Law / Frameworks / NIST CSF 2.0 / Govern
NIST CSF 2.0, GovernGV.PO-01
Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforcedNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), GV.PO-01
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 55
- laws
- 51
- places
- 0
- with court rulings behind them
- 6
- not yet in force
- 1
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 1.1 Legal and regulatory requirements involving AI are understood, managed, and documented.
- NIST AI RMFGOVERN 1.4 The risk management process and its outcomes are established through transparent...
- NIST AI 600-1GAI-RISK-07 Human-AI Configuration
- OWASP LLM Top 10LLM03:2026 Excessive Agency
- OWASP Agentic Top 10ASI09 Human-Agent Trust Exploitation
- MIT mitigations1.1 Board Structure & Oversight
- MIT mitigations1.2 Risk Management
- NIST Privacy FrameworkID.IM-P4 Data actions of the systems/products/services are inventoried.
- NIST Privacy FrameworkGV.PO-P1 Organizational privacy values and policies (e.g., conditions on data processing such...
A law in force is unmarked; the rest wear their state: not yet in force proposed
Sector security regimes
39 laws, 37 places| Place | Law | What it asks, as read here |
|---|---|---|
| Llei 22/2022, Cybersecurity Risk-Management Obligations |
Adopt technical and organisational measures proportionate to the cybersecurity risks facing your networks and information systems, covering at minimum a security policy for your critical infrastructure and information systems, a risk-management policy, incident management, business continuity and crisis management, supply-chain security, security in the acquisition, development and maintenance of your systems, testing and audit procedures, and the use of cryptography and encryption. |
|
| Netz- und Informationssystemsicherheitsgesetz (NISG), Security Measures for Operators of Essential Services and Digital Service Providers |
As a digital service provider, cover at minimum the security of your systems and facilities, incident handling, business-continuity management, monitoring, review and testing, and compliance with relevant international standards. |
|
| Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Cybersecurity Risk-Management Measures from , in 2 days |
Cover at least: risk analysis and information-system security concepts; incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security; security in the acquisition, development and maintenance of your systems, including vulnerability management and disclosure; effectiveness-assessment policies; basic cyber-hygiene practices and training; cryptography and, where appropriate, encryption policy; personnel security, access control and asset management; and multi-factor or continuous authentication. |
|
| Loi du 26 avril 2024, Cybersecurity Risk-Management Measures and Governance |
Cover at minimum: policies on risk analysis and information-system security; incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security, including the direct suppliers and service providers you rely on; security in the acquisition, development and maintenance of your network and information systems, including vulnerability handling and disclosure; policies to assess the effectiveness of your risk-management measures; basic cyber-hygiene practices and cybersecurity training; policies on the use of cryptography and, where applicable, encryption; personnel security, access-control policies and asset management; multi-factor or continuous authentication and secure voice, video, text and emergency communications where needed; and your own coordinated vulnerability-disclosure policy. |
|
| Cybersecurity Act, Risk-Management Measures and Governance (Zakon za kibersigurnost, ZKS) |
Cover, at minimum: risk-analysis and information-system-security policies, incident-handling procedures, business-continuity and backup management, supply-chain security, security in the acquisition, development and maintenance of your systems including vulnerability handling and disclosure, policies to evaluate the effectiveness of your own risk-management measures, basic cyber-hygiene practices and training, cryptography and encryption policies, and human-resources security and access control. |
|
| Zakon o kibernetičkoj sigurnosti, Risk-Management Measures and Governance |
Take risk-management measures sized to your exposure, covering at minimum: risk-analysis and information-system-security policies, incident-handling procedures (monitoring, logging and reporting), business continuity including backup management and disaster recovery, supply-chain security accounting for your direct suppliers' and service providers' vulnerabilities, security in the acquisition, development and maintenance of your systems including vulnerability handling and disclosure, policies to evaluate the effectiveness of your own measures, basic cyber-hygiene practices and training, cryptography and encryption policies, human-resources security and access control including asset inventories, and, where appropriate, multi-factor or continuous authentication and secured communications. |
|
| Security of Networks and Information Systems Law, Cybersecurity Risk-Management Measures and Governance |
Cover at least: risk-analysis and information-system security policies; incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security, including the security of your relationships with your direct suppliers and service providers; secure acquisition, development and maintenance of systems, including vulnerability handling and disclosure; policies to assess the effectiveness of these measures; basic cyber hygiene practices and cybersecurity training; cryptography and, where appropriate, encryption policies; human-resources security, access-control policies and asset management; and, where appropriate, multi-factor or continuous authentication, and secure voice, video, text and emergency communications. |
