Law / Frameworks / NIST CSF 2.0 / Identify

NIST CSF 2.0, IdentifyID.RA-05

Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritizationNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), ID.RA-05

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

19
laws
19
places
0
with court rulings behind them
2
not yet in force
3
proposed, not law

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force proposed

  • Côte d'Ivoire
  • Estonia
  • Ethiopia
  • Finland
  • France
  • Iceland
  • Israel
  • Kiribati
  • Kosovo
  • Marshall Islands
  • Massachusetts
  • Michigan
  • Micronesia
  • Morocco
  • New York
  • Romania
  • Serbia
  • Spain
  • Utah

Sector security regimes

14 laws, 14 places
PlaceLawWhat it asks, as read here
Côte d'Ivoire RGSSI and PPIC Compliance Duty

Where you are designated and notified as a critical-infrastructure operator or manager, renew a complete risk analysis of your critical infrastructure at least every six months and designate a cybersecurity focal point, a designation this vocabulary does not separately express.

Estonia Küberturvalisuse seadus (KüTS), System Security Measures and Management-Body Duties

Account for your own needs and security requirements, current European and international standards where relevant, the cost of the measures, their proportionality to your risk exposure and to the likelihood and severity of a cyber incident including its societal and economic impact, and a systemic, comprehensive approach that protects both the systems and their physical environment.

Ethiopia Critical Infrastructure Cybersecurity Proclamation, Critical Infrastructure Owner Obligations from , in 10 months

Conduct regular cybersecurity risk assessments and impact analyses, participate in the Administration's annual National Cybersecurity Risk Survey and supply the information it requests, and obtain and renew a cyber audit certificate and a cybersecurity inspection-and-evaluation certificate from the Administration, taking appropriate corrective action within the time the Administration sets on any gap the audit or inspection finds.

Finland Kyberturvallisuuslaki, Cybersecurity Risk-Management Measures and Governance

Identify, assess and manage the risks to the network and information systems you use in your operations or to provide your services, and act to prevent or minimise an incident's impact on your operations, their continuity, the recipients of your services and other services.

France Loi n° 2018-133 du 26 février 2018 (transposition NIS1), Security Requirements

Identify the risks that threaten the security of the networks and information systems you use to provide your services in the European Union, and take the necessary and proportionate technical and organisational measures to manage those risks, prevent an incident from compromising your networks and systems, and minimise its impact, so as to guarantee the continuity of your services.

Iceland Minimum Risk-Management and Preparedness Requirements for Critical Infrastructure

Maintain a documented security policy and risk-management process, assess and re-assess risk on a regular basis, and put in place technical and organisational security measures, including access control, tested regularly against current international best practice.

Kiribati Cybersecurity Act 2026, Critical Infrastructure Operator Obligations from a date not yet set

Comply with cybersecurity standards the DTO issues, submit to its periodic or ad hoc audits, inspections and penetration testing, and conduct and submit periodic cybersecurity assessments of the infrastructure's risk, vulnerability and preparedness.

Kosovo Law No. 08/L-173 on Cyber Security, Security Measures

As a digital service provider, identify the risks to the security of your network and information systems, analyze them, and take adequate organizational and technical measures to manage that risk.

Marshall Islands Cybersecurity Act 2025, Cybersecurity of Critical Information Infrastructure

At minimum: conduct rolling cybersecurity risk assessments at a frequency the Chief Information Security Officer prescribes; develop and implement internal cybersecurity policies and procedures, an internal incident-reporting policy, and an internal cybersecurity awareness program; and transmit the resulting mitigation actions to the Director within thirty days of completing each risk assessment.

Micronesia FSM Cybersecurity Act 2025 (Bill), Critical Information Infrastructure Risk-Management Duties proposed

Conduct a cybersecurity risk assessment of that infrastructure at least every two years, and maintain an internal cybersecurity policy, an internal cybersecurity incident-reporting policy, and an internal cybersecurity awareness program.

Show the other 4 laws
Morocco Loi n° 05-20 relative à la cybersécurité, Digital Service Provider and Platform Operator Security Duties

If you are a digital service provider, identify the risks threatening the security of your own networks and information systems, and take the technical and organizational measures needed to manage those risks, avoid incidents, and minimize their impact, so as to guarantee the continuity of your services.

Romania Ordonanța de urgență nr. 155/2024, Cybersecurity Risk-Management Measures

Take technical, operational and organisational measures proportionate to your risk exposure to identify, assess and manage the risks to the network and information systems you use in your operations or to provide your services.

Serbia Law on Information Security, ICT Systems of Special Importance and Security Measures

Adopt a risk-assessment act for the ICT system you operate, covering your exposure to risk, your size as an operator, the likelihood and severity of an incident, and its potential social and economic impact, and revise the act at least once a year.

Spain Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad, Cybersecurity Risk-Management Measures proposed

Expect a duty, once enacted, to carry out an individualised risk assessment and put in place technical, operational and organisational measures, proportionate to the risk, to secure the networks and information systems you use and to prevent or minimise the impact of an incident.

Security baseline statutes

5 laws, 5 places
PlaceLawWhat it asks, as read here
Israel Privacy Protection Regulations (Data Security), information security programme

At the high tier, conduct a data security risk assessment and a penetration test of the database's systems at least once every 18 months, and hold a quarterly internal discussion of security incidents.

Massachusetts Standards for the Protection of Personal Information of Residents of the Commonwealth

Designate one or more employees to maintain the WISP; identify and assess foreseeable internal and external risks to personal information and evaluate whether your safeguards limit them; train employees; discipline violations; cut off a terminated employee's access to records; restrict and secure physical access to records; review the WISP's scope at least annually or after a material change in business practice; document your response to any security-breach incident; and select only third-party service providers capable of maintaining appropriate security measures, requiring those measures by contract.

Michigan Senate Bill 360 (2025-2026), Identity Theft Protection Act reasonable security procedures duty proposed

If enacted as passed by the Senate, this would require a person (any private entity) or agency (a Michigan state government unit) that owns, possesses, collects, or accesses personal information to implement and maintain reasonable security procedures: designate a security coordinator, identify internal and external risks, include appropriate safeguards addressing those risks, assess the safeguards' effectiveness, contractually require every service provider to maintain safeguards conforming to the NIST Cybersecurity Framework 2.0 or another industry-standard framework, and evaluate and adjust the procedures for changed circumstances.

New York Stop Hacks and Improve Electronic Data Security (SHIELD) Act, data security program duty

Absent that safe harbor, develop, implement, and maintain a data security program with reasonable administrative safeguards (a designated coordinator, a risk assessment, employee training, vetted service-provider contracts, and periodic adjustment), reasonable technical safeguards (assessing network and software design risk, detecting and responding to attacks, and testing controls), and reasonable physical safeguards (securing storage and disposal and limiting access during and after collection).

Utah Cybersecurity Affirmative Defense Act

Build the program as a reasonable security program, a designated coordinator, procedures to detect, prevent and respond to a breach, employee training, and periodic risk assessments of network and software design, information handling, and data storage and disposal, adjusted as circumstances change, or have it reasonably conform to a current named framework: NIST SP 800-171; NIST SP 800-53 and 800-53A; the FedRAMP Security Assessment Framework; the CIS Critical Security Controls; the ISO/IEC 27000 family; the HIPAA Security Rule or Gramm-Leach-Bliley Title V regulations for information those regimes cover; or the PCI Data Security Standard for payment card information.

Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.