首页> 外文会议>IEEE Systems and Information Engineering Design Symposium >A Framework for the Evaluation of State Breach Reporting Laws
【24h】

A Framework for the Evaluation of State Breach Reporting Laws

机译:评估国家违约报告法的框架

获取原文
获取外文期刊封面目录资料

摘要

This paper develops a framework for evaluating the effectiveness of cyber security breach reporting laws across states. In doing so, trends and correlations in state reporting along with other relevant factors are identified using readily available data. This paper addresses two critical questions in the assessment of breach reporting legislation: 1) How does the rate of reporting security breaches across states compare with the rate of reporting of security threats to computer operating systems?, and 2) What factors other than the implementation of breach reporting legislation effect the rate of reporting security breaches across states? The framework developed in this paper can be applied in future analyses to evaluate the effectiveness of breach reporting legislation and can assist in pinpointing legislative weaknesses across states. Limitations in the availability of data inspired the generation of a number of recommendations for the improvement of breach reporting law evaluation. First, more time is needed to collect data, as most laws have been in place for two or fewer years. Second, each state should have a central database that records all reported cyber security breaches. This will allow for greater visibility to the public and would make for greater accessibility of data for both consumers and researchers. Finally, further research efforts should be conducted on the topic of OS security vulnerability patch rates and their relevance to the actual, realized cyber threat level of operating systems.
机译:本文制定了一个评估各州网络安全违约报告法的有效性的框架。在这样做时,使用易于可用的数据确定状态报告中的趋势和相关性以及其他相关因素。本文在评估违规报告立法时解决了两个关键问题:1)跨国公司报告安全违规率如何与计算机操作系统的安全威胁报告的比较?,以及2)除了实施之外的哪些因素违规报告立法影响了跨国公司报告安全违规行为的速度?本文开发的框架可以在将来的分析中应用,以评估违反报告立法的有效性,并有助于确定各州的立法弱点。数据可用性的限制激发了一些关于改进违约报告法评估的建议的一代。首先,需要更多的时间来收集数据,因为大多数法律已经到位两个或更少年。其次,每个州应具有记录所有报告的网络安全漏洞的中央数据库。这将允许对公众的更大可见性,并将为消费者和研究人员提供更大的数据可访问性。最后,应该对OS安全漏洞补丁率的主题进行进一步的研究,以及它们与实际的网络威胁的操作系统的相关性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号