Law / Frameworks / NIST CSF 2.0 / Identify
NIST CSF 2.0, IdentifyID.IM-01
Improvements are identified from evaluationsNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), ID.IM-01
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 18
- laws
- 16
- places
- 0
- with court rulings behind them
- 3
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFMAP 1.1 Intended purposes, potentially beneficial uses, context-specific laws, norms and...
- NIST AI RMFMAP 5.1 Likelihood and magnitude of each identified impact (both potentially beneficial and...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- MIT mitigations1.2 Risk Management
- MIT mitigations1.7 Societal Impact Assessment
- NIST Privacy FrameworkID.IM-P8 Data processing is mapped, illustrating the data actions and associated data elements...
- NIST Privacy FrameworkID.RA-P1 Contextual factors related to the systems/products/services and the data actions are...
A law in force is unmarked; the rest wear their state: not yet in force
Sector security regimes
14 laws, 13 places| Place | Law | What it asks, as read here |
|---|---|---|
| Cybersecurity Law: Mandatory Security Audit Regime |
Submit your networks or information systems to a mandatory security audit and severity-impact assessment by the Agence Nationale de la Cybersécurité at least once a year, or more often where circumstances require it. |
|
| Mandatory Information Systems Security Audit and Certification |
Undergo a security audit for certification of your information system every three years, performed by ARTCI or by an ARTCI-accredited Prestataire d'Audit de Sécurité des Systèmes d'Information (PASSI). Undergo a further mandatory periodic security audit eighteen months after your certificate is issued. +1 more |
|
| Digital Code, Book II: Electronic Communications Network and Service Security |
Give the cybersecurity authority confidential access, on request, to the arrangements you have made to secure your network, and submit your network to a security and integrity inspection the authority conducts or commissions, at your own expense. |
|
| Digital Code, Book VI: Critical Installation Protection and Operator Security Controls |
Submit your information systems, at your own cost, to a control the cybersecurity authority conducts to verify their security level and your compliance with security rules. |
|
| Critical Infrastructure Cybersecurity Proclamation, Critical Infrastructure Owner Obligations from , in 10 months |
Conduct regular cybersecurity risk assessments and impact analyses, participate in the Administration's annual National Cybersecurity Risk Survey and supply the information it requests, and obtain and renew a cyber audit certificate and a cybersecurity inspection-and-evaluation certificate from the Administration, taking appropriate corrective action within the time the Administration sets on any gap the audit or inspection finds. |
|
| Loi n° 2022-309 du 3 mars 2022 (loi Cyberscore), Cybersecurity Audit and Disclosure Duty |
Where a threshold decree brings you into scope, have a cybersecurity audit carried out by a provider ANSSI has qualified (a PASSI), covering the security and location of the data you host (directly or through a third party) and your own security. |
|
| BRH Circulaire 126, Information Security Rules for Financial Institutions |
Have your information system's security audited at least once every three years, and attach a copy of the audit report to your annual internal-control report. |
|
| Cybersecurity Act 2026, Critical Infrastructure Operator Obligations from a date not yet set |
Comply with cybersecurity standards the DTO issues, submit to its periodic or ad hoc audits, inspections and penetration testing, and conduct and submit periodic cybersecurity assessments of the infrastructure's risk, vulnerability and preparedness. |
|
| Cybersecurity Act 2025, Cybersecurity of Critical Information Infrastructure |
Submit to a Director-ordered audit of your critical information infrastructure, at your own cost and no more than once every two years, where the Director has reason to believe you have not complied with the Act or with a technical standard applicable to you, or that information you supplied is false, misleading, or incomplete. |
|
| Law on Information Security, Essential and Important Entities |
If designated an essential entity, obtain a certificate of compliance with the Montenegrin standard MEST ISO/IEC 27001 from an accredited body within 30 months of , and request a periodic re-verification from that body afterward (Article 18(4) to (6) and Article 73). |
Show the other 4 laws
| Law on Information Security, ICT Systems of Special Importance and Security Measures |
Adopt a security act built on that risk-assessment act, setting the principles, methods and procedures for reaching and keeping an adequate level of system security and the authority and responsibility for security and resources, and check your applied protection measures against it at least once a year, alone or with outside experts, producing a report on the check. |
|
| Cybersecurity Act 2025, Critical Infrastructure Operator Obligations from a date not yet set |
Once designated, register with the Minister CPR, notify the Minister CPR of any change in your legal ownership or in the person or entity operating the infrastructure, and conduct and submit periodic cybersecurity self-assessments to the Ministry CPR in the form and manner it prescribes. |
|
| Mandatory Security Audit and Digital-Trust Classification |
Undergo a mandatory information-systems security audit, performed by an expert the National Cybersecurity Agency lists as authorized, at least once every twelve months. Submit a protected electronic copy of the audit report to the Agency within ten days of the audit's completion, and implement every security recommendation the report contains. |
|
| Law on the Basic Principles of Ensuring Cybersecurity, Critical Infrastructure Owner Cyber-Defense and Audit Duty |
Organize an independent information-security audit of your critical infrastructure object, to the requirements the Cabinet of Ministers of Ukraine sets, or, where you are a bank, another financial-services-market participant the National Bank of Ukraine regulates and supervises, a payment-system operator or participant, or a payment-services technology operator, to the requirements the National Bank of Ukraine sets instead. |
Security baseline statutes
3 laws, 3 places| Place | Law | What it asks, as read here |
|---|---|---|
| Loi n°2010/012 du 21 décembre 2010 relative à la cybersécurité et à la cybercriminalité au Cameroun, articles 6, 7, 13-14, 24, 26-30, 32, 61(3) (mesures de sécurité et audit de sécurité obligatoire par l'ANTIC) |
Evaluate and revise your security systems as technology evolves, and make the changes your security practices, measures, and techniques need. |
|
| Cybersecurity Law: Network and Information System Security Duty |
Periodically evaluate and revise your security systems, and introduce necessary changes as technology evolves, under the Agence Nationale de la Cybersécurité's oversight. |
|
| Privacy Protection Regulations (Data Security), information security programme |
At the medium or high tier, conduct an internal or external audit of compliance with these Regulations at least once every 24 months. |
Vulnerability and incident reporting
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| New York Department of Financial Services Cybersecurity Regulation, Notices to the Superintendent |
By April 15 of each year, submit to the Superintendent electronically either a written certification that you materially complied with this Part for the prior calendar year or a written acknowledgment identifying the sections you did not materially comply with and a remediation timeline, each signed by your highest-ranking executive and your Chief Information Security Officer. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.