Law / Frameworks / NIST CSF 2.0 / Protect

NIST CSF 2.0, ProtectPR.IR-03

Mechanisms are implemented to achieve resilience requirements in normal and adverse situationsNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), PR.IR-03

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

7
laws
7
places
0
with court rulings behind them
1
not yet in force

A law in force is unmarked; the rest wear their state: not yet in force

  • Central African Republic
  • Djibouti
  • Gabon
  • Indonesia
  • Kosovo
  • Kyrgyzstan
  • Slovenia

Security baseline statutes

4 laws, 4 places
PlaceLawWhat it asks, as read here
Central African Republic Cybersecurity Law: Network and Information System Security Duty

Put in place technical mechanisms addressing threats to your systems' permanent availability, integrity, authentication, non-repudiation and data confidentiality, and to their physical security, and submit those mechanisms to the Agence Nationale de la Cybersécurité for approval.

Gabon Sécurité des systèmes d'information (dispositions communes)

Deploy technical mechanisms addressing threats to your systems' continuous availability, integrity, authentication, resistance to repudiation by third-party users, data confidentiality and physical security, and have those mechanisms cleared for conformity with the competent administrative authority's cybersecurity policy.

Indonesia Government Regulation on the Operation of Electronic Systems and Transactions, electronic-system security duty

Operate your Electronic System reliably and securely, and take legal responsibility for it operating as it should.

Secure your Electronic System's components, and have and run procedures and means to protect the system against disruption, failure, and loss.

Kyrgyzstan Digital Code, digital resilience baseline security measures

Maintain the integrity and availability of your digital systems and the confidentiality of the digital data you process, monitor for and help prevent incidents in the digital environment, manage the resulting risk under a risk-management system, and dedicate the resources your continuity of operation and recovery from an incident require.

Sector security regimes

3 laws, 3 places
PlaceLawWhat it asks, as read here
Djibouti Digital Code, Book II: Electronic Communications Network and Service Security

Take all appropriate measures to ensure the integrity of your network and the continuity of the services you supply, if you operate a public electronic communications network or provide a public electronic communications service in Djibouti.

Kosovo Law No. 08/L-173 on Cyber Security, Security Measures

As an operator of essential services, permanently apply organizational, physical and information-technology security measures that prevent a cyber incident, resolve one, and prevent or mitigate its impact.

Slovenia Zakon o informacijski varnosti (ZInfV-1), Cybersecurity Risk-Management Measures and Governance from , in 3 months

Once it binds, take technical, operational and organisational measures to secure the integrity, authenticity, confidentiality and availability of the network and information systems you use for your work or to provide your services, and to prevent or reduce the impact of an incident on the recipients of your services and on other services.

Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.