|
| Cybersecurity Act (Zákon o kybernetické bezpečnosti), Risk-Management Security Measures |
If you are in the higher-obligations regime, cover at least: an information security management system, top-management requirements, security roles, security-policy and documentation management, asset management, risk management, supplier management, human-resources security, change management, acquisition and development security, access management, handling of cybersecurity events and incidents, business-continuity management and cybersecurity auditing, plus physical security, communications-network security, identity administration and access-rights management, detection, logging and evaluation of cybersecurity events, application security, cryptographic algorithms, availability assurance, and, where applicable, security of industrial, control or similarly specific technical assets. If you are in the lower-obligations regime, a reduced set applies: a minimum cybersecurity assurance system, top-management requirements, asset management, risk management, human-resources security, business-continuity management, access management, identity and authorisation management, detection and logging of cybersecurity events, incident handling, communications-network security, application security, and cryptographic algorithms. |
|
| NIS 2-loven, Cybersecurity Risk-Management Measures and Registration |
Cover at minimum: risk-analysis and information-system-security policies; incident handling; operational continuity, including backup management, disaster recovery and crisis management; supply-chain security, including your relationship with your direct suppliers and service providers; security in acquiring, developing and maintaining your network and information systems, including vulnerability handling and disclosure; policies and procedures for assessing the effectiveness of your cybersecurity risk-management measures; basic cyber-hygiene practices and cybersecurity training; policies and procedures on the use of cryptography and, where relevant, encryption; personnel security, access-control policies and asset management; and, where relevant, multi-factor or continuous authentication, secured voice, video and text communication, and secured internal emergency-communication systems. |
|
| Critical Infrastructure Cybersecurity Proclamation, Critical Infrastructure Owner Obligations from , in 10 months |
Formulate and implement your own cybersecurity program and cybersecurity framework consistent with the mandatory national cybersecurity frameworks the Administration issues, classify and protect your critical assets to the Administration's standard, create the cybersecurity organizational structure the national framework calls for, and establish and manage a center responsible for monitoring, reporting, and responding to cyberattacks. |
Show the other 29 laws
| NIS2 Directive, Cybersecurity Risk-Management Measures |
Take technical, operational and organisational measures appropriate to the risk your network and information systems face, covering at minimum a risk analysis and information-system-security policy, incident handling, business continuity and crisis management, supply chain security, and security in the acquisition, development and maintenance of your systems. Maintain basic cyber hygiene practices and cybersecurity training, policies on cryptography and encryption where appropriate, human resources security and access control, and multi-factor authentication or continuous authentication solutions where appropriate. |
|
| Kyberturvallisuuslaki, Cybersecurity Risk-Management Measures and Governance |
Maintain a documented cybersecurity risk-management operating model covering at minimum: risk-management policy and effectiveness assessment; network and information system security policy; supply-chain security, including vulnerability handling and disclosure for your direct suppliers and service providers; asset management and identification of security-critical functions; personnel security and cybersecurity training; access-control and authentication procedures; cryptography policy; incident detection and handling; backup, recovery planning, crisis management and business continuity; basic cyber-hygiene practices; and, where appropriate, multi-factor or continuous authentication. |
|
| Loi n° 2018-133 du 26 février 2018 (transposition NIS1), Security Requirements |
Cover each of: the security of your systems and installations; incident management; business-continuity management; monitoring, audit and control; and compliance with international standards. |
|
| BSI-Gesetz (BSIG), Risk-Management Measures for Essential and Important Entities |
Cover at least: risk analysis and information-security policy; incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security; security in the acquisition, development and maintenance of your systems, including vulnerability management and disclosure; evaluation of your measures' effectiveness; basic cyber-hygiene training; cryptography; personnel security and access control; and multi-factor or continuous authentication. Document your compliance with this duty. |
|
| Law 5160/2024, Cybersecurity Risk-Management Measures and Governance |
