Law / Frameworks / NIST CSF 2.0 / Protect

NIST CSF 2.0, ProtectPR.DS-01

The confidentiality, integrity, and availability of data-at-rest are protectedNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), PR.DS-01

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

38
laws
35
places
0
with court rulings behind them
5
not yet in force

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force

  • Alabama
  • Angola
  • Arkansas
  • Belarus
  • Burundi
  • California
  • China
  • Colorado
  • Connecticut
  • Delaware
  • District of Columbia
  • Florida
  • Illinois
  • Indiana
  • Kansas
  • Kazakhstan
  • Lebanon
  • Liberia
  • Louisiana
  • Maryland
  • Massachusetts
  • Mexico
  • Micronesia
  • Montenegro
  • Nebraska
  • Nevada
  • New Mexico
  • Oregon
  • Rhode Island
  • Solomon Islands
  • Texas
  • Turkmenistan
  • Utah
  • Uzbekistan
  • Vietnam

Security baseline statutes

30 laws, 27 places
PlaceLawWhat it asks, as read here
Alabama Data Breach Notification Act, reasonable security measures and disposal of records

Implement and maintain reasonable security measures to protect sensitive personally identifying information against a breach of security: designate an employee or employees to coordinate the effort, identify internal and external risks, adopt and assess information safeguards, contractually require any service providers to maintain appropriate safeguards, adjust the measures for changed circumstances, and keep management, including the board of directors where one exists, informed of the overall status of the measures.

Arkansas Arkansas Personal Information Protection Act, reasonable security procedures

Implement and maintain reasonable security procedures and practices appropriate to the nature of the personal information you acquire, own, or license, to protect it from unauthorized access, destruction, use, modification, or disclosure.

Belarus Law No. 455-Z, Information System Operator's Duty to Protect Information (Article 40)

Ensure the integrity and safety of the information your system holds.

Take measures to prevent disclosure, loss, distortion, destruction, or unauthorized modification of that information, and to prevent blocking of legitimate access to it.

California Customer Records Act, Reasonable Security Procedures

Implement and maintain reasonable security procedures and practices appropriate to the nature of the personal information you own, license, or maintain, to protect it from unauthorized access, destruction, use, modification, or disclosure.

China Data Security Law, Data Security Protection Obligations

Take the technical measures and other necessary measures appropriate to your processing to keep your data secure.

Colorado Protection of personal identifying information, reasonable security procedures duty

Implement and maintain reasonable security procedures and practices, appropriate to the nature of the information and the nature and size of the business, to protect personal identifying information (a Social Security number, a personal identification number, a password or pass code, a state driver's license or identification card number, a government passport number, biometric data, an employer, student, or military identification number, or a financial transaction device) from unauthorized access, use, modification, disclosure, or destruction.

Connecticut Connected device provider's duty to protect recorded personal information with reasonable security measures

Implement and maintain reasonable security measures to protect any personally identifying information collected through the connected device's camera or microphone from unauthorized access, acquisition, destruction, disclosure, modification or use.

Connecticut Protection of Social Security Numbers and Personal Information Act, safeguarding and destruction duty

Safeguard the data, computer files and documents containing that personal information from misuse by third parties, and destroy, erase or make them unreadable before disposal.

Delaware Computer Security Breaches, protection of personal information

Implement and maintain reasonable procedures and practices to prevent the unauthorized acquisition, use, modification, disclosure, or destruction of that personal information, collected or maintained in the regular course of business.

District of Columbia Security requirements for personal information (Security Breach Protection Amendment Act of 2020)

Implement and maintain reasonable security safeguards, including procedures and practices appropriate to the nature of the personal information you hold and to your own nature and size.

Show the other 20 laws
Florida Florida Information Protection Act, data security and disposal duty

Take reasonable measures to protect and secure data in electronic form containing personal information. The statute states no further content for what 'reasonable' requires beyond this general standard.

Illinois Personal Information Protection Act, data security duty

Implement and maintain reasonable security measures to protect those records from unauthorized access, acquisition, destruction, use, modification, or disclosure.

Indiana Disclosure of Security Breach Act, data base owner's duty to maintain reasonable security procedures and dispose of records from a date not yet set

Implement and maintain reasonable procedures, including taking any appropriate corrective action, to protect and safeguard from unlawful use or disclosure any personal information of Indiana residents you collect or maintain.

Kansas Kansas Consumer Protection Act, reasonable security and records-destruction duty for holders of personal information

Implement and maintain reasonable procedures and practices appropriate to the nature of the information, and exercise reasonable care to protect it from unauthorized access, use, modification, or disclosure. Being subject to and compliant with another federal or state law or regulation governing the same procedures and practices is deemed compliance with this duty.

Kazakhstan Digital Code, general cybersecurity duty on digital-object owners and holders

Protect the confidentiality, integrity and availability of every digital object you own or hold in Kazakhstan, a category that expressly includes software you make available to others.

Louisiana Database Security Breach Notification Law, reasonable security procedures and destruction duty

Implement and maintain reasonable security procedures and practices appropriate to the nature of the information, to protect personal information from unauthorized access, destruction, use, modification, or disclosure.

Maryland Maryland Personal Information Protection Act (MPIPA), safeguards and secure-disposal duty

Absent that safe harbor, implement and maintain reasonable security procedures and practices, appropriate to the nature of the personal information held and the size of the business, to protect it from unauthorized access, use, modification, or disclosure.

Massachusetts Standards for the Protection of Personal Information of Residents of the Commonwealth

For personal information you store or transmit electronically, build a computer-system security program with secure user authentication, access controls limiting records to those who need them, encryption of records transmitted across public networks or wirelessly and of personal information stored on a laptop or other portable device, up-to-date firewalls and operating-system security patches for any internet-connected system, up-to-date malware protection, and employee training on the security system.

