Law / Frameworks / NIST CSF 2.0 / Protect

NIST CSF 2.0, ProtectPR.PS-04

Log records are generated and made available for continuous monitoringNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), PR.PS-04

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

6
laws
6
places
0
with court rulings behind them
0
not yet in force

The same ground elsewhere linked through the kinds of duty both controls are mapped from

  • Gabon
  • India
  • Israel
  • Montenegro
  • Morocco
  • Sierra Leone

Security baseline statutes

3 laws, 3 places
PlaceLawWhat it asks, as read here
Gabon Sécurité des systèmes d'information (dispositions communes)

Retain your systems' connection and traffic data for ten years, and submit your networks and information systems to a mandatory, periodic security audit on terms a regulation sets.

Israel Privacy Protection Regulations (Data Security), information security programme

At the medium or high tier, run an automatic mechanism monitoring access to the database's systems, retained at least 24 months, and appoint a data security officer where required.

Montenegro Law on Information Security, General Security Measures

Adopt rules for handling data, log who has accessed it, and oversee the security of that data (Article 12).

Sector security regimes

2 laws, 2 places
PlaceLawWhat it asks, as read here
Morocco Loi n° 05-20 relative à la cybersécurité, Digital Service Provider and Platform Operator Security Duties

Comply with the national cybersecurity authority's directives on retaining, for one year from generation, the technical data needed to identify a cybersecurity incident, including connection data, system logs, and the security-event traces your operating systems, applications and security products generate.

Sierra Leone Cyber Security and Crime Act, 2021, Critical National Information Infrastructure

If your system, data, or traffic data is designated, meet the minimum standards, guidelines, rules, or procedures the Presidential Order prescribes, which section 7(2) requires to cover at least securing systems by default and logging system and user activity for audit, and permit the National Computer Security Incidence Response Team to audit and inspect the designated infrastructure at any time.

Vulnerability and incident reporting

1 law, 1 place
PlaceLawWhat it asks, as read here
India CERT-In Cyber Security Directions, Incident Reporting, Logging and Time Synchronisation

Connect all your ICT systems' clocks to the Network Time Protocol server of the National Informatics Centre or the National Physical Laboratory, or to an NTP server traceable to one of them, and ensure any other time source you use does not deviate from NPL or NIC.

Enable logs of all your ICT systems and retain them securely, within Indian jurisdiction, on a rolling 180-day basis, and provide them to CERT-In together with an incident report or when CERT-In orders or directs you to.

Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.