Law / Frameworks / NIST CSF 2.0 / Respond

NIST CSF 2.0, RespondRS.MA-03

Incidents are categorized and prioritizedNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), RS.MA-03

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

2
laws
2
places
0
with court rulings behind them
0
not yet in force
  • China
  • Cuba

Vulnerability and incident reporting

2 laws, 2 places
PlaceLawWhat it asks, as read here
China National Cybersecurity Incident Reporting Measures

On discovering or becoming aware of a cybersecurity incident affecting your own operations, grade it against China's four-tier National Cybersecurity Incident Classification and Grading Guide (especially major, major, relatively major, ordinary), and report only where you grade it relatively major or above; an ordinary incident carries no report duty under this instrument.

Cuba Resolución 105/2021, Reglamento sobre el Modelo de Actuación Nacional para la Respuesta a Incidentes de Ciberseguridad

If you hold a private data network, ensure that a cybersecurity event or incident affecting it is recorded, classified and reported to CuCERT.

Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.