Law / Frameworks / NIST CSF 2.0 / Identify
NIST CSF 2.0, IdentifyID.RA-04
Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recordedNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), ID.RA-04
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 1
- law
- 1
- place
- 0
- with court rulings behind them
- 0
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFMAP 1.1 Intended purposes, potentially beneficial uses, context-specific laws, norms and...
- NIST AI RMFMAP 5.1 Likelihood and magnitude of each identified impact (both potentially beneficial and...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- MIT mitigations1.2 Risk Management
- MIT mitigations1.7 Societal Impact Assessment
- NIST Privacy FrameworkID.IM-P8 Data processing is mapped, illustrating the data actions and associated data elements...
- NIST Privacy FrameworkID.RA-P1 Contextual factors related to the systems/products/services and the data actions are...
Security baseline statutes
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Tort Liability for Cybersecurity Programs, affirmative defense for a reasonable security program |
To claim the defense against a tort claim alleging that a failure to implement reasonable information security controls resulted in a data breach of personal information or restricted information, create, maintain, and comply with a written cybersecurity program containing administrative, technical, operational, and physical safeguards, designed to continually evaluate and mitigate reasonably anticipated threats, evaluate the maximum probable loss from a data breach at least annually, and communicate to affected parties the extent of any risk and steps to reduce damages once a breach is known to have occurred. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.