Law / Frameworks / NIST CSF 2.0 / Protect
NIST CSF 2.0, ProtectPR.PS-04
Log records are generated and made available for continuous monitoringNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), PR.PS-04
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 6
- laws
- 6
- places
- 0
- with court rulings behind them
- 0
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 1.1 Legal and regulatory requirements involving AI are understood, managed, and documented.
- NIST AI RMFGOVERN 1.4 The risk management process and its outcomes are established through transparent...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-07 Human-AI Configuration
- OWASP LLM Top 10LLM03:2026 Excessive Agency
- OWASP Agentic Top 10ASI09 Human-Agent Trust Exploitation
- MIT mitigations4.1 System Documentation
- MIT mitigations1.1 Board Structure & Oversight
- NIST Privacy FrameworkGV.PO-P1 Organizational privacy values and policies (e.g., conditions on data processing such...
- NIST Privacy FrameworkCT.DM-P8 Audit/log records are determined, documented, implemented, and reviewed in accordance...
Security baseline statutes
3 laws, 3 places| Place | Law | What it asks, as read here |
|---|---|---|
| Sécurité des systèmes d'information (dispositions communes) |
Retain your systems' connection and traffic data for ten years, and submit your networks and information systems to a mandatory, periodic security audit on terms a regulation sets. |
|
| Privacy Protection Regulations (Data Security), information security programme |
At the medium or high tier, run an automatic mechanism monitoring access to the database's systems, retained at least 24 months, and appoint a data security officer where required. |
|
| Law on Information Security, General Security Measures |
Adopt rules for handling data, log who has accessed it, and oversee the security of that data (Article 12). |
Sector security regimes
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Loi n° 05-20 relative à la cybersécurité, Digital Service Provider and Platform Operator Security Duties |
Comply with the national cybersecurity authority's directives on retaining, for one year from generation, the technical data needed to identify a cybersecurity incident, including connection data, system logs, and the security-event traces your operating systems, applications and security products generate. |
|
| Cyber Security and Crime Act, 2021, Critical National Information Infrastructure |
If your system, data, or traffic data is designated, meet the minimum standards, guidelines, rules, or procedures the Presidential Order prescribes, which section 7(2) requires to cover at least securing systems by default and logging system and user activity for audit, and permit the National Computer Security Incidence Response Team to audit and inspect the designated infrastructure at any time. |
Vulnerability and incident reporting
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| CERT-In Cyber Security Directions, Incident Reporting, Logging and Time Synchronisation |
Connect all your ICT systems' clocks to the Network Time Protocol server of the National Informatics Centre or the National Physical Laboratory, or to an NTP server traceable to one of them, and ensure any other time source you use does not deviate from NPL or NIC. Enable logs of all your ICT systems and retain them securely, within Indian jurisdiction, on a rolling 180-day basis, and provide them to CERT-In together with an incident report or when CERT-In orders or directs you to. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.