Law / Frameworks / NIST CSF 2.0 / Identify

NIST CSF 2.0, IdentifyID.AM-05

Assets are prioritized based on classification, criticality, resources, and impact on the missionNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), ID.AM-05

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

4
laws
4
places
0
with court rulings behind them
1
not yet in force

A law in force is unmarked; the rest wear their state: not yet in force

  • Ethiopia
  • Hungary
  • Taiwan
  • Vietnam

Sector security regimes

3 laws, 3 places
PlaceLawWhat it asks, as read here
Ethiopia Critical Infrastructure Cybersecurity Proclamation, Critical Infrastructure Owner Obligations from , in 10 months

Formulate and implement your own cybersecurity program and cybersecurity framework consistent with the mandatory national cybersecurity frameworks the Administration issues, classify and protect your critical assets to the Administration's standard, create the cybersecurity organizational structure the national framework calls for, and establish and manage a center responsible for monitoring, reporting, and responding to cyberattacks.

Hungary Cybersecurity Act, Risk-Management Measures

Survey and register every electronic information system, central service and supporting system you use, appoint or designate the person responsible for the security of those systems, classify them into a security category, and apply protective measures proportionate to their risk.

Taiwan Cyber Security Management Act, Specific Non-Government Agency Cyber Security Management

Report to the competent authority for approval or recordation of the agency's assigned cyber security responsibility level, based on the sensitivity, volume and nature of the information the agency holds and the scale and nature of its information and communication systems.

Security baseline statutes

1 law, 1 place
PlaceLawWhat it asks, as read here
Vietnam Cybersecurity Law, Information System Classification and Protection Measures

Determine which of the five statutory levels your information system falls into, based on the damage an incident or a cybersecurity-law violation could cause to lawful rights and interests, public interests, social order and safety, or national security.

Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.