Law / Frameworks / NIST CSF 2.0 / Govern
NIST CSF 2.0, GovernGV.RR-01
Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improvingNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), GV.RR-01
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 25
- laws
- 25
- places
- 0
- with court rulings behind them
- 3
- not yet in force
- 2
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 1.1 Legal and regulatory requirements involving AI are understood, managed, and documented.
- NIST AI RMFGOVERN 1.4 The risk management process and its outcomes are established through transparent...
- NIST AI 600-1GAI-RISK-07 Human-AI Configuration
- OWASP LLM Top 10LLM03:2026 Excessive Agency
- OWASP Agentic Top 10ASI09 Human-Agent Trust Exploitation
- MIT mitigations1.1 Board Structure & Oversight
- MIT mitigations1.2 Risk Management
- NIST Privacy FrameworkID.IM-P4 Data actions of the systems/products/services are inventoried.
- NIST Privacy FrameworkGV.PO-P1 Organizational privacy values and policies (e.g., conditions on data processing such...
A law in force is unmarked; the rest wear their state: not yet in force proposed
Sector security regimes
22 laws, 22 places| Place | Law | What it asks, as read here |
|---|---|---|
| Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Cybersecurity Risk-Management Measures from , in 2 days |
Have your management body implement and oversee these measures and attend cybersecurity training designed for it, and offer your staff regular training. |
|
| Loi du 26 avril 2024, Cybersecurity Risk-Management Measures and Governance |
Have your management body approve these risk-management measures, supervise their implementation, and answer for a violation of this duty; you remain responsible for your own risk analysis and for the choice and implementation of the measures. |
|
| Cybersecurity Act, Risk-Management Measures and Governance (Zakon za kibersigurnost, ZKS) |
Have your management body approve and oversee these measures, and have every member of your management body complete cybersecurity training every two years and organise the same training for your staff; a member who fails to do so faces a personal fine of EUR 500 to 5,000. |
|
| Zakon o kibernetičkoj sigurnosti, Risk-Management Measures and Governance |
Have the members of your management body, or, if you are a public entity, the heads of your state administration or local self-government body, approve these measures and control their implementation, and have them attend, and make available to your staff, appropriate cybersecurity training covering risk-management issues and their effect on your services. |
|
| Security of Networks and Information Systems Law, Cybersecurity Risk-Management Measures and Governance |
Have your senior management approve these risk-management measures and oversee their implementation; senior management can be held accountable for the entity's breach of this duty, and must undergo, and offer staff, regular training so they can identify risks and assess cybersecurity risk-management practices. |
|
| NIS 2-loven, Cybersecurity Risk-Management Measures and Registration |
Have your management board (ledelsesorgan) approve these measures and oversee their implementation, and ensure its members attend relevant cybersecurity risk-management training and encourage similar training for your other staff. |
|
| Küberturvalisuse seadus (KüTS), System Security Measures and Management-Body Duties |
Designate at least one management board member (or, if you have only one, that member, or the equivalent office-holder if you have no board) to approve your security measures, monitor their implementation and answer for that duty, and have that person complete regular training to understand and assess cyber risk, its impact on your services, and how to manage it. |
|
| NIS2 Directive, Cybersecurity Risk-Management Measures |
Have your management body approve these measures, oversee their implementation, and complete cybersecurity training. |
|
| Kyberturvallisuuslaki, Cybersecurity Risk-Management Measures and Governance |
Have your board, supervisory board or chief executive approve and oversee this operating model; they must hold sufficient familiarity with cybersecurity risk management to do so. |
|
| Projet de loi Résilience des Infrastructures Critiques et Cybersécurité, Cybersecurity Risk-Management Measures (NIS2) proposed |
Take technical, operational and organisational measures appropriate and proportionate to the risks facing the network and information systems you use for your activities or services: have your management body approve and oversee the security measures and receive cybersecurity training, protect your networks and systems including where you use a subcontractor, put in place tools and procedures to defend your networks and handle incidents, and ensure the resilience of your activities. |
Show the other 12 laws
| BSI-Gesetz (BSIG), Risk-Management Measures for Essential and Important Entities |
Have your management body implement and oversee these measures and attend regular risk-management training; expect it to be liable to your organisation for culpable damage from a breach of that duty under the ordinary rules of company law. |
|
| Law 5160/2024, Cybersecurity Risk-Management Measures and Governance |
