Law / Frameworks / NIST CSF 2.0 / Identify

NIST CSF 2.0, IdentifyID.RA-06

Risk responses are chosen, prioritized, planned, tracked, and communicatedNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), ID.RA-06

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

34
laws
31
places
0
with court rulings behind them
1
not yet in force
4
proposed, not law

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force proposed

  • Austria
  • Belgium
  • Bulgaria
  • Cameroon
  • Central African Republic
  • China
  • Cyprus
  • Czech Republic
  • Democratic Republic of the Congo
  • Denmark
  • Djibouti
  • Estonia
  • Finland
  • France
  • Gabon
  • Gambia
  • Germany
  • Greece
  • Ireland
  • Italy
  • Kazakhstan
  • Latvia
  • Liechtenstein
  • Luxembourg
  • Marshall Islands
  • Micronesia
  • Morocco
  • Netherlands
  • Portugal
  • Spain
  • Sweden

Sector security regimes

29 laws, 26 places
PlaceLawWhat it asks, as read here
Austria Netz- und Informationssystemsicherheitsgesetz (NISG), Security Measures for Operators of Essential Services and Digital Service Providers

Take technical and organisational security measures for the network and information systems you use to provide the service, appropriate to the state of the art and proportionate to the risk that can be identified with reasonable effort.

Austria Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Cybersecurity Risk-Management Measures from , in 2 days

Implement technical, operational and organisational risk-management measures, appropriate and proportionate to the risk, to reduce risks to the network and information systems you use for your operations or to provide your services, and to prevent or minimise the impact of a cybersecurity incident on your users and on other services.

Belgium Loi du 26 avril 2024, Cybersecurity Risk-Management Measures and Governance

Take appropriate and proportionate technical, operational and organisational measures to manage the risks to the network and information systems you use in the course of your activities or to provide your services.

Bulgaria Cybersecurity Act, Risk-Management Measures and Governance (Zakon za kibersigurnost, ZKS)

Take appropriate and proportionate technical, operational and organisational measures to manage the risks to the security of the network and information systems you use in your core activity or in providing your services, sized to your exposure, your size, and the likelihood and severity of an incident.

Cyprus Security of Networks and Information Systems Law, Cybersecurity Risk-Management Measures and Governance

Take appropriate and proportionate technical, operational and organisational measures to manage the risks to the security of the network and information systems you use for your activities or to provide your services, proportionate to the risk, and to prevent or minimise the impact of an incident on the recipients of your services or on other services.

Czech Republic Cybersecurity Act (Zákon o kybernetické bezpečnosti), Risk-Management Security Measures

Adopt and implement organisational and technical security measures adequate and proportionate to securing the regulated service's proper provision and the cybersecurity of the assets you use to provide it, within a scope you determine and must regularly review.

Democratic Republic of the Congo Digital Code, Livre II: Trust Service Provider Security Risk-Management Duty

Take the technical and organizational measures necessary to prevent and manage the risks to the security of the trust services you provide, keeping the level of security proportional to the degree of risk given technological developments.

Denmark NIS 2-loven, Cybersecurity Risk-Management Measures and Registration

Take appropriate and proportionate technical, operational and organisational measures to manage the risks to the network and information systems you use for your operations or to provide your services, and to prevent an incident or minimise its impact on the recipients of your services and on other services.

Where you fall short of any of these requirements, take without undue delay all necessary, appropriate and proportionate corrective measures.

Djibouti Digital Code, Book II: Electronic Communications Network and Service Security

Take all technical and organizational measures necessary to secure your network and services at a level adapted to the existing risk, and comply with the technical security prescriptions the national cybersecurity authority issues.

Estonia Küberturvalisuse seadus (KüTS), System Security Measures and Management-Body Duties

Apply, on an ongoing basis, appropriate and proportionate technical, operational and organisational security measures, built on your own risk analysis, to manage the risks to the system you use in your activities or to provide your service, to prevent or minimise a cyber incident's impact on your service's recipients and on other services, and to prevent, detect or resolve a cyber incident.

Show the other 19 laws
Finland Kyberturvallisuuslaki, Cybersecurity Risk-Management Measures and Governance

Identify, assess and manage the risks to the network and information systems you use in your operations or to provide your services, and act to prevent or minimise an incident's impact on your operations, their continuity, the recipients of your services and other services.

France Loi n° 2018-133 du 26 février 2018 (transposition NIS1), Security Requirements

Identify the risks that threaten the security of the networks and information systems you use to provide your services in the European Union, and take the necessary and proportionate technical and organisational measures to manage those risks, prevent an incident from compromising your networks and systems, and minimise its impact, so as to guarantee the continuity of your services.

France Projet de loi Résilience des Infrastructures Critiques et Cybersécurité, Cybersecurity Risk-Management Measures (NIS2) proposed

Take technical, operational and organisational measures appropriate and proportionate to the risks facing the network and information systems you use for your activities or services: have your management body approve and oversee the security measures and receive cybersecurity training, protect your networks and systems including where you use a subcontractor, put in place tools and procedures to defend your networks and handle incidents, and ensure the resilience of your activities.

Gambia Information and Communications Act, 2009, security of information and communications services (safeguards duty)

Make those measures sufficient, having regard to best practices and their cost, to give a level of security appropriate to the risk your services present.

Germany BSI-Gesetz (BSIG), Risk-Management Measures for Essential and Important Entities

Adopt technical and organisational measures adequate and proportionate to the risks facing the network and information systems you use to provide your services, and to minimise the impact of a security incident on your services and on others.

Greece Law 5160/2024, Cybersecurity Risk-Management Measures and Governance

Take appropriate and proportionate technical, operational and organisational measures to manage the risks to the network and information systems you use for your activities or to provide your services, and to prevent or minimise the impact of an incident on the recipients of your services or on other services.

