yhtomit

profileabcity84
Wk5-TheGovernanceofNetworkandInformationSecurityIntheEuropeanUnion.pdf

Electronic copy available at: http://ssrn.com/abstract=2075916

1

27TH EUROPEAN COMMUNICATIONS POLICY

RESEARCH CONFERENCE (EUROCPR) Policies For The Future Internet

25-27 March 2012 | Ghent | Belgium

THE GOVERNANCE OF NETWORK AND INFORMATION SECURITY IN THE EUROPEAN UNION:

THE EUROPEAN PUBLIC-PRIVATE PARTNERSHIP FOR RESILIENCE (EP3R)

Kristina Irion, Central European University Abstract In public policy information and communications technology (ICT) infrastructures are typically regarded as critical information infrastructures and, thus, require security and protection against cyberthreats. The European Union (EU) Network and Information Security (NIS) policy combines public and private policies at the level of the operators which are highly interdependent. Any NIS policy success rests to an overwhelming degree on the commitment and compliance of the ICT infrastructure operators. Increasingly, policy makers have to pay attention to the supporting governance system which would give best effect to the NIS policy objectives.

This contribution focuses on NIS governance in the EU and explores mechanisms of cooperation between public and private operating ICT infrastructure through the lens of governance theory. It concludes that NIS governance objectives can be pursued in public- private partnerships, but not all functions of NIS policy can be suitably performed at the EU level. Any engagement with the industry needs to be supported by appropriate governance mechanisms that deliver high levels of commitment and compliance by private stakeholders. Against this backdrop this paper critically assesses the European Public-Private Partnership for Resilience (EP3R) NIS and offers recommendations for EU policy makers on a suitable Europe-wide multi-stakeholder governance framework to promote NIS strategy and high- level policy.

Keywords

Cybersecurity; network and information security; critical information infrastructure protection; governance theory; networks, public-private partnerships; European Union

Electronic copy available at: http://ssrn.com/abstract=2075916

2

Introduction

The information and communications technology (ICT) sector has long been acknowledged as serving a dual role: First, it is an important sector of economic activity, increasingly contributing to the overall economy and growth. Second, the ICT infrastructure forms the basis for a wide range of activities which are vital for both the economy and society (European Commission 2009, 1; 4; OECD 2008, 4, 22). In the European Union (EU), the ICT sector is directly responsible for 5% of European GDP, with a corresponding market value of € 660 billion annually (European Commission 2010a, 4). This figure does not yet include the ICT sector’s overall contribution to productivity growth which is estimated to amount to 20 percent directly and 30 percent from ICT investments, but its total impact is even wider when considering all ICT enabled economic activities (Ibid).

Governments around the world have risen to the challenge, and proposed measures that aim to mitigate risk and enhance the resilience of national ICT infrastructures in cooperation with the operators of these infrastructures. The following examples illustrate what is at stake, as well as the limitation of national policy-makers to bring about effective redress when relying on their traditional regulatory toolkit:

− In 2008 and 2010, a submarine communications cable linking Western Europe, the Middle East and South East Asia was damaged in the Mediterranean which affected Internet and telecommunications traffic of the two latter regions to Europe, including alternative routes which carried additional traffic (BBC 2008).

− Cybercriminals use the power of illegal botnets where large numbers of computers can be remotely controlled with the purpose of sending spam or to coordinate denial- of-service attacks. From the largest known botnets, “Mariposa” (in English “Butterfly”), for example, was reported to control between eight to 12 million individual computers at the time it was dismantled by an international team of Internet security companies and nation law enforcement agencies in 2010 (Menn 2010).1

− 2010 saw the spread of “Stuxnet”, a computer worm of unknown provenance which was designed to infiltrate the Windows operating system and to target industrial equipment by Siemens. The malware was reported to affect the supervisory control and data acquisition (SCADA) systems that control centrifuges, which according to speculations have set-back significantly the Iranian nuclear program (Fieldes 2011).

