Law / Frameworks / NIST CSF 2.0 / Respond
NIST CSF 2.0, RespondRS.MA-01
The incident response plan is executed in coordination with relevant third parties once an incident is declaredNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), RS.MA-01
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 3
- laws
- 3
- places
- 0
- with court rulings behind them
- 0
- not yet in force
Vulnerability and incident reporting
3 laws, 3 places| Place | Law | What it asks, as read here |
|---|---|---|
| Llei 22/2022, Incident Handling and Notification Obligation |
Manage and resolve any security incident affecting the critical infrastructure, networks or information systems you use to provide your essential or important service, including by ensuring any external provider of those systems applies the necessary security measures, and request the CSIRT-AD's opinion or specialised support where needed; the CSIRT-AD's indications to mitigate effects and restore affected systems are binding on you. |
|
| Cyber Security Law No. 16 of 2019, Article 8 private-sector incident-reporting and Center-cooperation duty |
Where the National Cyber Security Council designates an incident a threat to the Kingdom's own security and safety, the Center directs the response and every institution involved must comply with the Center's instructions and directives. |
|
| Cybersecurity Law, Incident Response and Reporting Duties |
When a cybersecurity incident occurs, implement that plan immediately and simultaneously report it to the specialised cybersecurity protection force. The Law states no fixed number of hours for this report, unlike the 24-hour and 72-hour clocks the same enterprise faces under Article 25(2) for a content-takedown or a user-information request, which are a content-moderation duty this row does not carry. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.