Law / Frameworks / NIST CSF 2.0 / Protect
NIST CSF 2.0, ProtectPR.DS-01
The confidentiality, integrity, and availability of data-at-rest are protectedNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), PR.DS-01
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 38
- laws
- 35
- places
- 0
- with court rulings behind them
- 5
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFMEASURE 2.5 The AI system to be deployed is demonstrated to be valid and reliable. Limitations of...
- NIST AI RMFMEASURE 2.6 The AI system is evaluated regularly for safety risks – as identified in the MAP...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-09 Information Security
- OWASP LLM Top 10LLM01:2026 Prompt Injection
- OWASP LLM Top 10LLM02:2026 Sensitive Information Disclosure
- OWASP Agentic Top 10ASI01 Agent Goal Hijack
- OWASP Agentic Top 10ASI03 Identity and Privilege Abuse
- MIT mitigations2.1 Model & Infrastructure Security
- MIT mitigations2.3 Model Safety Engineering
- NIST Privacy FrameworkPR.PO-P7 Response plans (Incident Response and Business Continuity) and recovery plans...
- NIST Privacy FrameworkPR.PO-P10 A vulnerability management plan is developed and implemented.
A law in force is unmarked; the rest wear their state: not yet in force
Security baseline statutes
30 laws, 27 places| Place | Law | What it asks, as read here |
|---|---|---|
| Data Breach Notification Act, reasonable security measures and disposal of records |
Implement and maintain reasonable security measures to protect sensitive personally identifying information against a breach of security: designate an employee or employees to coordinate the effort, identify internal and external risks, adopt and assess information safeguards, contractually require any service providers to maintain appropriate safeguards, adjust the measures for changed circumstances, and keep management, including the board of directors where one exists, informed of the overall status of the measures. |
|
| Arkansas Personal Information Protection Act, reasonable security procedures |
Implement and maintain reasonable security procedures and practices appropriate to the nature of the personal information you acquire, own, or license, to protect it from unauthorized access, destruction, use, modification, or disclosure. |
|
| Law No. 455-Z, Information System Operator's Duty to Protect Information (Article 40) |
Ensure the integrity and safety of the information your system holds. Take measures to prevent disclosure, loss, distortion, destruction, or unauthorized modification of that information, and to prevent blocking of legitimate access to it. |
|
| Customer Records Act, Reasonable Security Procedures |
Implement and maintain reasonable security procedures and practices appropriate to the nature of the personal information you own, license, or maintain, to protect it from unauthorized access, destruction, use, modification, or disclosure. |
|
| Data Security Law, Data Security Protection Obligations |
Take the technical measures and other necessary measures appropriate to your processing to keep your data secure. |
|
| Protection of personal identifying information, reasonable security procedures duty |
Implement and maintain reasonable security procedures and practices, appropriate to the nature of the information and the nature and size of the business, to protect personal identifying information (a Social Security number, a personal identification number, a password or pass code, a state driver's license or identification card number, a government passport number, biometric data, an employer, student, or military identification number, or a financial transaction device) from unauthorized access, use, modification, disclosure, or destruction. |
|
| Connected device provider's duty to protect recorded personal information with reasonable security measures |
Implement and maintain reasonable security measures to protect any personally identifying information collected through the connected device's camera or microphone from unauthorized access, acquisition, destruction, disclosure, modification or use. |
|
| Protection of Social Security Numbers and Personal Information Act, safeguarding and destruction duty |
Safeguard the data, computer files and documents containing that personal information from misuse by third parties, and destroy, erase or make them unreadable before disposal. |
|
| Computer Security Breaches, protection of personal information |
Implement and maintain reasonable procedures and practices to prevent the unauthorized acquisition, use, modification, disclosure, or destruction of that personal information, collected or maintained in the regular course of business. |
|
| Security requirements for personal information (Security Breach Protection Amendment Act of 2020) |
Implement and maintain reasonable security safeguards, including procedures and practices appropriate to the nature of the personal information you hold and to your own nature and size. |
Show the other 20 laws