All three examples have in common that the incident is not limited to one country but

causes regional and, as in the cases of “Mariposa” and “Stuxnet,” even global, distributed impact. The actual risk scenarios vary, covering online disruption and congestion at the level of ICT infrastructure, to illegal botnets conducting cybercriminal activities and damaging industrial systems. It serves as an illustration of (1) the technical, logistical and organisational complexity, (2) ICT interconnectedness and interdependencies across sectors, as well as (3) the high degree of uncertainty with regards to the threats, which develop as dynamically as the overall ICT sector. The systemic interdependencies between ICT infrastructures in relation to other sectors can render a local event a transnational cybersecurity incident. In facing these challenges, national public policies need to address this complexity, work in partnership with the stakeholders, and formulate policies that take into account ICT’s global ecosystem.

Countries, thus, readily recognize the need for supranational and coordinated approaches to cybersecurity. International policy steering in a variety of intergovernmental fora attempts to diffuse political, technical and economic cybersecurity strategies and best practices at national levels. The United Nations discuss cybersecurity in a politico-military

3

context focusing on cyber-warfare, or in an economic context emphasizing cyber-crime (Maurer 2011, 6). The Council of Europe’s “Convention on Cybercrime,” which laid the foundation for a common policy for the protection of society against online crime, entered into force in 2004 and has been ratified in 32 nations (including non-member countries). In spite of being a non-binding instrument, the Organization for Economic Cooperation and Development’s (OECD) “Guidelines for the Security of Information Systems and Networks” from 2002 has been influential in promoting a culture of Cybersecurity.2 The International Telecommunications Union (ITU), a specialized United Nations agency, initiated the “Global Cybersecurity Agenda.” which is a framework for international cooperation aimed at enhancing confidence and security in the information society.

About a decade ago, the concern about network and information security (NIS) entered EU public policy and immediately ranked high on the policy agenda. For the European Commission (2006a, 3) "networks and information systems are increasingly central to our economies and to the fabric of society" and ensuring the functionality of these systems is of paramount necessity. The European Commission defines NIS as "the ability of a [electronic] network or an information system to resist […] accidental events or malicious actions that compromise its availability, authenticity, integrity and confidentiality" (European Commission 2001, 9). In 2009, the ever growing dependence on ICT infrastructure led to it being perceived as a critical information infrastructure which catapulted electronic communications and information networks into the leagues of electricity grids, transport networks, health care and water facilities in terms of national security relevance (European Commission 2009a).

It is already conventional wisdom that NIS is beyond what governments can achieve by means of traditional top-down, command and control regulation (Hämmerli and Renda 2010, 85; OECD 2008, 4). Private ownership in public ICT infrastructure and its interconnectedness dictate a multi-stakeholder effort with shared responsibilities (Alderson and Soo Hoo 2004, 1; European Commission 2001, 2; 2009, 5; Hämmerli and Renda 2010, 16; Shore et al 2011, 4). Increasingly, policy makers have to pay attention to the supporting governance system which buttresses NIS policy objectives because it creates the indispensable commitment and compliance on the part of the operators of ICT infrastructure. To this end public-private partnerships (PPPs) for cybersecurity have come into existence at the national level as the prevailing mode of governance (European Commission 2009, 5: OECD 2008, 8; Shore et al 2011, 4). Also the European Commission (2009, 7) promotes "[a] multi-stakeholder, multi-level approach ... taking place at the European level while fully respecting and complementing national responsibilities." A new European Public-Private Partnership for Resilience (EP3R), which was launched in 2009, embodies the ambition to create a European-wide multi-stakeholder governance framework.

This paper analyzes the notion of a European-wide multi-stakeholder governance framework through the lens of governance theory and it reflects critically the prevailing PPP paradigm. Governance theory is most suitable because it conceptualizes the need for new modes of governance that can accommodate an international ecosystem, high (technical) complexity and multi-stakeholder co-operation. Our understanding of governance systems has much advanced and is informed by experiences and observations in various contexts with similar concerns, such as for example environmental policy. This research links to governance network theory, which is underpinned by the literature on incentive-based regulation in order to derive parameters for a successful engagement and proposes measures to better align economic incentives and public policy. A similar approach has been chosen by Dunn-Cavelty and Suter (2009), however, with a focus on national PPPs for cybersecurity. The only study that takes an EU governance perspective is one by the Center for European Policy Studies’ (CEPS) Task Force on Protecting Critical Infrastructure in the EU (Hämmerli and Renda 2010). This contribution will take the study further and analyze the governance

4

model underlying EP3R and conclude with recommendations for a European-wide multi- stakeholder governance framework.

