Law / Frameworks / NIST CSF 2.0 / Protect
NIST CSF 2.0, ProtectPR.PS-06
Secure software development practices are integrated, and their performance is monitored throughout the software development life cycleNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), PR.PS-06
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 10
- laws
- 10
- places
- 0
- with court rulings behind them
- 1
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFMEASURE 2.5 The AI system to be deployed is demonstrated to be valid and reliable. Limitations of...
- NIST AI RMFMEASURE 2.6 The AI system is evaluated regularly for safety risks – as identified in the MAP...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-09 Information Security
- OWASP LLM Top 10LLM01:2026 Prompt Injection
- OWASP LLM Top 10LLM02:2026 Sensitive Information Disclosure
- OWASP Agentic Top 10ASI01 Agent Goal Hijack
- OWASP Agentic Top 10ASI03 Identity and Privilege Abuse
- MIT mitigations2.1 Model & Infrastructure Security
- MIT mitigations2.3 Model Safety Engineering
- NIST Privacy FrameworkPR.PO-P7 Response plans (Incident Response and Business Continuity) and recovery plans...
- NIST Privacy FrameworkPR.PO-P10 A vulnerability management plan is developed and implemented.
A law in force is unmarked; the rest wear their state: not yet in force
Product security requirements
8 laws, 8 places| Place | Law | What it asks, as read here |
|---|---|---|
| Security Standards for Smart Devices |
Do not manufacture or supply a consumer grade smart device with a universal default password from for a product manufactured on or after that date; the device's hardware and any pre-installed or required software must use a password unique to that unit or set by the user, for every state other than the factory default. |
|
| Anatel Cybersecurity Requirements for CPE (Customer Premises Equipment) |
Do not ship the device with weak, blank, or identical-across-all-units default credentials, and do not derive an initial password from information easy to obtain by scanning network traffic, such as a MAC address; alternatively, force the user to set a new password meeting the strength rules the first time the device is used or after a factory reset. Do not hard-code credentials or cryptographic keys in the device's software or firmware source code, encrypt or hash any password, key, or credential you store or transmit, implement inactive-session timeouts, ship with unused communication ports and services disabled, and let the user disable non-essential communication features. |
|
| Security of Connected Devices |
Equip the device with a security feature or features appropriate to its nature, function, and the information it may collect, contain, or transmit, designed to protect the device and that information from unauthorized access, destruction, use, modification, or disclosure. Where the device authenticates outside a local area network, give each unit a unique preprogrammed password or require the user to generate a new means of authentication before first use; meeting a NIST-conforming Internet of Things cybersecurity labeling scheme's baseline criteria and conformity assessment is an alternative way to satisfy the duty. |
|
| Cybersecurity Law, Network Product and Service Security Duties |
Meet the mandatory requirements of the applicable national standard for your product or service, and do not embed a malicious program in it. |
|
| Security of Networks and Information Systems Law, Radio Equipment Cybersecurity Requirements |
Construct the equipment so that it does not harm the network, and its operation does not misuse network resources so as to cause an unacceptable degradation of service. Incorporate safeguards to protect the personal data and privacy of the equipment's users and subscriber, and support features protecting against fraud. |
|
| Cyber Resilience Act, Essential Requirements and Manufacturer Obligations from , in 14 months |
Once it applies, design, develop, and produce the product so it ships without known exploitable vulnerabilities, with a secure default configuration, protection against unauthorised access, and encryption of data at rest and in transit. |
|
| Security requirements for Internet-connected devices |
Equip the connected device with reasonable security features appropriate to its nature, function and the information it may collect, store or transmit, satisfied by giving each device a unique preprogrammed authentication credential or by requiring the user to generate new credentials before first use, or by complying with an applicable federal security requirement for connected devices. |
|
| Product Security Requirements for Connectable Products |
Ban universal default passwords and easily guessable passwords across the product's hardware and pre-installed or required software; a password must be unique per unit or set by the user, and must not be built from incremental counters or from publicly derivable identifiers. |
Sector security regimes
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Lei de Protecção das Redes e Sistemas Informáticos, Security Duties for Information-Society Systems, Computer Programs and Databases |
Apply this Law's security measures and techniques to any computer program you make available; the text states no separate support period, update or vulnerability-disclosure-channel duty for the program itself (Article 18). |
Security baseline statutes
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Decreto No. 360/2019 and its Reglamento de Seguridad de las TIC (Resolución 128/2019), TIC Security System duty |
If you produce equipment or provide network, program, application or IT services, whether from inside or outside Cuba, implement the requirements that guarantee the secure operation of the equipment and services you supply; obtain a Ministry of Communications operating license before offering TIC security services to a third party, a license reserved to a state entity whose staff reside permanently in the country. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.