Law / Frameworks / NIST CSF 2.0 / Govern
NIST CSF 2.0, GovernGV.PO-02
Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational missionNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), GV.PO-02
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 2
- laws
- 2
- places
- 0
- with court rulings behind them
- 0
- not yet in force
Security baseline statutes
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Ohio Data Protection Act, cybersecurity program safe harbor |
Adopt a revised or amended version of the chosen framework or standard no later than one year after its publication date, to keep the program's reasonable conformance current. |
|
| Cybersecurity Affirmative Defense Act |
Update the program to a revised framework within one year of the revision's publication, and to an amended regulation within a reasonable time weighed against the risk to personal information and the cost and effort of compliance. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.