Ireland European Union (NIS) Regulations 2018, Security Requirements

Take appropriate and proportionate technical and organisational measures, having regard to the state of the art, to manage the risks to the network and information systems you use and to prevent or minimise the impact of an incident on the continuity of your service.

Ireland National Cyber Security Bill, Cybersecurity Risk-Management Measures proposed

Take appropriate and proportionate technical, operational and organisational measures to manage the risks to the network and information systems you use for your operations or services, with your management board approving and overseeing those measures.

Italy Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Risk-Management Measures

Adopt technical, operational and organisational measures adequate and proportionate to the risks facing the network and information systems you use in your activities or in providing your services, and to prevent or minimise the impact of an incident on the recipients of your services and on other services.

Latvia Nacionālās kiberdrošības likums, Cybersecurity Risk-Management Measures

Take appropriate and proportionate technical and organisational measures to manage the cyber risks to the security of the electronic communications networks and information systems you use, and to prevent or minimise to the greatest extent possible the impact of a cyber incident on your service recipients and on other services.

Liechtenstein Cyber-Sicherheitsgesetz (CSG), Risk-Management Measures for Essential and Important Entities

Take technical, operational and organisational measures appropriate and proportionate to the risks facing the network and information systems you use for your operations or to provide your services, and to prevent or minimise the impact of a security incident on the recipients of your services and on other services.

Luxembourg Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Risk-Management Measures for Essential and Important Entities

Take technical, operational and organisational measures appropriate and proportionate to the risks facing the network and information systems you use for your activities or to provide your services, and act to eliminate or reduce the impact of an incident on the recipients of your services and on other services.

Where you find you are not complying with these measures, take, without undue delay, all necessary, appropriate and proportionate corrective measures.

Marshall Islands Cybersecurity Act 2025, Cybersecurity of Critical Information Infrastructure

Implement technical, operational, and organizational measures to manage the cybersecurity risks that may affect your designated critical information infrastructure, and measures to prevent and mitigate the impact of a cybersecurity incident or threat.

Micronesia FSM Cybersecurity Act 2025 (Bill), Critical Information Infrastructure Risk-Management Duties proposed

Implement technical, operational, and organizational measures to manage cybersecurity risks to your designated critical information infrastructure, and measures to prevent or mitigate the impact of a cybersecurity incident or threat on it.

Morocco Loi n° 05-20 relative à la cybersécurité, Digital Service Provider and Platform Operator Security Duties

If you are a digital service provider, identify the risks threatening the security of your own networks and information systems, and take the technical and organizational measures needed to manage those risks, avoid incidents, and minimize their impact, so as to guarantee the continuity of your services.

Netherlands Cyberbeveiligingswet, Cybersecurity Risk-Management Measures and Governance

Take appropriate and proportionate technical, operational and organisational measures to manage the risks to the network and information systems you use for your work or to provide your services, and to prevent an incident or limit its effect on the recipients of your services and on other services.

Portugal Regime Jurídico da Cibersegurança, Cybersecurity Risk-Management Measures and Governance

Take appropriate technical, operational and organisational measures to manage the risks to the network and information systems you use in your operations, and to prevent or minimise the impact of an incident on the recipients of your services and on other services, at a level proportionate to your risk exposure, your size and the likelihood and severity of an incident.

Spain Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad, Cybersecurity Risk-Management Measures proposed

Expect a duty, once enacted, to carry out an individualised risk assessment and put in place technical, operational and organisational measures, proportionate to the risk, to secure the networks and information systems you use and to prevent or minimise the impact of an incident.

Sweden Cybersäkerhetslag, Cybersecurity Risk-Management Measures

Take appropriate and proportionate technical, operational and organisational measures, on an all-hazards basis, to protect the network and information systems you use for your operations or to provide your services, and their physical environment, against an incident, at minimum covering risk-analysis strategy, incident handling, business continuity and crisis management, supply-chain security, security in system acquisition/development/maintenance, effectiveness-assessment procedures, basic cyber hygiene and staff training, cryptography and encryption policies, personnel security, access control and asset management, and, where relevant, authentication, secure communications and secure emergency-communication systems.

Security baseline statutes

4 laws, 4 places
PlaceLawWhat it asks, as read here
Cameroon Loi n°2010/012 du 21 décembre 2010 relative à la cybersécurité et à la cybercriminalité au Cameroun, articles 6, 7, 13-14, 24, 26-30, 32, 61(3) (mesures de sécurité et audit de sécurité obligatoire par l'ANTIC)

Take all technical and administrative measures necessary to guarantee the security of the services you offer.

Central African Republic Cybersecurity Law: Network and Information System Security Duty

Take all technical and administrative measures necessary to guarantee the security of the services you offer, and adopt standardized systems to continually identify, assess, treat and manage the risks to your information systems' security.

Gabon Sécurité des systèmes d'information (dispositions communes)

Take all technical and administrative measures necessary to guarantee the security of the services you offer, including a standardised system to identify, evaluate, treat and continuously manage the risks affecting your information systems' security.

Kazakhstan Digital Code, general cybersecurity duty on digital-object owners and holders

Implement technical measures, including cryptographic protection where applicable, together with organizational and legal measures, aimed at preventing, detecting and eliminating cyber threats to that digital object.

Vulnerability and incident reporting

1 law, 1 place
PlaceLawWhat it asks, as read here
China Data Security Law, Risk Monitoring and Incident Reporting Duty

Strengthen risk monitoring of your data-processing activity, and on discovering a data-security defect, vulnerability, or other risk, immediately take remedial measures.

Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.