Law / Frameworks / NIST AI RMF
NIST AI Risk Management Framework
Below are its 72 controls in the framework's own order, and under each one the laws we track that bear on it. Each mapping is our reading that a law bears on a control, never a finding that running the control meets the law.
Where the law lands in the framework
37of 72 controls have law747laws257places
Of these laws, 653 are in force, 63 not yet in force, 2 blocked by a court, and 29 proposed and not law.
11 of the 22 controls under Measure have no law we track under them.
- in force
- not yet in force
- blocked by a court
- proposed
- no law we track
Each requirement line of the AI and scraping laws we track was read on its own and mapped to the control it bears on most closely, and to a second or third only where the line has more than one limb.
Govern
12 of 19 controls with law| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Blocked | Proposed |
|---|---|---|---|---|---|---|---|
| GOVERN 1Policies, processes, procedures, and practices across the organization related to the mapping, measuring, and managing of AI risks are in place, transparent, and implemented effectively. | |||||||
| GOVERN 1.1 | Legal and regulatory requirements involving AI are understood, managed, and documented. 30 laws, 8 not yet in force, 2 proposed | 30 | 22 | 8 | 0 | 2 | |
| GOVERN 1.2 | The characteristics of trustworthy AI are integrated into organizational policies, processes, procedures, and practices. 4 laws, 2 proposed | 4 | 4 | 0 | 0 | 2 | |
| GOVERN 1.3 | Processes, procedures, and practices are in place to determine the needed level of risk management activities based on the organization’s risk tolerance. no law we track | no law we track | |||||
| GOVERN 1.4 | The risk management process and its outcomes are established through transparent policies, procedures, and other controls based on organizational risk priorities. 10 laws, 3 not yet in force, 1 proposed | 10 | 10 | 3 | 0 | 1 | |
| GOVERN 1.5 | Ongoing monitoring and periodic review of the risk management process and its outcomes are planned and organizational roles and responsibilities clearly defined, including determining the frequency of periodic review. 2 laws | 2 | 2 | 0 | 0 | 0 | |
| GOVERN 1.6 | Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities. 1 law | 1 | 1 | 0 | 0 | 0 | |
| GOVERN 1.7 | Processes and procedures are in place for decommissioning and phasing out AI systems safely and in a manner that does not increase risks or decrease the organization’s trustworthiness. no law we track | no law we track | |||||
| GOVERN 2Accountability structures are in place so that the appropriate teams and individuals are empowered, responsible, and trained for mapping, measuring, and managing AI risks. | |||||||
| GOVERN 2.1 | Roles and responsibilities and lines of communication related to mapping, measuring, and managing AI risks are documented and are clear to individuals and teams throughout the organization. 2 laws, 1 not yet in force | 2 | 2 | 1 | 0 | 0 | |
| GOVERN 2.2 | The organization’s personnel and partners receive AI risk management training to enable them to perform their duties and responsibilities consistent with related policies, procedures, and agreements. 1 law | 1 | 1 | 0 | 0 | 0 | |
| GOVERN 2.3 | Executive leadership of the organization takes responsibility for decisions about risks associated with AI system development and deployment. no law we track | no law we track | |||||
| GOVERN 3Workforce diversity, equity, inclusion, and accessibility processes are prioritized in the mapping, measuring, and managing of AI risks throughout the lifecycle. | |||||||
| GOVERN 3.1 | Decision-making related to mapping, measuring, and managing AI risks throughout the lifecycle is informed by a diverse team (e.g., diversity of demographics, disciplines, experience, expertise, and backgrounds). no law we track | no law we track | |||||
| GOVERN 3.2 | Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems. 2 laws, 2 not yet in force | 2 | 1 | 2 | 0 | 0 | |
| GOVERN 4Organizational teams are committed to a culture that considers and communicates AI risk. | |||||||
| GOVERN 4.1 | Organizational policies and practices are in place to foster a critical thinking and safety-first mindset in the design, development, deployment, and uses of AI systems to minimize potential negative impacts. 3 laws, 2 not yet in force | 3 | 3 | 2 | 0 | 0 | |
| GOVERN 4.2 | Organizational teams document the risks and potential impacts of the AI technology they design, develop, deploy, evaluate, and use, and they communicate about the impacts more broadly. 13 laws, 5 not yet in force, 1 proposed | 13 | 11 | 5 | 0 | 1 | |
| GOVERN 4.3 | Organizational practices are in place to enable AI testing, identification of incidents, and information sharing. 3 laws, 2 not yet in force | 3 | 3 | 2 | 0 | 0 | |
| GOVERN 5Processes are in place for robust engagement with relevant AI actors. | |||||||
| GOVERN 5.1 | Organizational policies and practices are in place to collect, consider, prioritize, and integrate feedback from those external to the team that developed or deployed the AI system regarding the potential individual and societal impacts related to AI risks. no law we track | no law we track | |||||
| GOVERN 5.2 | Mechanisms are established to enable the team that developed or deployed AI systems to regularly incorporate adjudicated feedback from relevant AI actors into system design and implementation. no law we track | no law we track | |||||
| GOVERN 6Policies and procedures are in place to address AI risks and benefits arising from third-party software and data and other supply chain issues. | |||||||
| GOVERN 6.1 | Policies and procedures are in place that address AI risks associated with third-party entities, including risks of infringement of a third-party’s intellectual property or other rights. 4 laws, 3 not yet in force | 4 | 3 | 3 | 0 | 0 | |
| GOVERN 6.2 | Contingency processes are in place to handle failures or incidents in third-party data or AI systems deemed to be high-risk. no law we track | no law we track | |||||
Map
9 of 18 controls with law| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Blocked | Proposed |
|---|---|---|---|---|---|---|---|
| MAP 1Context is established and understood. | |||||||
| MAP 1.1 | Intended purposes, potentially beneficial uses, context-specific laws, norms and expectations, and prospective settings in which the AI system will be deployed are understood and documented. Considerations include: the specific set or types of users along with their expectations; potential positive and negative impacts of system uses to individuals, communities, organizations, society, and the planet; assumptions and related limitations about AI system purposes, uses, and risks across the development or product AI lifecycle; and related TEVV and system metrics. 2 laws, 1 not yet in force | 2 | 2 | 1 | 0 | 0 | |
