Law / Frameworks / NIST CSF 2.0 / Govern
NIST CSF 2.0, GovernGV.RR-02
Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforcedNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), GV.RR-02
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 24
- laws
- 22
- places
- 0
- with court rulings behind them
- 1
- not yet in force
- 2
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 1.1 Legal and regulatory requirements involving AI are understood, managed, and documented.
- NIST AI RMFGOVERN 1.4 The risk management process and its outcomes are established through transparent...
- NIST AI 600-1GAI-RISK-07 Human-AI Configuration
- OWASP LLM Top 10LLM03:2026 Excessive Agency
- OWASP Agentic Top 10ASI09 Human-Agent Trust Exploitation
- MIT mitigations1.1 Board Structure & Oversight
- MIT mitigations1.2 Risk Management
- NIST Privacy FrameworkID.IM-P4 Data actions of the systems/products/services are inventoried.
- NIST Privacy FrameworkGV.PO-P1 Organizational privacy values and policies (e.g., conditions on data processing such...
A law in force is unmarked; the rest wear their state: not yet in force proposed
Sector security regimes
14 laws, 12 places| Place | Law | What it asks, as read here |
|---|---|---|
| Law No. 25/2024, On Cybersecurity |
Register your critical or important information infrastructure with the National Authority for Cybersecurity (AKSK), establish a Computer Security Incident Response Team and a single point of contact for AKSK and other CSIRTs, and implement the technical, organisational and operational risk management measures a Council of Ministers methodology sets for your designated category. |
|
| Llei 22/2022, Cybersecurity Risk-Management Obligations |
Designate an Information Security Delegate, a natural person, a unit or a collegiate body, as the point of contact and technical coordination between your organisation and the competent national authority and the CSIRT-AD, and designate a substitute to assume the role during an absence, vacancy or illness. |
|
| RGSSI and PPIC Compliance Duty |
Where you are designated and notified as a critical-infrastructure operator or manager, renew a complete risk analysis of your critical infrastructure at least every six months and designate a cybersecurity focal point, a designation this vocabulary does not separately express. |
|
| BRH Circulaire 126, Information Security Rules for Financial Institutions |
Maintain an information-security committee (or, for a non-bank financial institution, have your board of directors perform this function) to validate and approve the security measures your policy adopts. Designate an information-security officer independent of the IT department, reporting to risk management or directly to general management, with the data and access needed to do the job. |
|
| Cybersecurity Act, Risk-Management Measures |
Survey and register every electronic information system, central service and supporting system you use, appoint or designate the person responsible for the security of those systems, classify them into a security category, and apply protective measures proportionate to their risk. |
|
| Cybersecurity Act 2026, Critical Infrastructure Operator Obligations from a date not yet set |
Appoint a member of senior management as Chief Information Security Officer, and develop, implement, communicate to staff and keep records of technical and organisational policies, practices and processes to manage risk to your network and information infrastructure and to prevent, mitigate and remedy a cybersecurity incident. |
|
| Nacionālās kiberdrošības likums, Cybersecurity Risk-Management Measures |
Have your head or governing body appoint a cybersecurity manager within three months of notifying your essential- or important-provider status, and notify the National Cybersecurity Centre and the Constitution Protection Bureau of the appointment within five working days. |
|
| Banque du Liban Basic Circular No. 144 (Prevention of Electronic Criminal Acts) |
Maintain a Compliance Department responsible for implementing this Decision. |
|
| Kibernetinio saugumo įstatymas (Law on Cyber Security), Risk-Management Measures |
Designate a cybersecurity manager and/or security officer who organises your risk assessment and prepares your risk-assessment reports and risk-management plans for approval, and have your management body, head and designated representative complete cybersecurity training at least once every two years. |
|
| Ordonanța de urgență nr. 155/2024, Cybersecurity Risk-Management Measures |
Have your governing body approve these measures, supervise their implementation, and bear responsibility for them; designate a network-and-information-system security officer; and expect the DNSC director to issue an implementing order narrowing these requirements within 120 days of the OUG's entry into force (due by roughly ). |
Show the other 4 laws
| Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad, Cybersecurity Risk-Management Measures proposed |
Expect a duty to designate a responsable de la seguridad de la informacion (information security officer) as point of contact and technical coordinator, with an accredited-personnel requirement where your entity is classified as essential. |
|
| Real Decreto-ley 12/2018, Security Obligations for Operators of Essential Services and Digital Service Providers |
If designated an operator of essential services, designate a responsable de la seguridad de la informacion within three months of your designation, notify the competent authority of the appointment, and file a Declaracion de Aplicabilidad of the security measures you apply within six months of designation, reviewing it at least every three years. |
