Law / Frameworks / NIST CSF 2.0 / Identify
NIST CSF 2.0, IdentifyID.IM-02
Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third partiesNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), ID.IM-02
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 1
- law
- 1
- place
- 0
- with court rulings behind them
- 0
- not yet in force
Security baseline statutes
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Privacy Protection Regulations (Data Security), information security programme |
At the high tier, conduct a data security risk assessment and a penetration test of the database's systems at least once every 18 months, and hold a quarterly internal discussion of security incidents. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.