Law / Frameworks / NIST CSF 2.0 / Protect
NIST CSF 2.0, ProtectPR.PS-01
Configuration management practices are established and appliedNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), PR.PS-01
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 1
- law
- 1
- place
- 0
- with court rulings behind them
- 0
- not yet in force
Product security requirements
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Anatel Cybersecurity Requirements for CPE (Customer Premises Equipment) |
Do not hard-code credentials or cryptographic keys in the device's software or firmware source code, encrypt or hash any password, key, or credential you store or transmit, implement inactive-session timeouts, ship with unused communication ports and services disabled, and let the user disable non-essential communication features. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.