| MAP 1.2 | Interdisciplinary AI actors, competencies, skills, and capacities for establishing context reflect demographic diversity and broad domain and user experience expertise, and their participation is documented. Opportunities for interdisciplinary collaboration are prioritized. no law we track | no law we track | |||||
| MAP 1.3 | The organization’s mission and relevant goals for AI technology are understood and documented. no law we track | no law we track | |||||
| MAP 1.4 | The business value or context of business use has been clearly defined or – in the case of assessing existing AI systems – re-evaluated. no law we track | no law we track | |||||
| MAP 1.5 | Organizational risk tolerances are determined and documented. no law we track | no law we track | |||||
| MAP 1.6 | System requirements (e.g., “the system shall respect the privacy of its users”) are elicited from and understood by relevant AI actors. Design decisions take socio-technical implications into account to address AI risks. 29 laws, 11 not yet in force, 1 proposed | 29 | 24 | 11 | 0 | 1 | |
| MAP 2Categorization of the AI system is performed. | |||||||
| MAP 2.1 | The specific tasks and methods used to implement the tasks that the AI system will support are defined (e.g., classifiers, generative models, recommenders). no law we track | no law we track | |||||
| MAP 2.2 | Information about the AI system’s knowledge limits and how system output may be utilized and overseen by humans is documented. Documentation provides sufficient information to assist relevant AI actors when making decisions and taking subsequent actions. 5 laws, 4 not yet in force | 5 | 5 | 4 | 0 | 0 | |
| MAP 2.3 | Scientific integrity and TEVV considerations are identified and documented, including those related to experimental design, data collection and selection (e.g., availability, representativeness, suitability), system trustworthiness, and construct validation. 9 laws, 3 not yet in force, 1 proposed | 9 | 6 | 3 | 0 | 1 | |
| MAP 3AI capabilities, targeted usage, goals, and expected benefits and costs compared with appropriate benchmarks are understood. | |||||||
| MAP 3.1 | Potential benefits of intended AI system functionality and performance are examined and documented. no law we track | no law we track | |||||
| MAP 3.2 | Potential costs, including non-monetary costs, which result from expected or realized AI errors or system functionality and trustworthiness – as connected to organizational risk tolerance – are examined and documented. no law we track | no law we track | |||||
| MAP 3.3 | Targeted application scope is specified and documented based on the system’s capability, established context, and AI system categorization. 202 laws, 15 not yet in force, 2 blocked, 9 proposed | 202 | 119 | 15 | 2 | 9 | |
| MAP 3.4 | Processes for operator and practitioner proficiency with AI system performance and trustworthiness – and relevant technical standards and certifications – are defined, assessed, and documented. 1 law, 1 not yet in force | 1 | 1 | 1 | 0 | 0 | |
| MAP 3.5 | Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the GOVERN function. 22 laws, 8 not yet in force, 1 proposed | 22 | 21 | 8 | 0 | 1 | |
| MAP 4Risks and benefits are mapped for all components of the AI system including third-party software and data. | |||||||
| MAP 4.1 | Approaches for mapping AI technology and legal risks of its components – including the use of third-party data or software – are in place, followed, and documented, as are risks of infringement of a third party’s intellectual property or other rights. 381 laws, 10 not yet in force | 381 | 224 | 10 | 0 | 0 | |
| MAP 4.2 | Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. no law we track | no law we track | |||||
| MAP 5Impacts to individuals, groups, communities, organizations, and society are characterized. | |||||||
| MAP 5.1 | Likelihood and magnitude of each identified impact (both potentially beneficial and harmful) based on expected use, past uses of AI systems in similar contexts, public incident reports, feedback from those external to the team that developed or deployed the AI system, or other data are identified and documented. 11 laws, 2 not yet in force, 5 proposed | 11 | 9 | 2 | 0 | 5 | |
| MAP 5.2 | Practices and personnel for supporting regular engagement with relevant AI actors and integrating feedback about positive, negative, and unanticipated impacts are in place and documented. no law we track | no law we track | |||||
Measure
11 of 22 controls with law| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Blocked | Proposed |
|---|---|---|---|---|---|---|---|
| MEASURE 1Appropriate methods and metrics are identified and applied. | |||||||
| MEASURE 1.1 | Approaches and metrics for measurement of AI risks enumerated during the MAP function are selected for implementation starting with the most significant AI risks. The risks or trustworthiness characteristics that will not – or cannot – be measured are properly documented. no law we track | no law we track | |||||
| MEASURE 1.2 | Appropriateness of AI metrics and effectiveness of existing controls are regularly assessed and updated, including reports of errors and potential impacts on affected communities. no law we track | no law we track | |||||
| MEASURE 1.3 | Internal experts who did not serve as front-line developers for the system and/or independent assessors are involved in regular assessments and updates. Domain experts, users, AI actors external to the team that developed or deployed the AI system, and affected communities are consulted in support of assessments as necessary per organizational risk tolerance. 2 laws, 1 not yet in force | 2 | 2 | 1 | 0 | 0 | |
| MEASURE 2AI systems are evaluated for trustworthy characteristics. | |||||||
| MEASURE 2.1 | Test sets, metrics, and details about the tools used during TEVV are documented. no law we track | no law we track | |||||
| MEASURE 2.2 | Evaluations involving human subjects meet applicable requirements (including human subject protection) and are representative of the relevant population. no law we track | no law we track | |||||
| MEASURE 2.3 | AI system performance or assurance criteria are measured qualitatively or quantitatively and demonstrated for conditions similar to deployment setting(s). Measures are documented. 2 laws, 2 not yet in force | 2 | 1 | 2 | 0 | 0 | |
| MEASURE 2.4 | The functionality and behavior of the AI system and its components – as identified in the MAP function – are monitored when in production. 9 laws, 5 not yet in force, 1 proposed | 9 | 5 | 5 | 0 | 1 | |
| MEASURE 2.5 | The AI system to be deployed is demonstrated to be valid and reliable. Limitations of the generalizability beyond the conditions under which the technology was developed are documented. 2 laws, 2 not yet in force | 2 | 2 | 2 | 0 | 0 | |
