Law / Frameworks / NIST CSF 2.0 / Detect
NIST CSF 2.0, DetectDE.CM-09
Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse eventsNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), DE.CM-09
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 9
- laws
- 8
- places
- 0
- with court rulings behind them
- 1
- not yet in force
- 1
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFMEASURE 2.5 The AI system to be deployed is demonstrated to be valid and reliable. Limitations of...
- NIST AI RMFMEASURE 2.6 The AI system is evaluated regularly for safety risks – as identified in the MAP...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-09 Information Security
- OWASP LLM Top 10LLM01:2026 Prompt Injection
- OWASP LLM Top 10LLM02:2026 Sensitive Information Disclosure
- OWASP Agentic Top 10ASI01 Agent Goal Hijack
- OWASP Agentic Top 10ASI03 Identity and Privilege Abuse
- MIT mitigations2.1 Model & Infrastructure Security
- MIT mitigations2.3 Model Safety Engineering
- NIST Privacy FrameworkPR.PO-P7 Response plans (Incident Response and Business Continuity) and recovery plans...
- NIST Privacy FrameworkPR.PO-P10 A vulnerability management plan is developed and implemented.
A law in force is unmarked; the rest wear their state: not yet in force proposed
Vulnerability and incident reporting
4 laws, 4 places| Place | Law | What it asks, as read here |
|---|---|---|
| Data Security Law, Risk Monitoring and Incident Reporting Duty |
Strengthen risk monitoring of your data-processing activity, and on discovering a data-security defect, vulnerability, or other risk, immediately take remedial measures. |
|
| Cybersecurity Act 2025, Cybersecurity Incident Reporting Obligations |
Establish mechanisms and processes to promptly detect a cybersecurity threat, vulnerability, or incident affecting your critical information infrastructure. |
|
| FSM Cybersecurity Act 2025 (Bill), Critical Information Infrastructure Incident Reporting Clock proposed |
Establish mechanisms and processes to promptly detect a cybersecurity threat or incident affecting your critical information infrastructure. |
|
| Cybersecurity Law, Incident Response and Reporting Duties |
As the manager of an information system, connect its cybersecurity monitoring to the National Cybersecurity Centre of the Ministry of Public Security, or to the Ministry of National Defence's centre for a military system, and report a cybersecurity incident to that specialised force. |
Security baseline statutes
3 laws, 3 places| Place | Law | What it asks, as read here |
|---|---|---|
| Digital Code, Livre IV: Digital Services Provider Security Obligations |
Implement systems qualified to detect events likely to affect the security of your own information systems; the qualification of the detection systems and of the service providers operating them is delivered by the Ministry responsible for digital affairs, the Agence Nationale de Cybersécurité having been consulted. |
|
| Law on Information and Its Protection, information-security duty |
Where the duty is triggered, maintain administrative, technical and organizational measures that: prevent unauthorized access to information and its transfer to a person without a right of access; detect an unauthorized access event in a timely manner; prevent adverse consequences from a breach of the access procedure; prevent disruption of the technical means used to process the information; permit immediate restoration of information altered or destroyed by unauthorized access; and continuously monitor the level of the information's protection. |
|
| Cybersecurity Law, Information System Classification and Protection Measures |
At level 3 or level 4, and not on the Prime Minister's list of information systems critical to national security, perform every Article 10(1) task and, without discretion, promulgate cybersecurity design-and-operation rules, apply management measures meeting national cybersecurity standards, back up and store data protecting the system's components, inspect and supervise compliance, monitor the system, and respond to and remedy incidents; file a dossier proposing your system's level and put it into operation only once that level is approved. |
Sector security regimes
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Digital Code, Book VI: Critical Installation Protection and Operator Security Controls |
Implement a qualified system for detecting events capable of affecting your information systems' security, if you operate a public electronic communications network or provide a public electronic communications service in Djibouti. The detection system, and any service provider you use to run it, must be qualified by the national cybersecurity authority. |
|
| Critical Infrastructure Cybersecurity Proclamation, Critical Infrastructure Owner Obligations from , in 10 months |
Formulate and implement your own cybersecurity program and cybersecurity framework consistent with the mandatory national cybersecurity frameworks the Administration issues, classify and protect your critical assets to the Administration's standard, create the cybersecurity organizational structure the national framework calls for, and establish and manage a center responsible for monitoring, reporting, and responding to cyberattacks. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.