Most, perhaps all, of the legal requirements are not meaningfully attached to security threats. While they're all good things for projects to do, they seem out of scope for a security baseline and thus violate the "meaningful" part of the "FRAM" guidance.