The paper is structured as follows: The first section presents the ICT sector’s deregulation history and the resulting governance structure of the liberalized ICT sector. The next section offers a concise overview of the challenges of NIS policy, interrogating the roles and incentives of the operators of ICT networks to make investments in security. In section three, the focus is on the NIS policy shaping up at the EU level with a view on governance functions granted to ENISA and the newly set-up EP3R. Governance theory and incentive based regulation are then introduced in order to approach and operationalize the European stakeholder governance challenge. The final section provides an assessment of the European- wide multi-stakeholder governance framework embodied in the EP3R, followed by the conclusions which offer a set of policy recommendations addressed to the EU policy makers on the governance structure supporting NIS policy at the EU level.

Governing the liberalised ICT sector in the EU

Before the 1980s national security had been one of the arguments to justify the telecommunications monopolies prevalent in Europe. Countries would argue that only the state could guarantee the security of the public switched telephony networks (PSTN) and its services (mostly voice telephony and early forms of data communications such as Fax and BTX). When the information society was still a new era to come, the famous Bangemann Report (High-level Group on the Information Society 1994) articulated the need for a regulatory environment absent of exclusive rights which stimulated private investments into ICT infrastructure. The EU legislator followed this recommendation and successively liberalized the telecommunications sector, which was by and large completed in 1998. As one of the accompanying measures intended to compensate for the absence of direct state control, network security and integrity was identified as licensing criteria for the private sector provision of telecommunications infrastructure (European Commission 1994, 28, 31).

Today's ICT sector has dramatically changed from these early days of a one-network paradigm. If we abstract from the often persistent bottlenecks at the level of local fixed infrastructure, ICT markets in the member states have made significant progress in achieving fixed and mobile infrastructure competition. The ICT infrastructure comprises all these privately owned networks, which are for the sake of communications interconnected. The Internet is the paradigmatic example of a network of interconnected networks that spans the globe. Since liberalization, the EU regulates the electronic communications sector, and the regulatory framework is not only concerned with creating a level playing field for competition but also with other public interest objectives, such as universal service, consumer protection and – most relevant to this survey - the security and integrity of networks and services. Member states transpose the regulatory package for electronic communications to their national system of sector-specific regulation, which is then implemented by national regulatory authorities (NRAs). Additionally, the public and the private sector collaborate on information sharing, standard-setting and best practices, testing ICT resilience and business continuity; because it is understood that mandating security is not enough.

Governance at the EU level involves the delegation of competences to new European

policy networks in the electronic communications sector and the creation of EU-wide coordination mechanisms. European policy networks are established to foster regulatory harmonization and uniformity of policy implementation across Europe by providing expertise, all the while promoting international regulatory learning. In telecommunications, the European Regulators Group (ERG) was founded in 2002 under EC law, which was replaced as of 2009 with the Body of European Regulators for Electronic Communications

5

(BEREC). This has enhanced competencies for harmonization and is composed of the heads of NRAs of member states (Regulation (EC) No 1211/2009). The establishment of the European Network and Information Security Agency (ENISA) is a first move towards institutionalized governance at the EU level. The two other relevant collaborations at EU level concern NIS cooperation among member states and European institutions, i.e. the European Forum for Member States (EFMS), and the bespoke European-wide partnership known as EP3R. After the subsequent discussion of the challenges an EU-wide NIS policy faces, the paper returns to the NIS policy framework at the EU level.

The network and information security policy challenge

This section summarizes the literature on the economics of NIS in relation to ICT infrastructure and extrapolates these findings to the EU level. There are two interrelated concerns: First, economic theory implies for various reasons an underprovision of NIS. Second, already at the level of the nation state NIS efforts often lack systemic efficiency and internal consistency, which hampers the overall effectiveness of private initiatives and public policies aimed at improving security and resilience of ICT networks. Both concerns are ascribed in the following sub-sections, however, it is important to bear in mind that the ICT ecosystem is wider and connects many more services and stakeholders and, thus, creates interdependencies that are beyond the scope of this paper (see for example Bauer and van Eeten 2009, ENISA 2011).

