Law / Frameworks / NIST CSF 2.0 / Recover
NIST CSF 2.0, RecoverRC.RP-06
The end of incident recovery is declared based on criteria, and incident-related documentation is completedNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), RC.RP-06
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 3
- laws
- 3
- places
- 0
- with court rulings behind them
- 0
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 1.1 Legal and regulatory requirements involving AI are understood, managed, and documented.
- NIST AI RMFGOVERN 4.2 Organizational teams document the risks and potential impacts of the AI technology...
- NIST AI 600-1GAI-RISK-09 Information Security
- MIT mitigations4.2 Risk Disclosure
- MIT mitigations4.3 Incident Reporting
- NIST Privacy FrameworkGV.PO-P5 Legal, regulatory, and contractual requirements regarding privacy are understood and managed.
- NIST Privacy FrameworkGV.MT-P4 Policies, processes, and procedures for communicating progress on managing privacy...
Vulnerability and incident reporting
3 laws, 3 places| Place | Law | What it asks, as read here |
|---|---|---|
| Loi du 26 avril 2024, Significant-Incident Notification Obligations |
Submit an interim report if the national CSIRT or the competent sectoral authority asks for one, and a final report no later than one month after the incident notification, describing the incident in detail, its severity and impact, the likely threat or root cause, the mitigation measures applied and in progress, and any cross-border impact. |
|
| National Cybersecurity Incident Reporting Measures |
Within 30 days of completing disposal of a relatively major incident or above, submit a summary report covering the incident's cause, your emergency response, the harm caused, accountability, remediation, and lessons learned, through the same channel you used for the original report. |
|
| Cyber Security Management Act, Cyber Security Incident Reporting |
Submit an investigation, handling and corrective-action report on the incident to that authority, and to the Ministry of Digital Affairs as well where the incident is a major one. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.