Law / Frameworks / NIST CSF 2.0 / Govern

NIST CSF 2.0, GovernGV.PO-01

Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforcedNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), GV.PO-01

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

55
laws
51
places
0
with court rulings behind them
6
not yet in force
1
proposed, not law

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force proposed

  • Andorra
  • Austria
  • Belgium
  • Bulgaria
  • China
  • Connecticut
  • Croatia
  • Cuba
  • Cyprus
  • Czech Republic
  • Denmark
  • Ethiopia
  • European Union
  • Finland
  • France
  • Germany
  • Greece
  • Haiti
  • Hungary
  • Iceland
  • India
  • Indonesia
  • Iowa
  • Ireland
  • Israel
  • Italy
  • Kiribati
  • Lebanon
  • Liechtenstein
  • Lithuania
  • Luxembourg
  • Marshall Islands
  • Massachusetts
  • Micronesia
  • Montenegro
  • Netherlands
  • New York
  • Ohio
  • Oregon
  • Poland
  • Portugal
  • Rhode Island
  • Romania
  • Serbia
  • Slovakia
  • Slovenia
  • Spain
  • Sweden
  • Taiwan
  • Utah
  • Vietnam

Sector security regimes

39 laws, 37 places
PlaceLawWhat it asks, as read here
Andorra Llei 22/2022, Cybersecurity Risk-Management Obligations

Adopt technical and organisational measures proportionate to the cybersecurity risks facing your networks and information systems, covering at minimum a security policy for your critical infrastructure and information systems, a risk-management policy, incident management, business continuity and crisis management, supply-chain security, security in the acquisition, development and maintenance of your systems, testing and audit procedures, and the use of cryptography and encryption.

Austria Netz- und Informationssystemsicherheitsgesetz (NISG), Security Measures for Operators of Essential Services and Digital Service Providers

As a digital service provider, cover at minimum the security of your systems and facilities, incident handling, business-continuity management, monitoring, review and testing, and compliance with relevant international standards.

Austria Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Cybersecurity Risk-Management Measures from , in 2 days

Cover at least: risk analysis and information-system security concepts; incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security; security in the acquisition, development and maintenance of your systems, including vulnerability management and disclosure; effectiveness-assessment policies; basic cyber-hygiene practices and training; cryptography and, where appropriate, encryption policy; personnel security, access control and asset management; and multi-factor or continuous authentication.

Belgium Loi du 26 avril 2024, Cybersecurity Risk-Management Measures and Governance

Cover at minimum: policies on risk analysis and information-system security; incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security, including the direct suppliers and service providers you rely on; security in the acquisition, development and maintenance of your network and information systems, including vulnerability handling and disclosure; policies to assess the effectiveness of your risk-management measures; basic cyber-hygiene practices and cybersecurity training; policies on the use of cryptography and, where applicable, encryption; personnel security, access-control policies and asset management; multi-factor or continuous authentication and secure voice, video, text and emergency communications where needed; and your own coordinated vulnerability-disclosure policy.

Bulgaria Cybersecurity Act, Risk-Management Measures and Governance (Zakon za kibersigurnost, ZKS)

Cover, at minimum: risk-analysis and information-system-security policies, incident-handling procedures, business-continuity and backup management, supply-chain security, security in the acquisition, development and maintenance of your systems including vulnerability handling and disclosure, policies to evaluate the effectiveness of your own risk-management measures, basic cyber-hygiene practices and training, cryptography and encryption policies, and human-resources security and access control.

Croatia Zakon o kibernetičkoj sigurnosti, Risk-Management Measures and Governance

Take risk-management measures sized to your exposure, covering at minimum: risk-analysis and information-system-security policies, incident-handling procedures (monitoring, logging and reporting), business continuity including backup management and disaster recovery, supply-chain security accounting for your direct suppliers' and service providers' vulnerabilities, security in the acquisition, development and maintenance of your systems including vulnerability handling and disclosure, policies to evaluate the effectiveness of your own measures, basic cyber-hygiene practices and training, cryptography and encryption policies, human-resources security and access control including asset inventories, and, where appropriate, multi-factor or continuous authentication and secured communications.

