Law / Frameworks / NIST CSF 2.0 / Identify
NIST CSF 2.0, IdentifyID.AM-07
Inventories of data and corresponding metadata for designated data types are maintainedNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), ID.AM-07
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 1
- law
- 1
- place
- 0
- with court rulings behind them
- 0
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 1.1 Legal and regulatory requirements involving AI are understood, managed, and documented.
- NIST AI RMFGOVERN 1.4 The risk management process and its outcomes are established through transparent...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-07 Human-AI Configuration
- OWASP LLM Top 10LLM03:2026 Excessive Agency
- OWASP Agentic Top 10ASI09 Human-Agent Trust Exploitation
- MIT mitigations3.2 Data Governance
- MIT mitigations4.1 System Documentation
- NIST Privacy FrameworkGV.PO-P1 Organizational privacy values and policies (e.g., conditions on data processing such...
- NIST Privacy FrameworkCT.PO-P2 Policies, processes, and procedures for enabling data review, transfer, sharing or...
Security baseline statutes
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Data Classification Policy |
Classify all digital data you process, store, modify, or transfer into at least four sensitivity tiers (Public Data, Private Insensitive Data, Private Sensitive Data, Highly Sensitive Data) and label it accordingly. Maintain a unified data catalog with metadata describing your classified data, and review the classification periodically. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.