Economics of network and information security  Economic theory which is supported by limited empirical research holds that the optimal level of cybersecurity cannot be achieved by relying on market forces alone. As Andersson and Malm put it:

All private firms are responsible to their shareholders for operational business risks and have to prepare for contingencies and emergencies. However, in general, market incentives are not compelling enough for private actors to provide the appropriate level of security for society as a whole. To survive in a market-driven economy, companies need to minimize costs and maximize profits. Keeping reserve stock, maintaining redundant systems, and employing back-up staff all cost money. With pressure to cut costs, less resources are available for contingencies and crisis management. (2007, 146). What Hämmerli and Renda (2010, 49f.) refer to as the efficiency-security trade-off

certainly occurs with any extensive engagement in NIS that is costly and requires sustained attention; both likely to exceed what customers are willing to pay for (see also Assaf 2008, 11f.; Moore 2010, 5). In their article, Bauer and van Eeten (2009, 710f.) discuss the role of incentives in information security and introduce empirical data on security incentives of players within the ICT value chain, however, excluding ICT network operators. The findings of security-enhancing and security-reducing incentives confirm the existence of efficiency- security trade-off. This trade–off is ascribed to a number of factors which are believed to distort ICT network operators’ incentives to invest more in NIS: Market failures, imperfect information and moral hazard, which are now in turn explained.

Market failures are commonly attributed to the public good characteristic of security at large and negative externalities stemming from individual decision-making that impact NIS (Andersson and Malm 2007, 142; Bauer and van Eeten 2009). From a societal perspective, Bauer and van Eeten then raise the crucial question whether ‘the cost and benefits taken into account by market players reflect the social costs and benefits’ (2009, 707). With economic theory this question would be denied because the economic incentives of private actors are not aligned to support the societal desirable higher levels of security.

6

Negative externalities offer a separate economic explanation for market failures that are a result of private sector entities pursuing sub-optimal investments in NIS. According to Andersson and Malm (2007, 143), an externality is an effect of an individual’s actions that affects the welfare of others. In the context of cybersecurity, private operators of ICT networks are unlikely to consider the societal effect of a security incident that would disrupt their networks and services beyond what is the operator’s individual equation of investments in business continuity and resilience. Consequently, the sum of individual decisions about investments in cybersecurity is unlikely to achieve the societal optimal level of cybersecurity (see also Hämmerli and Renda 2010, 54; Moore 2010, 6).

Imperfect information is cited as another reason why market-based solutions to NIS are likely to be inefficient. When information is incomplete economic actors are not in the position to make informed decisions on risk management (Hämmerli and Renda 2010, 53; Moore 2010, 7). In the context of NIS, the lack of information is particularly pervasive because of ICT’s interconnectedness and the related possibility of contamination from other networks, as well as the high level of uncertainty as to the nature of future risks in a highly dynamic technological environment. Individual companies may not be able to shoulder this task on their own, which is why most European national governments facilitate the work of Computer Emergency Response Teams (CERTs), which collect, analyze and disseminate risk-relevant information.3 Aside from risk information, Andersson and Malm maintain that ‘[i]t is costly and extremely difficult to accurately evaluate emergency preparedness’ (2007, 144). Nonetheless, the constant assessment of the emergency preparedness and its adequacy in the light of the relevant risk information remains an effort private actors may fall short of implementing, in addition to a similar exercise that would be required on a society-wide basis.

The last explanation as to why there is an underprovision of NIS from a societal

perspective is moral hazard. Moral hazard connotes private actors’ expectation not to bear the full responsibilities and costs of any large-scale cybersecurity incident because they speculate on government intervention in the event of a major crisis that would effectively bail them out (Andersson and Malm 2007, 144). Other considerations that are bound to limit a private actor’s willingness to prepare for large cybersecurity incidents are liabilities that are ultimately capped at the costs of a bankruptcy. Taken together these factors are disincentives for operators to scale up their without doubt existing efforts to ensure the security and integrity of NIS networks until they have reached a societal optimal level. There is certainly more that could be invoked to explain this outcome, such as for example rational ignorance or behavioral economics (see Hämmerli and Renda 2010, 56f., Moore 2010 5f.), however, for the purpose of this paper it suffices to understand the need to “get incentives straight” aimed at raising the bar for NIS preparedness.

