Law / Frameworks / NIST CSF 2.0 / Protect

NIST CSF 2.0, ProtectPR.AT-02

Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mindNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), PR.AT-02

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

20
laws
20
places
0
with court rulings behind them
2
not yet in force
1
proposed, not law

A law in force is unmarked; the rest wear their state: not yet in force proposed

  • Austria
  • Bulgaria
  • Croatia
  • Cyprus
  • Denmark
  • Estonia
  • European Union
  • Finland
  • France
  • Germany
  • Greece
  • Indonesia
  • Liechtenstein
  • Lithuania
  • Luxembourg
  • Netherlands
  • Portugal
  • Slovenia
  • Sweden
  • Taiwan

Sector security regimes

19 laws, 19 places
PlaceLawWhat it asks, as read here
Austria Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Cybersecurity Risk-Management Measures from , in 2 days

Have your management body implement and oversee these measures and attend cybersecurity training designed for it, and offer your staff regular training.

Bulgaria Cybersecurity Act, Risk-Management Measures and Governance (Zakon za kibersigurnost, ZKS)

Have your management body approve and oversee these measures, and have every member of your management body complete cybersecurity training every two years and organise the same training for your staff; a member who fails to do so faces a personal fine of EUR 500 to 5,000.

Croatia Zakon o kibernetičkoj sigurnosti, Risk-Management Measures and Governance

Have the members of your management body, or, if you are a public entity, the heads of your state administration or local self-government body, approve these measures and control their implementation, and have them attend, and make available to your staff, appropriate cybersecurity training covering risk-management issues and their effect on your services.

Cyprus Security of Networks and Information Systems Law, Cybersecurity Risk-Management Measures and Governance

Have your senior management approve these risk-management measures and oversee their implementation; senior management can be held accountable for the entity's breach of this duty, and must undergo, and offer staff, regular training so they can identify risks and assess cybersecurity risk-management practices.

Denmark NIS 2-loven, Cybersecurity Risk-Management Measures and Registration

Have your management board (ledelsesorgan) approve these measures and oversee their implementation, and ensure its members attend relevant cybersecurity risk-management training and encourage similar training for your other staff.

Estonia Küberturvalisuse seadus (KüTS), System Security Measures and Management-Body Duties

Designate at least one management board member (or, if you have only one, that member, or the equivalent office-holder if you have no board) to approve your security measures, monitor their implementation and answer for that duty, and have that person complete regular training to understand and assess cyber risk, its impact on your services, and how to manage it.

European Union NIS2 Directive, Cybersecurity Risk-Management Measures

Have your management body approve these measures, oversee their implementation, and complete cybersecurity training.

Finland Kyberturvallisuuslaki, Cybersecurity Risk-Management Measures and Governance

Have your board, supervisory board or chief executive approve and oversee this operating model; they must hold sufficient familiarity with cybersecurity risk management to do so.

France Projet de loi Résilience des Infrastructures Critiques et Cybersécurité, Cybersecurity Risk-Management Measures (NIS2) proposed

Take technical, operational and organisational measures appropriate and proportionate to the risks facing the network and information systems you use for your activities or services: have your management body approve and oversee the security measures and receive cybersecurity training, protect your networks and systems including where you use a subcontractor, put in place tools and procedures to defend your networks and handle incidents, and ensure the resilience of your activities.

Germany BSI-Gesetz (BSIG), Risk-Management Measures for Essential and Important Entities

Have your management body implement and oversee these measures and attend regular risk-management training; expect it to be liable to your organisation for culpable damage from a breach of that duty under the ordinary rules of company law.

Show the other 9 laws
Greece Law 5160/2024, Cybersecurity Risk-Management Measures and Governance

Within three months of this duty's entry into force, have your management body approve the cybersecurity risk-management measures you take to comply with the measures below, supervise their implementation, and ensure every board member receives training and that equivalent training reaches your staff at least annually.

Liechtenstein Cyber-Sicherheitsgesetz (CSG), Risk-Management Measures for Essential and Important Entities

Have your leadership body (Leitungsorgan) approve and oversee these measures and attend, and offer your staff, regular training on recognising and assessing cybersecurity risk and risk-management practice.

Lithuania Kibernetinio saugumo įstatymas (Law on Cyber Security), Risk-Management Measures

Designate a cybersecurity manager and/or security officer who organises your risk assessment and prepares your risk-assessment reports and risk-management plans for approval, and have your management body, head and designated representative complete cybersecurity training at least once every two years.

Luxembourg Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Risk-Management Measures for Essential and Important Entities

Have your management body approve these risk-management measures, oversee their implementation, and complete regular training on assessing risk and risk-management practice; expect the body to be held liable for the entity's violation of this duty.

Netherlands Cyberbeveiligingswet, Cybersecurity Risk-Management Measures and Governance

Have your management board approve these measures, and ensure every board member holds the knowledge and skills to identify network-and-information-system risks, assess your cybersecurity risk-management measures, and assess their consequences for your services, within two years of this duty taking effect for a member already serving.

Portugal Regime Jurídico da Cibersegurança, Cybersecurity Risk-Management Measures and Governance

Have your management, direction and administration body approve these measures, supervise their implementation, ensure compliance with supervision and enforcement obligations, and ensure regular cybersecurity training; know that a member of that body can be held personally liable, by act or omission, on a finding of intent or gross negligence, for an infringement of this Decree-Law, and that this responsibility cannot be delegated away.

Slovenia Zakon o informacijski varnosti (ZInfV-1), Cybersecurity Risk-Management Measures and Governance from , in 3 months

Have your responsible person, the individual who leads, supervises or manages the entity or a public-administration body's head, approve these measures and oversee their implementation, and complete cybersecurity risk-management training at least every four years.

Sweden Cybersäkerhetslag, Cybersecurity Risk-Management Measures

Have the individuals in your management undergo training on these security measures.

Taiwan Bank and Financial Holding Company Internal Control Rules, Dedicated Information Security Unit

Provide the dedicated unit's personnel at least 15 hours, and other information-technology personnel at least 6 hours, of information-security training annually.

Security baseline statutes

1 law, 1 place
PlaceLawWhat it asks, as read here
Indonesia Government Regulation on the Operation of Electronic Systems and Transactions, electronic-system security duty

Protect your users and the wider public from harm caused by the Electronic System you operate, and provide, train, and equip personnel tasked with and responsible for securing the system's facilities and infrastructure.

Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.