Law / Frameworks / NIST CSF 2.0 / Respond

NIST CSF 2.0, RespondRS.AN-07

Incident data and metadata are collected, and their integrity and provenance are preservedNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), RS.AN-07

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

5
laws
4
places
0
with court rulings behind them
1
not yet in force

A law in force is unmarked; the rest wear their state: not yet in force

  • Indonesia
  • South Korea
  • United States
  • Uzbekistan

Vulnerability and incident reporting

5 laws, 4 places
PlaceLawWhat it asks, as read here
Indonesia Government Regulation on the Operation of Electronic Systems and Transactions, security-incident reporting duty

On a system failure or disruption with a serious impact resulting from another party's act against your Electronic System, such as an attack or intrusion, secure the affected Electronic Information and/or Electronic Document.

South Korea Information and Communications Network Act, Report on Computer Security Incidents

Preserve, and submit on demand to the Minister of Science and ICT or the Korea Internet and Security Agency, the data needed to analyze the incident's cause; submitting false data or refusing to submit it is separately finable.

United States Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) from a date not yet set

Once the final rule takes effect, promptly submit an update to a previously submitted covered cyber incident report whenever substantial new or different information becomes available or a ransom payment is later made, continuing until your organization notifies the Agency that the incident has concluded and been fully mitigated and resolved, and preserve data relevant to the incident or payment under the procedures the final rule establishes.

United States Safeguarding Covered Defense Information and Cyber Incident Reporting (DFARS 252.204-7012)

Preserve and protect forensic images of the affected information systems and related monitoring and packet-capture data for at least 90 days counted from the date you submit the cyber incident report, not from the date you discovered the incident, so the Department of Defense can request the media or decline interest.

Uzbekistan Law on Cybersecurity, cybersecurity incident notification duty

Take steps to prevent the loss of digital evidence needed to fully investigate the incident, and keep the records needed to analyze it.

Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.