Law / Frameworks / NIST CSF 2.0 / Identify
NIST CSF 2.0, IdentifyID.RA-05
Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritizationNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), ID.RA-05
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 19
- laws
- 19
- places
- 0
- with court rulings behind them
- 2
- not yet in force
- 3
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFMAP 1.1 Intended purposes, potentially beneficial uses, context-specific laws, norms and...
- NIST AI RMFMAP 5.1 Likelihood and magnitude of each identified impact (both potentially beneficial and...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- MIT mitigations1.2 Risk Management
- MIT mitigations1.7 Societal Impact Assessment
- NIST Privacy FrameworkID.IM-P8 Data processing is mapped, illustrating the data actions and associated data elements...
- NIST Privacy FrameworkID.RA-P1 Contextual factors related to the systems/products/services and the data actions are...
A law in force is unmarked; the rest wear their state: not yet in force proposed
Sector security regimes
14 laws, 14 places| Place | Law | What it asks, as read here |
|---|---|---|
| RGSSI and PPIC Compliance Duty |
Where you are designated and notified as a critical-infrastructure operator or manager, renew a complete risk analysis of your critical infrastructure at least every six months and designate a cybersecurity focal point, a designation this vocabulary does not separately express. |
|
| Küberturvalisuse seadus (KüTS), System Security Measures and Management-Body Duties |
Account for your own needs and security requirements, current European and international standards where relevant, the cost of the measures, their proportionality to your risk exposure and to the likelihood and severity of a cyber incident including its societal and economic impact, and a systemic, comprehensive approach that protects both the systems and their physical environment. |
|
| Critical Infrastructure Cybersecurity Proclamation, Critical Infrastructure Owner Obligations from , in 10 months |
Conduct regular cybersecurity risk assessments and impact analyses, participate in the Administration's annual National Cybersecurity Risk Survey and supply the information it requests, and obtain and renew a cyber audit certificate and a cybersecurity inspection-and-evaluation certificate from the Administration, taking appropriate corrective action within the time the Administration sets on any gap the audit or inspection finds. |
|
| Kyberturvallisuuslaki, Cybersecurity Risk-Management Measures and Governance |
Identify, assess and manage the risks to the network and information systems you use in your operations or to provide your services, and act to prevent or minimise an incident's impact on your operations, their continuity, the recipients of your services and other services. |
|
| Loi n° 2018-133 du 26 février 2018 (transposition NIS1), Security Requirements |
Identify the risks that threaten the security of the networks and information systems you use to provide your services in the European Union, and take the necessary and proportionate technical and organisational measures to manage those risks, prevent an incident from compromising your networks and systems, and minimise its impact, so as to guarantee the continuity of your services. |
|
| Minimum Risk-Management and Preparedness Requirements for Critical Infrastructure |
Maintain a documented security policy and risk-management process, assess and re-assess risk on a regular basis, and put in place technical and organisational security measures, including access control, tested regularly against current international best practice. |
|
| Cybersecurity Act 2026, Critical Infrastructure Operator Obligations from a date not yet set |
Comply with cybersecurity standards the DTO issues, submit to its periodic or ad hoc audits, inspections and penetration testing, and conduct and submit periodic cybersecurity assessments of the infrastructure's risk, vulnerability and preparedness. |
|
| Law No. 08/L-173 on Cyber Security, Security Measures |
As a digital service provider, identify the risks to the security of your network and information systems, analyze them, and take adequate organizational and technical measures to manage that risk. |
|
| Cybersecurity Act 2025, Cybersecurity of Critical Information Infrastructure |
At minimum: conduct rolling cybersecurity risk assessments at a frequency the Chief Information Security Officer prescribes; develop and implement internal cybersecurity policies and procedures, an internal incident-reporting policy, and an internal cybersecurity awareness program; and transmit the resulting mitigation actions to the Director within thirty days of completing each risk assessment. |
|
| FSM Cybersecurity Act 2025 (Bill), Critical Information Infrastructure Risk-Management Duties proposed |