| MEASURE 2.6 | The AI system is evaluated regularly for safety risks – as identified in the MAP function. The AI system to be deployed is demonstrated to be safe, its residual negative risk does not exceed the risk tolerance, and it can fail safely, particularly if made to operate beyond its knowledge limits. Safety metrics reflect system reliability and robustness, real-time monitoring, and response times for AI system failures. 18 laws, 10 not yet in force, 1 proposed | 18 | 18 | 10 | 0 | 1 | |
| MEASURE 2.7 | AI system security and resilience – as identified in the MAP function – are evaluated and documented. 3 laws, 2 not yet in force | 3 | 2 | 2 | 0 | 0 | |
| MEASURE 2.8 | Risks associated with transparency and accountability – as identified in the MAP function – are examined and documented. 113 laws, 24 not yet in force, 1 blocked, 18 proposed | 113 | 68 | 24 | 1 | 18 | |
| MEASURE 2.9 | The AI model is explained, validated, and documented, and AI system output is interpreted within its context – as identified in the MAP function – to inform responsible use and governance. 10 laws, 1 not yet in force | 10 | 9 | 1 | 0 | 0 | |
| MEASURE 2.10 | Privacy risk of the AI system – as identified in the MAP function – is examined and documented. 15 laws, 2 not yet in force | 15 | 15 | 2 | 0 | 0 | |
| MEASURE 2.11 | Fairness and bias – as identified in the MAP function – are evaluated and results are documented. 13 laws, 3 not yet in force, 1 proposed | 13 | 10 | 3 | 0 | 1 | |
| MEASURE 2.12 | Environmental impact and sustainability of AI model training and management activities – as identified in the MAP function – are assessed and documented. no law we track | no law we track | |||||
| MEASURE 2.13 | Effectiveness of the employed TEVV metrics and processes in the MEASURE function are evaluated and documented. no law we track | no law we track | |||||
| MEASURE 3Mechanisms for tracking identified AI risks over time are in place. | |||||||
| MEASURE 3.1 | Approaches, personnel, and documentation are in place to regularly identify and track existing, unanticipated, and emergent AI risks based on factors such as intended and actual performance in deployed contexts. no law we track | no law we track | |||||
| MEASURE 3.2 | Risk tracking approaches are considered for settings where AI risks are difficult to assess using currently available measurement techniques or where metrics are not yet available. no law we track | no law we track | |||||
| MEASURE 3.3 | Feedback processes for end users and impacted communities to report problems and appeal system outcomes are established and integrated into AI system evaluation metrics. 17 laws, 2 not yet in force, 5 proposed | 17 | 15 | 2 | 0 | 5 | |
| MEASURE 4Feedback about efficacy of measurement is gathered and assessed. | |||||||
| MEASURE 4.1 | Measurement approaches for identifying AI risks are connected to deployment context(s) and informed through consultation with domain experts and other end users. Approaches are documented. no law we track | no law we track | |||||
| MEASURE 4.2 | Measurement results regarding AI system trustworthiness in deployment context(s) and across the AI lifecycle are informed by input from domain experts and relevant AI actors to validate whether the system is performing consistently as intended. Results are documented. no law we track | no law we track | |||||
| MEASURE 4.3 | Measurable performance improvements or declines based on consultations with relevant AI actors, including affected communities, and field data about context-relevant risks and trustworthiness characteristics are identified and documented. no law we track | no law we track | |||||
Manage
5 of 13 controls with law| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Blocked | Proposed |
|---|---|---|---|---|---|---|---|
| MANAGE 1AI risks based on assessments and other analytical output from the MAP and MEASURE functions are prioritized, responded to, and managed. | |||||||
| MANAGE 1.1 | A determination is made as to whether the AI system achieves its intended purposes and stated objectives and whether its development or deployment should proceed. no law we track | no law we track | |||||
| MANAGE 1.2 | Treatment of documented AI risks is prioritized based on impact, likelihood, and available resources or methods. no law we track | no law we track | |||||
| MANAGE 1.3 | Responses to the AI risks deemed high priority, as identified by the MAP function, are developed, planned, and documented. Risk response options can include mitigating, transferring, avoiding, or accepting. 8 laws, 1 not yet in force, 3 proposed | 8 | 5 | 1 | 0 | 3 | |
| MANAGE 1.4 | Negative residual risks (defined as the sum of all unmitigated risks) to both downstream acquirers of AI systems and end users are documented. no law we track | no law we track | |||||
| MANAGE 2Strategies to maximize AI benefits and minimize negative impacts are planned, prepared, implemented, documented, and informed by input from relevant AI actors. | |||||||
| MANAGE 2.1 | Resources required to manage AI risks are taken into account – along with viable non-AI alternative systems, approaches, or methods – to reduce the magnitude or likelihood of potential impacts. no law we track | no law we track | |||||
| MANAGE 2.2 | Mechanisms are in place and applied to sustain the value of deployed AI systems. no law we track | no law we track | |||||
| MANAGE 2.3 | Procedures are followed to respond to and recover from a previously unknown risk when it is identified. no law we track | no law we track | |||||
| MANAGE 2.4 | Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use. 4 laws, 3 not yet in force | 4 | 2 | 3 | 0 | 0 | |
| MANAGE 3AI risks and benefits from third-party entities are managed. | |||||||
| MANAGE 3.1 | AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented. 2 laws, 1 not yet in force | 2 | 2 | 1 | 0 | 0 | |
| MANAGE 3.2 | Pre-trained models which are used for development are monitored as part of AI system regular monitoring and maintenance. no law we track | no law we track | |||||
| MANAGE 4Risk treatments, including response and recovery, and communication plans for the identified and measured AI risks are documented and monitored regularly. | |||||||
| MANAGE 4.1 | Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management. 17 laws, 3 not yet in force, 1 proposed | 17 | 14 | 3 | 0 | 1 | |
| MANAGE 4.2 | Measurable activities for continual improvements are integrated into AI system updates and include regular engagement with interested parties, including relevant AI actors. no law we track | no law we track | |||||
| MANAGE 4.3 | Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented. 10 laws, 2 not yet in force | 10 | 7 | 2 | 0 | 0 | |
AI duties with no home in the NIST AI RMF
24 lines in 12 lawsEach line below was read against the AI RMF and recorded as having no control to sit under.
