Law / Frameworks / NIST CSF 2.0 / Govern

NIST CSF 2.0, GovernGV.RR-04

Cybersecurity is included in human resources practicesNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), GV.RR-04

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

2
laws
2
places
0
with court rulings behind them
1
not yet in force

A law in force is unmarked; the rest wear their state: not yet in force

  • Ethiopia
  • Latvia

Sector security regimes

2 laws, 2 places
PlaceLawWhat it asks, as read here
Ethiopia Critical Infrastructure Cybersecurity Proclamation, Critical Infrastructure Owner Obligations from , in 10 months

Employ cybersecurity professionals who hold a certification the Administration issues or recognizes, ensure the security of the supply chain of the technology products you use, obtain the Administration's security clearance before integrating a new or upgraded information and communication technology system acquired by purchase, donation, development, or any other means, and ensure that any employee or officer with access to your critical assets holds a security clearance from the relevant government body.

Latvia Nacionālās kiberdrošības likums, Cybersecurity Risk-Management Measures

Since , screen a staff member with privileged access to your ICT systems against a criminal-record check for a listed offence (terrorism, an offence against the state, or an offence against property or the economy) before assigning them that access, unless they are rehabilitated or their conviction has been expunged.

Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.