Beyond "Complacency and Panic": Will the NIS Directive Improve the Cybersecurity of Critical National Infrastructure?

被引:0
作者
Michels, Johan David [1 ,2 ,3 ]
Walden, Ian [3 ,4 ]
机构
[1] Queen Mary Univ London, Cloud Legal Project, London, England
[2] Queen Mary Univ London, Microsoft Cloud Comp Res Ctr, London, England
[3] Queen Mary Univ London, Ctr Commercial Law Studies, London, England
[4] Queen Mary Univ London, Informat & Commun Law, London, England
关键词
Air transport; Cybersecurity; Data sharing; Essential facilities; EU law; Transparency;
D O I
暂无
中图分类号
D9 [法律]; DF [法律];
学科分类号
0301 ;
摘要
This article examines the safeguarding and information obligations the NIS Directive imposes on operators of essential services (OES). The Directive aims to ensure that such services are protected from disruption by requiring OES to take "appropriate and proportionate" security measures. In this article, we look at what this means in practice, with a focus on air transport services. We argue that OES need to identify, assess, and address the cyber risks they face and that such risk management inevitably entails a level of subjective judgement and difficult trade-offs. Regulators should accordingly accord OES significant discretion. However, this raises the risk that OES will abuse their discretion, particularly by engaging in "paper compliance". Regulators will need to actively challenge OES to ensure that they exercise this discretion appropriately.
引用
收藏
页码:25 / 47
页数:23
相关论文
共 112 条
[1]  
ANDERSON R, 2018, SECURITY ENG, P1, DOI DOI 10.1145/3206004.3206023
[2]  
ANDERSON R, 2001, C ACSAC 01, P6
[3]  
ANDERSON R, 2009, ISSE 2008 SECURING E, P77
[4]  
[Anonymous], CRIT NAT INFR
[5]  
[Anonymous], 2012, UNDERSTANDING REGULA, P302
[6]  
AVIRAM A, 2006, LAW EC CYBER SECURIT, P154
[7]  
BALDWIN, 2012, UNDERSTANDING REGULA, P150
[8]  
BALDWIN, 2012, UNDERSTANDING REGULA, P309
[9]  
BALDWIN, 2012, UNDERSTANDING REGULA, P310
[10]  
BALDWIN, 2012, UNDERSTANDING REGULA, P304