首页> 外文OA文献 >Economic impacts of rules- versus risk-based cybersecurity regulations for critical infrastructure providers.
【2h】

Economic impacts of rules- versus risk-based cybersecurity regulations for critical infrastructure providers.

机译:基于规则和基于风险的网络安全法规对关键基础设施提供商的经济影响。

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

What's the optimal way to regulate cybersecurity for the critical infrastructure operators in charge of electricity transmission? Should regulation follow the US style (a mostly rules-based model), the EU approach (which is mostly risk-based), or a balance of both? The authors discuss the economic issues behind making this choice and present a cybersecurity economics model for public policy in the presence of strategic attackers. They calibrated these models in the field with the support of National Grid, which operates in the UK and on the US East Coast. The model shows that optimal choices are subject to phase transitions: depending on the combination of incentives, operators will stop investing in risk assessment and only care about compliance (and vice versa). This finding suggests that different approaches might be more appropriate in different conditions and that just pushing for more rules could have unintended consequences.
机译:对于负责电力传输的关键基础设施运营商,调节网络安全的最佳方法是什么?监管应该遵循美国风格(主要基于规则的模型),遵循欧盟方法(主要基于风险的模型)还是两者兼而有之?作者讨论了做出此选择背后的经济问题,并提出了在战略攻击者在场的情况下公共政策的网络安全经济学模型。他们在英国和美国东海岸运营的国家电网的支持下,在现场对这些模型进行了校准。该模型表明,最佳选择会经历阶段过渡:根据激励措施的组合,运营商将停止对风险评估的投资,而仅关注合规性(反之亦然)。这一发现表明,不同的方法在不同的条件下可能更合适,而仅仅推动制定更多的规则可能会带来意想不到的后果。

著录项

  • 作者

    Massacci F.;

  • 作者单位
  • 年度 2016
  • 总页数
  • 原文格式 PDF
  • 正文语种 {"code":"en","name":"English","id":9}
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号