Law / Frameworks / NIST CSF 2.0 / Protect
NIST CSF 2.0, ProtectPR.AT-02
Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mindNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), PR.AT-02
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 20
- laws
- 20
- places
- 0
- with court rulings behind them
- 2
- not yet in force
- 1
- proposed, not law
A law in force is unmarked; the rest wear their state: not yet in force proposed
Sector security regimes
19 laws, 19 places| Place | Law | What it asks, as read here |
|---|---|---|
| Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Cybersecurity Risk-Management Measures from , in 2 days |
Have your management body implement and oversee these measures and attend cybersecurity training designed for it, and offer your staff regular training. |
|
| Cybersecurity Act, Risk-Management Measures and Governance (Zakon za kibersigurnost, ZKS) |
Have your management body approve and oversee these measures, and have every member of your management body complete cybersecurity training every two years and organise the same training for your staff; a member who fails to do so faces a personal fine of EUR 500 to 5,000. |
|
| Zakon o kibernetičkoj sigurnosti, Risk-Management Measures and Governance |
Have the members of your management body, or, if you are a public entity, the heads of your state administration or local self-government body, approve these measures and control their implementation, and have them attend, and make available to your staff, appropriate cybersecurity training covering risk-management issues and their effect on your services. |
|
| Security of Networks and Information Systems Law, Cybersecurity Risk-Management Measures and Governance |
Have your senior management approve these risk-management measures and oversee their implementation; senior management can be held accountable for the entity's breach of this duty, and must undergo, and offer staff, regular training so they can identify risks and assess cybersecurity risk-management practices. |
|
| NIS 2-loven, Cybersecurity Risk-Management Measures and Registration |
Have your management board (ledelsesorgan) approve these measures and oversee their implementation, and ensure its members attend relevant cybersecurity risk-management training and encourage similar training for your other staff. |
|
| Küberturvalisuse seadus (KüTS), System Security Measures and Management-Body Duties |
Designate at least one management board member (or, if you have only one, that member, or the equivalent office-holder if you have no board) to approve your security measures, monitor their implementation and answer for that duty, and have that person complete regular training to understand and assess cyber risk, its impact on your services, and how to manage it. |
|
| NIS2 Directive, Cybersecurity Risk-Management Measures |
Have your management body approve these measures, oversee their implementation, and complete cybersecurity training. |
|
| Kyberturvallisuuslaki, Cybersecurity Risk-Management Measures and Governance |
Have your board, supervisory board or chief executive approve and oversee this operating model; they must hold sufficient familiarity with cybersecurity risk management to do so. |
|
| Projet de loi Résilience des Infrastructures Critiques et Cybersécurité, Cybersecurity Risk-Management Measures (NIS2) proposed |
Take technical, operational and organisational measures appropriate and proportionate to the risks facing the network and information systems you use for your activities or services: have your management body approve and oversee the security measures and receive cybersecurity training, protect your networks and systems including where you use a subcontractor, put in place tools and procedures to defend your networks and handle incidents, and ensure the resilience of your activities. |
|
| BSI-Gesetz (BSIG), Risk-Management Measures for Essential and Important Entities |
Have your management body implement and oversee these measures and attend regular risk-management training; expect it to be liable to your organisation for culpable damage from a breach of that duty under the ordinary rules of company law. |
Show the other 9 laws
| Law 5160/2024, Cybersecurity Risk-Management Measures and Governance |
Within three months of this duty's entry into force, have your management body approve the cybersecurity risk-management measures you take to comply with the measures below, supervise their implementation, and ensure every board member receives training and that equivalent training reaches your staff at least annually. |
|
| Cyber-Sicherheitsgesetz (CSG), Risk-Management Measures for Essential and Important Entities |
Have your leadership body (Leitungsorgan) approve and oversee these measures and attend, and offer your staff, regular training on recognising and assessing cybersecurity risk and risk-management practice. |
|
| Kibernetinio saugumo įstatymas (Law on Cyber Security), Risk-Management Measures |
Designate a cybersecurity manager and/or security officer who organises your risk assessment and prepares your risk-assessment reports and risk-management plans for approval, and have your management body, head and designated representative complete cybersecurity training at least once every two years. |
|
| Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Risk-Management Measures for Essential and Important Entities |
Have your management body approve these risk-management measures, oversee their implementation, and complete regular training on assessing risk and risk-management practice; expect the body to be held liable for the entity's violation of this duty. |
|
| Cyberbeveiligingswet, Cybersecurity Risk-Management Measures and Governance |
Have your management board approve these measures, and ensure every board member holds the knowledge and skills to identify network-and-information-system risks, assess your cybersecurity risk-management measures, and assess their consequences for your services, within two years of this duty taking effect for a member already serving. |
|
| Regime Jurídico da Cibersegurança, Cybersecurity Risk-Management Measures and Governance |
Have your management, direction and administration body approve these measures, supervise their implementation, ensure compliance with supervision and enforcement obligations, and ensure regular cybersecurity training; know that a member of that body can be held personally liable, by act or omission, on a finding of intent or gross negligence, for an infringement of this Decree-Law, and that this responsibility cannot be delegated away. |
|
| Zakon o informacijski varnosti (ZInfV-1), Cybersecurity Risk-Management Measures and Governance from , in 3 months |
Have your responsible person, the individual who leads, supervises or manages the entity or a public-administration body's head, approve these measures and oversee their implementation, and complete cybersecurity risk-management training at least every four years. |
|
| Cybersäkerhetslag, Cybersecurity Risk-Management Measures |
Have the individuals in your management undergo training on these security measures. |
|
| Bank and Financial Holding Company Internal Control Rules, Dedicated Information Security Unit |
Provide the dedicated unit's personnel at least 15 hours, and other information-technology personnel at least 6 hours, of information-security training annually. |
Security baseline statutes
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Government Regulation on the Operation of Electronic Systems and Transactions, electronic-system security duty |
Protect your users and the wider public from harm caused by the Electronic System you operate, and provide, train, and equip personnel tasked with and responsible for securing the system's facilities and infrastructure. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.