Law / Frameworks / NIST CSF 2.0 / Identify
NIST CSF 2.0, IdentifyID.AM-08
Systems, hardware, software, services, and data are managed throughout their life cyclesNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), ID.AM-08
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 25
- laws
- 25
- places
- 0
- with court rulings behind them
- 3
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI 600-1GAI-RISK-04 Data Privacy
- MIT mitigations3.2 Data Governance
- MIT mitigations4.1 System Documentation
- NIST Privacy FrameworkGV.PO-P1 Organizational privacy values and policies (e.g., conditions on data processing such...
- NIST Privacy FrameworkCT.PO-P2 Policies, processes, and procedures for enabling data review, transfer, sharing or...
A law in force is unmarked; the rest wear their state: not yet in force
Security baseline statutes
25 laws, 25 places| Place | Law | What it asks, as read here |
|---|---|---|
| Data Breach Notification Act, reasonable security measures and disposal of records |
Take reasonable measures to dispose, or arrange for the disposal, of records containing sensitive personally identifying information within its custody or control once the records are no longer to be retained, by shredding, erasing, or otherwise modifying the information to make it unreadable or undecipherable through any reasonable means consistent with industry standards. |
|
| Alaska Personal Information Protection Act, disposal of records duty |
When disposing of records containing personal information, take all reasonable measures necessary to protect against unauthorized access to or use of the records, including burning, pulverizing, or shredding paper documents and destroying or erasing electronic and nonpaper media so the personal information cannot practicably be read or reconstructed. Adopt written policies and procedures relating to the adequate destruction and proper disposal of records containing personal information. |
|
| Discarding and disposing of records containing personal identifying information |
Redact that personal identifying information, or destroy the paper record or document, before discarding or disposing of it. This duty reaches paper records and documents only; it states no separate duty over electronic data. |
|
| Disposal of personal identifying information, written policy duty |
Develop a written policy for the destruction or proper disposal of paper and electronic documents containing personal identifying information, and, once those documents are no longer needed, destroy or arrange for their destruction by shredding, erasing, or otherwise modifying the personal identifying information to make it unreadable or indecipherable. |
|
| Protection of Social Security Numbers and Personal Information Act, safeguarding and destruction duty |
Safeguard the data, computer files and documents containing that personal information from misuse by third parties, and destroy, erase or make them unreadable before disposal. |
|
| Security requirements for personal information (Security Breach Protection Amendment Act of 2020) |
When destroying records that contain personal information, including computerized or electronic records and devices, take reasonable steps to protect against unauthorized access to or use of the information, considering the sensitivity of the records, your own nature and size, the costs and benefits of different destruction methods, and available technology. |
|
| Florida Information Protection Act, data security and disposal duty |
Take all reasonable measures to dispose, or arrange for the disposal, of customer records containing personal information within your custody or control once the records are no longer to be retained, by shredding, erasing, or otherwise modifying the personal information to make it unreadable or undecipherable through any means. |
|
| Disposal of records containing personal information |
Shred the record, erase the personal information, modify the record to make the personal information unreadable, or take other action you reasonably believe will ensure that no unauthorized person will have access to the personal information, before discarding or disposing of a customer's record. Personal information here is personally identifiable data about a customer's medical condition, account or credit balance, information supplied on opening an account or applying for credit, or a tax return, combined with an identifier such as a Social Security number, driver license number, or date of birth. |
|
| Destruction of Personal Information Records |
Take reasonable measures to protect against unauthorized access to or use of personal information in connection with or after its disposal. Implement and monitor compliance with policies and procedures that require papers containing personal information to be burned, pulverized, recycled, or shredded, and electronic or other nonpaper media containing personal information to be destroyed or erased, so the information cannot practicably be read or reconstructed. +1 more |
|
| Personal Information Protection Act, safe disposal of personal information |
Dispose of paper records containing personal information by redacting, burning, pulverizing, or shredding them, and destroy or erase electronic media containing personal information, so the information cannot practicably be read or reconstructed. |
Show the other 15 laws
| Disclosure of Security Breach Act, data base owner's duty to maintain reasonable security procedures and dispose of records from a date not yet set |
Do not dispose of or abandon records or documents containing unencrypted and unredacted personal information of Indiana residents without shredding, incinerating, mutilating, erasing, or otherwise rendering the information illegible or unusable. |
