首页> 外文期刊>Computers & Security >Legally 'reasonable' security requirements: A 10-year FTC retrospective
【24h】

Legally 'reasonable' security requirements: A 10-year FTC retrospective

机译:合法的“合理”安全要求:FTC的十年回顾

获取原文
获取原文并翻译 | 示例
           

摘要

Growth in electronic commerce has enabled businesses to reduce costs and expand markets by deploying information technology through new and existing business practices. However, government laws and regulations require businesses to employ reasonable security measures to thwart risks associated with this technology. Because many security vulnerabilities are only discovered after attacker exploitation, regulators update their interpretation of reasonable security to stay current with emerging threats. With a focus on determining what businesses must do to comply with these changing interpretations of the law, we conducted an empirical, multi-case study to discover and measure the meaning and evolution of "reasonable" security by examining 19 regulatory enforcement actions by the U.S. Federal Trade Commission (FTC) over a 10 year period. The results reveal trends in FTC enforcement actions that are institutionalizing security knowledge as evidenced by 39 security requirements that mitigate 110 legal security vulnerabilities.
机译:电子商务的增长使企业能够通过新的和现有的业务实践来部署信息技术,从而降低成本并扩展市场。但是,政府法律法规要求企业采取合理的安全措施来阻止与此技术相关的风险。由于许多安全漏洞仅在攻击者利用后才发现,因此监管机构会更新其对合理安全性的解释,以跟上新出现的威胁。为了确定企业必须采取哪些行动来遵守这些不断变化的法律解释,我们进行了一项实证性的多案例研究,通过检查美国的19种监管执法措施来发现和衡量“合理”安全的含义和演变。联邦贸易委员会(FTC)为期10年。结果揭示了FTC执法行动的趋势,这些趋势正在使安全性知识制度化,39个安全性要求可以缓解110个法律安全性漏洞。

著录项

  • 来源
    《Computers & Security》 |2011年第4期|p.178-193|共16页
  • 作者单位

    Carnegie Mellon University, Institute for Software Research, 5000 Forbes Avenue, 5210 Wean Hall, Pittsburgh, PA 15213, USA;

    Department of Business Management, North Carolina State University, 2801 Founders Driue, Box 7229, Nelson Hall, Raleigh, NC 27695, USA;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    requirements; security; reasonability; legal compliance; case study;

    机译:要求;安全性;合理性;法律合规性;案例研究;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号