Law / Frameworks / NIST CSF 2.0 / Govern

NIST CSF 2.0, GovernGV.SC-06

Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationshipsNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), GV.SC-06

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

7
laws
7
places
0
with court rulings behind them
0
not yet in force
  • Alaska
  • Czech Republic
  • European Union
  • Hawaii
  • North Carolina
  • Tunisia
  • Turkey

Sector security regimes

3 laws, 3 places
PlaceLawWhat it asks, as read here
Czech Republic Cybersecurity Act (Zákon o kybernetické bezpečnosti), Risk-Management Security Measures

Where a supplier implements a security measure on your behalf, select that supplier consistent with the measure's requirements and write those requirements into your contract with the supplier.

European Union DORA, Articles 28-30 (ICT Third-Party Risk Management)

Before entering into an ICT services contract, assess whether it supports a critical or important function, whether supervisory conditions for contracting are met, and the concentration risk under Article 29, including whether the provider is easily substitutable and whether you already rely on it, or a closely connected provider, for other critical functions.

Tunisia Mandatory Security Audit and Digital-Trust Classification

Where you host a governmental electronic system or service, do so only with a hosting or cloud provider holding the government-cloud or national-cloud label, or expect the same consequence your other Article 6 failures draw.

Security baseline statutes

3 laws, 3 places
PlaceLawWhat it asks, as read here
Alaska Alaska Personal Information Protection Act, disposal of records duty

Before contracting with a third party to destroy records, complete due diligence, such as reviewing an independent audit of the third party's operations, checking references or trade-association certification, or reviewing the third party's own information security policies and procedures.

Hawaii Destruction of Personal Information Records

Where a records-destruction vendor is contracted to destroy personal information, satisfy this duty by exercising due diligence: reviewing an independent audit of the vendor's operations or compliance, obtaining reliable information about the vendor or requiring the vendor be certified by a recognized trade association, or reviewing and evaluating the vendor's information security policies and procedures.

North Carolina Identity Theft Protection Act, destruction of personal information records

Where a records-destruction vendor is used, conduct due diligence before contracting with it, such as reviewing an independent audit of the vendor's operations, checking its trade certification, or evaluating its information-security procedures, and monitor its ongoing compliance.

Vulnerability and incident reporting

1 law, 1 place
PlaceLawWhat it asks, as read here
Turkey Cybersecurity Law, Reporting and Cooperation Duties

Where cybersecurity products, systems, or services are procured for use in a public institution or in critical infrastructure, source them only from a provider the Directorate has certified or authorized.

Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.