Law / Frameworks / NIST CSF 2.0 / Identify
NIST CSF 2.0, IdentifyID.RA-01
Vulnerabilities in assets are identified, validated, and recordedNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), ID.RA-01
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 1
- law
- 1
- place
- 0
- with court rulings behind them
- 0
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFMEASURE 2.5 The AI system to be deployed is demonstrated to be valid and reliable. Limitations of...
- NIST AI RMFMEASURE 2.6 The AI system is evaluated regularly for safety risks – as identified in the MAP...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-09 Information Security
- OWASP LLM Top 10LLM01:2026 Prompt Injection
- OWASP LLM Top 10LLM02:2026 Sensitive Information Disclosure
- OWASP Agentic Top 10ASI01 Agent Goal Hijack
- OWASP Agentic Top 10ASI03 Identity and Privilege Abuse
- MIT mitigations2.1 Model & Infrastructure Security
- MIT mitigations2.3 Model Safety Engineering
- NIST Privacy FrameworkPR.PO-P7 Response plans (Incident Response and Business Continuity) and recovery plans...
- NIST Privacy FrameworkPR.PO-P10 A vulnerability management plan is developed and implemented.
Product security requirements
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre VI (cybersécurité), sécurité des réseaux et essai de vulnérabilité des produits |
Before or while selling an information and communication technology product in Benin, have an independent security expert accredited by the ministry in charge of electronic communications carry out a vulnerability test and a security assurance evaluation of the product. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.