Law / Frameworks / NIST CSF 2.0 / Govern

NIST CSF 2.0, GovernGV.SC-07

The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationshipNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), GV.SC-07

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

4
laws
4
places
0
with court rulings behind them
1
not yet in force

A law in force is unmarked; the rest wear their state: not yet in force

  • Estonia
  • Israel
  • Kiribati
  • North Carolina

Sector security regimes

2 laws, 2 places
PlaceLawWhat it asks, as read here
Estonia Küberturvalisuse seadus (KüTS), System Security Measures and Management-Body Duties

Where you delegate management of your system to another person, or host it with another person, you remain responsible for ensuring that person applies the security measures.

Kiribati Cybersecurity Act 2026, Critical Infrastructure Operator Obligations from a date not yet set

Establish, implement and maintain a cybersecurity risk-management framework, and take reasonable contractual, technical and organisational measures to manage cybersecurity risk arising from your third-party suppliers, service providers and contractors.

Security baseline statutes

2 laws, 2 places
PlaceLawWhat it asks, as read here
Israel Privacy Protection Regulations (Data Security), information security programme

Where an external service provider is given access to the database, agree in writing on the data and systems it may access, its reporting and data-destruction duties, and monitor its compliance.

North Carolina Identity Theft Protection Act, destruction of personal information records

Where a records-destruction vendor is used, conduct due diligence before contracting with it, such as reviewing an independent audit of the vendor's operations, checking its trade certification, or evaluating its information-security procedures, and monitor its ongoing compliance.

Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.