Law / Frameworks / NIST CSF 2.0 / Protect
NIST CSF 2.0, ProtectPR.IR-01
Networks and environments are protected from unauthorized logical access and usageNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), PR.IR-01
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 9
- laws
- 9
- places
- 0
- with court rulings behind them
- 0
- not yet in force
Sector security regimes
6 laws, 6 places| Place | Law | What it asks, as read here |
|---|---|---|
| Lei de Protecção das Redes e Sistemas Informáticos, Security Duties for Information-Society Systems, Computer Programs and Databases |
Guarantee the security of any device or set of devices, and the network supporting communication between them, that stores, processes, retrieves, receives or transmits data in execution of a computer program (Article 12). Where you are responsible for managing, operating or providing services for a computer infrastructure, apply the measures and techniques needed to secure and protect the assets essential to that infrastructure's proper functioning (Article 13). |
|
| Loi n° 1/10, Articles 3, 4(3) and 14: security-of-service duty and diligence penalty for network operators and service providers |
Guarantee the security of the services you offer, and put in place the technical processes and means needed to fight cyber fraud. |
|
| Information and Communications Act, 2009, security of information and communications services (safeguards duty) |
Take appropriate technical and organizational measures, jointly with other service providers where necessary, to safeguard the security of your services. |
|
| National Communication Act, 2012, Licensee Security Duty |
Provide protection, technical security and safety for the Licensee's own facilities, equipment and communication networks, so as to ensure system efficiency and reliability (Sec. 88(3)). |
|
| Law on Communications, network and subscriber-information protection duties |
Implement technical and organizational methods to protect communication networks, telecommunications facilities, restricted-access information about the organization of communication networks, and information transmitted over those networks, and cooperate with law-enforcement bodies to protect communication facilities and structures from unauthorized access. |
|
| Law on the Basic Principles of Ensuring Cybersecurity, Critical Infrastructure Owner Cyber-Defense and Audit Duty |
Ensure the cyber-defense of the communication and technological systems of your critical infrastructure object, and protect its technological information, in accordance with legislative requirements. |
Security baseline statutes
3 laws, 3 places| Place | Law | What it asks, as read here |
|---|---|---|
| Decreto No. 360/2019 and its Reglamento de Seguridad de las TIC (Resolución 128/2019), TIC Security System duty |
If you provide Internet access service, additionally draft internal security-operation procedures, name the person responsible for network security, and adopt technical and organizational measures against malware contamination and network attacks and intrusions. |
|
| Law No. 175 of 2018 on Anti-Cyber and Information Technology Crimes, System-Security Duty on a System Manager |
Do not intentionally expose a website, private account, email account, or information system you manage to the commission of a crime under this Law; doing so carries imprisonment of not less than one year plus a fine of EGP 20,000 to 200,000. |
|
| Government Regulation on the Operation of Electronic Systems and Transactions, electronic-system security duty |
Provide a security system covering procedures and technical measures, such as antivirus, anti-spam, a firewall, intrusion detection or prevention, or an information security management system, to prevent and counter a threat or attack against your Electronic System. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.