Law / Frameworks / NIST CSF 2.0 / Detect

NIST CSF 2.0, DetectDE.CM-09

Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse eventsNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), DE.CM-09

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

9
laws
8
places
0
with court rulings behind them
1
not yet in force
1
proposed, not law

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force proposed

  • China
  • Democratic Republic of the Congo
  • Djibouti
  • Ethiopia
  • Marshall Islands
  • Micronesia
  • Turkmenistan
  • Vietnam

Vulnerability and incident reporting

4 laws, 4 places
PlaceLawWhat it asks, as read here
China Data Security Law, Risk Monitoring and Incident Reporting Duty

Strengthen risk monitoring of your data-processing activity, and on discovering a data-security defect, vulnerability, or other risk, immediately take remedial measures.

Marshall Islands Cybersecurity Act 2025, Cybersecurity Incident Reporting Obligations

Establish mechanisms and processes to promptly detect a cybersecurity threat, vulnerability, or incident affecting your critical information infrastructure.

Micronesia FSM Cybersecurity Act 2025 (Bill), Critical Information Infrastructure Incident Reporting Clock proposed

Establish mechanisms and processes to promptly detect a cybersecurity threat or incident affecting your critical information infrastructure.

Vietnam Cybersecurity Law, Incident Response and Reporting Duties

As the manager of an information system, connect its cybersecurity monitoring to the National Cybersecurity Centre of the Ministry of Public Security, or to the Ministry of National Defence's centre for a military system, and report a cybersecurity incident to that specialised force.

Security baseline statutes

3 laws, 3 places
PlaceLawWhat it asks, as read here
Democratic Republic of the Congo Digital Code, Livre IV: Digital Services Provider Security Obligations

Implement systems qualified to detect events likely to affect the security of your own information systems; the qualification of the detection systems and of the service providers operating them is delivered by the Ministry responsible for digital affairs, the Agence Nationale de Cybersécurité having been consulted.

Turkmenistan Law on Information and Its Protection, information-security duty

Where the duty is triggered, maintain administrative, technical and organizational measures that: prevent unauthorized access to information and its transfer to a person without a right of access; detect an unauthorized access event in a timely manner; prevent adverse consequences from a breach of the access procedure; prevent disruption of the technical means used to process the information; permit immediate restoration of information altered or destroyed by unauthorized access; and continuously monitor the level of the information's protection.

Vietnam Cybersecurity Law, Information System Classification and Protection Measures

At level 3 or level 4, and not on the Prime Minister's list of information systems critical to national security, perform every Article 10(1) task and, without discretion, promulgate cybersecurity design-and-operation rules, apply management measures meeting national cybersecurity standards, back up and store data protecting the system's components, inspect and supervise compliance, monitor the system, and respond to and remedy incidents; file a dossier proposing your system's level and put it into operation only once that level is approved.

Sector security regimes

2 laws, 2 places
PlaceLawWhat it asks, as read here
Djibouti Digital Code, Book VI: Critical Installation Protection and Operator Security Controls

Implement a qualified system for detecting events capable of affecting your information systems' security, if you operate a public electronic communications network or provide a public electronic communications service in Djibouti. The detection system, and any service provider you use to run it, must be qualified by the national cybersecurity authority.

Ethiopia Critical Infrastructure Cybersecurity Proclamation, Critical Infrastructure Owner Obligations from , in 10 months

Formulate and implement your own cybersecurity program and cybersecurity framework consistent with the mandatory national cybersecurity frameworks the Administration issues, classify and protect your critical assets to the Administration's standard, create the cybersecurity organizational structure the national framework calls for, and establish and manage a center responsible for monitoring, reporting, and responding to cyberattacks.

Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.