Law / Frameworks / NIST CSF 2.0 / Govern

NIST CSF 2.0, GovernGV.RR-03

Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policiesNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), GV.RR-03

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

2
laws
2
places
0
with court rulings behind them
0
not yet in force
  • Iowa
  • Kyrgyzstan

Security baseline statutes

2 laws, 2 places
PlaceLawWhat it asks, as read here
Iowa Tort Liability for Cybersecurity Programs, affirmative defense for a reasonable security program

Fund the program at a scale and scope that is appropriate if the cost to operate it is no less than the covered entity's most recently calculated maximum probable loss value.

Kyrgyzstan Digital Code, digital resilience baseline security measures

Maintain the integrity and availability of your digital systems and the confidentiality of the digital data you process, monitor for and help prevent incidents in the digital environment, manage the resulting risk under a risk-management system, and dedicate the resources your continuity of operation and recovery from an incident require.

Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.