European Cybersecurity Certification Schemes and cybersecurity in the EU internal market

Author:

Stewart Ferguson Donald DavidORCID

Abstract

AbstractThe principal question addressed by this paper is: how adequate are the minimum security objectives of the European Union Cybersecurity Act (Regulation (EU) 2019/881) in assisting organisations in the European Union internal market with resisting and recovering from cyber threats? The question is answered by first identifying the scope of the minimum security objectives. Scope identification, performed through legislative interpretation, reveals an integrated system of security objectives with significant gaps. Second, the minimum security objectives are evaluated within a model of cyber attacks from attack reconnaissance to legal proceedings to reveal further significant gaps. Finally, the minimum security objectives are evaluated within five cyber attack scenarios, reflecting the highest ranking cyber threats to the internal market. The simulation analysis accentuates the findings of the model analysis and identifies further significant gaps. In conclusion, the minimum security objectives are found to be largely inadequate in assisting organisations in the European Union internal market with resisting and recovering from cyber threats. The analysis of the adequacy of the minimum security objectives is timely, as the first European cybersecurity certification schemes are currently being designed.

Funder

ERDF

Georg-August-Universität Göttingen

Publisher

Springer Fachmedien Wiesbaden GmbH

Subject

Anesthesiology and Pain Medicine

Reference202 articles.

1. European Union Agency for Cybersecurity (2019on) Regulation (EU) 2019/881 of 17 April 2019 on ENISA and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 [2019] OJ L151/15 (Cybersecurity Act). EU,

2. Leteinturier A et al Recommendations for the implementation of the CSP Certification scheme’ (CSPCERT WG 2019). https://drive.google.com/file/d/1J2NJt-mk2iF_ewhPNnhTywpo0zOVcY8J/view. Accessed 13 Dec 2019

3. European Commission (2019) Towards a more secure and trusted cloud in Europe. https://ec.europa.eu/digital-single-market/en/news/towards-more-secure-and-trusted-cloud-europe. Accessed 13 Dec 2019

4. ENISA (2020) Cybersecurity Certification. https://www.enisa.europa.eu/publications/cybersecurity-certification-eucc-candidate-scheme/. Accessed 8 Oct 2020

5. Raustiala K ‘Compliance & Effectiveness in International Regulatory Cooperation’ (2000) 32/3 Case W. Res. J. Int’l Law. https://scholarlycommons.law.case.edu/cgi/viewcontent.cgi?article=1497&context=jil. Accessed 2 Dec 2019 (387)

Cited by 2 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. The outcome efficacy of the entity risk management requirements of the NIS 2 Directive;International Cybersecurity Law Review;2023-08-17

2. Power System Monitoring, Control and Protection for Network, IOT and Cyber Security;2022 2nd International Conference on Advance Computing and Innovative Technologies in Engineering (ICACITE);2022-04-28

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3