Law / Frameworks / NIST CSF 2.0 / Identify

NIST CSF 2.0, IdentifyID.IM-01

Improvements are identified from evaluationsNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), ID.IM-01

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

18
laws
16
places
0
with court rulings behind them
3
not yet in force

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force

  • Cameroon
  • Central African Republic
  • Côte d'Ivoire
  • Djibouti
  • Ethiopia
  • France
  • Haiti
  • Israel
  • Kiribati
  • Marshall Islands
  • Montenegro
  • New York
  • Serbia
  • Tonga
  • Tunisia
  • Ukraine

Sector security regimes

14 laws, 13 places
PlaceLawWhat it asks, as read here
Central African Republic Cybersecurity Law: Mandatory Security Audit Regime

Submit your networks or information systems to a mandatory security audit and severity-impact assessment by the Agence Nationale de la Cybersécurité at least once a year, or more often where circumstances require it.

Côte d'Ivoire Mandatory Information Systems Security Audit and Certification

Undergo a security audit for certification of your information system every three years, performed by ARTCI or by an ARTCI-accredited Prestataire d'Audit de Sécurité des Systèmes d'Information (PASSI).

Undergo a further mandatory periodic security audit eighteen months after your certificate is issued.

+1 more
Djibouti Digital Code, Book II: Electronic Communications Network and Service Security

Give the cybersecurity authority confidential access, on request, to the arrangements you have made to secure your network, and submit your network to a security and integrity inspection the authority conducts or commissions, at your own expense.

Djibouti Digital Code, Book VI: Critical Installation Protection and Operator Security Controls

Submit your information systems, at your own cost, to a control the cybersecurity authority conducts to verify their security level and your compliance with security rules.

Ethiopia Critical Infrastructure Cybersecurity Proclamation, Critical Infrastructure Owner Obligations from , in 10 months

Conduct regular cybersecurity risk assessments and impact analyses, participate in the Administration's annual National Cybersecurity Risk Survey and supply the information it requests, and obtain and renew a cyber audit certificate and a cybersecurity inspection-and-evaluation certificate from the Administration, taking appropriate corrective action within the time the Administration sets on any gap the audit or inspection finds.

France Loi n° 2022-309 du 3 mars 2022 (loi Cyberscore), Cybersecurity Audit and Disclosure Duty

Where a threshold decree brings you into scope, have a cybersecurity audit carried out by a provider ANSSI has qualified (a PASSI), covering the security and location of the data you host (directly or through a third party) and your own security.

Haiti BRH Circulaire 126, Information Security Rules for Financial Institutions

Have your information system's security audited at least once every three years, and attach a copy of the audit report to your annual internal-control report.

Kiribati Cybersecurity Act 2026, Critical Infrastructure Operator Obligations from a date not yet set

Comply with cybersecurity standards the DTO issues, submit to its periodic or ad hoc audits, inspections and penetration testing, and conduct and submit periodic cybersecurity assessments of the infrastructure's risk, vulnerability and preparedness.

Marshall Islands Cybersecurity Act 2025, Cybersecurity of Critical Information Infrastructure

Submit to a Director-ordered audit of your critical information infrastructure, at your own cost and no more than once every two years, where the Director has reason to believe you have not complied with the Act or with a technical standard applicable to you, or that information you supplied is false, misleading, or incomplete.

Montenegro Law on Information Security, Essential and Important Entities

If designated an essential entity, obtain a certificate of compliance with the Montenegrin standard MEST ISO/IEC 27001 from an accredited body within 30 months of , and request a periodic re-verification from that body afterward (Article 18(4) to (6) and Article 73).

Show the other 4 laws
Serbia Law on Information Security, ICT Systems of Special Importance and Security Measures

Adopt a security act built on that risk-assessment act, setting the principles, methods and procedures for reaching and keeping an adequate level of system security and the authority and responsibility for security and resources, and check your applied protection measures against it at least once a year, alone or with outside experts, producing a report on the check.

Tonga Cybersecurity Act 2025, Critical Infrastructure Operator Obligations from a date not yet set

Once designated, register with the Minister CPR, notify the Minister CPR of any change in your legal ownership or in the person or entity operating the infrastructure, and conduct and submit periodic cybersecurity self-assessments to the Ministry CPR in the form and manner it prescribes.

Tunisia Mandatory Security Audit and Digital-Trust Classification

Undergo a mandatory information-systems security audit, performed by an expert the National Cybersecurity Agency lists as authorized, at least once every twelve months.

Submit a protected electronic copy of the audit report to the Agency within ten days of the audit's completion, and implement every security recommendation the report contains.

Ukraine Law on the Basic Principles of Ensuring Cybersecurity, Critical Infrastructure Owner Cyber-Defense and Audit Duty

Organize an independent information-security audit of your critical infrastructure object, to the requirements the Cabinet of Ministers of Ukraine sets, or, where you are a bank, another financial-services-market participant the National Bank of Ukraine regulates and supervises, a payment-system operator or participant, or a payment-services technology operator, to the requirements the National Bank of Ukraine sets instead.

Security baseline statutes

3 laws, 3 places
PlaceLawWhat it asks, as read here
Cameroon Loi n°2010/012 du 21 décembre 2010 relative à la cybersécurité et à la cybercriminalité au Cameroun, articles 6, 7, 13-14, 24, 26-30, 32, 61(3) (mesures de sécurité et audit de sécurité obligatoire par l'ANTIC)

Evaluate and revise your security systems as technology evolves, and make the changes your security practices, measures, and techniques need.

Central African Republic Cybersecurity Law: Network and Information System Security Duty

Periodically evaluate and revise your security systems, and introduce necessary changes as technology evolves, under the Agence Nationale de la Cybersécurité's oversight.

Israel Privacy Protection Regulations (Data Security), information security programme

At the medium or high tier, conduct an internal or external audit of compliance with these Regulations at least once every 24 months.

Vulnerability and incident reporting

1 law, 1 place
PlaceLawWhat it asks, as read here
New York New York Department of Financial Services Cybersecurity Regulation, Notices to the Superintendent

By April 15 of each year, submit to the Superintendent electronically either a written certification that you materially complied with this Part for the prior calendar year or a written acknowledgment identifying the sections you did not materially comply with and a remediation timeline, each signed by your highest-ranking executive and your Chief Information Security Officer.

Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.