Compliance & Frameworks
No regulation says the word TSCM — except one NIST control that does. Framework by framework, here is where technical surveillance risk sits in the obligations you already carry — with primary sources cited.
United States
NIST SP 800-53 RA-6: The TSCM Survey Control
RA-6 is the one control in NIST SP 800-53 that names technical surveillance countermeasures outright. Here is what it requires, who has to implement it, and how to satisfy it with a defensible program rather than a checkbox.
→United States
SEC Cyber Disclosure Rules and Boardroom Surveillance
The SEC's 2023 cybersecurity rules require disclosure of material incidents on Form 8-K and of risk management practices under Regulation S-K Item 106. A covert device capturing material non-public information is squarely inside that frame.
→United States
The Defend Trade Secrets Act and Reasonable Measures
Under the DTSA, information is only a trade secret if you took reasonable measures to keep it secret. Courts examine what you actually did. A documented counter-surveillance program for the rooms where secrets are discussed is evidence most plaintiffs wish they had.
→International standard
ISO 27001 and Technical Surveillance Risk
ISO/IEC 27001:2022 does not say the word TSCM — but its risk assessment clause and Annex A physical controls leave certified organizations little room to ignore covert surveillance of the rooms where sensitive information is spoken.
→UK and EU framework guidance lives on the UK edition of this site.
Switch edition →This guidance is general information, not legal advice. Regulatory obligations depend on your entity classification, jurisdiction and facts — confirm specifics with your counsel or compliance function.