Adaptive governance for the Internet of Things: Coping with emerging security risks

被引:32
作者
Brass, Irina [1 ]
Sowell, Jesse H. [2 ]
机构
[1] Univ Coll London UCL, Dept Sci Technol Engn & Publ Policy, Shropshire House,4th Floor,11-20 Capper St, London WC1E 6JA, England
[2] Texas A&M Univ, Dept Int Affairs, Bush Sch Govt & Publ Serv, College Stn, TX USA
基金
英国工程与自然科学研究理事会;
关键词
cybersecurity; disruptive technology; internet of things; planned adaptive risk regulation; regulatory governance;
D O I
10.1111/rego.12343
中图分类号
D9 [法律]; DF [法律];
学科分类号
0301 ;
摘要
The Internet of Things (IoT) is a disruptive innovation known for its socio-economic potential, but also for generating unprecedented vulnerabilities and threats. As a dynamic sociotechnical system, the IoT comprises well-known cybersecurity risks and endemic uncertainties that arise as IoT adoption increases and the system evolves. We highlight the impact of these challenges by analyzing how insecure IoT devices pose threats to both consumer protection and the Internet's infrastructure. While recent regulatory responses are starting to target IoT security risks, crucial deficiencies - especially related to the feedback necessary to keep pace with emerging risks and uncertainties - must be addressed. We propose a model of adaptive regulatory governance that integrates the benefits of centralized risk regulatory frameworks with the operational knowledge and mitigation mechanisms developed by epistemic communities that manage day-to-day Internet security. Rather than focusing on the choice of regulatory instruments, this model builds on the "planned adaptive regulation" literature to highlight the need to systematically plan for a knowledge-sharing interface in regulatory governance design for disruptive technologies, facilitating the feedback necessary to address evolving IoT security risks.
引用
收藏
页码:1092 / 1110
页数:19
相关论文
共 74 条
[1]   The economics of information security [J].
Anderson, Ross ;
Moore, Tyler .
SCIENCE, 2006, 314 (5799) :610-613
[2]  
[Anonymous], 2015, PLANNED ADAPTATION D
[3]  
[Anonymous], 2016, ARS TECHNICA
[4]  
[Anonymous], 2017, The Next Production Revolution, DOI DOI 10.1787/9789264271036-EN
[5]  
[Anonymous], 2018, Rapid evidence assessment on labelling schemes and implications for consumer IoT security
[6]  
[Anonymous], Report: 80% of Data Breaches Caused by Lack of Cyber Security Skills
[7]  
Antonakakis M, 2017, PROCEEDINGS OF THE 26TH USENIX SECURITY SYMPOSIUM (USENIX SECURITY '17), P1093
[8]  
*APWG, 2019, UN GLOB RESP CYB
[9]  
APWG, 2019, BUCH S GLOB CYB AW A
[10]   Action research [J].
Avison, D ;
Lau, F ;
Myers, M ;
Nielsen, PA .
COMMUNICATIONS OF THE ACM, 1999, 42 (01) :94-97