Law / Frameworks / NIST CSF 2.0 / Govern

NIST CSF 2.0, GovernGV.PO-02

Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational missionNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), GV.PO-02

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

2
laws
2
places
0
with court rulings behind them
0
not yet in force
  • Ohio
  • Utah

Security baseline statutes

2 laws, 2 places
PlaceLawWhat it asks, as read here
Ohio Ohio Data Protection Act, cybersecurity program safe harbor

Adopt a revised or amended version of the chosen framework or standard no later than one year after its publication date, to keep the program's reasonable conformance current.

Utah Cybersecurity Affirmative Defense Act

Update the program to a revised framework within one year of the revision's publication, and to an amended regulation within a reasonable time weighed against the risk to personal information and the cost and effort of compliance.

Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.