Law / Frameworks / NIST CSF 2.0 / Identify

NIST CSF 2.0, IdentifyID.IM-04

Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improvedNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), ID.IM-04

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

12
laws
10
places
0
with court rulings behind them
1
not yet in force

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force

  • Angola
  • Democratic Republic of the Congo
  • Haiti
  • Iceland
  • Latvia
  • Taiwan
  • Tonga
  • Tunisia
  • Uzbekistan
  • Vietnam

Sector security regimes

7 laws, 7 places
PlaceLawWhat it asks, as read here
Angola Lei de Protecção das Redes e Sistemas Informáticos, Security Duties for Information-Society Systems, Computer Programs and Databases

Where you operate or provide an internet service, promote user registration and carry out the measures and instruments needed to anticipate, detect, react to and recover from security risk situations on your networks (Article 14).

Democratic Republic of the Congo Digital Code, Livre II: Trust Service Provider Security Risk-Management Duty

Prevent and limit the consequences of security incidents, inform the parties concerned of the harmful effects of such incidents, and ensure the continuity of your services in the event of technical failures or cessation of activity.

Haiti BRH Circulaire 126, Information Security Rules for Financial Institutions

Develop, test and maintain a risk-based contingency plan, including an offsite recovery center kept separate from your main site, and a regularly checked backup system.

Iceland Minimum Risk-Management and Preparedness Requirements for Critical Infrastructure

Maintain a documented incident-response plan and a business-continuity plan covering incident logging, root-cause analysis, restoration of normal operation, and prevention of recurrence, and operate an active internal-control system consistent with this Act and any sector-specific law.

Latvia Nacionālās kiberdrošības likums, Cybersecurity Risk-Management Measures

Draft a cyber-risk-management and ICT-business-continuity plan and give your staff regular training on carrying it out; the plan's required content and the minimum cybersecurity requirements your systems must meet are set by Cabinet Regulation No. 397 of , 'Minimālās kiberdrošības prasības'.

Taiwan Bank and Financial Holding Company Internal Control Rules, Dedicated Information Security Unit

Have the dedicated unit plan, manage and execute the information security system to control information security risk, supervise every unit's compliance with it, and build the mechanisms for cyber security protection, threat-intelligence assessment, and cyber security incident notification and response.

Tonga Cybersecurity Act 2025, Critical Infrastructure Operator Obligations from a date not yet set

Develop, maintain and implement policies, practices and procedures to detect, share information about, mitigate and respond to cybersecurity threats and incidents, communicate them to your staff, and keep records evidencing your compliance available to the Minister CPR on request.

Vulnerability and incident reporting

4 laws, 4 places
PlaceLawWhat it asks, as read here
Angola Lei de Protecção das Redes e Sistemas Informáticos, Incident-Management Planning, Alert Dissemination and CERT Coordination Duties

Before starting your activity, submit an accident-and-incident management plan to Angola's data protection regulator and to the body responsible for promoting the information society, for use in a computer emergency (Article 15(1)).

Taiwan Cyber Security Management Act, Cyber Security Incident Reporting

Establish a notification and response mechanism for a cyber security incident before one occurs.

Tunisia Cybersecurity Incident Reporting and Emergency Response

Create your own cybersecurity emergency response center, or join a public, sectoral or private one, and have it coordinate with the national emergency-response contact point.

Vietnam Cybersecurity Law, Incident Response and Reporting Duties

As an enterprise providing a service on a telecommunications network, the Internet, or another value-added service in cyberspace in Vietnam, warn users of the cybersecurity risks in the service and give guidance on preventive measures, and keep an emergency response plan ready to address cybersecurity weaknesses, risks and incidents.

Security baseline statutes

1 law, 1 place
PlaceLawWhat it asks, as read here
Uzbekistan Law on Cybersecurity, general cybersecurity duties on cybersecurity subjects

Maintain a functioning capability to respond to cybersecurity incidents, or use an outsourced provider with the State Security Service's authorization if you have none of your own.

Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.