Toward a Global Cybersecurity Standard of Care? Exploring the Implications of the 2014 NIST Cybersecurity Framework on Shaping Reasonable National and International Cybersecurity Practices

Toward a Global Cybersecurity Standard of Care? Exploring the Implications of the 2014 NIST Cybersecurity Framework on Shaping Reasonable National and International Cybersecurity Practices
复制标题

迈向全球网络安全护理标准?

DOI:
--
复制
发表时间:
2014
期刊:
影响因子:
--
通讯作者:
A. Craig
A. Craig
中科院分区:
--
文献类型:
--
作者:
Scott J. Shackelford;Andrew A. Proia;Brenton Martell;A. Craig

文献摘要

被引文献

相似文献

尽管美国国会和多边旨在加强网络安全的努力迄今为止在很大程度上未能实现其目标,但法院正在利用包括疏忽在内的现有理论来追究公司对网络攻击的责任。然而,这些决定在很大程度上是随意的,部分原因是对网络安全最佳实践的构成感到困惑。本文分析了新兴的网络安全注意义务,并探讨了2014年美国国家标准与技术研究院(NIST)网络安全框架对特别是过失法的潜在影响。鉴于在这一领域的最佳实践尚未得到很好的定义,NIST框架有可能帮助定义不仅是关键基础设施公司的标准,而且是私营部门的标准。有一些证据表明这已经发生了,例如2013年11月FCC/电信发布的一份声明:“电信行业和联邦通信委员会计划使用一个新兴的网络安全标准框架来评估和优先考虑该行业的最佳实践,因为它致力于解决不断变化的网络威胁.”NIST框架不仅有可能改变美国的网络安全格局,也有可能改变其他司法管辖区的网络安全格局,这些司法管辖区倾向于采取自愿的方式来加强网络安全,如英国、欧盟和印度。对于活跃在不同司法管辖区的企业,并取决于利益相关者对NIST框架的理解,全球网络安全责任可能会出现,这将促进一致性,并有助于网络和平,即使没有监管行动。
Even though U.S. congressional and multilateral efforts aimed at enhancing cybersecurity have thus far largely failed in their aims, courts are using existing doctrines including negligence to hold companies accountable for cyber attacks. However, decisions have been largely haphazard due in part to confusion over what constitutes cybersecurity best practices. This Article analyzes the emerging cybersecurity duty of care, and examines the potential impact of the 2014 National Institute of Standards and Technology (NIST) cybersecurity framework on particularly on negligence law. Given that best practices are not yet well-defined in this space, the NIST framework has the potential to help define the standard for not only critical infrastructure firms, but the private sector writ large. There is some evidence this is already happening, such as in reference to an FCC/telecom release in November 2013: “The telecommunications industry and the Federal Communications Commission plan to use an emerging framework of cybersecurity standards to assess and prioritize best practices for the sector as it works to address evolving cyber threats...” The NIST framework has the potential to shift the cybersecurity landscape not only in the United States, but also potentially in other jurisdictions favoring a largely voluntary approach to enhancing cybersecurity such as the United Kingdom, the European Union, and India. For businesses active across jurisdictions, and depending on the uptake of the NIST framework by stakeholders, a global duty of cybersecurity care could emerge that would promote consistency and contribute to cyber peace even absent regulatory action.