Law / Frameworks / NIST CSF 2.0 / Protect
NIST CSF 2.0, ProtectPR.AA-03
Users, services, and hardware are authenticatedNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), PR.AA-03
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 4
- laws
- 4
- places
- 0
- with court rulings behind them
- 0
- not yet in force
Sector security regimes
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Banque du Liban Basic Circular No. 144 (Prevention of Electronic Criminal Acts) |
Adopt at least two-factor authentication for any user accessing the system from outside the bank or financial institution, fully encrypt highly sensitive data, filter inbound email, verify the security of devices employees use outside the institution, run penetration testing, monitor network traffic, and verify data integrity. |
|
| Law on Information Security, ICT Systems of Special Importance and Security Measures |
Take technical, operational, organisational and physical protection measures across the areas Article 10 lists, including multi-factor authentication or a continuous-authentication solution, secured voice, video and text communication, and secured communication channels for emergencies. |
Product security requirements
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Anatel Cybersecurity Requirements for CPE (Customer Premises Equipment) |
Print any factory-set password on a label on the device and restore it whenever the device is reset to factory settings; require any user-set password to be at least 8 characters with an uppercase letter, a lowercase letter, a number, and a special character, and check new passwords against a password dictionary or an equivalent method to block weak or commonly used ones. |
Security baseline statutes
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Government Regulation on the Operation of Electronic Systems and Transactions, electronic-system security duty |
Where you operate an Electronic Agent, an automated device that carries out an action on Electronic Information for a user without that user's direct intervention, such as an automated transaction or e-commerce system, additionally run a standard operating procedure meeting six security-control principles for user data and Electronic Transactions: confidentiality, integrity, availability, authenticity, authorization, and non-repudiation, and test a transacting user's identity and authorization before completing the transaction. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.