AI governance 6
| Place | Law | The duty, as read |
|---|---|---|
| AI Auditor Registry Act (AB 1405) from , in 2.3 years | If you offer, sell, or conduct a covered AI audit, an audit assessing internal controls, processes, or systems implemented for an AI system or model that are necessary for compliance with California law, register with the Government Operations Agency before doing so, starting . If you register as an AI auditor, give the agency your business name, contact information, the California laws or regulations you audit under, relevant certifications, a description of your services, and a standard operating procedure describing the standards you apply and the basis for your accuracy and reliability claims. +5 more |
|
| Independent Verification Organizations Act (SB 813) from , in 3 months | If you want to be designated as an IVO, apply once the Government Operations Agency publishes its application requirements and designation criteria, due by . If you are a designated IVO, submit an annual report on your standards, methodologies, governance changes, and conflicts of interest to the agency and the Legislature, starting no sooner than 12 months after your designation. |
|
| AI Act, Article 19 (automatically generated logs) from , in 14 months | Retain the logs for a period appropriate to the system's intended purpose, at least six months, longer where other Union or national law, such as data-protection law, requires it. If you are a financial institution, keep the logs as part of the documentation your sector's internal-governance rules already require. |
|
| AI Act, Article 26(6) (deployer log-keeping) from , in 14 months | Retain the logs for a period appropriate to the system's intended purpose, at least six months, longer where other Union or national law, such as data-protection law, requires it. If you are a financial institution, keep the logs as part of the documentation your sector's internal-governance rules already require. |
|
| Electronic Information and Transactions Law, electronic agent liability | A qualifying Electronic Agent operator must let a user correct information they submitted while a transaction is still in process. |
|
| Regulation of Artificial Intelligence Act 2026 | Do not knowingly give false or misleading information to an adjudicator, or disclose confidential material relevant to an adjudicator's finding without authorisation (ss. 95, 104). |
AI transparency 3
| Place | Law | The duty, as read |
|---|---|---|
| Provisions on the Administration of Deep Synthesis Internet Information Services, Articles 16 and 17 | Retain the log information the Provisions require |
|
| Subscription-Based AI Provider Disclosure Duty from , in 2 days | Before entering into or renewing a consumer subscription for an AI technology, or collecting a fee for one, give the consumer written notice of the key terms and conditions and obtain the consumer's written acceptance. In the initial-subscription notice, disclose any quantitative or qualitative limitations you may impose, including limitations you may impose in response to the consumer's own conduct. +2 more |
|
| Act 250 (HB 178), attorney duty to verify and disclose AI-generated evidence | As an attorney appearing in a Louisiana court, exercise reasonable diligence to verify the authenticity of evidence, including evidence that may be artificially generated or altered, before offering it to the court. |
AI prohibited practices 1
| Place | Law | The duty, as read |
|---|---|---|
| Identity Protection Modifications, AI Defamation and Identity Replication (SB 256, 2026 General Session) | Give a person written notice before filing a defamation action over digitally created content; if you are the publisher and remove the content within 10 days of that notice, the plaintiff's recovery is limited to actual damages |
AI risk obligations 1
| Place | Law | The duty, as read |
|---|---|---|
| AI Framework Act, Article 34 (business-operator duties for high-impact AI) | Keep that documentation, and the basis for it, for five years, including in electronic form. |
AI sector rules 1
| Place | Law | The duty, as read |
|---|---|---|
| Health Insurance Preauthorization AI Disclosure (SB 319, 2026 General Session) from , in 3 months | Set an authorization validity period of at least 12 months for a drug, device, or covered service treating a chronic or long-term care condition, and at least six months for an outpatient covered service |
Scraping duties no NIST framework has a home for
141 lines in 106 lawsThe AI RMF's third-party data controls, MAP 4.1 and GOVERN 6.1, are the only NIST home for a duty not to collect without authorisation. Each line below fits neither, and was recorded as having no control.
Computer misuse 89
| Place | Law | The duty, as read |
|---|---|---|
| Penal Code, Part Twelve, Chapter One (Cyber Crimes and Punishment) | Do not alter, damage, destroy, disrupt, or otherwise interfere with a computer system, program, or data without authorization, including by installing a virus, hijacking a network connection, or forging or deceptively accessing a computer system. Do not disclose a password, access code, or other means of access to a program, computer system, or data without authorization. +1 more |
|
| Criminal use of a computer | Do not introduce false information into, or tamper with, disrupt, or disable, a computer, computer system, program, or network you access without a right to do so. |
|
| Criminal Code, Interference in the Computer Transmissions | Do not interfere, in any way, with computer transmissions or programs; the offence is a penal contravention whether or not the interference causes serious consequences. |
|
| Code pénal, atteintes aux systèmes de traitement automatisé de données | Do not introduce, delete, or modify data held in a system without authorization. |
|
| Penal Code, Attacks on Information Systems | Do not obstruct or interrupt a network or information system, or delete, damage, alter, or make inaccessible data within one, without authorization. |
|
| Computer tampering (Arizona's computer-misuse statute) | Do not design a crawler or bot to prevent a user from exiting a site or a connected location in order to compel the user's device to keep communicating with or displaying your service. |
|
| Unauthorized release of proprietary or confidential computer security information | Do not communicate, release, or publish proprietary or confidential security information, security-related measures, algorithms, or encryption devices specific to a particular computer, system, or network without that system's owner's or operator's authorization. |
|
| Unlawful possession of an access device | Do not knowingly possess, traffic in, publish, or control another person's access device, a credential or similar means of reaching an account or system, without the consent of its issuer, owner, or authorized user and with intent to use or distribute it; this can reach obtaining or trading in login credentials used to collect data from behind a login wall. |
|
| Unlawful interference with access to computers; unlawful use or access of computers | Do not knowingly and without authorization interfere with, deny, or cause the denial of access to a computer, system, or network to a person who has the duty and right to use it. |
|
| StGB Sections 118a and 126a to 126c, Computer-Misuse Offenses | Do not alter, delete, suppress, or render unusable data over which you lack sole authority, in a way that damages another, per StGB Section 126a. Do not seriously disrupt a computer system's functioning by entering or transmitting data, per StGB Section 126b. +1 more |