| Florida Information Protection Act, data security and disposal duty |
Take reasonable measures to protect and secure data in electronic form containing personal information. The statute states no further content for what 'reasonable' requires beyond this general standard. |
|
| Personal Information Protection Act, data security duty |
Implement and maintain reasonable security measures to protect those records from unauthorized access, acquisition, destruction, use, modification, or disclosure. |
|
| Disclosure of Security Breach Act, data base owner's duty to maintain reasonable security procedures and dispose of records from a date not yet set |
Implement and maintain reasonable procedures, including taking any appropriate corrective action, to protect and safeguard from unlawful use or disclosure any personal information of Indiana residents you collect or maintain. |
|
| Kansas Consumer Protection Act, reasonable security and records-destruction duty for holders of personal information |
Implement and maintain reasonable procedures and practices appropriate to the nature of the information, and exercise reasonable care to protect it from unauthorized access, use, modification, or disclosure. Being subject to and compliant with another federal or state law or regulation governing the same procedures and practices is deemed compliance with this duty. |
|
| Digital Code, general cybersecurity duty on digital-object owners and holders |
Protect the confidentiality, integrity and availability of every digital object you own or hold in Kazakhstan, a category that expressly includes software you make available to others. |
|
| Database Security Breach Notification Law, reasonable security procedures and destruction duty |
Implement and maintain reasonable security procedures and practices appropriate to the nature of the information, to protect personal information from unauthorized access, destruction, use, modification, or disclosure. |
|
| Maryland Personal Information Protection Act (MPIPA), safeguards and secure-disposal duty |
Absent that safe harbor, implement and maintain reasonable security procedures and practices, appropriate to the nature of the personal information held and the size of the business, to protect it from unauthorized access, use, modification, or disclosure. |
|
| Standards for the Protection of Personal Information of Residents of the Commonwealth |
For personal information you store or transmit electronically, build a computer-system security program with secure user authentication, access controls limiting records to those who need them, encryption of records transmitted across public networks or wirelessly and of personal information stored on a laptop or other portable device, up-to-date firewalls and operating-system security patches for any internet-connected system, up-to-date malware protection, and employee training on the security system. |
|
| Ley Federal de Protección al Consumidor, Electronic Transaction Security Duty (Arts. 76 Bis, 76 Bis 1) |
Where you offer, market or sell goods, products or services to a consumer in Mexico through electronic, optical or other technological means, keep the information that consumer gives you confidential, and do not disclose or transmit it to another provider outside the transaction without the consumer's express authorization or a competent authority's request. Use an available technical security element to give security and confidentiality to that consumer information, and tell the consumer, before the transaction closes, the general characteristics of that element. |
|
| Law on Information Security, General Security Measures |
Protect the confidentiality, integrity and availability of the data you process, store or transmit through the planning, design, construction, use, maintenance and decommissioning of that system (Article 15). |
|
| Financial Data Protection and Consumer Notification of Data Security Breach Act, security procedures and practices duty |
Implement and maintain reasonable security procedures and practices appropriate to the nature and sensitivity of the personal information held and to the nature, size, and resources of the business and its operations, including safeguards that protect the information when it is disposed of. |
|
| Security measures for a data collector accepting payment cards, encryption duty, and conditioned liability shield from a date not yet set |
If you do not accept payment cards, do not transfer a Nevada resident's personal information through an electronic, nonvoice transmission other than a facsimile outside your secure system, and do not move a data storage device containing that personal information beyond your logical or physical controls, unless the data is encrypted using an encryption technology adopted by an established standards-setting body, with appropriate management and safeguards of the cryptographic keys. |
|
| Security measures for data collectors maintaining personal information from a date not yet set |
