Law / Frameworks / NIST CSF 2.0 / Govern

NIST CSF 2.0, GovernGV.RM-03

Cybersecurity risk management activities and outcomes are included in enterprise risk management processesNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), GV.RM-03

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

1
law
1
place
0
with court rulings behind them
0
not yet in force

Vulnerability and incident reporting

1 law, 1 place
PlaceLawWhat it asks, as read here
United States SEC Cybersecurity Risk Management, Governance, and Incident Disclosure (Regulation S-K Item 106; Form 8-K Item 1.05)

Separately, describe in your annual report, under Regulation S-K Item 106, your processes for assessing, identifying and managing material cybersecurity risks and your board's and management's oversight of those risks.

Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.