Law / Frameworks / NIST CSF 2.0 / Govern
NIST CSF 2.0, GovernGV.SC-05
Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third partiesNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), GV.SC-05
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 17
- laws
- 16
- places
- 0
- with court rulings behind them
- 3
- not yet in force
- 1
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 6.1 Policies and procedures are in place that address AI risks associated with third-party...
- NIST AI RMFMANAGE 3.1 AI risks and benefits from third-party resources are regularly monitored, and risk...
- NIST AI 600-1GAI-RISK-12 Value Chain and Component Integration
- MIT mitigations3.3 Access Management
- NIST Privacy FrameworkID.DE-P2 Data processing ecosystem parties (e.g., service providers, customers, partners,...
- NIST Privacy FrameworkID.DE-P3 Contracts with data processing ecosystem parties are used to implement appropriate...
A law in force is unmarked; the rest wear their state: not yet in force proposed
Security baseline statutes
13 laws, 12 places| Place | Law | What it asks, as read here |
|---|---|---|
| Data Breach Notification Act, reasonable security measures and disposal of records |
Implement and maintain reasonable security measures to protect sensitive personally identifying information against a breach of security: designate an employee or employees to coordinate the effort, identify internal and external risks, adopt and assess information safeguards, contractually require any service providers to maintain appropriate safeguards, adjust the measures for changed circumstances, and keep management, including the board of directors where one exists, informed of the overall status of the measures. |
|
| Protection of personal identifying information, reasonable security procedures duty |
Where personal identifying information is disclosed to a third-party service provider, require that provider to implement and maintain its own reasonable security procedures and practices, unless the covered entity retains primary responsibility and implements technical controls that protect the information from unauthorized access or effectively eliminate the third party's ability to access it. |
|
| Security requirements for personal information (Security Breach Protection Amendment Act of 2020) |
If you disclose a District resident's personal information to a nonaffiliated third-party service provider, require by written agreement that the third party implement and maintain its own reasonable security procedures and practices over that information. |
|
| Personal Information Protection Act, data security duty |
Require, by contract, that any party to whom personal information is disclosed also implement and maintain reasonable security measures over it. |
|
| Personal Information Protection Act, safe disposal of personal information |
Where a third party is contracted to dispose of the materials, require it to implement and monitor policies and procedures that prohibit unauthorized access to, acquisition of, or use of personal information during collection, transportation, and disposal. |
|
| Privacy Protection Regulations (Data Security), information security programme |
Where an external service provider is given access to the database, agree in writing on the data and systems it may access, its reporting and data-destruction duties, and monitor its compliance. |
|
| Maryland Personal Information Protection Act (MPIPA), safeguards and secure-disposal duty |
Where a nonaffiliated third-party service provider will receive personal information under a written contract entered into on or after , require by that contract that the provider also implement and maintain reasonable security procedures and practices appropriate to the information disclosed. |
|
| Standards for the Protection of Personal Information of Residents of the Commonwealth |
Designate one or more employees to maintain the WISP; identify and assess foreseeable internal and external risks to personal information and evaluate whether your safeguards limit them; train employees; discipline violations; cut off a terminated employee's access to records; restrict and secure physical access to records; review the WISP's scope at least annually or after a material change in business practice; document your response to any security-breach incident; and select only third-party service providers capable of maintaining appropriate security measures, requiring those measures by contract. |
|
| Senate Bill 360 (2025-2026), Identity Theft Protection Act reasonable security procedures duty proposed |
If enacted as passed by the Senate, this would require a person (any private entity) or agency (a Michigan state government unit) that owns, possesses, collects, or accesses personal information to implement and maintain reasonable security procedures: designate a security coordinator, identify internal and external risks, include appropriate safeguards addressing those risks, assess the safeguards' effectiveness, contractually require every service provider to maintain safeguards conforming to the NIST Cybersecurity Framework 2.0 or another industry-standard framework, and evaluate and adjust the procedures for changed circumstances. |
|
| Financial Data Protection and Consumer Notification of Data Security Breach Act, security procedures and practices duty |
Where personal information is disclosed to a nonaffiliated third-party service provider, require by contract that the provider implement and maintain reasonable security procedures and practices of its own, appropriate to the nature of the information disclosed and reasonably designed to protect it from unauthorized access, acquisition, destruction, use, modification, or disclosure. |
Show the other 3 laws
| Security measures for data collectors maintaining personal information from a date not yet set |
Require, by contract, any person to whom you disclose a Nevada resident's personal information to implement and maintain the same reasonable security measures. |
|
| Data Breach Notification Act, security and disposal duties from a date not yet set |
Where personal identifying information is disclosed to a service provider under a contract, require by that contract that the service provider also implement and maintain reasonable security procedures and practices appropriate to the nature of the information. |
|
| Identity Theft Protection Act of 2015, risk-based information security program from a date not yet set |
If you disclose personal information about a Rhode Island resident to a nonaffiliated third party, require by written contract that the third party implement and maintain reasonable security procedures and practices of the same kind, appropriate to its own size and scope, the nature of the information, and the purpose for which it was collected. |
Sector security regimes
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Cybersecurity Act (Zákon o kybernetické bezpečnosti), Risk-Management Security Measures |
Where a supplier implements a security measure on your behalf, select that supplier consistent with the measure's requirements and write those requirements into your contract with the supplier. |
|
| DORA, Articles 28-30 (ICT Third-Party Risk Management) |
Put every ICT services contract in writing in one document, covering at minimum the functions and locations involved, data-protection and access-on-termination provisions, service levels, the provider's duty to assist you on an incident and to cooperate with your regulators, termination rights, and your security-awareness programme. For a contract supporting a critical or important function, add quantitative service level targets, an unrestricted right to monitor, inspect and audit the provider, the provider's cooperation in your threat-led penetration testing, and an exit strategy with a mandatory transition period. |
Vulnerability and incident reporting
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| National Cybersecurity Incident Reporting Measures |
Where an organization or individual provides you network-security or system-operation-and-maintenance services under contract, require that provider by contract to promptly report to you any cybersecurity incident it discovers through monitoring, and to assist your own reporting under these Measures; this is the paragraph that reaches a cloud host, managed-security vendor, or AI operator serving you as its customer. |
|
| Safeguarding Covered Defense Information and Cyber Incident Reporting (DFARS 252.204-7012) |
Include this clause, unaltered except to identify the parties, in every subcontract or similar contractual instrument that involves covered defense information or operationally critical support, including a subcontract for a commercial product or service. Where an external cloud service provider stores, processes, or transmits covered defense information for you, require that provider by contract to meet security requirements equivalent to the FedRAMP Moderate baseline and to carry out the same incident reporting, malicious software, media preservation, forensic access, and damage assessment duties this clause places on you. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.