EU‐wide policy coherence  Raising the bar for NIS preparedness alone does not suffice to reach optimal security levels in the interconnected and interdependent ICT sector. Moreover, an overall effective NIS policy is required that integrates numerous decentralized measures of various, mainly private, actors. The concept of policy coherence concerns the interplay of public policies and individual ICT network operators’ NIS measures so that they are coordinated and reinforce each other.4 The European Commission recognizes the need for a coherent policy approach that is not limited to the individual country:

The high dependence on [critical information infrastructures], their cross-border interconnectedness and interdependencies with other infrastructures, as well as the vulnerabilities and threats they face raise the need to address their security and resilience in a systemic perspective as the frontline of defense against failures and attacks. (European Commission 2009a, 4)

7

In practice, however, the required coordination between public and private actors, as well as their partial policies that would bring about system-wide effectiveness is for various reasons difficult to achieve.

To start with, Andersson and Malm (2007, 145f.) identify a gap between public and private sector initiatives towards emergency preparedness measures which came into existence with the privatization of the underlying infrastructures. In a sense, liberalization has disconnected the state’s primary responsibility for national security from the assets which are now privately owned and controlled. This is essentially not bad since the security of certain critical infrastructures may have even improved from being a badly managed state asset to becoming a professionally operated private asset. This gap is better perceived as spheres of influence of government and private actors that do not meet and therefore leave risks unaddressed. NIS policy is about addressing this gap mostly through a combination of regulation and incentives that would ideally produce an adequate level of risk reliance and emergency preparedness. The other challenge to the coherence of NIS policy is the systematic integration and coordination of all activities and actors at the national, regional and – to some extent - also global level. Each country is responsible for building an organization that supports the coordination among ICT network operators and the public sector into its national approach to NIS before it can achieve any robust level of security. This has led many countries to herald PPPs because it offers a governance structure that would accommodate public and private actors according to their various roles and responsibilities. Setting-up a PPP, however, is not an end in itself, but requires careful management and a buy-in by ICT network operators on the basis of a policy that inasmuch as possible aligns the socially desirable level of NIS with the operators’ willingness to invest in NIS measures. In addition, the European Commission argues the rationale for a European-wide integrated approach:

A purely national approach runs the risk of producing a fragmentation and inefficiency across Europe. Differences in national approaches and the lack of systematic cross-border cooperation substantially reduce the effectiveness of domestic countermeasures, inter alia because, due to the interconnectedness of [critical information infrastructures], a low level of security and resilience of [critical information infrastructures]in a country has the potential to increase vulnerabilities and risks in other ones (European Commission 2009a, 5)

In order to sum up, ICT network operators are certainly willing to take precautionary

measures to protect against operational business risks, but they are not compelled to internalize the risks of ICT network disruptions for society at large. The economics of NIS argue for a role of public policy to better align private incentives to enhance the overall levels of NIS preparedness and resilience, but it does not question the competence of the operators of ICT networks to implement NIS measures. Governments are well advised to leave the details of technical implementation of NIS measures to the competent operators, who are better placed to appropriately manage risks posed to the security of their networks and services (see also Hämmerli and Renda 2010, 86, 89). Instead, governments have to devise policies that mitigate known disincentives as well as introduce positive and negative incentives to stimulate appropriate NIS investments by operators (ibid 2010, 81). Individual measures must be embedded in a governance structure that fosters coordination among public and private actors, here notably the ICT network providers, in the interest of delivering an overall consistent and effective policy at various levels.

8

EU policy for network and information security

The EU’s strategy and policy pertaining to NIS has clearly been developed with some priority over the last five years. It should be noted that the EU has no specific competence for NIS as a policy area, which appears to be at first glance more a matter of national security, i.e. a domain reserved for member states. However, the EU has used its powers under Article 95 of the former EC Treaty (now Article 114 of the Treaty on the Functioning of the European Union) to introduce harmonized regulation on the security and integrity of electronic communications networks and services and for the establishment of ENISA. Other EU NIS activities are based on the so-called flexibility clause in Article 308 of the EC Treaty (now Articles 352 and 353 of the Treaty on the Functioning of the European Union):

If action by the Community should prove necessary to attain, in the course of the operation of the common market, one of the objectives of the Community, and this Treaty has not provided the necessary powers, the Council shall, acting unanimously on a proposal from the Commission and after consulting the European Parliament, take the appropriate measures.