Show the other 79 laws
| Criminal Code, unauthorised access, illegal interception, and system interference | Do not intentionally damage, delete, corrupt, modify, or block computer data, or seriously obstruct a computer system's operation, in a way that causes significant damage. |
|
| Criminal Code, Crimes Against Computer Security | Do not develop, use, distribute, or sell a program or device known to be intended for defeating a protection system or for unauthorized access to, or destruction, blocking, or modification of, computer information. |
|
| Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre VI (cybercriminalité), atteintes aux réseaux et systèmes d'information | Do not cause an interruption of a computer system's normal operation, or damage, delete, deteriorate, alter, or suppress computer data, without right. Do not produce, sell, obtain, import, or distribute a device, program, password, or access code designed to commit any of the above offenses. +1 more |
|
| Computer Misuse Act 1996, unauthorised access and modification offences | Do not modify computer material, or cause a computer to cease to function, without authorisation. |
|
| Information, Communications and Media Act of Bhutan 2018, unauthorized access and tampering with computer systems | Do not cause a stoppage or denial of service, delete or alter data, diminish a system's value or utility, or introduce a computer contaminant, with intent to cause or knowing it is likely to cause wrongful loss, gain, or damage; this is punishable as tampering with computer material under the Penal Code of Bhutan. |
|
| Código Penal, Manipulación Informática | Do not manipulate a computer data-processing or data-transfer operation to produce an incorrect result, or to avoid a process that would otherwise have produced a correct one, in order to obtain an undue benefit at a third party's expense. |
|
| Cybercrime and Computer Related Crimes Act, 2018 (Act No. 18 of 2018) | Do not damage, delete, alter, or interfere with computer data, or hinder or interfere with the functioning of a computer or computer system, without lawful excuse. Do not manufacture, sell, distribute, or possess a device, password, or access code designed or adapted to commit an offence under the Act. +1 more |
|
| Loi n°025-2018/AN du 31 mai 2018 portant Code pénal, computer and data systems offenses (Livre VII, Titre I, Chapitre 1) | Do not hinder or falsify the operation of a computer system, or introduce, damage, delete, alter, or suppress computer data without right. Do not produce, sell, obtain, import, or distribute a device, program, password, or access code intended to commit any of the above offenses, unless it is for authorized testing or protecting a computer system. +1 more |
|
| Criminal Code, unauthorized use of a computer | Do not use, possess, traffic in, or permit another person to have access to a computer password to commit either of the above. |
|
| Criminal Law, Arts. 285-286 (unauthorized computer intrusion and system destruction) | Do not damage or destroy a computer information system's function, data, or programs (Art. 286). |
|
| Kazneni zakon, Computer Crime Chapter (Arts. 266-273) | Do not make, acquire, sell, possess, distribute or make available a device, computer program or computer data created or adapted to commit any of these offences; doing so is itself a criminal offence carrying up to three years' imprisonment, or up to two years for passwords, access codes or similar data. |
|
| Attacks against Information Systems Law, Articles 3, 4, 7, 11-12 (Illegal Access, System Interference, Tools, Corporate Liability) | Do not intentionally and without right seriously hinder or interrupt an information system's operation, including by inputting, transmitting, damaging, deleting, deteriorating, altering or suppressing its data or by blocking access to it. Do not, intentionally and without right, produce, sell, procure for use, import, distribute or otherwise make available a computer program designed or adapted primarily to commit an offence under articles 3 to 6, or a password, access code or similar data giving access to an information system, intending it to be used to commit such an offence. |
|
| Digital Code, Book VI: Fraudulent Access to Information Systems | Do not introduce, or attempt to introduce, data into an information system without authorization. |
|
| Ley No. 53-07 sobre Crímenes y Delitos de Alta Tecnología, Acceso Ilícito | Do not divulge, generate, copy, capture, use, alter, traffic in, or decode an access code or similar mechanism used to achieve illicit access to such a system, and do not falsify an access device. |
|
| COIP, ataque a la integridad de sistemas informáticos | Do not destroy, damage, delete, deteriorate, alter, suspend, obstruct, or suppress computer data or an information system's logical components, and do not design, acquire, or distribute malicious software meant to do so. |
|
| Law No. 175 of 2018 on Anti-Cyber and Information Technology Crimes | Do not disrupt, slow, damage, or alter the design of a website, email account, or information system without authorization. |
|
| Karistusseadustik (Penal Code) Sections 206 and 207, Interference with Computer Data and Hindering of Functioning of Computer Systems | Do not alter, delete, damage or block data in a computer system, and do not interfere with or hinder the functioning of a computer system, including by an automated crawler's request volume or behavior. |
|
| Code pénal STAD Offenses, Unauthorized Access to and Interference with Automated Data Processing Systems | Do not impair, falsify, corrupt, or delete data on a French computer system in the course of an automated crawl, which Articles 323-2 and 323-3 punish separately from unauthorized access itself, with a higher penalty where the system is a State personal-data system. |
|
| Information and Communications Act, 2009, Computer Misuse and Cyber Crime part | Do not modify data held in a computer system, or degrade, interrupt, or deny access to a computer system, without lawful authority or excuse. Do not manufacture, sell, import, distribute, or possess a device or data designed or adapted primarily to commit an offence under this Part. +1 more |
|
| Ausspaehen, Abfangen und Manipulation von Daten (Computer Misuse and Data Interference) | Do not produce, obtain, sell, or distribute passwords, security codes, or software designed to commit these offences. Do not unlawfully delete, suppress, render unusable, or alter data. +1 more |
|
| Electronic Transactions Act, Cyber Offences | Do not disclose a password or access code, or modify a programme or electronic record, without authority. |
|
| Código Penal, Decreto 17-73, Arts. 274 'A' a 274 'G' (Delitos Informáticos) | Do not destroy, erase, or render useless another's computer records or the programs a computer uses, and do not distribute destructive programs capable of damaging computerized records, programs, or equipment. |
|
| Hawaii Computer Crime Law, Part IX (unauthorized computer access, computer fraud, computer damage) | Knowingly accessing a computer with intent to commit theft is computer fraud, graded by the degree of theft intended, up to a class A felony. Knowingly or intentionally causing unauthorized damage to a computer, computer system, or computer network is computer damage, graded up to a class A felony where the computer manages or controls critical infrastructure. |
|
