Law / Frameworks / NIST CSF 2.0 / Protect

NIST CSF 2.0, ProtectPR.PS-02

Software is maintained, replaced, and removed commensurate with riskNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), PR.PS-02

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

5
laws
5
places
0
with court rulings behind them
1
not yet in force

A law in force is unmarked; the rest wear their state: not yet in force

  • Australia
  • Brazil
  • China
  • European Union
  • United Kingdom

Product security requirements

5 laws, 5 places
PlaceLawWhat it asks, as read here
Australia Security Standards for Smart Devices

Publish, before supply, the period including an end date for which the device will receive security updates, provide or supply the product with a statement of compliance with the security standard, and retain a copy of that statement for five years.

Brazil Anatel Cybersecurity Requirements for CPE (Customer Premises Equipment)

Publish a clear support policy stating how long and in what circumstances you will provide security updates, and provide security updates free of charge for at least 2 years after the product's launch or for as long as you keep distributing it to consumers, whichever period is longer.

Maintain a public, Portuguese-language support page listing known vulnerabilities in your products together with their mitigations, and keep making corrected software or firmware available.

China Cybersecurity Law, Network Product and Service Security Duties

On discovering a security defect, vulnerability, or other risk in your product or service, immediately take remedial measures, notify affected users as provided, and report the defect or vulnerability to the competent authority; the statute states no numeric clock for this notice, only immediacy.

Provide continuous security maintenance for your product or service and do not terminate it within the period fixed by regulation or agreed with your user.

European Union Cyber Resilience Act, Essential Requirements and Manufacturer Obligations from , in 14 months

Maintain a support period of at least five years, or the product's expected use time if shorter, handle vulnerabilities in the product and its components throughout that period, and keep each security update available for ten years after release or for the remainder of the support period, whichever is longer.

Put in place a coordinated vulnerability disclosure policy and a contact channel for reporting a vulnerability, and disclose the end date of the support period to the buyer at the time of purchase.

United Kingdom Product Security Requirements for Connectable Products

Publish the minimum period for which the product will receive security updates, in plain language, before or at the point of sale, and never shorten that stated period once published.

Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.