It is beyond the scope of this paper to discuss in depth EU competences in this area, however, it must be observed that measures on the basis of the flexibility clause are passed unanimously by the Council.5 Hämmerli and Renda argue in this context for a strict subsidiarity test to be applied “to identify the functions that should exist at EU level and the ones that are most effectively addressed at member state level.” (2010, 81)

NIS is an umbrella strategy which combines sector-specific regulation, cybercrime law, and policies aiming at critical information infrastructure protection (CIIP). The EU NIS policy rests on a three-pronged approach (European Commission 2001, 19; 2006a, 3):

(1). Regulatory package for electronic communications; (2). Cybercrime legislation; and (3). NIS measures and the CIIP.

In quick succession relevant policy documents have been issued comprising all the instruments available to the EU policy maker. Table 1 below offers an overview of all relevant NIS policy initiatives. In the following the European Union's NIS policy and strategy will be summarized in the light of the evolving governance issues. Table 1: EU activities shaping NIS policy Year Event 2001 Communication on Network and Information Security: Proposal for A

European Policy Approach [COM(2001)298] 2002 Council Resolution on a common approach and specific actions in the area of

network and information security [2002/C 43/02] 2003 Council Resolution on a European approach towards a culture of network and

information security [2003/C 48/01] 2004 Establishing the European Network and Information Security Agency

(ENISA) [Regulation (EC) No 460/2004] 2005

2006 Communication on a Strategy for a Secure Information Society - Dialogue,

partnership and empowerment [COM(2006)251] 2007 Council Resolution on a Strategy for a Secure Information Society in Europe

[2007/C 68/01] 2008 − 1st extension of ENISA's mandate [Regulation (EC) No 1007/2008]

− Public consultation on the future of network and information security

9

2009 − European Commission communication on Critical Information Infrastructure Protection "Protecting Europe from large scale cyber-attacks and disruptions: enhancing preparedness, security and resilience", including CIIP Action Plan [COM (2009) 149]

− Council Resolution on a Collaborative European Approach to NIS [2009/C 321/01]

− Presidency Conclusions of the Ministerial Conference on Critical Information Infrastructure Protection, Tallinn (EE)

− Update of the regulatory package e-communications, new chapter on security and integrity of networks and services

2010 Adoption of the Digital Agenda for Europe [COM/2010/0245] 2011 − 2nd extension of ENISA's mandate [Regulation (EU) No 580/2011]

− European Forum for Member States issues European principles and guidelines for Internet resilience and stability

− Communication on Critical Information Infrastructure Protection Achievements and next steps: towards global cyber-security’ [COM(2011) 163]

− Council conclusions on Critical Information Infrastructure Protection "Achievements and next steps: towards global cyber-security"

Source: Overview based on Servida (2010) and expanded

Regulatory package on electronic communications  The European Union regulatory package on electronic communications contains a number of provisions on the integrity and security of public communication networks. These provisions are addressed to the member states which have the duty to transpose them into their national laws. The Framework Directive (Article 8 (4)) lists the integrity and security of public communications networks as one of the policy objectives which member states' NRAs have to implement in the interest of the citizens of the EU. The Universal Service Directive (Article 23) requires member states to ensure the availability of public telephony in the event of catastrophic network breakdown or in cases of force majeure.

In 2009, amendments to the Framework Directive introduced a new chapter dedicated to the security and integrity of networks and services. The new regulation assigns responsibilities to operators of electronic communication networks and providers of electronic communications services which required them to strengthen the resilience of their operations. The regulation mandated the undertaking of appropriate technical and organizational measures commensurate to the risks posed to the security of networks and services (Framework Directive, Article 13a (1)). This so-called state-of-the-art principle requires risk management that entails particular measures to prevent and mitigate the impact of security incidents on users and interconnected networks (Ibid.). Operators of public communication networks are under an obligation to take appropriate measures to guarantee the integrity of their networks and to ensure service continuity (Framework Directive, Article 13a (2)).6

National regulators and also ENISA are now equipped with new powers to obtain

sufficient information from the network operators and service providers about security incidents and to appraise the level of security (Framework Directive, Article 13a (3), (4), and 14). A new regulatory instrument is the security breach notification. In the event of a breach of security or loss of integrity that manifests itself with some severity, the operators and providers are under an obligation to notify the competent national authorities (Framework Directive, Article 13a (3)). Where deemed appropriate, the national regulator can pass the information on to other national regulatory authorities and ENISA (Framework Directive,

10

Article 13a (4)). The regulators will report annually to the European Commission and ENISA on the notifications received and relevant actions taken.

