Law / Frameworks / NIST CSF 2.0 / Identify
NIST CSF 2.0, IdentifyID.RA-08
Processes for receiving, analyzing, and responding to vulnerability disclosures are establishedNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), ID.RA-08
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 5
- laws
- 5
- places
- 0
- with court rulings behind them
- 1
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFMEASURE 2.5 The AI system to be deployed is demonstrated to be valid and reliable. Limitations of...
- NIST AI RMFMEASURE 2.6 The AI system is evaluated regularly for safety risks – as identified in the MAP...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-09 Information Security
- OWASP LLM Top 10LLM01:2026 Prompt Injection
- OWASP LLM Top 10LLM02:2026 Sensitive Information Disclosure
- OWASP Agentic Top 10ASI01 Agent Goal Hijack
- OWASP Agentic Top 10ASI03 Identity and Privilege Abuse
- MIT mitigations2.1 Model & Infrastructure Security
- MIT mitigations2.3 Model Safety Engineering
- NIST Privacy FrameworkPR.PO-P7 Response plans (Incident Response and Business Continuity) and recovery plans...
- NIST Privacy FrameworkPR.PO-P10 A vulnerability management plan is developed and implemented.
A law in force is unmarked; the rest wear their state: not yet in force
Product security requirements
4 laws, 4 places| Place | Law | What it asks, as read here |
|---|---|---|
| Security Standards for Smart Devices |
Publish a means for a security issue affecting the device to be reported to the manufacturer, and provide status updates on the resolution of a reported issue. |
|
| Anatel Cybersecurity Requirements for CPE (Customer Premises Equipment) |
Provide a dedicated, securely reachable channel, such as an HTTPS web form or a PGP-encrypted email address, for a customer, end user, or third party to report a security vulnerability, and publish a coordinated vulnerability-disclosure policy on your website covering how you want to be notified, what a reporter should expect, and your process's scope and limits. |
|
| Cyber Resilience Act, Essential Requirements and Manufacturer Obligations from , in 14 months |
Put in place a coordinated vulnerability disclosure policy and a contact channel for reporting a vulnerability, and disclose the end date of the support period to the buyer at the time of purchase. |
|
| Product Security Requirements for Connectable Products |
Publish at least one point of contact for reporting a security issue affecting the product, in English, free of charge, without requiring the reporter's personal information, and state when the reporter will get an acknowledgment and status updates. |
Vulnerability and incident reporting
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Nacionālās kiberdrošības likums, Coordinated Vulnerability Disclosure and Remediation |
Once the competent cyber incident prevention institution relays a substantiated report that a vulnerability exists in a system or network you operate, remediate it within the deadline the institution sets, no later than 90 days from when you received the information. Report your remediation progress to the institution as you go, and, if you cannot remediate within 90 days for objective reasons, request an extension, which the institution may grant up to a total of 180 days from the report's submission. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.