Within three months of this duty's entry into force, have your management body approve the cybersecurity risk-management measures you take to comply with the measures below, supervise their implementation, and ensure every board member receives training and that equivalent training reaches your staff at least annually. |
|
| National Cyber Security Bill, Cybersecurity Risk-Management Measures proposed |
Take appropriate and proportionate technical, operational and organisational measures to manage the risks to the network and information systems you use for your operations or services, with your management board approving and overseeing those measures. |
|
| Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Risk-Management Measures |
Have your management body approve and oversee these measures; expect its members to face liability for an infringement of this duty. |
|
| Cyber-Sicherheitsgesetz (CSG), Risk-Management Measures for Essential and Important Entities |
Have your leadership body (Leitungsorgan) approve and oversee these measures and attend, and offer your staff, regular training on recognising and assessing cybersecurity risk and risk-management practice. |
|
| Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Risk-Management Measures for Essential and Important Entities |
Have your management body approve these risk-management measures, oversee their implementation, and complete regular training on assessing risk and risk-management practice; expect the body to be held liable for the entity's violation of this duty. |
|
| Cyberbeveiligingswet, Cybersecurity Risk-Management Measures and Governance |
Have your management board approve these measures, and ensure every board member holds the knowledge and skills to identify network-and-information-system risks, assess your cybersecurity risk-management measures, and assess their consequences for your services, within two years of this duty taking effect for a member already serving. |
|
| Ustawa o krajowym systemie cyberbezpieczeństwa (KSC), System Zarządzania Bezpieczeństwem Informacji from , in 6 months |
Have the entity's management implement and oversee the system, proportionate to the assessed risk, the entity's size, the cost of implementation, and the likelihood and severity of an incident. |
|
| Regime Jurídico da Cibersegurança, Cybersecurity Risk-Management Measures and Governance |
Have your management, direction and administration body approve these measures, supervise their implementation, ensure compliance with supervision and enforcement obligations, and ensure regular cybersecurity training; know that a member of that body can be held personally liable, by act or omission, on a finding of intent or gross negligence, for an infringement of this Decree-Law, and that this responsibility cannot be delegated away. |
|
| Ordonanța de urgență nr. 155/2024, Cybersecurity Risk-Management Measures |
Have your governing body approve these measures, supervise their implementation, and bear responsibility for them; designate a network-and-information-system security officer; and expect the DNSC director to issue an implementing order narrowing these requirements within 120 days of the OUG's entry into force (due by roughly ). |
|
| Zakon o informacijski varnosti (ZInfV-1), Cybersecurity Risk-Management Measures and Governance from , in 3 months |
Have your responsible person, the individual who leads, supervises or manages the entity or a public-administration body's head, approve these measures and oversee their implementation, and complete cybersecurity risk-management training at least every four years. |
|
| Bank and Financial Holding Company Internal Control Rules, Dedicated Information Security Unit |
Appoint a deputy general manager or equivalent as Chief Information Security Officer over that unit, and have that officer report the prior year's overall information-security performance to the board of directors annually and report a material information-security problem promptly when it arises. |
Vulnerability and incident reporting
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| New York Department of Financial Services Cybersecurity Regulation, Notices to the Superintendent |
By April 15 of each year, submit to the Superintendent electronically either a written certification that you materially complied with this Part for the prior calendar year or a written acknowledgment identifying the sections you did not materially comply with and a remediation timeline, each signed by your highest-ranking executive and your Chief Information Security Officer. |
|
| SEC Cybersecurity Risk Management, Governance, and Incident Disclosure (Regulation S-K Item 106; Form 8-K Item 1.05) |
Separately, describe in your annual report, under Regulation S-K Item 106, your processes for assessing, identifying and managing material cybersecurity risks and your board's and management's oversight of those risks. |
Security baseline statutes
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Government Regulation on the Operation of Electronic Systems and Transactions, electronic-system security duty |
Operate your Electronic System reliably and securely, and take legal responsibility for it operating as it should. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.