Law / Frameworks / NIST CSF 2.0 / Respond
NIST CSF 2.0, RespondRS.MI-01
Incidents are containedNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), RS.MI-01
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 7
- laws
- 7
- places
- 0
- with court rulings behind them
- 2
- not yet in force
A law in force is unmarked; the rest wear their state: not yet in force
Vulnerability and incident reporting
7 laws, 7 places| Place | Law | What it asks, as read here |
|---|---|---|
| Data Security Law, Risk Monitoring and Incident Reporting Duty |
On an actual data-security incident, immediately take disposal measures, promptly notify affected users as provided, and report the incident to the competent authority; the statute states no numeric deadline, only immediacy and promptness. |
|
| Digital Code, Livre IV: General Cyberattack Cooperation and Incident-Reporting Duty |
Comply with the measures the Agence Nationale de Cybersécurité prescribes to put an end to the disruption. |
|
| Critical Infrastructure Cybersecurity Proclamation, Cyber Incident Reporting to National CERT from , in 10 months |
Notify the National Computer Emergency Response Center of a cyber incident within 48 hours of becoming aware of it, using the system the Administration establishes, and implement the mandatory recommendations or directions the Center provides within the time it sets. |
|
| Cybersecurity Act 2026, Duty to Report a Cybersecurity Incident from a date not yet set |
When you are the subject of a cybersecurity incident or threat of one, gather information about it, assess the risk to your critical infrastructure, customers, suppliers and other stakeholders, take appropriate preventative, mitigating and remedial measures to limit that risk, and report all material information about a significant cybersecurity incident to the National CERT and any relevant Sectoral CERT within 24 hours after you detect it, in the form or manner the CERT prescribes. |
|
| Nacionālās kiberdrošības likums, Incident Notification |
Immediately take all action necessary to contain a detected cyber incident, immediately inform the competent cyber incident prevention institution (in practice CERT.LV for most private-sector and civilian public-sector subjects), and follow its instructions. |
|
| Information and Communications Network Act, Report on Computer Security Incidents |
Analyze the cause of the incident, respond based on the results of that analysis, and take measures to keep the resulting damage at bay. |
|
| Cybersecurity Incident Reporting and Emergency Response |
Immediately inform the national contact point or your emergency response center of any cybersecurity incident or attack, and comply with the emergency measures either one orders. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.