Cover at minimum: risk analysis and information-system security policy; incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security, including your direct suppliers and service providers; security in the acquisition, development and maintenance of your systems, including vulnerability handling and disclosure; policies to assess the effectiveness of your risk-management measures; basic cyber-hygiene practices and staff training; cryptography and, where relevant, encryption policy; personnel security, access control and asset management; and, where appropriate, multi-factor or continuous authentication and secure voice, video, text and emergency communications. |
|
| BRH Circulaire 126, Information Security Rules for Financial Institutions |
Have a written information-security policy, updated annually and approved by your board of directors. |
|
| Cybersecurity Act, Risk-Management Measures |
Issue an information-security policy for your users and the requirements it sets, and review it at least every two years. |
|
| Minimum Risk-Management and Preparedness Requirements for Critical Infrastructure |
Maintain a documented security policy and risk-management process, assess and re-assess risk on a regular basis, and put in place technical and organisational security measures, including access control, tested regularly against current international best practice. |
|
| European Union (NIS) Regulations 2018, Security Requirements |
As a relevant digital service provider, additionally take into account the security of your systems and facilities, incident handling, business continuity management, monitoring, auditing and testing, and compliance with international standards, and keep documentation sufficient for the competent authority to verify your compliance. |
|
| Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Risk-Management Measures |
Cover at least: risk-analysis and information-system security policies; incident handling, including the procedures and tools to carry out the Article 25 and 26 notifications; business continuity, including backup management, disaster recovery and crisis management; and supply-chain security. |
|
| Cybersecurity Act 2026, Critical Infrastructure Operator Obligations from a date not yet set |
Appoint a member of senior management as Chief Information Security Officer, and develop, implement, communicate to staff and keep records of technical and organisational policies, practices and processes to manage risk to your network and information infrastructure and to prevent, mitigate and remedy a cybersecurity incident. |
|
| Banque du Liban Basic Circular No. 144 (Prevention of Electronic Criminal Acts) |
Prepare policies and take preventive measures and procedures against crimes committed by electronic means, including a cybercrime risk analysis, a budget for an information-technology security policy, insurance covering electronic-crime risk, a continuously updated incident-response and business-continuity plan, a dedicated prevention team, and employee and customer awareness training. |
|
| Cyber-Sicherheitsgesetz (CSG), Risk-Management Measures for Essential and Important Entities |
Cover at least: risk analysis and information-system-security policy; incident handling; business continuity, including backup management and disaster recovery, and crisis management; supply-chain security; security in the acquisition, development and maintenance of your systems, including vulnerability management and disclosure; evaluating your measures' effectiveness; basic cyber-hygiene procedures and training; cryptography and, where appropriate, encryption; personnel security, access-control concepts and asset management; and multi-factor or continuous authentication, plus secured voice, video and text communication. |
|
| Kibernetinio saugumo įstatymas (Law on Cyber Security), Risk-Management Measures |
Adopt and keep current cybersecurity policy documents, periodically analyse and manage your cybersecurity risks, designate the persons responsible for cybersecurity, manage cybersecurity incidents and report on them, secure your supply chain, and deploy technical cybersecurity measures. |
|
| Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Risk-Management Measures for Essential and Important Entities |
Cover at least: risk analysis and information-system-security policy; incident handling; business continuity, including backup management and crisis management; supply-chain security, including the security of your relationships with direct suppliers and service providers; security in the acquisition, development and maintenance of your systems, including vulnerability handling and disclosure; evaluating the effectiveness of your own risk-management measures; basic cyber-hygiene practices and cybersecurity training; policies on cryptography and, where appropriate, encryption; personnel security, access-control policy and asset management; and multi-factor or continuous authentication, secure voice, video and text communications, and secure emergency communication systems as needed. |
|
| Cybersecurity Act 2025, Cybersecurity of Critical Information Infrastructure |
At minimum: conduct rolling cybersecurity risk assessments at a frequency the Chief Information Security Officer prescribes; develop and implement internal cybersecurity policies and procedures, an internal incident-reporting policy, and an internal cybersecurity awareness program; and transmit the resulting mitigation actions to the Director within thirty days of completing each risk assessment. |
|
| FSM Cybersecurity Act 2025 (Bill), Critical Information Infrastructure Risk-Management Duties proposed |
