Law / Frameworks / NIST CSF 2.0 / Recover

NIST CSF 2.0, RecoverRC.CO-04

Public updates on incident recovery are shared using approved methods and messagingNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), RC.CO-04

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

5
laws
5
places
0
with court rulings behind them
0
not yet in force

The same ground elsewhere linked through the kinds of duty both controls are mapped from

  • Cameroon
  • Central African Republic
  • Estonia
  • Gabon
  • Kosovo

Security baseline statutes

3 laws, 3 places
PlaceLawWhat it asks, as read here
Cameroon Loi n°2010/012 du 21 décembre 2010 relative à la cybersécurité et à la cybercriminalité au Cameroun, articles 6, 7, 13-14, 24, 26-30, 32, 61(3) (mesures de sécurité et audit de sécurité obligatoire par l'ANTIC)

Inform your users of the dangers of using your network or service, the specific security risks it faces, and the technical means available to secure their communications.

Central African Republic Cybersecurity Law: Network and Information System Security Duty

Inform your users of the dangers of using your network or information system, the particular security-violation risks involved, and the technical means available to secure their communications or restrict access to certain services.

Gabon Sécurité des systèmes d'information (dispositions communes)

If your activity is to offer users access to an information system, inform them of the danger of using an unsecured system, the need for a parental-control device, the particular risks of a security breach, and the existence of a technical means to restrict access to certain services, and offer them at least one such means.

Vulnerability and incident reporting

2 laws, 2 places
PlaceLawWhat it asks, as read here
Estonia Küberturvalisuse seadus (KüTS), Duty to Notify of a Cyber Incident

Where relevant, notify within a reasonable time any person the significant incident or a significant cyber threat may affect, or the public where you cannot notify affected persons individually; RIA may also itself inform the public after consulting you, or require you to, where public awareness serves prevention, resolution or the public interest.

Kosovo Law No. 08/L-173 on Cyber Security, Incident Reporting and Enforcement

As an operator of essential services, notify the Agency for Cyber Security immediately, and no later than 24 hours after becoming aware, of a cyber incident with a significant impact on system security or service continuity, and notify affected persons or the public within a reasonable time where individual notice is impractical.

Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.