Conduct a cybersecurity risk assessment of that infrastructure at least every two years, and maintain an internal cybersecurity policy, an internal cybersecurity incident-reporting policy, and an internal cybersecurity awareness program. |
Show the other 4 laws
| Loi n° 05-20 relative à la cybersécurité, Digital Service Provider and Platform Operator Security Duties |
If you are a digital service provider, identify the risks threatening the security of your own networks and information systems, and take the technical and organizational measures needed to manage those risks, avoid incidents, and minimize their impact, so as to guarantee the continuity of your services. |
|
| Ordonanța de urgență nr. 155/2024, Cybersecurity Risk-Management Measures |
Take technical, operational and organisational measures proportionate to your risk exposure to identify, assess and manage the risks to the network and information systems you use in your operations or to provide your services. |
|
| Law on Information Security, ICT Systems of Special Importance and Security Measures |
Adopt a risk-assessment act for the ICT system you operate, covering your exposure to risk, your size as an operator, the likelihood and severity of an incident, and its potential social and economic impact, and revise the act at least once a year. |
|
| Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad, Cybersecurity Risk-Management Measures proposed |
Expect a duty, once enacted, to carry out an individualised risk assessment and put in place technical, operational and organisational measures, proportionate to the risk, to secure the networks and information systems you use and to prevent or minimise the impact of an incident. |
Security baseline statutes
5 laws, 5 places| Place | Law | What it asks, as read here |
|---|---|---|
| Privacy Protection Regulations (Data Security), information security programme |
At the high tier, conduct a data security risk assessment and a penetration test of the database's systems at least once every 18 months, and hold a quarterly internal discussion of security incidents. |
|
| Standards for the Protection of Personal Information of Residents of the Commonwealth |
Designate one or more employees to maintain the WISP; identify and assess foreseeable internal and external risks to personal information and evaluate whether your safeguards limit them; train employees; discipline violations; cut off a terminated employee's access to records; restrict and secure physical access to records; review the WISP's scope at least annually or after a material change in business practice; document your response to any security-breach incident; and select only third-party service providers capable of maintaining appropriate security measures, requiring those measures by contract. |
|
| Senate Bill 360 (2025-2026), Identity Theft Protection Act reasonable security procedures duty proposed |
If enacted as passed by the Senate, this would require a person (any private entity) or agency (a Michigan state government unit) that owns, possesses, collects, or accesses personal information to implement and maintain reasonable security procedures: designate a security coordinator, identify internal and external risks, include appropriate safeguards addressing those risks, assess the safeguards' effectiveness, contractually require every service provider to maintain safeguards conforming to the NIST Cybersecurity Framework 2.0 or another industry-standard framework, and evaluate and adjust the procedures for changed circumstances. |
|
| Stop Hacks and Improve Electronic Data Security (SHIELD) Act, data security program duty |
Absent that safe harbor, develop, implement, and maintain a data security program with reasonable administrative safeguards (a designated coordinator, a risk assessment, employee training, vetted service-provider contracts, and periodic adjustment), reasonable technical safeguards (assessing network and software design risk, detecting and responding to attacks, and testing controls), and reasonable physical safeguards (securing storage and disposal and limiting access during and after collection). |
|
| Cybersecurity Affirmative Defense Act |
Build the program as a reasonable security program, a designated coordinator, procedures to detect, prevent and respond to a breach, employee training, and periodic risk assessments of network and software design, information handling, and data storage and disposal, adjusted as circumstances change, or have it reasonably conform to a current named framework: NIST SP 800-171; NIST SP 800-53 and 800-53A; the FedRAMP Security Assessment Framework; the CIS Critical Security Controls; the ISO/IEC 27000 family; the HIPAA Security Rule or Gramm-Leach-Bliley Title V regulations for information those regimes cover; or the PCI Data Security Standard for payment card information. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.