Law / Frameworks / NIST CSF 2.0 / Identify
NIST CSF 2.0, IdentifyID.AM-04
Inventories of services provided by suppliers are maintainedNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), ID.AM-04
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 1
- law
- 1
- place
- 0
- with court rulings behind them
- 0
- not yet in force
Sector security regimes
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| DORA, Articles 28-30 (ICT Third-Party Risk Management) |
Maintain and update a register of all your ICT services contracts, distinguishing those supporting a critical or important function, report on it at least yearly to your competent authority, and produce it in full on the authority's request. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.