Law / Frameworks / NIST CSF 2.0 / Identify

NIST CSF 2.0, IdentifyID.RA-08

Processes for receiving, analyzing, and responding to vulnerability disclosures are establishedNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), ID.RA-08

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

5
laws
5
places
0
with court rulings behind them
1
not yet in force

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force

  • Australia
  • Brazil
  • European Union
  • Latvia
  • United Kingdom

Product security requirements

4 laws, 4 places
PlaceLawWhat it asks, as read here
Australia Security Standards for Smart Devices

Publish a means for a security issue affecting the device to be reported to the manufacturer, and provide status updates on the resolution of a reported issue.

Brazil Anatel Cybersecurity Requirements for CPE (Customer Premises Equipment)

Provide a dedicated, securely reachable channel, such as an HTTPS web form or a PGP-encrypted email address, for a customer, end user, or third party to report a security vulnerability, and publish a coordinated vulnerability-disclosure policy on your website covering how you want to be notified, what a reporter should expect, and your process's scope and limits.

European Union Cyber Resilience Act, Essential Requirements and Manufacturer Obligations from , in 14 months

Put in place a coordinated vulnerability disclosure policy and a contact channel for reporting a vulnerability, and disclose the end date of the support period to the buyer at the time of purchase.

United Kingdom Product Security Requirements for Connectable Products

Publish at least one point of contact for reporting a security issue affecting the product, in English, free of charge, without requiring the reporter's personal information, and state when the reporter will get an acknowledgment and status updates.

Vulnerability and incident reporting

1 law, 1 place
PlaceLawWhat it asks, as read here
Latvia Nacionālās kiberdrošības likums, Coordinated Vulnerability Disclosure and Remediation

Once the competent cyber incident prevention institution relays a substantiated report that a vulnerability exists in a system or network you operate, remediate it within the deadline the institution sets, no later than 90 days from when you received the information.

Report your remediation progress to the institution as you go, and, if you cannot remediate within 90 days for objective reasons, request an extension, which the institution may grant up to a total of 180 days from the report's submission.

Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.