Law / Frameworks / NIST CSF 2.0 / Protect
NIST CSF 2.0, ProtectPR.DS-02
The confidentiality, integrity, and availability of data-in-transit are protectedNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), PR.DS-02
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 5
- laws
- 5
- places
- 0
- with court rulings behind them
- 1
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFMEASURE 2.5 The AI system to be deployed is demonstrated to be valid and reliable. Limitations of...
- NIST AI RMFMEASURE 2.6 The AI system is evaluated regularly for safety risks – as identified in the MAP...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-09 Information Security
- OWASP LLM Top 10LLM01:2026 Prompt Injection
- OWASP LLM Top 10LLM02:2026 Sensitive Information Disclosure
- OWASP Agentic Top 10ASI01 Agent Goal Hijack
- OWASP Agentic Top 10ASI03 Identity and Privilege Abuse
- MIT mitigations2.1 Model & Infrastructure Security
- MIT mitigations2.3 Model Safety Engineering
- NIST Privacy FrameworkPR.PO-P7 Response plans (Incident Response and Business Continuity) and recovery plans...
- NIST Privacy FrameworkPR.PO-P10 A vulnerability management plan is developed and implemented.
A law in force is unmarked; the rest wear their state: not yet in force
Security baseline statutes
3 laws, 3 places| Place | Law | What it asks, as read here |
|---|---|---|
| Data Classification Policy |
Encrypt Tier 3 (Private Sensitive) and Tier 4 (Highly Sensitive) data whenever you transmit it between physical locations. |
|
| Standards for the Protection of Personal Information of Residents of the Commonwealth |
For personal information you store or transmit electronically, build a computer-system security program with secure user authentication, access controls limiting records to those who need them, encryption of records transmitted across public networks or wirelessly and of personal information stored on a laptop or other portable device, up-to-date firewalls and operating-system security patches for any internet-connected system, up-to-date malware protection, and employee training on the security system. |
|
| Security measures for a data collector accepting payment cards, encryption duty, and conditioned liability shield from a date not yet set |
If you do not accept payment cards, do not transfer a Nevada resident's personal information through an electronic, nonvoice transmission other than a facsimile outside your secure system, and do not move a data storage device containing that personal information beyond your logical or physical controls, unless the data is encrypted using an encryption technology adopted by an established standards-setting body, with appropriate management and safeguards of the cryptographic keys. |
Sector security regimes
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Law on Information Security, ICT Systems of Special Importance and Security Measures |
Take technical, operational, organisational and physical protection measures across the areas Article 10 lists, including multi-factor authentication or a continuous-authentication solution, secured voice, video and text communication, and secured communication channels for emergencies. |
|
| Law No. 40 of 2006 on Electronic Payment Systems and Financial and Banking Operations, Secure-Services and Banking-Confidentiality Duty |
Take the measures necessary to provide secure services to customers and preserve banking confidentiality when conducting an electronic funds transfer. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.