| Código Penal, seguridad de las redes y de los sistemas informáticos | Do not introduce, delete, alter or suppress computer data, or disable a computer system's operation, without authorization. |
|
| Büntető Törvénykönyv (Criminal Code), Sections 423-424, Violation of Information Systems or Data | Do not hinder an information system's operation, or modify, delete, or render inaccessible data stored in it, without authorization; Btk. Section 423(2) makes this a felony independent of Section 423(1)'s access offense. |
|
| Criminal Justice (Offences Relating to Information Systems) Act 2017 | Do not intentionally hinder or interrupt an information system, or delete, damage, alter, suppress or intercept data on it, without lawful authority (ss. 3-5). Do not produce, distribute or make available a computer programme, password, code or similar data designed for committing any of the section 2 to 5 offences (s. 6). |
|
| Codice Penale Art. 615-quater, Illicit Possession or Distribution of Access Devices | Do not obtain, hold, produce, reproduce, distribute, or supply codes, passwords, devices, or other means suited to accessing a computer or telematic system protected by security measures, or instructions enabling that access, without authorization. |
|
| Unlawful acts concerning computers (Kansas's computer-crime statute) | Do not knowingly and without authorization disclose a password, code, or other means of access to a computer, computer network, social networking website, or another person's personal electronic content. |
|
| Penal Code, disruption of an informatization object | Do not carry out intentional acts or omissions directed at disrupting the operation of an informatization object, such as a server or online service. |
|
| Krimināllikums Sections 241, 243, 244, Automated Data Processing System Offences | Do not modify, damage, destroy, impair, or conceal information in an automated data processing system without authorization, or knowingly enter false information into it, per Section 243. Do not manufacture, adapt, distribute, acquire, transport, or store a tool, device, software, password, or access code intended to influence such a system's resources, or to gain unauthorized access to it for committing a crime, per Section 244. |
|
| Law No. 81/2018 on Electronic Transactions and Personal Data, Illegal Access to an Information System and Related IT-System Offences | Do not fraudulently damage or hinder the operation of an information system, or fraudulently enter, delete, or modify digital data hosted by one. Do not intentionally hinder, disturb, or disrupt access to a service, hardware, software, or data source through the information network. |
|
| Penal Code Act, 2010, Misuse of Property of Another | Do not interfere with a computer or electronic storage device owned by another, or the data or programmes on it, without the owner's consent, if you intend to secure an advantage for yourself or cause damage. |
|
| Strafgesetzbuch Arts. 126a to 126c, Data Damage, System Interference and Misuse of Devices | Do not change, delete, or otherwise make unusable or suppress data processed, transmitted, or supplied by automation that is not at your sole disposal, in a way that causes damage to another person. Do not seriously interfere with the functioning of a computer system that you may not use, or may not use alone, by entering or transmitting data. +1 more |
|
| Aggravated criminal invasion of computer privacy | Do not intentionally or knowingly damage a computer resource, or introduce or allow the introduction of a computer virus into one, without a reasonable ground to believe you have the right to do so. |
|
| Criminal Code Article 337D, Misuse of Hardware | Do not modify, damage, destroy, or impair the operation of computer equipment, a computer, a computer system, or a computer network without authorisation while crawling or otherwise interacting with it in Malta, under Article 337D of the Criminal Code. |
|
| Obtaining computer services by fraud or misrepresentation; penalties | Do not obtain, or attempt to obtain, a subscription-based or otherwise paid commercial computer service by false representation, false statement, unauthorized account charging, equipment tampering, or any other fraudulent means. |
|
| Tampering with computer data, computer equipment, and computer users | Do not deny computer system services to an authorized user. |
|
| Code Pénal Arts. 389-1 to 389-9, Unauthorized Access, System Interference and Data Damage | Do not produce, hold, or supply a tool, device, password or access code principally designed to commit these offences, other than for authorized testing, research, or protecting an information system. |
|
| Electronic Transactions Law, Computer Misuse Contraventions | Do not damage, delete, deteriorate, alter, or suppress data belonging to a computer system without authorisation. Do not intentionally affect the functioning of a computer system or network by introducing, transmitting, damaging, deleting, deteriorating, altering, or suppressing data. |
|
| Computer Crimes Act, unauthorized computer use | Do not alter, damage, disrupt or destroy computer property or a computer service, or introduce data known to be false with intent to harm another's property or financial interests. |
|
| Copyright Act 1994, Technological Protection Measures | Do not make, import, sell, distribute, or advertise a device, or provide a service or publish information, intended to circumvent a technological protection measure if you know or have reason to believe it will be used to infringe copyright in the protected work. |
|
| Ley No. 1042, interference with and damage to computer systems, as reformed by Ley No. 1219 | Do not interfere with, alter, damage, or disable a computer system or the data it holds. |
|
| Loi n° 2019-33, accès illégal et maintien frauduleux | Do not cause the suppression, modification or alteration of data, or a malfunction of the system, when accessing or remaining present in it without right. |
|
| Criminal Code, Computer and Information Offences | Do not destroy important information stored on a computer or other information-processing device, or input or spread false information through a computer network in a way that causes confusion in information processing. |
|
| Criminal Code, Damage and Unauthorized Entry into a Computer System | Do not delete, alter, damage or conceal computer data, a program, or a computer system without authorization, or otherwise disable or hinder the use of a computer system, data, program or computer communication. |
|
| Prevention of Electronic Crimes Act 2016, unauthorized access and interference offences | Do not interfere with, damage, or disrupt an information system or data in Pakistan without authorization, which section 5 of the Act separately punishes. |
|
| Código Penal, arts. 146 b y 174 b, introducidos por la Ley N° 4439/2011, acceso indebido a datos y a sistemas informáticos | Do not obstruct a data-processing operation by destroying, disabling, removing or altering the infrastructure that carries it out. |
|
| Ley 30096, unauthorized access and data/system integrity offenses | Do not damage, introduce, delete, deteriorate, alter, suppress, or make inaccessible another party's computer data. Do not disable a computer system, impede access to it, or hinder or prevent its operation or the provision of its services. +1 more |
|
