Law / Frameworks / NIST CSF 2.0 / Identify

NIST CSF 2.0, IdentifyID.AM-08

Systems, hardware, software, services, and data are managed throughout their life cyclesNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), ID.AM-08

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

25
laws
25
places
0
with court rulings behind them
3
not yet in force

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force

  • Alabama
  • Alaska
  • Arizona
  • Colorado
  • Connecticut
  • District of Columbia
  • Florida
  • Georgia
  • Hawaii
  • Illinois
  • Indiana
  • Kansas
  • Kuwait
  • Louisiana
  • Maryland
  • Michigan
  • Nebraska
  • New Jersey
  • New Mexico
  • North Carolina
  • Oregon
  • Rhode Island
  • Texas
  • Utah
  • Vermont

Security baseline statutes

25 laws, 25 places
PlaceLawWhat it asks, as read here
Alabama Data Breach Notification Act, reasonable security measures and disposal of records

Take reasonable measures to dispose, or arrange for the disposal, of records containing sensitive personally identifying information within its custody or control once the records are no longer to be retained, by shredding, erasing, or otherwise modifying the information to make it unreadable or undecipherable through any reasonable means consistent with industry standards.

Alaska Alaska Personal Information Protection Act, disposal of records duty

When disposing of records containing personal information, take all reasonable measures necessary to protect against unauthorized access to or use of the records, including burning, pulverizing, or shredding paper documents and destroying or erasing electronic and nonpaper media so the personal information cannot practicably be read or reconstructed.

Adopt written policies and procedures relating to the adequate destruction and proper disposal of records containing personal information.

Arizona Discarding and disposing of records containing personal identifying information

Redact that personal identifying information, or destroy the paper record or document, before discarding or disposing of it. This duty reaches paper records and documents only; it states no separate duty over electronic data.

Colorado Disposal of personal identifying information, written policy duty

Develop a written policy for the destruction or proper disposal of paper and electronic documents containing personal identifying information, and, once those documents are no longer needed, destroy or arrange for their destruction by shredding, erasing, or otherwise modifying the personal identifying information to make it unreadable or indecipherable.

Connecticut Protection of Social Security Numbers and Personal Information Act, safeguarding and destruction duty

Safeguard the data, computer files and documents containing that personal information from misuse by third parties, and destroy, erase or make them unreadable before disposal.

District of Columbia Security requirements for personal information (Security Breach Protection Amendment Act of 2020)

When destroying records that contain personal information, including computerized or electronic records and devices, take reasonable steps to protect against unauthorized access to or use of the information, considering the sensitivity of the records, your own nature and size, the costs and benefits of different destruction methods, and available technology.

Florida Florida Information Protection Act, data security and disposal duty

Take all reasonable measures to dispose, or arrange for the disposal, of customer records containing personal information within your custody or control once the records are no longer to be retained, by shredding, erasing, or otherwise modifying the personal information to make it unreadable or undecipherable through any means.

Georgia Disposal of records containing personal information

Shred the record, erase the personal information, modify the record to make the personal information unreadable, or take other action you reasonably believe will ensure that no unauthorized person will have access to the personal information, before discarding or disposing of a customer's record. Personal information here is personally identifiable data about a customer's medical condition, account or credit balance, information supplied on opening an account or applying for credit, or a tax return, combined with an identifier such as a Social Security number, driver license number, or date of birth.

Hawaii Destruction of Personal Information Records

Take reasonable measures to protect against unauthorized access to or use of personal information in connection with or after its disposal.

Implement and monitor compliance with policies and procedures that require papers containing personal information to be burned, pulverized, recycled, or shredded, and electronic or other nonpaper media containing personal information to be destroyed or erased, so the information cannot practicably be read or reconstructed.

+1 more
Illinois Personal Information Protection Act, safe disposal of personal information

Dispose of paper records containing personal information by redacting, burning, pulverizing, or shredding them, and destroy or erase electronic media containing personal information, so the information cannot practicably be read or reconstructed.

Show the other 15 laws
Indiana Disclosure of Security Breach Act, data base owner's duty to maintain reasonable security procedures and dispose of records from a date not yet set

Do not dispose of or abandon records or documents containing unencrypted and unredacted personal information of Indiana residents without shredding, incinerating, mutilating, erasing, or otherwise rendering the information illegible or unusable.