Cyprus Security of Networks and Information Systems Law, Cybersecurity Risk-Management Measures and Governance

Cover at least: risk-analysis and information-system security policies; incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security, including the security of your relationships with your direct suppliers and service providers; secure acquisition, development and maintenance of systems, including vulnerability handling and disclosure; policies to assess the effectiveness of these measures; basic cyber hygiene practices and cybersecurity training; cryptography and, where appropriate, encryption policies; human-resources security, access-control policies and asset management; and, where appropriate, multi-factor or continuous authentication, and secure voice, video, text and emergency communications.

Czech Republic Cybersecurity Act (Zákon o kybernetické bezpečnosti), Risk-Management Security Measures

If you are in the higher-obligations regime, cover at least: an information security management system, top-management requirements, security roles, security-policy and documentation management, asset management, risk management, supplier management, human-resources security, change management, acquisition and development security, access management, handling of cybersecurity events and incidents, business-continuity management and cybersecurity auditing, plus physical security, communications-network security, identity administration and access-rights management, detection, logging and evaluation of cybersecurity events, application security, cryptographic algorithms, availability assurance, and, where applicable, security of industrial, control or similarly specific technical assets.

If you are in the lower-obligations regime, a reduced set applies: a minimum cybersecurity assurance system, top-management requirements, asset management, risk management, human-resources security, business-continuity management, access management, identity and authorisation management, detection and logging of cybersecurity events, incident handling, communications-network security, application security, and cryptographic algorithms.

Denmark NIS 2-loven, Cybersecurity Risk-Management Measures and Registration

Cover at minimum: risk-analysis and information-system-security policies; incident handling; operational continuity, including backup management, disaster recovery and crisis management; supply-chain security, including your relationship with your direct suppliers and service providers; security in acquiring, developing and maintaining your network and information systems, including vulnerability handling and disclosure; policies and procedures for assessing the effectiveness of your cybersecurity risk-management measures; basic cyber-hygiene practices and cybersecurity training; policies and procedures on the use of cryptography and, where relevant, encryption; personnel security, access-control policies and asset management; and, where relevant, multi-factor or continuous authentication, secured voice, video and text communication, and secured internal emergency-communication systems.

Ethiopia Critical Infrastructure Cybersecurity Proclamation, Critical Infrastructure Owner Obligations from , in 10 months

Formulate and implement your own cybersecurity program and cybersecurity framework consistent with the mandatory national cybersecurity frameworks the Administration issues, classify and protect your critical assets to the Administration's standard, create the cybersecurity organizational structure the national framework calls for, and establish and manage a center responsible for monitoring, reporting, and responding to cyberattacks.

Show the other 29 laws
European Union NIS2 Directive, Cybersecurity Risk-Management Measures

Take technical, operational and organisational measures appropriate to the risk your network and information systems face, covering at minimum a risk analysis and information-system-security policy, incident handling, business continuity and crisis management, supply chain security, and security in the acquisition, development and maintenance of your systems.

Maintain basic cyber hygiene practices and cybersecurity training, policies on cryptography and encryption where appropriate, human resources security and access control, and multi-factor authentication or continuous authentication solutions where appropriate.

Finland Kyberturvallisuuslaki, Cybersecurity Risk-Management Measures and Governance

Maintain a documented cybersecurity risk-management operating model covering at minimum: risk-management policy and effectiveness assessment; network and information system security policy; supply-chain security, including vulnerability handling and disclosure for your direct suppliers and service providers; asset management and identification of security-critical functions; personnel security and cybersecurity training; access-control and authentication procedures; cryptography policy; incident detection and handling; backup, recovery planning, crisis management and business continuity; basic cyber-hygiene practices; and, where appropriate, multi-factor or continuous authentication.

France Loi n° 2018-133 du 26 février 2018 (transposition NIS1), Security Requirements

Cover each of: the security of your systems and installations; incident management; business-continuity management; monitoring, audit and control; and compliance with international standards.

Germany BSI-Gesetz (BSIG), Risk-Management Measures for Essential and Important Entities

Cover at least: risk analysis and information-security policy; incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security; security in the acquisition, development and maintenance of your systems, including vulnerability management and disclosure; evaluation of your measures' effectiveness; basic cyber-hygiene training; cryptography; personnel security and access control; and multi-factor or continuous authentication.

