslag, Cybersecurity Risk-Management Measures

Through its governance duty. What it requires

Taiwan Bank and Financial Holding Company Internal Control Rules, Dedicated Information Security Unit

Through its governance duty. What it requires

Taiwan Cyber Security Management Act, Specific Non-Government Agency Cyber Security Management

Through its governance duty. What it requires

Taiwan Telecommunications Management Act, Cyber Security and Critical Infrastructure Protection Plans

Through its governance duty. What it requires

Tonga Cybersecurity Act 2025, Critical Infrastructure Operator Obligations from a date not yet set

Through its governance duty. What it requires

Security baseline statutes

16 laws, 16 places
PlaceLawHow it reaches this Safeguard
Alabama Data Breach Notification Act, reasonable security measures and disposal of records

Through its retention duty. What it requires

Cameroon Loi n°2010/012 du 21 décembre 2010 relative à la cybersécurité et à la cybercriminalité au Cameroun, articles 6, 7, 13-14, 24, 26-30, 32, 61(3) (mesures de sécurité et audit de sécurité obligatoire par l'ANTIC)

Through its governance duty. What it requires

China Data Security Law, Data Security Protection Obligations

Through its governance duty. What it requires

Florida Florida Information Protection Act, data security and disposal duty

Through its retention duty. What it requires

Gabon Sécurité des systèmes d'information (dispositions communes)

Through its governance duty. What it requires

Hawaii Destruction of Personal Information Records

Through its retention duty. What it requires

Kansas Kansas Consumer Protection Act, reasonable security and records-destruction duty for holders of personal information

Through its retention duty. What it requires

Kuwait Data Classification Policy

Through its governance, retention duties. What it requires

Kyrgyzstan Digital Code, digital resilience baseline security measures

Through its governance duty. What it requires

Michigan Identity Theft Protection Act, destruction of data no longer needed

Through its retention duty. What it requires

Show the other 6 laws
Montenegro Law on Information Security, General Security Measures

Through its governance duty. What it requires

Mozambique Cybersecurity Law, General Security Requirements for the Public Administration and the Private Sector

Through its governance duty. What it requires

North Carolina Identity Theft Protection Act, destruction of personal information records

Through its retention duty. What it requires

Peru Proyecto de Ley 9906/2024-CR, Ley de Seguridad Digital o Ciberseguridad proposed

Through its governance duty. What it requires

Vermont Document Safe Destruction Act, safe destruction of records containing personal information

Through its retention duty. What it requires

Vietnam Cybersecurity Law, Information System Classification and Protection Measures

Through its governance duty. What it requires

Product security requirements

2 laws, 2 places
PlaceLawHow it reaches this Safeguard
Australia Security Standards for Smart Devices

Through its governance duty. What it requires

China Cybersecurity Law, Network Product and Service Security Duties

Through its governance duty. What it requires

CIS Critical Security Controls® (CIS Controls®) v8.1 © Center for Internet Security, Inc. Safeguard numbers are used under a CIS Controls Supporter License; the one-line descriptions beside them are our own, not CIS text. Every Safeguard of the framework.