Kansas Kansas Consumer Protection Act, reasonable security and records-destruction duty for holders of personal information

Unless a federal law or regulation requires otherwise, destroy or arrange for the destruction of records containing personal information once you no longer intend to maintain or possess them, by shredding, erasing, or otherwise rendering the personal information unreadable or undecipherable.

Kuwait Data Classification Policy

Transfer or remove Tier 3 and Tier 4 data from a data center's or server's storage before decommissioning that equipment.

Louisiana Database Security Breach Notification Law, reasonable security procedures and destruction duty

Take all reasonable steps to destroy or arrange for the destruction of records containing personal information no longer to be retained, by shredding, erasing, or otherwise modifying the information to make it unreadable or undecipherable.

Maryland Maryland Personal Information Protection Act (MPIPA), safeguards and secure-disposal duty

When destroying a customer's, an employee's, or a former employee's records containing personal information, take reasonable steps to protect against unauthorized access to or use of that information, weighing the sensitivity of the records, the size of the business, the cost of different destruction methods, and available technology.

Michigan Identity Theft Protection Act, destruction of data no longer needed

Destroy, or arrange for the destruction of, any data containing personal information about an individual once that data is removed from the database and is not being retained elsewhere for a purpose state or federal law does not prohibit; retaining the data for an investigation, audit, or internal review does not violate this duty. Destroy the data by shredding, erasing, or otherwise modifying it so it cannot be read, deciphered, or reconstructed through generally available means.

Nebraska Financial Data Protection and Consumer Notification of Data Security Breach Act, security procedures and practices duty

Implement and maintain reasonable security procedures and practices appropriate to the nature and sensitivity of the personal information held and to the nature, size, and resources of the business and its operations, including safeguards that protect the information when it is disposed of.

New Jersey Identity Theft Prevention Act, methods of destruction of customer records

Destroy, or arrange for the destruction of, a customer's records containing personal information once they are no longer retained, by shredding, erasing, or otherwise modifying the personal information to make it unreadable, undecipherable, or non-reconstructable through generally available means.

New Mexico Data Breach Notification Act, security and disposal duties from a date not yet set

Arrange for proper disposal, shredding, erasing, or otherwise rendering the information unreadable or undecipherable, of records containing personal identifying information once they are no longer reasonably needed for business purposes.

North Carolina Identity Theft Protection Act, destruction of personal information records

Take reasonable measures to protect against unauthorized access to or use of personal information in connection with or after its disposal: burn, pulverize, or shred paper records, and destroy or erase electronic and other nonpaper media, so the information cannot practicably be read or reconstructed, under written policies that describe the destruction procedure and are monitored for compliance.

Oregon Oregon Consumer Information Protection Act, requirement to develop safeguards for personal information

Develop, implement and maintain reasonable administrative, technical and physical safeguards to protect the security, confidentiality and integrity of personal information, including its secure disposal.

Rhode Island Identity Theft Protection Act of 2015, risk-based information security program from a date not yet set

Do not retain personal information longer than reasonably required to provide the requested services, meet the purpose for which it was collected, or comply with a written retention policy or a legal requirement; destroy it securely, for example by shredding, pulverization, incineration, or erasure, regardless of the medium it is stored in.

Texas Identity Theft Enforcement and Protection Act, business duty to protect sensitive personal information

Destroy or arrange for the destruction of customer records containing sensitive personal information no longer to be retained, by shredding, erasing, or otherwise modifying the information to make it unreadable or indecipherable through any means.

Utah Protection of Personal Information Act, reasonable procedures and records-destruction duty

Destroy, or arrange for the destruction of, records containing personal information that are not to be retained, by the method the section specifies.

Vermont Document Safe Destruction Act, safe destruction of records containing personal information

Take all reasonable steps to destroy or arrange for the destruction of a customer's records containing personal information once the business no longer retains them, by shredding, erasing or otherwise modifying the information to make it unreadable or indecipherable through any means.

An entity in the business of disposing of personal financial information on another business's behalf must implement and monitor policies and procedures that protect against unauthorized access to or use of the information during and after its collection, transportation and disposal.

Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.