Document your compliance with this duty.

Greece Law 5160/2024, Cybersecurity Risk-Management Measures and Governance

Cover at minimum: risk analysis and information-system security policy; incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security, including your direct suppliers and service providers; security in the acquisition, development and maintenance of your systems, including vulnerability handling and disclosure; policies to assess the effectiveness of your risk-management measures; basic cyber-hygiene practices and staff training; cryptography and, where relevant, encryption policy; personnel security, access control and asset management; and, where appropriate, multi-factor or continuous authentication and secure voice, video, text and emergency communications.

Haiti BRH Circulaire 126, Information Security Rules for Financial Institutions

Have a written information-security policy, updated annually and approved by your board of directors.

Hungary Cybersecurity Act, Risk-Management Measures

Issue an information-security policy for your users and the requirements it sets, and review it at least every two years.

Iceland Minimum Risk-Management and Preparedness Requirements for Critical Infrastructure

Maintain a documented security policy and risk-management process, assess and re-assess risk on a regular basis, and put in place technical and organisational security measures, including access control, tested regularly against current international best practice.

Ireland European Union (NIS) Regulations 2018, Security Requirements

As a relevant digital service provider, additionally take into account the security of your systems and facilities, incident handling, business continuity management, monitoring, auditing and testing, and compliance with international standards, and keep documentation sufficient for the competent authority to verify your compliance.

Italy Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Risk-Management Measures

Cover at least: risk-analysis and information-system security policies; incident handling, including the procedures and tools to carry out the Article 25 and 26 notifications; business continuity, including backup management, disaster recovery and crisis management; and supply-chain security.

Kiribati Cybersecurity Act 2026, Critical Infrastructure Operator Obligations from a date not yet set

Appoint a member of senior management as Chief Information Security Officer, and develop, implement, communicate to staff and keep records of technical and organisational policies, practices and processes to manage risk to your network and information infrastructure and to prevent, mitigate and remedy a cybersecurity incident.

Lebanon Banque du Liban Basic Circular No. 144 (Prevention of Electronic Criminal Acts)

Prepare policies and take preventive measures and procedures against crimes committed by electronic means, including a cybercrime risk analysis, a budget for an information-technology security policy, insurance covering electronic-crime risk, a continuously updated incident-response and business-continuity plan, a dedicated prevention team, and employee and customer awareness training.

Liechtenstein Cyber-Sicherheitsgesetz (CSG), Risk-Management Measures for Essential and Important Entities

Cover at least: risk analysis and information-system-security policy; incident handling; business continuity, including backup management and disaster recovery, and crisis management; supply-chain security; security in the acquisition, development and maintenance of your systems, including vulnerability management and disclosure; evaluating your measures' effectiveness; basic cyber-hygiene procedures and training; cryptography and, where appropriate, encryption; personnel security, access-control concepts and asset management; and multi-factor or continuous authentication, plus secured voice, video and text communication.

Lithuania Kibernetinio saugumo įstatymas (Law on Cyber Security), Risk-Management Measures

Adopt and keep current cybersecurity policy documents, periodically analyse and manage your cybersecurity risks, designate the persons responsible for cybersecurity, manage cybersecurity incidents and report on them, secure your supply chain, and deploy technical cybersecurity measures.

Luxembourg Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Risk-Management Measures for Essential and Important Entities

Cover at least: risk analysis and information-system-security policy; incident handling; business continuity, including backup management and crisis management; supply-chain security, including the security of your relationships with direct suppliers and service providers; security in the acquisition, development and maintenance of your systems, including vulnerability handling and disclosure; evaluating the effectiveness of your own risk-management measures; basic cyber-hygiene practices and cybersecurity training; policies on cryptography and, where appropriate, encryption; personnel security, access-control policy and asset management; and multi-factor or continuous authentication, secure voice, video and text communications, and secure emergency communication systems as needed.

Marshall Islands Cybersecurity Act 2025, Cybersecurity of Critical Information Infrastructure

At minimum: conduct rolling cybersecurity risk assessments at a frequency the Chief Information Security Officer prescribes; develop and implement internal cybersecurity policies and procedures, an internal incident-reporting policy, and an internal cybersecurity awareness program; and transmit the resulting mitigation actions to the Director within thirty days of completing each risk assessment.