|
| Bank and Financial Holding Company Internal Control Rules, Dedicated Information Security Unit |
Establish a dedicated information security unit reporting to the general manager, that does not also handle information-technology operations or any other function creating a conflict of interest, staffed with adequate personnel and equipment. Appoint a deputy general manager or equivalent as Chief Information Security Officer over that unit, and have that officer report the prior year's overall information-security performance to the board of directors annually and report a material information-security problem promptly when it arises. +1 more |
|
| Cyber Security Management Act, Specific Non-Government Agency Cyber Security Management |
Appoint a dedicated Chief Information Security Officer to promote and oversee the agency's cyber security affairs. |
Security baseline statutes
9 laws, 9 places| Place | Law | What it asks, as read here |
|---|---|---|
| Data Breach Notification Act, reasonable security measures and disposal of records |
Implement and maintain reasonable security measures to protect sensitive personally identifying information against a breach of security: designate an employee or employees to coordinate the effort, identify internal and external risks, adopt and assess information safeguards, contractually require any service providers to maintain appropriate safeguards, adjust the measures for changed circumstances, and keep management, including the board of directors where one exists, informed of the overall status of the measures. |
|
| Data Security Law, Data Security Protection Obligations |
If you process important data, an official classification this corpus cannot flag against on its own, designate a person responsible for data security and a managing body, and implement that responsibility. |
|
| Decreto No. 360/2019 and its Reglamento de Seguridad de las TIC (Resolución 128/2019), TIC Security System duty |
If you provide Internet access service, additionally draft internal security-operation procedures, name the person responsible for network security, and adopt technical and organizational measures against malware contamination and network attacks and intrusions. |
|
| Privacy Protection Regulations (Data Security), information security programme |
At the medium or high tier, run an automatic mechanism monitoring access to the database's systems, retained at least 24 months, and appoint a data security officer where required. |
|
| Data Classification Policy |
Form a data classification team including your information security and information technology leads, and direct employees to report immediately any breach of this classification scheme, recording it with the corrective action taken. |
|
| Standards for the Protection of Personal Information of Residents of the Commonwealth |
Designate one or more employees to maintain the WISP; identify and assess foreseeable internal and external risks to personal information and evaluate whether your safeguards limit them; train employees; discipline violations; cut off a terminated employee's access to records; restrict and secure physical access to records; review the WISP's scope at least annually or after a material change in business practice; document your response to any security-breach incident; and select only third-party service providers capable of maintaining appropriate security measures, requiring those measures by contract. |
|
| Senate Bill 360 (2025-2026), Identity Theft Protection Act reasonable security procedures duty proposed |
If enacted as passed by the Senate, this would require a person (any private entity) or agency (a Michigan state government unit) that owns, possesses, collects, or accesses personal information to implement and maintain reasonable security procedures: designate a security coordinator, identify internal and external risks, include appropriate safeguards addressing those risks, assess the safeguards' effectiveness, contractually require every service provider to maintain safeguards conforming to the NIST Cybersecurity Framework 2.0 or another industry-standard framework, and evaluate and adjust the procedures for changed circumstances. |
|
| Law on Information Security, General Security Measures |
Designate an employee to monitor your compliance with these measures (Article 18(3)). |
|
| Cybersecurity Affirmative Defense Act |
Build the program as a reasonable security program, a designated coordinator, procedures to detect, prevent and respond to a breach, employee training, and periodic risk assessments of network and software design, information handling, and data storage and disposal, adjusted as circumstances change, or have it reasonably conform to a current named framework: NIST SP 800-171; NIST SP 800-53 and 800-53A; the FedRAMP Security Assessment Framework; the CIS Critical Security Controls; the ISO/IEC 27000 family; the HIPAA Security Rule or Gramm-Leach-Bliley Title V regulations for information those regimes cover; or the PCI Data Security Standard for payment card information. |
Vulnerability and incident reporting
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| CERT-In Cyber Security Directions, Incident Reporting, Logging and Time Synchronisation |
Designate a Point of Contact to interface with CERT-In, using the format CERT-In publishes, and keep that designation current. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.