Law / Frameworks / NIST CSF 2.0 / Recover
NIST CSF 2.0, RecoverRC.RP-02
Recovery actions are selected, scoped, prioritized, and performedNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), RC.RP-02
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 3
- laws
- 3
- places
- 0
- with court rulings behind them
- 0
- not yet in force
Vulnerability and incident reporting
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Information and Communications Act, 2009, security of information and communications services (subscriber risk notification) |
Notifying subscribers of a security risk does not excuse you from taking immediate measures to restore your service's normal security level. |
|
| Cybersecurity Incident Reporting and Emergency Response |
Where an incident or attack has disrupted your information system or communications network, or endangered the national cyberspace's security, remedy the failure within thirty days of the Agency's warning, or expect the minister of communication technologies to order the temporary isolation of your systems. |
Security baseline statutes
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Law No. 455-Z, Information System Operator's Duty to Protect Information (Article 40) |
Where necessary, take measures to restore information that has been lost. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.