Micronesia FSM Cybersecurity Act 2025 (Bill), Critical Information Infrastructure Risk-Management Duties proposed

Conduct a cybersecurity risk assessment of that infrastructure at least every two years, and maintain an internal cybersecurity policy, an internal cybersecurity incident-reporting policy, and an internal cybersecurity awareness program.

Montenegro Law on Information Security, Essential and Important Entities

If designated, adopt a cyber-security risk and security analysis, an incident-handling policy, a business-continuity and cyber-crisis plan, a supply-chain security act and system-governance acts, apply cryptographic protection where your work requires it, and assess the effectiveness of these measures (Article 16).

Netherlands Cyberbeveiligingswet, Cybersecurity Risk-Management Measures and Governance

Cover at minimum: risk analysis and information-system security policy; incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security, including the direct suppliers and service providers you rely on; security in acquiring, developing and maintaining your systems, including vulnerability handling and disclosure; policies to assess the effectiveness of your risk-management measures; basic cyber-hygiene practices and staff training; cryptography and, where applicable, encryption policy; personnel security, access control and asset management; and, where appropriate, multi-factor or continuous authentication, and secure voice, video, text and emergency communications.

Poland Ustawa o krajowym systemie cyberbezpieczeństwa (KSC), System Zarządzania Bezpieczeństwem Informacji from , in 6 months

Once it applies, implement an information security management system in the information system used in the processes affecting your provision of the service, covering systematic risk assessment and risk management, physical, personnel and supply-chain security, business continuity and disaster-recovery planning, continuous monitoring, effectiveness evaluation, cybersecurity training and basic cyber-hygiene, cryptography, secure communications and multi-factor authentication where appropriate, asset management, and access control.

Portugal Regime Jurídico da Cibersegurança, Cybersecurity Risk-Management Measures and Governance

Cover at minimum: incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security, including your relationship with your direct suppliers and service providers; security in the acquisition, development and maintenance of your systems, including vulnerability handling and disclosure; policies to assess the effectiveness of your risk-management measures; basic cyber-hygiene practices and cybersecurity training, including for your top management; cryptography and, where applicable, encryption policy; personnel security, access control and asset management; and multi-factor or continuous authentication, secure communications and secure emergency communication systems.

Romania Ordonanța de urgență nr. 155/2024, Cybersecurity Risk-Management Measures

Cover at least: risk-analysis and system-security policy and its periodic review; evaluating the effectiveness of your risk-management measures; cryptography and encryption policy; supply-chain security, including the security of your relationship with your direct suppliers and service providers; security of system acquisition, development, maintenance and decommissioning, including vulnerability management and disclosure; human-resources security, access control and asset management; incident management; business continuity, including backups, disaster recovery and crisis management; basic cyber-hygiene practices and training; and multi-factor or continuous authentication.

Serbia Law on Information Security, ICT Systems of Special Importance and Security Measures

Adopt a security act built on that risk-assessment act, setting the principles, methods and procedures for reaching and keeping an adequate level of system security and the authority and responsibility for security and resources, and check your applied protection measures against it at least once a year, alone or with outside experts, producing a report on the check.

Slovakia Zákon o kybernetickej bezpečnosti (Cybersecurity Act), Risk-Management Measures

Within 12 months of your registration as an essential-service operator, and graded by your own risk analysis, adopt, maintain and carry out general security measures covering at minimum: information- and cyber-security governance; vulnerability and threat management; asset and risk management; incident and event handling; business continuity, backup and disaster recovery; secure acquisition, development and configuration of your networks, systems and applications; compliance assessment and control; cryptography; human-resources security; identity and access management; network-operations security; protection against malicious code and unwanted content; system, network and communications security; event monitoring, logging and reporting; physical and endpoint security; records, privacy and information-labelling protection; supply-chain security; and procurement and use of certified ICT products, services and processes.

Slovenia Zakon o informacijski varnosti (ZInfV-1), Cybersecurity Risk-Management Measures and Governance from , in 3 months

Cover at minimum: management support for information and cybersecurity, personnel integrity checks before, during and after employment, basic cyber-hygiene practices and training, human-resources security and access-rights management, backup management, logging of events on your network and information systems, and, where relevant, supply-chain security, cryptography and encryption policy, and multi-factor or continuous authentication.