Conduct a cybersecurity risk assessment of that infrastructure at least every two years, and maintain an internal cybersecurity policy, an internal cybersecurity incident-reporting policy, and an internal cybersecurity awareness program. |
|
| Law on Information Security, Essential and Important Entities |
If designated, adopt a cyber-security risk and security analysis, an incident-handling policy, a business-continuity and cyber-crisis plan, a supply-chain security act and system-governance acts, apply cryptographic protection where your work requires it, and assess the effectiveness of these measures (Article 16). |
|
| Cyberbeveiligingswet, Cybersecurity Risk-Management Measures and Governance |
Cover at minimum: risk analysis and information-system security policy; incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security, including the direct suppliers and service providers you rely on; security in acquiring, developing and maintaining your systems, including vulnerability handling and disclosure; policies to assess the effectiveness of your risk-management measures; basic cyber-hygiene practices and staff training; cryptography and, where applicable, encryption policy; personnel security, access control and asset management; and, where appropriate, multi-factor or continuous authentication, and secure voice, video, text and emergency communications. |
|
| Ustawa o krajowym systemie cyberbezpieczeństwa (KSC), System Zarządzania Bezpieczeństwem Informacji from , in 6 months |
Once it applies, implement an information security management system in the information system used in the processes affecting your provision of the service, covering systematic risk assessment and risk management, physical, personnel and supply-chain security, business continuity and disaster-recovery planning, continuous monitoring, effectiveness evaluation, cybersecurity training and basic cyber-hygiene, cryptography, secure communications and multi-factor authentication where appropriate, asset management, and access control. |
|
| Regime Jurídico da Cibersegurança, Cybersecurity Risk-Management Measures and Governance |
Cover at minimum: incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security, including your relationship with your direct suppliers and service providers; security in the acquisition, development and maintenance of your systems, including vulnerability handling and disclosure; policies to assess the effectiveness of your risk-management measures; basic cyber-hygiene practices and cybersecurity training, including for your top management; cryptography and, where applicable, encryption policy; personnel security, access control and asset management; and multi-factor or continuous authentication, secure communications and secure emergency communication systems. |
|
| Ordonanța de urgență nr. 155/2024, Cybersecurity Risk-Management Measures |
Cover at least: risk-analysis and system-security policy and its periodic review; evaluating the effectiveness of your risk-management measures; cryptography and encryption policy; supply-chain security, including the security of your relationship with your direct suppliers and service providers; security of system acquisition, development, maintenance and decommissioning, including vulnerability management and disclosure; human-resources security, access control and asset management; incident management; business continuity, including backups, disaster recovery and crisis management; basic cyber-hygiene practices and training; and multi-factor or continuous authentication. |
|
| Law on Information Security, ICT Systems of Special Importance and Security Measures |
Adopt a security act built on that risk-assessment act, setting the principles, methods and procedures for reaching and keeping an adequate level of system security and the authority and responsibility for security and resources, and check your applied protection measures against it at least once a year, alone or with outside experts, producing a report on the check. |
|
| Zákon o kybernetickej bezpečnosti (Cybersecurity Act), Risk-Management Measures |
Within 12 months of your registration as an essential-service operator, and graded by your own risk analysis, adopt, maintain and carry out general security measures covering at minimum: information- and cyber-security governance; vulnerability and threat management; asset and risk management; incident and event handling; business continuity, backup and disaster recovery; secure acquisition, development and configuration of your networks, systems and applications; compliance assessment and control; cryptography; human-resources security; identity and access management; network-operations security; protection against malicious code and unwanted content; system, network and communications security; event monitoring, logging and reporting; physical and endpoint security; records, privacy and information-labelling protection; supply-chain security; and procurement and use of certified ICT products, services and processes. |
|
| Zakon o informacijski varnosti (ZInfV-1), Cybersecurity Risk-Management Measures and Governance from , in 3 months |
Cover at minimum: management support for information and cybersecurity, personnel integrity checks before, during and after employment, basic cyber-hygiene practices and training, human-resources security and access-rights management, backup management, logging of events on your network and information systems, and, where relevant, supply-chain security, cryptography and encryption policy, and multi-factor or continuous authentication. |
|