Newly added is the competence of the European Commission to adopt technical

implementation measures; however this is not yet relied on (Framework Directive, Article 13a (4)). This provision is the basis for the introduction of harmonized technical provisions that specify the state-of-the art principle, standards for network integrity and business continuity, as well as measures defining the circumstances, format and procedures applicable for notification requirements. Such technical regulation should be based on European and international standards whenever possible and do not preclude member state actions towards this end. Member states have to transpose the reform of the electronic communications package by 25 May 2011. This reform is a component of the wider NIS strategy in the EU, which has as additional component CIIP.

Policy on Network and Information Security (NIS)  In 2001, the European Commission issued its proposal for a European policy approach to NIS (European Commission 2001). The communication acknowledges the critical function of networks and information systems for a wide array of activities (including for utilities such as water and electricity supply), and that society at large is relying on the security of these systems. The definition of NIS which features in the introduction of this paper is used until today. The European Commission's NIS policy rationale is threefold:

1. Enhancing the effectiveness of existing legal provisions based on a common understanding of the security issues and the specific means to address them;

2. Formulating policies which would reinforce market processes and increase the effectiveness of the existing regulatory framework; and

3. Responding to the transnational scope of networks and information systems formulating a European Union wide policy (19).

In essence, NIS policy at the European Union level uses a range of reinforcing policy measures, in particular to address the governance deficit through improved communication, coordination and cooperation at various levels and among all actors from the public and the private sectors (European Commission 2005, 2).

A 2006 Communication which aimed to revitalize the European Commission's 2001 proposals carried forward a coherent approach to NIS (European Commission 2006a). It conceives a new strategy for a secure information society "based on a culture of security and founded on dialogue, partnership and empowerment" (3). Central to the outlined strategy is an open and inclusive multi-stakeholder dialogue which reflects the complementary roles of public and private sector organizations in promoting a culture of security. The Council endorsed the development of a comprehensive and dynamic EU-wide NIS strategy and the holistic approach proposed by the Commission (Council Resolution 2007). In the following, the European Commission consulted with the public on the future of NIS in the EU. The responses back the European Commission’s further endeavors to strengthen NIS community throughout the EU, and develop PPP to exchange best practices and enhance the resilience of infrastructures.7

As part of a horizontal effort to protect critical infrastructures in the EU the European

Commission devised the European Programme for Critical Infrastructure Protection (EPCIP). It addresses critical infrastructures across sectors which, "if disrupted or destroyed, would have a serious impact on the health, safety, security or economic well-being of citizens or the effective functioning of governments in the Member States" (European Commission 2004, 3). It establishes the notion that critical infrastructure protection involves "a consistent, cooperative partnership between the owners and operators of critical infrastructure and Member States authorities" (6). EPCIP follows a sector-by-sector approach which leads to

11

designated policies for the protection of critical information infrastructures. The relevant Directive does not yet identify critical information infrastructures, which is subject to a future review when priority should be given to the ICT sector, Article 3 (3) of the ECI Directive. According to a definition, the concept of critical information infrastructures would comprise "ICT systems that are critical infrastructures for themselves or that are essential for the operation of critical infrastructures (telecommunications, computers/software, Internet, satellites, etc.)" (European Commission 2005, 19).

The process of EU NIS policy development reached a new dimension when the

European Commission published its 2009 Communication entitled "Protecting Europe from large scale cyber-attacks and disruptions: enhancing preparedness, security and resilience" and accompanying Impact Assessments (2009a). It sets out the CIIP Action Plan that argues the need for the Europe-wide multi-stakeholder governance framework and lays out the foundations for an EU Computer Emergency Response Teams (CERT-EU).8 The subsequent Council Resolution on a collaborative European approach to NIS (Council of the European Union 2009) and the Council conclusions on CIIP entitled "Achievements and next steps: towards global cyber-security" endorse the policy proposals and the progress made. The 2010 Digital Agenda for Europe is one of the seven flagship initiatives of the Europe2020 Strategy. It dedicates several key actions to NIS policy (European Commission 2010a), and seeks to exploit and advance the potential of ICTs and to translate this potential into sustainable growth and innovation.