Spain Real Decreto-ley 12/2018, Security Obligations for Operators of Essential Services and Digital Service Providers

Adopt technical and organisational measures, proportionate to the risk and reflecting the state of the art, to manage the risks to the networks and information systems you use to provide the service, even where that management is outsourced; as a digital service provider, address at minimum the security of your systems and facilities, incident management, business-continuity management, monitoring, auditing and testing, and compliance with relevant international standards.

Sweden Cybersäkerhetslag, Cybersecurity Risk-Management Measures

Take appropriate and proportionate technical, operational and organisational measures, on an all-hazards basis, to protect the network and information systems you use for your operations or to provide your services, and their physical environment, against an incident, at minimum covering risk-analysis strategy, incident handling, business continuity and crisis management, supply-chain security, security in system acquisition/development/maintenance, effectiveness-assessment procedures, basic cyber hygiene and staff training, cryptography and encryption policies, personnel security, access control and asset management, and, where relevant, authentication, secure communications and secure emergency-communication systems.

Taiwan Cyber Security Management Act, Specific Non-Government Agency Cyber Security Management

Formulate, revise and implement a cyber security maintenance plan matching the agency's assigned responsibility level, and submit its implementation status and any corrective-action report to the central competent authority in charge of the relevant sector.

Taiwan Telecommunications Management Act, Cyber Security and Critical Infrastructure Protection Plans

Draw up an info-communications security maintenance plan covering the management scope and classification of covered systems, compliance-verification measures, plan-implementation measures, and joint-defense and incident-response measures, and implement it.

Where the competent authority designates the enterprise's PSTN, in whole or in part, as critical telecommunications infrastructure, additionally draw up a critical telecommunications infrastructure protection plan before the competent authority's own deadline, submit it for the competent authority's evaluation before implementing it, and comply with the technical specifications for info-communications security evaluation the competent authority sets for that infrastructure.

Security baseline statutes

16 laws, 15 places
PlaceLawWhat it asks, as read here
China Data Security Law, Data Security Protection Obligations

Establish and maintain a full-process data-security management system covering the collection, storage, use, processing, transmission, provision, and disclosure of the data you process, and provide data-security education and training to your staff.

Connecticut Adoption of cybersecurity controls by businesses, exemption from punitive damages

To claim it, have created, maintained and complied with a written cybersecurity program with administrative, technical and physical safeguards for personal and restricted information, at the time of the breach, designed to protect the information's security, confidentiality and integrity and scaled to the entity's size, complexity, activities, the sensitivity of the information, and the cost and availability of security tools.

Connecticut Protection of Social Security Numbers and Personal Information Act, safeguarding and destruction duty

If you collect Social Security numbers in the course of business, create a privacy protection policy, published or publicly displayed, that protects their confidentiality, prohibits their unlawful disclosure and limits access to them.

Cuba Decreto No. 360/2019 and its Reglamento de Seguridad de las TIC (Resolución 128/2019), TIC Security System duty

Design, implement, manage and keep updated a TIC Security System proportionate to the assets it protects and the risks it faces, and adopt a written TIC Security Plan describing the policies, measures and procedures that follow from it.

India Information Technology Act, Compensation for Failure to Protect Data, and Sensitive Personal Data or Information Rules, Reasonable Security Practices

Implement and maintain a comprehensive, documented information security programme with managerial, technical, operational, and physical control measures commensurate with the information assets you protect and the nature of your business; certifying to the international Standard IS/ISO/IEC 27001, or to a Central-Government-approved industry code of best practice, satisfies this duty as a matter of law, provided the certification is audited by an independent, government-approved auditor at least once a year or after a significant upgrade to your process or computer resource.

Indonesia Government Regulation on the Operation of Electronic Systems and Transactions, electronic-system security duty

Where you operate an Electronic Agent, an automated device that carries out an action on Electronic Information for a user without that user's direct intervention, such as an automated transaction or e-commerce system, additionally run a standard operating procedure meeting six security-control principles for user data and Electronic Transactions: confidentiality, integrity, availability, authenticity, authorization, and non-repudiation, and test a transacting user's identity and authorization before completing the transaction.