|
| Kansas Consumer Protection Act, reasonable security and records-destruction duty for holders of personal information |
Unless a federal law or regulation requires otherwise, destroy or arrange for the destruction of records containing personal information once you no longer intend to maintain or possess them, by shredding, erasing, or otherwise rendering the personal information unreadable or undecipherable. |
|
| Data Classification Policy |
Transfer or remove Tier 3 and Tier 4 data from a data center's or server's storage before decommissioning that equipment. |
|
| Database Security Breach Notification Law, reasonable security procedures and destruction duty |
Take all reasonable steps to destroy or arrange for the destruction of records containing personal information no longer to be retained, by shredding, erasing, or otherwise modifying the information to make it unreadable or undecipherable. |
|
| Maryland Personal Information Protection Act (MPIPA), safeguards and secure-disposal duty |
When destroying a customer's, an employee's, or a former employee's records containing personal information, take reasonable steps to protect against unauthorized access to or use of that information, weighing the sensitivity of the records, the size of the business, the cost of different destruction methods, and available technology. |
|
| Identity Theft Protection Act, destruction of data no longer needed |
Destroy, or arrange for the destruction of, any data containing personal information about an individual once that data is removed from the database and is not being retained elsewhere for a purpose state or federal law does not prohibit; retaining the data for an investigation, audit, or internal review does not violate this duty. Destroy the data by shredding, erasing, or otherwise modifying it so it cannot be read, deciphered, or reconstructed through generally available means. |
|
| Financial Data Protection and Consumer Notification of Data Security Breach Act, security procedures and practices duty |
Implement and maintain reasonable security procedures and practices appropriate to the nature and sensitivity of the personal information held and to the nature, size, and resources of the business and its operations, including safeguards that protect the information when it is disposed of. |
|
| Identity Theft Prevention Act, methods of destruction of customer records |
Destroy, or arrange for the destruction of, a customer's records containing personal information once they are no longer retained, by shredding, erasing, or otherwise modifying the personal information to make it unreadable, undecipherable, or non-reconstructable through generally available means. |
|
| Data Breach Notification Act, security and disposal duties from a date not yet set |
Arrange for proper disposal, shredding, erasing, or otherwise rendering the information unreadable or undecipherable, of records containing personal identifying information once they are no longer reasonably needed for business purposes. |
|
| Identity Theft Protection Act, destruction of personal information records |
Take reasonable measures to protect against unauthorized access to or use of personal information in connection with or after its disposal: burn, pulverize, or shred paper records, and destroy or erase electronic and other nonpaper media, so the information cannot practicably be read or reconstructed, under written policies that describe the destruction procedure and are monitored for compliance. |
|
| Oregon Consumer Information Protection Act, requirement to develop safeguards for personal information |
Develop, implement and maintain reasonable administrative, technical and physical safeguards to protect the security, confidentiality and integrity of personal information, including its secure disposal. |
|
| Identity Theft Protection Act of 2015, risk-based information security program from a date not yet set |
Do not retain personal information longer than reasonably required to provide the requested services, meet the purpose for which it was collected, or comply with a written retention policy or a legal requirement; destroy it securely, for example by shredding, pulverization, incineration, or erasure, regardless of the medium it is stored in. |
|
| Identity Theft Enforcement and Protection Act, business duty to protect sensitive personal information |
Destroy or arrange for the destruction of customer records containing sensitive personal information no longer to be retained, by shredding, erasing, or otherwise modifying the information to make it unreadable or indecipherable through any means. |
|
| Protection of Personal Information Act, reasonable procedures and records-destruction duty |
Destroy, or arrange for the destruction of, records containing personal information that are not to be retained, by the method the section specifies. |
|
| Document Safe Destruction Act, safe destruction of records containing personal information |
Take all reasonable steps to destroy or arrange for the destruction of a customer's records containing personal information once the business no longer retains them, by shredding, erasing or otherwise modifying the information to make it unreadable or indecipherable through any means. An entity in the business of disposing of personal financial information on another business's behalf must implement and monitor policies and procedures that protect against unauthorized access to or use of the information during and after its collection, transportation and disposal. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.