| Kodeks karny, Unauthorized Access to Information and Computer-Misuse Offenses | Do not produce, obtain, sell, or supply a device, computer program, password, or access code adapted to commit an Art. 267, 268a, 269, or 269a offense; doing so is a separate offense under Art. 269b carrying imprisonment up to 5 years, unless you act solely to secure a system or to develop a securing method. |
|
| Law on Combating Cybercrime, Unauthorised Access, Interference and Fraudulent Copying of Data | Do not hinder or attempt to hinder the functioning of an information system. |
|
| Rhode Island Computer Crime chapter, unauthorized access and computer trespass | Do not use a computer or network without authority and with intent to disable, alter, or erase data or programs, or to cause a malfunction, even where no fraudulent purpose is involved. |
|
| Cod penal, Art. 360-366, Infracțiuni contra siguranței și integrității sistemelor și datelor informatice (Offences Against the Security and Integrity of Computer Systems and Data) | Do not produce, distribute, or possess a device, program, password, or access code intended to commit one of these offences, per Cod penal art. 365. |
|
| Criminal Code Article 273, Creation, Use and Distribution of Malicious Computer Programs | Do not create, use, or distribute computer programs, or other computer information, known to be intended for unauthorized destruction, blocking, modification, or copying of computer information, or for defeating computer-information security tools, under Criminal Code Article 273; this reaches tools built to circumvent a site's technical access controls. |
|
| Electronic Crimes Act, illegal access and related computer-misuse offences | Do not interfere with data on, or the operation of, a computer system without lawful excuse or justification. |
|
| Computer Misuse Act, unauthorized access, interception and modification | Do not modify data held in a computer system without authorization, including to impair the system's operation or the reliability of the data it holds. |
|
| Crimes Act 2013, computer-access and interference offences | Do not produce, sell, procure, import, distribute, or make available a device, access code, or password designed or intended for use in accessing an electronic system without authorisation. |
|
| Computer Crimes Law, Unlawful Access to Computer or Telematics Systems | Do not hold or access tools suited to enter a security-measure-protected system, or equipment or programmes designed to alter such a system or its data, without justified reason. |
|
| Criminal Code, Offences Against the Security of Computer Data | Do not delete, alter, damage, or conceal computer data or a program without authorisation. |
|
| Trestný zákon, Unauthorized Access to a Computer System and Related Offences | Do not interfere with a computer system's operation or with computer data within it without authorization, including by unauthorized insertion, transmission, damage, deletion, degradation, alteration, suppression, or blocking of computer data. Do not produce, import, procure, sell, exchange, distribute, or otherwise make available a device, computer program, password, access code, or similar data created to enable unauthorized access to a computer system. |
|
| South Dakota Unlawful Use of a Computer System, Software, or Data | Do not disrupt, deny, or inhibit access to software, data, or a computer system, or modify, change, alter, destroy, or disable software, data, or a computer system, without the owner's consent; these acts carry felony exposure up to a Class 2 felony (up to twenty-five years and a $50,000 fine) where the access is also part of a deceptive scheme to obtain money, property, or services. |
|
| Information and Communications Network Act, Article 48 (network intrusion and anti-circumvention) | Do not build, install, or distribute a tool whose purpose is to bypass a network's normal access-control or authentication procedures. |
|
| Penal Code Act, 2008, computer and electronic related offences | Do not deliberately introduce a computer virus into a computer or computer network without authority from its owner. |
|
| Computer Crime Act, unauthorised access, modification and dealing with unlawfully obtained data from a date not yet set | Do not intentionally cause unauthorised modification or damage to a computer, computer system, or computer programme in the course of an automated collection process. |
|
| Law by Decree No. 10 of 2018 on Cybercrime, Unauthorised Access and Computer Interference | Do not obstruct or disrupt access to a service, device, programme, or data source on the network (art. 5). Do not introduce anything that suspends or disrupts a system's operation, or damages, deletes, or modifies a programme, on the network (art. 6). |
|
| Wetboek van Strafrecht, Hacking and Denial of Access (arts. 187b-187c) | Do not hinder another person's access to or use of a computer system by flooding it with data. |
|
| Criminal Code, Offenses Against Computer Security | Do not build or use a program whose purpose is committing one of the offenses in this chapter (Article 362). |
|
| Turkish Penal Code, Information System Crimes | Do not obstruct or disrupt a computer system's operation, or corrupt, destroy, alter, or render inaccessible the data it holds, or insert or transmit its data without authorisation, regardless of whether the data taken is personal. |
|
| Criminal Code, Creation and Distribution of Malicious Software | Do not create, distribute or sell software or technical means designed for unauthorized interference in the operation of an information, electronic communications or information-and-communications system or network. |
|
| Criminal Code, Unauthorized Interference with Information Systems | Do not interfere, without authorization, in the operation of an information, electronic communications or information-and-communications system or network. |
|
| Virgin Islands Computer Crimes Act, unauthorized access and computer trespass | Do not access or cause to be accessed a computer, computer system, or computer network to devise or execute a scheme to defraud, or to obtain money, property, or services by false or fraudulent pretenses, representations, or promises. Do not access, without authorization and for a fraudulent or other illegal purpose, a computer, computer system, computer network, computer software, computer program, or the data it contains, to alter, damage, or destroy it. |
|
| Código Penal arts. 297 bis, 297 ter, 297 quater, 358 quater, and 358 quinquies, computer-offence provisions inserted by Ley N° 20.327 | Do not destroy, alter, or render unusable data or computer systems belonging to another without authorization. |
|
| Cybercrime Act 2021, computer-access and interference offences | Do not do any act that causes unauthorised interference to a computer system, program or data; the fine and prison term rise sharply where the interference causes a financial loss over VT1,000,000, threatens national security or public health or safety, or causes physical injury or death. Do not produce, sell, import, export, distribute or make available software, a device, a password or an access code for the purpose of unauthorised interception or interference with a computer system, except for authorised training, testing or protection of a computer system. |
|
| Unauthorised access to a protected computer or telematic system (Legge N. DXXXI, arts. 158 ter-158 quater) | Do not cause the destruction or damage of a system, or of the data, information, or programs it holds, or interrupt its operation, when you access it; the penalty is higher where the system belongs to the Holy See, Vatican City State, or another public authority. Do not obtain, reproduce, disseminate, or supply passwords or other means of accessing a protected system, or instructions for doing so, for profit or to cause harm. |
