Law / Frameworks / NIST CSF 2.0 / Protect
NIST CSF 2.0, ProtectPR.AA-05
Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of dutiesNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), PR.AA-05
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 2
- laws
- 2
- places
- 0
- with court rulings behind them
- 0
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFMEASURE 2.5 The AI system to be deployed is demonstrated to be valid and reliable. Limitations of...
- NIST AI RMFMEASURE 2.6 The AI system is evaluated regularly for safety risks – as identified in the MAP...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-09 Information Security
- OWASP LLM Top 10LLM01:2026 Prompt Injection
- OWASP LLM Top 10LLM02:2026 Sensitive Information Disclosure
- OWASP Agentic Top 10ASI01 Agent Goal Hijack
- OWASP Agentic Top 10ASI03 Identity and Privilege Abuse
- MIT mitigations2.1 Model & Infrastructure Security
- MIT mitigations2.3 Model Safety Engineering
- NIST Privacy FrameworkPR.PO-P7 Response plans (Incident Response and Business Continuity) and recovery plans...
- NIST Privacy FrameworkPR.PO-P10 A vulnerability management plan is developed and implemented.
Security baseline statutes
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Standards for the Protection of Personal Information of Residents of the Commonwealth |
For personal information you store or transmit electronically, build a computer-system security program with secure user authentication, access controls limiting records to those who need them, encryption of records transmitted across public networks or wirelessly and of personal information stored on a laptop or other portable device, up-to-date firewalls and operating-system security patches for any internet-connected system, up-to-date malware protection, and employee training on the security system. |
|
| Law on Information and Its Protection, information-security duty |
Where the duty is triggered, maintain administrative, technical and organizational measures that: prevent unauthorized access to information and its transfer to a person without a right of access; detect an unauthorized access event in a timely manner; prevent adverse consequences from a breach of the access procedure; prevent disruption of the technical means used to process the information; permit immediate restoration of information altered or destroyed by unauthorized access; and continuously monitor the level of the information's protection. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.