Iowa Tort Liability for Cybersecurity Programs, affirmative defense for a reasonable security program

To claim the defense against a tort claim alleging that a failure to implement reasonable information security controls resulted in a data breach of personal information or restricted information, create, maintain, and comply with a written cybersecurity program containing administrative, technical, operational, and physical safeguards, designed to continually evaluate and mitigate reasonably anticipated threats, evaluate the maximum probable loss from a data breach at least annually, and communicate to affected parties the extent of any risk and steps to reduce damages once a breach is known to have occurred.

Israel Privacy Protection Regulations (Data Security), information security programme

An app operating a database of the personal data of a person in Israel, above the small-collection thresholds already recorded on this jurisdiction's privacy-topic row, must prescribe a written data security procedure covering physical protection, access authorizations, identification and authentication, encryption, and incident handling, scaled to the security-level tier (basic, medium, or high) that the volume and sensitivity of the data it holds places it in.

Massachusetts Standards for the Protection of Personal Information of Residents of the Commonwealth

Develop, implement, and maintain a comprehensive written information security program (WISP), in one or more readily accessible parts, with administrative, technical, and physical safeguards appropriate to your size, scope, resources, amount of stored data, and the sensitivity of the personal information you hold.

Montenegro Law on Information Security, General Security Measures

Adopt rules for handling data, log who has accessed it, and oversee the security of that data (Article 12).

Show the other 6 laws
New York Stop Hacks and Improve Electronic Data Security (SHIELD) Act, data security program duty

Absent that safe harbor, develop, implement, and maintain a data security program with reasonable administrative safeguards (a designated coordinator, a risk assessment, employee training, vetted service-provider contracts, and periodic adjustment), reasonable technical safeguards (assessing network and software design risk, detecting and responding to attacks, and testing controls), and reasonable physical safeguards (securing storage and disposal and limiting access during and after collection).

Ohio Ohio Data Protection Act, cybersecurity program safe harbor

To seek that defense, create, maintain, and comply with a written cybersecurity program with administrative, technical, and physical safeguards, covering personal information alone or personal information together with restricted information, and scale the program to the covered entity's size and complexity, the nature and scope of its activities, the sensitivity of the information protected, the cost and availability of security tools, and the resources available to it.

Oregon Oregon Consumer Information Protection Act, requirement to develop safeguards for personal information

Satisfy this duty either by already being subject to and complying with Gramm-Leach-Bliley Act Title V regulations, HIPAA and HITECH regulations, or another state or federal law providing greater protection, or by implementing an information security program with a designated coordinator, a periodic risk assessment, employee training, vetted service-provider contracts, network and software risk assessment and patch management, attack detection and testing, and secure destruction of records when the information is no longer needed.

Rhode Island Identity Theft Protection Act of 2015, risk-based information security program from a date not yet set

Implement and maintain a risk-based information security program with reasonable security procedures and practices appropriate to your size and scope, the nature of the information, and the purpose for which it was collected, to protect the information from unauthorized access, use, modification, destruction, or disclosure and to preserve its confidentiality, integrity, and availability.

Utah Cybersecurity Affirmative Defense Act

To claim the defense against a claim of failing to implement reasonable information security controls, failing to appropriately respond to a breach, or failing to appropriately notify an affected individual, have in place at the time of the breach a written cybersecurity program designed to protect the type of personal information at issue and scaled to your size, complexity, activities, and the sensitivity of the information you hold.

Vietnam Cybersecurity Law, Information System Classification and Protection Measures

At level 1 or level 2, perform every Article 10(1) task (determine your system's level, assess and manage its cybersecurity risk, supervise and inspect its protection activities, apply protection measures, follow the reporting regime, and raise cybersecurity awareness), and choose which Article 10(2) measures to apply based on your own needs and capacity.

At level 3 or level 4, and not on the Prime Minister's list of information systems critical to national security, perform every Article 10(1) task and, without discretion, promulgate cybersecurity design-and-operation rules, apply management measures meeting national cybersecurity standards, back up and store data protecting the system's components, inspect and supervise compliance, monitor the system, and respond to and remedy incidents; file a dossier proposing your system's level and put it into operation only once that level is approved.

Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.