Managing (in)Security Through Regulation: A Key Phase for Nation States

From: CircleID

By Arun Raghu

Not so long ago, the notion of introducing laws and other regulatory responses to address cyber security issues was regarded with significant hesitation by governments and policy makers. To some extent, this hesitation may well have stemmed from a general perception by those who do not work directly in the field that the world of cyber security is somewhat of a ‘dark art’. More recently, however, there has been a substantial shift in this attitude, with proposals to regulate a range of cyber security related matters becoming increasingly numerous. This shift needs to be regarded with a degree of guarded pragmatism: regulation certainly has the potential to enhance attitudes to cyber security and ultimately security postures within nation states. However, if handled poorly, the effect of regulation may be to achieve the complete opposite.

A shift in the wind as security goes mainstream

Ostensibly, it seems a positive development that policy makers around the globe have begun to regard cyber security as a domain into which they are prepared to step and regulate in an effort to protect consumers, businesses and states from the harms that can flow from poorly secured IT hardware, software and processes. The USA and EU have been the chief domains of discussion in this regard, as the former continues to grapple with implementing a legal framework to facilitate security incident information sharing between government agencies and the private sector, while the latter moves toward implementing its Network and Information Security Directive. Other jurisdictions are also looking at implementing significant regulatory measures – for example, the German Bundestag has just passed an IT Security Act that prescribes minimum security requirements for operators of critical infrastructure and providers of telecommunications services.

Read Complete Article

Facebooktwittergoogle_plusredditpinterestlinkedinmail

Leave a Reply

Your email address will not be published.

Please Answer: *