|
| Ley Especial contra los Delitos Informáticos, unauthorized access and sabotage of systems (Arts. 6-11) | Do not import, distribute, sell, or use equipment or programs meant to defeat a system's security measures. |
|
| Law on Cybersecurity, unauthorized access prohibition | Do not distribute software, or use a tool, that obstructs, disrupts, or harms the operation of a telecom network, computer network, information system, or database. |
|
| Virginia Computer Trespass, malicious intent or deceptive means requirement | Intentionally deceptive circumvention of a technical barrier to disable or alter data or programs squarely fits this statute's elements. |
|
| West Virginia Computer Crime and Abuse Act | Do not knowingly and willfully access a computer, computer service, or computer network to execute a scheme to defraud or to obtain money, property, or services by fraudulent pretenses; this is a felony punishable by up to $10,000 and ten years, or both. Do not introduce ransomware into a computer, computer system, or computer network with intent to extort money or other consideration; this is a separate felony punishable by up to $100,000 and ten years, or both. |
|
| Wisconsin computer crimes statute | Intentionally flooding a computer, program, system, or network with messages that exceed its processing capacity, causing an interruption in service, is a separate offense under this statute regardless of whether any data is altered. |
|
| Cyber and Data Protection Act, Insertion of Computer-Misuse Offences into the Criminal Law Code | Do not damage, delete, alter, or block access to computer data, or interfere with the functioning of a computer or information system, without lawful authority. Do not communicate, disclose, or use an access code, password, or programme designed to gain unauthorised access to data or a computer system. |
Copyright and text and data mining (TDM) 8
| Place | Law | The duty, as read |
|---|---|---|
| Copyright Act 2013, economic rights, computer program copying, and technological protection measures | Do not manufacture, import for sale or rental, or supply a device or means designed to circumvent a technological measure applied to a work, sound recording, or communication to the public to prevent or restrict its copying. |
|
| Text und Data Mining (General Text and Data Mining Exception) | May reproduce lawfully accessible works for text and data mining, but must delete the reproduction once it is no longer needed for that purpose. |
|
| Szjt. Section 35/A, Text and Data Mining Exception | Keep any copies made for text-and-data mining only for as long as the mining itself requires. |
|
| Text and Data Mining Exceptions, Copyright and Related Rights Act 2000 ss. 53A-53B | A reproduction made under the research and non-commercial text-and-data-mining exception must be stored in a secure manner appropriate to the work and retained only as necessary for the purposes of the scientific research, including verification of results (s. 53A(3A)). |
|
| Legge sul Diritto d'Autore Artt. 70-ter and 70-quater, Text-and-Data-Mining Exceptions | Keep any copy made for text-and-data-mining purposes only for as long as needed for that purpose, and secure it to at least the level Article 70-ter requires. |
|
| Autortiesību likums Article 21.1, Text and Data Mining Exception (Scraping and AI Training) | Keep a copy made under the text-and-data-mining exception only as long as needed for the mining itself, per Article 21.1(2). |
|
| Auteurswet, artt. 15n and 15o, Text and Data Mining Exceptions | Keep a reproduction made under either exception only as long as needed for the text-and-data-mining purpose. |
|
| Autorský zákon, TDM Exception | Keep a reproduction made under the general text-and-data-mining exception only for as long as the mining requires. |
Unfair competition 6
| Place | Law | The duty, as read |
|---|---|---|
| UWG Section 1, General Unfair Commercial Practices Clause | Do not apply, in the course of trade, an unfair commercial practice or other unfair conduct capable of more than trivially disadvantaging a competing undertaking, per UWG Section 1. |
|
| Unfair Competition Law (predicate vehicle for scraping claims) | Causing measurable harm to, or impairing the operation of, a target's computer system through your crawling can expose you to trespass to chattels; merely unwanted access without such harm does not, under Intel Corp. v. Hamidi (Cal. 2003). |
|
| Verbot unlauterer geschaeftlicher Handlungen und Mitbewerberschutz (General Clause and Competitor Protection) | Do not denigrate or disparage a competitor's identifying marks, goods, services, activities, or personal or business circumstances. Do not assert or spread unproven facts capable of damaging a competitor's business or credit. +2 more |
|
| Oklahoma Deceptive Trade Practices Act | Do not pass off your goods or services as another's, or make a false representation about the source, sponsorship, approval, affiliation, characteristics, or quantity of goods or services, in the course of business. |
|
| Unfair Competition Prevention and Trade Secret Protection Act, Art. 2(1) items ka and pa (data misappropriation and general catch-all) | Do not create, provide, or distribute a technology or device whose main purpose is to circumvent a technical measure protecting data. |
|
| Fair Trade Act, general clause against deceptive or unfair competitive conduct | Do not engage in deceptive conduct, or conduct that is obviously unfair and capable of affecting trading order, toward a competitor; Article 25 is a residual clause the Fair Trade Commission can apply to a novel unfair-competition claim, including one framed around reuse of a competitor's content or data, that no more specific provision of the Act covers. |
Personal data 2
| Place | Law | The duty, as read |
|---|---|---|
| Data Protection Act, 2019, reach over scraped personal data | Before moving scraped personal data outside Barbados, confirm an adequate level of protection or an appropriate safeguard. |
|
| Loi n° 24.001 portant protection des données à caractère personnel, collecte de données publiquement accessibles et transfert transfrontalier | Before transferring personal data you collected in the Central African Republic, or personal data about a person there, to another country, confirm the destination offers a similar level of protection or rely on one of the Act's specific derogations. Give the data protection agency prior notice before transferring personal data to a State outside the CEMAC or CEEAC, and rely on the agency's authorization, supported by appropriate contractual guarantees, where the destination lacks equivalent protection. |
Contract terms of service (ToS) 1
| Place | Law | The duty, as read |
|---|---|---|
| Electronic Transactions Act 2008, electronic contract and signature recognition | Do not rely on an electronic signature to satisfy a signature requirement unless it identifies the signatory, indicates their approval, is as reliable as the purpose requires, and the recipient consents to receiving it. |
Where the law and the framework part
35 of the 72 controls have no law we track under them.
165 requirement lines were read as having no control in this framework to sit under; they are listed above.
The framework's text
Full text of the NIST AI Risk Management Framework, public domain (a US government work).
Read it from the publisher: nvlpubs.nist.gov