Implement and maintain reasonable security measures to protect those records from unauthorized access, acquisition, destruction, use, modification, or disclosure. |
|
| Data Breach Notification Act, security and disposal duties from a date not yet set |
Implement and maintain reasonable security procedures and practices, appropriate to the nature of the personal identifying information held, to protect it from unauthorized access, destruction, use, modification, or disclosure. |
|
| Oregon Consumer Information Protection Act, requirement to develop safeguards for personal information |
Develop, implement and maintain reasonable administrative, technical and physical safeguards to protect the security, confidentiality and integrity of personal information, including its secure disposal. |
|
| Identity Theft Protection Act of 2015, risk-based information security program from a date not yet set |
Implement and maintain a risk-based information security program with reasonable security procedures and practices appropriate to your size and scope, the nature of the information, and the purpose for which it was collected, to protect the information from unauthorized access, use, modification, destruction, or disclosure and to preserve its confidentiality, integrity, and availability. |
|
| Identity Theft Enforcement and Protection Act, business duty to protect sensitive personal information |
Implement and maintain reasonable procedures, including taking any appropriate corrective action, to protect that sensitive personal information from unlawful use or disclosure. The statute states no further content for what 'reasonable' requires beyond this general standard. |
|
| Protection of Personal Information Act, reasonable procedures and records-destruction duty |
Implement and maintain reasonable procedures to prevent the unlawful use or disclosure of that personal information. The statute states no further content for what 'reasonable' requires beyond this general standard. |
|
| Law on Cybersecurity, general cybersecurity duties on cybersecurity subjects |
Prevent unlawful disclosure, theft, loss, corruption, blocking, or falsification of data in your information systems and resources, and act promptly when such a case is detected. |
|
| Law on Informatization, information security duty for information resource and system owners |
Where your information resources or systems contain state secrets or confidential information, you must protect them under the procedure the Cabinet of Ministers sets for that category. |
Sector security regimes
7 laws, 7 places| Place | Law | What it asks, as read here |
|---|---|---|
| Lei de Protecção das Redes e Sistemas Informáticos, Security Duties for Information-Society Systems, Computer Programs and Databases |
Where you use a database, follow technical rules and specialised procedures adequate to protect its access, storage, file duplication, treatment and the recovery of automated information (Article 19). |
|
| Loi n° 1/10, Articles 3, 4(3) and 14: security-of-service duty and diligence penalty for network operators and service providers |
Exercise the diligence and competence necessary to prevent the disclosure of computer data you hold on behalf of a third party, or face a fine of 10,000,000 to 30,000,000 Burundian francs (BIF) under Article 14. |
|
| Banque du Liban Basic Circular No. 144 (Prevention of Electronic Criminal Acts) |
Adopt at least two-factor authentication for any user accessing the system from outside the bank or financial institution, fully encrypt highly sensitive data, filter inbound email, verify the security of devices employees use outside the institution, run penetration testing, monitor network traffic, and verify data integrity. |
|
| Telecommunications Act 2007, Security Safeguards for Customer Information and Communications |
Ensure that customer information and customer communications in your custody or control are protected by security safeguards appropriate to their sensitivity. |
|
| FSM Telecommunications Act of 2014, Security Safeguards for Customer Information |
Apply appropriate security safeguards to prevent the collection, use, maintenance, or disclosure of a customer's information without the customer's consent. |
|
| Telecommunications Act 2009, Security Safeguards for Consumer Information |
Apply appropriate security safeguards to prevent the collection, use, maintenance, or disclosure of a consumer's information. |
|
| Law on Communications, network and subscriber-information protection duties |
Ensure the safekeeping of subscriber information obtained on contracting and about services rendered, including their duration, content, and routing, and protect that information during automated processing. |
Vulnerability and incident reporting
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Cybersecurity Law, Incident Response and Reporting Duties |
Apply technical measures to secure data processing, including personal-data processing, consistent with this Law, Vietnam's law on data, and its Law on Personal Data Protection. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.