Law / Frameworks / NIST CSF 2.0 / Identify
NIST CSF 2.0, IdentifyID.IM-04
Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improvedNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), ID.IM-04
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 12
- laws
- 10
- places
- 0
- with court rulings behind them
- 1
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 4.3 Organizational practices are in place to enable AI testing, identification of...
- NIST AI RMFMANAGE 4.1 Post-deployment AI system monitoring plans are implemented, including mechanisms for...
- NIST AI 600-1GAI-RISK-09 Information Security
- NIST AI 600-1GAI-RISK-04 Data Privacy
- OWASP LLM Top 10LLM01:2026 Prompt Injection
- OWASP LLM Top 10LLM02:2026 Sensitive Information Disclosure
- OWASP Agentic Top 10ASI01 Agent Goal Hijack
- OWASP Agentic Top 10ASI03 Identity and Privilege Abuse
- MIT mitigations3.6 Incident Response & Recovery
- MIT mitigations4.3 Incident Reporting
- NIST Privacy FrameworkPR.PO-P7 Response plans (Incident Response and Business Continuity) and recovery plans...
- NIST Privacy FrameworkCM.AW-P7 Impacted individuals and organizations are notified about a privacy breach or event.
A law in force is unmarked; the rest wear their state: not yet in force
Sector security regimes
7 laws, 7 places| Place | Law | What it asks, as read here |
|---|---|---|
| Lei de Protecção das Redes e Sistemas Informáticos, Security Duties for Information-Society Systems, Computer Programs and Databases |
Where you operate or provide an internet service, promote user registration and carry out the measures and instruments needed to anticipate, detect, react to and recover from security risk situations on your networks (Article 14). |
|
| Digital Code, Livre II: Trust Service Provider Security Risk-Management Duty |
Prevent and limit the consequences of security incidents, inform the parties concerned of the harmful effects of such incidents, and ensure the continuity of your services in the event of technical failures or cessation of activity. |
|
| BRH Circulaire 126, Information Security Rules for Financial Institutions |
Develop, test and maintain a risk-based contingency plan, including an offsite recovery center kept separate from your main site, and a regularly checked backup system. |
|
| Minimum Risk-Management and Preparedness Requirements for Critical Infrastructure |
Maintain a documented incident-response plan and a business-continuity plan covering incident logging, root-cause analysis, restoration of normal operation, and prevention of recurrence, and operate an active internal-control system consistent with this Act and any sector-specific law. |
|
| Nacionālās kiberdrošības likums, Cybersecurity Risk-Management Measures |
Draft a cyber-risk-management and ICT-business-continuity plan and give your staff regular training on carrying it out; the plan's required content and the minimum cybersecurity requirements your systems must meet are set by Cabinet Regulation No. 397 of , 'Minimālās kiberdrošības prasības'. |
|
| Bank and Financial Holding Company Internal Control Rules, Dedicated Information Security Unit |
Have the dedicated unit plan, manage and execute the information security system to control information security risk, supervise every unit's compliance with it, and build the mechanisms for cyber security protection, threat-intelligence assessment, and cyber security incident notification and response. |
|
| Cybersecurity Act 2025, Critical Infrastructure Operator Obligations from a date not yet set |
Develop, maintain and implement policies, practices and procedures to detect, share information about, mitigate and respond to cybersecurity threats and incidents, communicate them to your staff, and keep records evidencing your compliance available to the Minister CPR on request. |
Vulnerability and incident reporting
4 laws, 4 places| Place | Law | What it asks, as read here |
|---|---|---|
| Lei de Protecção das Redes e Sistemas Informáticos, Incident-Management Planning, Alert Dissemination and CERT Coordination Duties |
Before starting your activity, submit an accident-and-incident management plan to Angola's data protection regulator and to the body responsible for promoting the information society, for use in a computer emergency (Article 15(1)). |
|
| Cyber Security Management Act, Cyber Security Incident Reporting |
Establish a notification and response mechanism for a cyber security incident before one occurs. |
|
| Cybersecurity Incident Reporting and Emergency Response |
Create your own cybersecurity emergency response center, or join a public, sectoral or private one, and have it coordinate with the national emergency-response contact point. |
|
| Cybersecurity Law, Incident Response and Reporting Duties |
As an enterprise providing a service on a telecommunications network, the Internet, or another value-added service in cyberspace in Vietnam, warn users of the cybersecurity risks in the service and give guidance on preventive measures, and keep an emergency response plan ready to address cybersecurity weaknesses, risks and incidents. |
Security baseline statutes
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Law on Cybersecurity, general cybersecurity duties on cybersecurity subjects |
Maintain a functioning capability to respond to cybersecurity incidents, or use an outsourced provider with the State Security Service's authorization if you have none of your own. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.