Law / Frameworks / NIST CSF 2.0 / Govern
NIST CSF 2.0, GovernGV.SC-07
The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationshipNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), GV.SC-07
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 4
- laws
- 4
- places
- 0
- with court rulings behind them
- 1
- not yet in force
A law in force is unmarked; the rest wear their state: not yet in force
Sector security regimes
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Küberturvalisuse seadus (KüTS), System Security Measures and Management-Body Duties |
Where you delegate management of your system to another person, or host it with another person, you remain responsible for ensuring that person applies the security measures. |
|
| Cybersecurity Act 2026, Critical Infrastructure Operator Obligations from a date not yet set |
Establish, implement and maintain a cybersecurity risk-management framework, and take reasonable contractual, technical and organisational measures to manage cybersecurity risk arising from your third-party suppliers, service providers and contractors. |
Security baseline statutes
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Privacy Protection Regulations (Data Security), information security programme |
Where an external service provider is given access to the database, agree in writing on the data and systems it may access, its reporting and data-destruction duties, and monitor its compliance. |
|
| Identity Theft Protection Act, destruction of personal information records |
Where a records-destruction vendor is used, conduct due diligence before contracting with it, such as reviewing an independent audit of the vendor's operations, checking its trade certification, or evaluating its information-security procedures, and monitor its ongoing compliance. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.