Law / Frameworks / NIST CSF 2.0 / Recover

NIST CSF 2.0, RecoverRC.RP-06

The end of incident recovery is declared based on criteria, and incident-related documentation is completedNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), RC.RP-06

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

3
laws
3
places
0
with court rulings behind them
0
not yet in force

The same ground elsewhere linked through the kinds of duty both controls are mapped from

  • Belgium
  • China
  • Taiwan

Vulnerability and incident reporting

3 laws, 3 places
PlaceLawWhat it asks, as read here
Belgium Loi du 26 avril 2024, Significant-Incident Notification Obligations

Submit an interim report if the national CSIRT or the competent sectoral authority asks for one, and a final report no later than one month after the incident notification, describing the incident in detail, its severity and impact, the likely threat or root cause, the mitigation measures applied and in progress, and any cross-border impact.

China National Cybersecurity Incident Reporting Measures

Within 30 days of completing disposal of a relatively major incident or above, submit a summary report covering the incident's cause, your emergency response, the harm caused, accountability, remediation, and lessons learned, through the same channel you used for the original report.

Taiwan Cyber Security Management Act, Cyber Security Incident Reporting

Submit an investigation, handling and corrective-action report on the incident to that authority, and to the Ministry of Digital Affairs as well where the incident is a major one.

Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.