| Real Decreto-ley 12/2018, Security Obligations for Operators of Essential Services and Digital Service Providers |
Adopt technical and organisational measures, proportionate to the risk and reflecting the state of the art, to manage the risks to the networks and information systems you use to provide the service, even where that management is outsourced; as a digital service provider, address at minimum the security of your systems and facilities, incident management, business-continuity management, monitoring, auditing and testing, and compliance with relevant international standards. |
|
| Cybersäkerhetslag, Cybersecurity Risk-Management Measures |
Take appropriate and proportionate technical, operational and organisational measures, on an all-hazards basis, to protect the network and information systems you use for your operations or to provide your services, and their physical environment, against an incident, at minimum covering risk-analysis strategy, incident handling, business continuity and crisis management, supply-chain security, security in system acquisition/development/maintenance, effectiveness-assessment procedures, basic cyber hygiene and staff training, cryptography and encryption policies, personnel security, access control and asset management, and, where relevant, authentication, secure communications and secure emergency-communication systems. |
|
| Cyber Security Management Act, Specific Non-Government Agency Cyber Security Management |
Formulate, revise and implement a cyber security maintenance plan matching the agency's assigned responsibility level, and submit its implementation status and any corrective-action report to the central competent authority in charge of the relevant sector. |
|
| Telecommunications Management Act, Cyber Security and Critical Infrastructure Protection Plans |
Draw up an info-communications security maintenance plan covering the management scope and classification of covered systems, compliance-verification measures, plan-implementation measures, and joint-defense and incident-response measures, and implement it. Where the competent authority designates the enterprise's PSTN, in whole or in part, as critical telecommunications infrastructure, additionally draw up a critical telecommunications infrastructure protection plan before the competent authority's own deadline, submit it for the competent authority's evaluation before implementing it, and comply with the technical specifications for info-communications security evaluation the competent authority sets for that infrastructure. |
Security baseline statutes
16 laws, 15 places| Place | Law | What it asks, as read here |
|---|---|---|
| Data Security Law, Data Security Protection Obligations |
Establish and maintain a full-process data-security management system covering the collection, storage, use, processing, transmission, provision, and disclosure of the data you process, and provide data-security education and training to your staff. |
|
| Adoption of cybersecurity controls by businesses, exemption from punitive damages |
To claim it, have created, maintained and complied with a written cybersecurity program with administrative, technical and physical safeguards for personal and restricted information, at the time of the breach, designed to protect the information's security, confidentiality and integrity and scaled to the entity's size, complexity, activities, the sensitivity of the information, and the cost and availability of security tools. |
|
| Protection of Social Security Numbers and Personal Information Act, safeguarding and destruction duty |
If you collect Social Security numbers in the course of business, create a privacy protection policy, published or publicly displayed, that protects their confidentiality, prohibits their unlawful disclosure and limits access to them. |
|
| Decreto No. 360/2019 and its Reglamento de Seguridad de las TIC (Resolución 128/2019), TIC Security System duty |
Design, implement, manage and keep updated a TIC Security System proportionate to the assets it protects and the risks it faces, and adopt a written TIC Security Plan describing the policies, measures and procedures that follow from it. |
|
| Information Technology Act, Compensation for Failure to Protect Data, and Sensitive Personal Data or Information Rules, Reasonable Security Practices |
Implement and maintain a comprehensive, documented information security programme with managerial, technical, operational, and physical control measures commensurate with the information assets you protect and the nature of your business; certifying to the international Standard IS/ISO/IEC 27001, or to a Central-Government-approved industry code of best practice, satisfies this duty as a matter of law, provided the certification is audited by an independent, government-approved auditor at least once a year or after a significant upgrade to your process or computer resource. |
|
| Government Regulation on the Operation of Electronic Systems and Transactions, electronic-system security duty |
Where you operate an Electronic Agent, an automated device that carries out an action on Electronic Information for a user without that user's direct intervention, such as an automated transaction or e-commerce system, additionally run a standard operating procedure meeting six security-control principles for user data and Electronic Transactions: confidentiality, integrity, availability, authenticity, authorization, and non-repudiation, and test a transacting user's identity and authorization before completing the transaction. |
|
| Tort Liability for Cybersecurity Programs, affirmative defense for a reasonable security program |
