Law / Frameworks / NIST CSF 2.0 / Protect

NIST CSF 2.0, ProtectPR.PS-06

Secure software development practices are integrated, and their performance is monitored throughout the software development life cycleNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), PR.PS-06

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

10
laws
10
places
0
with court rulings behind them
1
not yet in force

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force

  • Angola
  • Australia
  • Brazil
  • California
  • China
  • Cuba
  • Cyprus
  • European Union
  • Oregon
  • United Kingdom

Product security requirements

8 laws, 8 places
PlaceLawWhat it asks, as read here
Australia Security Standards for Smart Devices

Do not manufacture or supply a consumer grade smart device with a universal default password from for a product manufactured on or after that date; the device's hardware and any pre-installed or required software must use a password unique to that unit or set by the user, for every state other than the factory default.

Brazil Anatel Cybersecurity Requirements for CPE (Customer Premises Equipment)

Do not ship the device with weak, blank, or identical-across-all-units default credentials, and do not derive an initial password from information easy to obtain by scanning network traffic, such as a MAC address; alternatively, force the user to set a new password meeting the strength rules the first time the device is used or after a factory reset.

Do not hard-code credentials or cryptographic keys in the device's software or firmware source code, encrypt or hash any password, key, or credential you store or transmit, implement inactive-session timeouts, ship with unused communication ports and services disabled, and let the user disable non-essential communication features.

California Security of Connected Devices

Equip the device with a security feature or features appropriate to its nature, function, and the information it may collect, contain, or transmit, designed to protect the device and that information from unauthorized access, destruction, use, modification, or disclosure.

Where the device authenticates outside a local area network, give each unit a unique preprogrammed password or require the user to generate a new means of authentication before first use; meeting a NIST-conforming Internet of Things cybersecurity labeling scheme's baseline criteria and conformity assessment is an alternative way to satisfy the duty.

China Cybersecurity Law, Network Product and Service Security Duties

Meet the mandatory requirements of the applicable national standard for your product or service, and do not embed a malicious program in it.

Cyprus Security of Networks and Information Systems Law, Radio Equipment Cybersecurity Requirements

Construct the equipment so that it does not harm the network, and its operation does not misuse network resources so as to cause an unacceptable degradation of service.

Incorporate safeguards to protect the personal data and privacy of the equipment's users and subscriber, and support features protecting against fraud.

European Union Cyber Resilience Act, Essential Requirements and Manufacturer Obligations from , in 14 months

Once it applies, design, develop, and produce the product so it ships without known exploitable vulnerabilities, with a secure default configuration, protection against unauthorised access, and encryption of data at rest and in transit.

Oregon Security requirements for Internet-connected devices

Equip the connected device with reasonable security features appropriate to its nature, function and the information it may collect, store or transmit, satisfied by giving each device a unique preprogrammed authentication credential or by requiring the user to generate new credentials before first use, or by complying with an applicable federal security requirement for connected devices.

United Kingdom Product Security Requirements for Connectable Products

Ban universal default passwords and easily guessable passwords across the product's hardware and pre-installed or required software; a password must be unique per unit or set by the user, and must not be built from incremental counters or from publicly derivable identifiers.

Sector security regimes

1 law, 1 place
PlaceLawWhat it asks, as read here
Angola Lei de Protecção das Redes e Sistemas Informáticos, Security Duties for Information-Society Systems, Computer Programs and Databases

Apply this Law's security measures and techniques to any computer program you make available; the text states no separate support period, update or vulnerability-disclosure-channel duty for the program itself (Article 18).

Security baseline statutes

1 law, 1 place
PlaceLawWhat it asks, as read here
Cuba Decreto No. 360/2019 and its Reglamento de Seguridad de las TIC (Resolución 128/2019), TIC Security System duty

If you produce equipment or provide network, program, application or IT services, whether from inside or outside Cuba, implement the requirements that guarantee the secure operation of the equipment and services you supply; obtain a Ministry of Communications operating license before offering TIC security services to a third party, a license reserved to a state entity whose staff reside permanently in the country.

Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.