Law / Frameworks / NIST CSF 2.0 / Govern

NIST CSF 2.0, GovernGV.RM-06

A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicatedNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), GV.RM-06

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

5
laws
5
places
0
with court rulings behind them
1
not yet in force

A law in force is unmarked; the rest wear their state: not yet in force

  • Cameroon
  • Central African Republic
  • Gabon
  • Hungary
  • Kiribati

Security baseline statutes

3 laws, 3 places
PlaceLawWhat it asks, as read here
Cameroon Loi n°2010/012 du 21 décembre 2010 relative à la cybersécurité et à la cybercriminalité au Cameroun, articles 6, 7, 13-14, 24, 26-30, 32, 61(3) (mesures de sécurité et audit de sécurité obligatoire par l'ANTIC)

Adopt standardized systems that let you continuously identify, assess, treat, and manage the risks to your information systems' security.

Central African Republic Cybersecurity Law: Network and Information System Security Duty

Take all technical and administrative measures necessary to guarantee the security of the services you offer, and adopt standardized systems to continually identify, assess, treat and manage the risks to your information systems' security.

Gabon Sécurité des systèmes d'information (dispositions communes)

Take all technical and administrative measures necessary to guarantee the security of the services you offer, including a standardised system to identify, evaluate, treat and continuously manage the risks affecting your information systems' security.

Sector security regimes

2 laws, 2 places
PlaceLawWhat it asks, as read here
Hungary Cybersecurity Act, Risk-Management Measures

Establish and operate a risk-management framework for the electronic information systems in your organization's possession, following a directly applicable EU legal act or, absent one, the decree of the minister responsible for informatics.

Kiribati Cybersecurity Act 2026, Critical Infrastructure Operator Obligations from a date not yet set

Establish, implement and maintain a cybersecurity risk-management framework, and take reasonable contractual, technical and organisational measures to manage cybersecurity risk arising from your third-party suppliers, service providers and contractors.

Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.