To claim the defense against a tort claim alleging that a failure to implement reasonable information security controls resulted in a data breach of personal information or restricted information, create, maintain, and comply with a written cybersecurity program containing administrative, technical, operational, and physical safeguards, designed to continually evaluate and mitigate reasonably anticipated threats, evaluate the maximum probable loss from a data breach at least annually, and communicate to affected parties the extent of any risk and steps to reduce damages once a breach is known to have occurred. |
|
| Privacy Protection Regulations (Data Security), information security programme |
An app operating a database of the personal data of a person in Israel, above the small-collection thresholds already recorded on this jurisdiction's privacy-topic row, must prescribe a written data security procedure covering physical protection, access authorizations, identification and authentication, encryption, and incident handling, scaled to the security-level tier (basic, medium, or high) that the volume and sensitivity of the data it holds places it in. |
|
| Standards for the Protection of Personal Information of Residents of the Commonwealth |
Develop, implement, and maintain a comprehensive written information security program (WISP), in one or more readily accessible parts, with administrative, technical, and physical safeguards appropriate to your size, scope, resources, amount of stored data, and the sensitivity of the personal information you hold. |
|
| Law on Information Security, General Security Measures |
Adopt rules for handling data, log who has accessed it, and oversee the security of that data (Article 12). |
Show the other 6 laws
| Stop Hacks and Improve Electronic Data Security (SHIELD) Act, data security program duty |
Absent that safe harbor, develop, implement, and maintain a data security program with reasonable administrative safeguards (a designated coordinator, a risk assessment, employee training, vetted service-provider contracts, and periodic adjustment), reasonable technical safeguards (assessing network and software design risk, detecting and responding to attacks, and testing controls), and reasonable physical safeguards (securing storage and disposal and limiting access during and after collection). |
|
| Ohio Data Protection Act, cybersecurity program safe harbor |
To seek that defense, create, maintain, and comply with a written cybersecurity program with administrative, technical, and physical safeguards, covering personal information alone or personal information together with restricted information, and scale the program to the covered entity's size and complexity, the nature and scope of its activities, the sensitivity of the information protected, the cost and availability of security tools, and the resources available to it. |
|
| Oregon Consumer Information Protection Act, requirement to develop safeguards for personal information |
Satisfy this duty either by already being subject to and complying with Gramm-Leach-Bliley Act Title V regulations, HIPAA and HITECH regulations, or another state or federal law providing greater protection, or by implementing an information security program with a designated coordinator, a periodic risk assessment, employee training, vetted service-provider contracts, network and software risk assessment and patch management, attack detection and testing, and secure destruction of records when the information is no longer needed. |
|
| Identity Theft Protection Act of 2015, risk-based information security program from a date not yet set |
Implement and maintain a risk-based information security program with reasonable security procedures and practices appropriate to your size and scope, the nature of the information, and the purpose for which it was collected, to protect the information from unauthorized access, use, modification, destruction, or disclosure and to preserve its confidentiality, integrity, and availability. |
|
| Cybersecurity Affirmative Defense Act |
To claim the defense against a claim of failing to implement reasonable information security controls, failing to appropriately respond to a breach, or failing to appropriately notify an affected individual, have in place at the time of the breach a written cybersecurity program designed to protect the type of personal information at issue and scaled to your size, complexity, activities, and the sensitivity of the information you hold. |
|
| Cybersecurity Law, Information System Classification and Protection Measures |
At level 1 or level 2, perform every Article 10(1) task (determine your system's level, assess and manage its cybersecurity risk, supervise and inspect its protection activities, apply protection measures, follow the reporting regime, and raise cybersecurity awareness), and choose which Article 10(2) measures to apply based on your own needs and capacity. At level 3 or level 4, and not on the Prime Minister's list of information systems critical to national security, perform every Article 10(1) task and, without discretion, promulgate cybersecurity design-and-operation rules, apply management measures meeting national cybersecurity standards, back up and store data protecting the system's components, inspect and supervise compliance, monitor the system, and respond to and remedy incidents; file a dossier proposing your system's level and put it into operation only once that level is approved. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.