Law / Frameworks / NIST CSF 2.0 / Protect

NIST CSF 2.0, ProtectPR.DS-02

The confidentiality, integrity, and availability of data-in-transit are protectedNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), PR.DS-02

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

5
laws
5
places
0
with court rulings behind them
1
not yet in force

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force

  • Kuwait
  • Massachusetts
  • Nevada
  • Serbia
  • Yemen

Security baseline statutes

3 laws, 3 places
PlaceLawWhat it asks, as read here
Kuwait Data Classification Policy

Encrypt Tier 3 (Private Sensitive) and Tier 4 (Highly Sensitive) data whenever you transmit it between physical locations.

Massachusetts Standards for the Protection of Personal Information of Residents of the Commonwealth

For personal information you store or transmit electronically, build a computer-system security program with secure user authentication, access controls limiting records to those who need them, encryption of records transmitted across public networks or wirelessly and of personal information stored on a laptop or other portable device, up-to-date firewalls and operating-system security patches for any internet-connected system, up-to-date malware protection, and employee training on the security system.

Nevada Security measures for a data collector accepting payment cards, encryption duty, and conditioned liability shield from a date not yet set

If you do not accept payment cards, do not transfer a Nevada resident's personal information through an electronic, nonvoice transmission other than a facsimile outside your secure system, and do not move a data storage device containing that personal information beyond your logical or physical controls, unless the data is encrypted using an encryption technology adopted by an established standards-setting body, with appropriate management and safeguards of the cryptographic keys.

Sector security regimes

2 laws, 2 places
PlaceLawWhat it asks, as read here
Serbia Law on Information Security, ICT Systems of Special Importance and Security Measures

Take technical, operational, organisational and physical protection measures across the areas Article 10 lists, including multi-factor authentication or a continuous-authentication solution, secured voice, video and text communication, and secured communication channels for emergencies.

Yemen Law No. 40 of 2006 on Electronic Payment Systems and Financial and Banking Operations, Secure-Services and Banking-Confidentiality Duty

Take the measures necessary to provide secure services to customers and preserve banking confidentiality when conducting an electronic funds transfer.

Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.