Mexico Ley Federal de Protección al Consumidor, Electronic Transaction Security Duty (Arts. 76 Bis, 76 Bis 1)

Where you offer, market or sell goods, products or services to a consumer in Mexico through electronic, optical or other technological means, keep the information that consumer gives you confidential, and do not disclose or transmit it to another provider outside the transaction without the consumer's express authorization or a competent authority's request.

Use an available technical security element to give security and confidentiality to that consumer information, and tell the consumer, before the transaction closes, the general characteristics of that element.

Montenegro Law on Information Security, General Security Measures

Protect the confidentiality, integrity and availability of the data you process, store or transmit through the planning, design, construction, use, maintenance and decommissioning of that system (Article 15).

Nebraska Financial Data Protection and Consumer Notification of Data Security Breach Act, security procedures and practices duty

Implement and maintain reasonable security procedures and practices appropriate to the nature and sensitivity of the personal information held and to the nature, size, and resources of the business and its operations, including safeguards that protect the information when it is disposed of.

Nevada Security measures for a data collector accepting payment cards, encryption duty, and conditioned liability shield from a date not yet set

If you do not accept payment cards, do not transfer a Nevada resident's personal information through an electronic, nonvoice transmission other than a facsimile outside your secure system, and do not move a data storage device containing that personal information beyond your logical or physical controls, unless the data is encrypted using an encryption technology adopted by an established standards-setting body, with appropriate management and safeguards of the cryptographic keys.

Nevada Security measures for data collectors maintaining personal information from a date not yet set

Implement and maintain reasonable security measures to protect those records from unauthorized access, acquisition, destruction, use, modification, or disclosure.

New Mexico Data Breach Notification Act, security and disposal duties from a date not yet set

Implement and maintain reasonable security procedures and practices, appropriate to the nature of the personal identifying information held, to protect it from unauthorized access, destruction, use, modification, or disclosure.

Oregon Oregon Consumer Information Protection Act, requirement to develop safeguards for personal information

Develop, implement and maintain reasonable administrative, technical and physical safeguards to protect the security, confidentiality and integrity of personal information, including its secure disposal.

Rhode Island Identity Theft Protection Act of 2015, risk-based information security program from a date not yet set

Implement and maintain a risk-based information security program with reasonable security procedures and practices appropriate to your size and scope, the nature of the information, and the purpose for which it was collected, to protect the information from unauthorized access, use, modification, destruction, or disclosure and to preserve its confidentiality, integrity, and availability.

Texas Identity Theft Enforcement and Protection Act, business duty to protect sensitive personal information

Implement and maintain reasonable procedures, including taking any appropriate corrective action, to protect that sensitive personal information from unlawful use or disclosure. The statute states no further content for what 'reasonable' requires beyond this general standard.

Utah Protection of Personal Information Act, reasonable procedures and records-destruction duty

Implement and maintain reasonable procedures to prevent the unlawful use or disclosure of that personal information. The statute states no further content for what 'reasonable' requires beyond this general standard.

Uzbekistan Law on Cybersecurity, general cybersecurity duties on cybersecurity subjects

Prevent unlawful disclosure, theft, loss, corruption, blocking, or falsification of data in your information systems and resources, and act promptly when such a case is detected.

Uzbekistan Law on Informatization, information security duty for information resource and system owners

Where your information resources or systems contain state secrets or confidential information, you must protect them under the procedure the Cabinet of Ministers sets for that category.

Sector security regimes

7 laws, 7 places
PlaceLawWhat it asks, as read here
Angola Lei de Protecção das Redes e Sistemas Informáticos, Security Duties for Information-Society Systems, Computer Programs and Databases

Where you use a database, follow technical rules and specialised procedures adequate to protect its access, storage, file duplication, treatment and the recovery of automated information (Article 19).

Burundi Loi n° 1/10, Articles 3, 4(3) and 14: security-of-service duty and diligence penalty for network operators and service providers

Exercise the diligence and competence necessary to prevent the disclosure of computer data you hold on behalf of a third party, or face a fine of 10,000,000 to 30,000,000 Burundian francs (BIF) under Article 14.

Lebanon Banque du Liban Basic Circular No. 144 (Prevention of Electronic Criminal Acts)

Adopt at least two-factor authentication for any user accessing the system from outside the bank or financial institution, fully encrypt highly sensitive data, filter inbound email, verify the security of devices employees use outside the institution, run penetration testing, monitor network traffic, and verify data integrity.

Liberia Telecommunications Act 2007, Security Safeguards for Customer Information and Communications

Ensure that customer information and customer communications in your custody or control are protected by security safeguards appropriate to their sensitivity.

Micronesia FSM Telecommunications Act of 2014, Security Safeguards for Customer Information

Apply appropriate security safeguards to prevent the collection, use, maintenance, or disclosure of a customer's information without the customer's consent.

Solomon Islands Telecommunications Act 2009, Security Safeguards for Consumer Information

Apply appropriate security safeguards to prevent the collection, use, maintenance, or disclosure of a consumer's information.

Turkmenistan Law on Communications, network and subscriber-information protection duties

Ensure the safekeeping of subscriber information obtained on contracting and about services rendered, including their duration, content, and routing, and protect that information during automated processing.

Vulnerability and incident reporting

1 law, 1 place
PlaceLawWhat it asks, as read here
Vietnam Cybersecurity Law, Incident Response and Reporting Duties

Apply technical measures to secure data processing, including personal-data processing, consistent with this Law, Vietnam's law on data, and its Law on Personal Data Protection.

Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.