ENISA: Leveraging cooperation with expertise  In 2004, the EU made (at first) a measured institutional commitment to NIS when establishing the ENISA which is based in Heraklion, Greece. Under its constituting regulation (No 460/2004), ENISA is a European agency; its initial five year mandate has been extended twice to last now until September 2013. ENISA's mission is to enhance the NIS capabilities of European institutions and the member states, in particular the business community thereof. It therefore acts as a hub of expertise in NIS, which encompasses both cybersecurity and the protection of CIIP (Scott et al 2011, 11).

The objectives and tasks of ENISA were devised with the mission’s critical role of

facilitating broad cooperation among all NIS stakeholders. In carrying out its specific technical and scientific tasks ENISA has to reach out and connect all relevant actors in public and private sectors, act as a liaison and seek synergies between public and private actors in the member states and at European Union level. As a platform for exchange and cooperation, ENISA conducts consultations, collaborates on risk assessments and management activities, and engages in awareness-raising, the exchange of best practices and acts as a NIS information hub for all users. ENISA's mandate could be therefore described as an attempt to leverage the desired cooperation with expertise.

Pursuant to the Commission‘s proposal of 2010 to modernize ENISA, it has been

strengthened after the body was in a limbo for the last 5 years as a consequence of its short- lived mandate.9 The initial mandate (which was strictly non-operational) was expanded by assigning breach notification responsibilities to ENISA under Art. 13a and 13b of the Framework Directive 2002/21/EC as amended by Directive 2009/140/EC. According to the mandate, ENISA would assume increasingly more responsibility regarding EP3R, and after its mandate is reinforced the running of EP3R would be one of its key activities. With a constituency that includes private stakeholders, the agency has built up a good reputation and ability to reach out effectively to the private sector, which would afford it added value in the European context. ENISA also has a role in coordinating European-wide cybersecurity exercises, and it contributes to the new CERT-EU, which has been set-up primarily with the aim of enhancing the incident response capabilities of EU institutions and bodies. ENISA will

12

in the near future also be instrumental in the development of a European Information Sharing and Alert System (EISAS) which connects national CERTs with the CERT-EU.

European Public Private Partnership for Resilience (EP3R)  With its launch in 2009, EP3R embodies the Europe-wide governance framework “to involve relevant public and private stakeholders in public policy and strategic decision making discussions to strengthen security and resilience in the context of CIIP” with a European and international dimension (EP3R 2010, 5).10 EP3R complements the European Forum for Member States (EFMS) which is reserved for public authorities, whereas EP3R serves as the primary venue for exchange and partnership between the public and private sector (Ibid.). Already the impact assessment exercise conducted prior to the CIIP Action Plan in 2009 favors a non-binding and bottom-up approach to CIIP collaboration between public and private actors (2009b). Through a consultative process, public and private sector stakeholders could shape the objectives, principles and structure of this network. However, the foundational Non-paper has borrowed a lot of the language used in earlier European Commission documents, although now endorsed by various stakeholders (EP3R 2010).

According to the understanding expressed in the Non-paper that provides for the establishment of EP3R the high-level objectives are:

(1). Provide a platform for information sharing and stock taking of good policy and industrial

practices in order to foster a common understanding on the economic and market dimensions of security and resilience in the context of CIIP as well as on the roles and responsibilities of public and private stakeholders;

(2). Discuss public policy priorities, objectives and measures with a view to define framework conditions and socio-economic incentives to improve the coherence and coordination of policies for security and resilience in Europe;

(3). Identify and promote the adoption of good baseline practices for security and resilience, with a view to pursue minimum security and resilience standards and coordinated risk assessment approaches (EP3R 2010, 6)

The founding non-paper identifies as core principles complementarity with existing

national public-private initiatives, trusted collaboration among stakeholders (in particular when it comes to the sharing of sensitive information by the private sector), a bi-directional value relationship for governments and industry, and finally, an open and inclusive platform for stakeholder contribution as core principles (Ibid.). The aspect of operational information sharing is presently not included in EP3R's mandate because this is part of the ongoing activities of CERTs and PPPs at the national level. EP3R’s first three working groups now operationally cover the following areas:

− key assets, resources and functions for the continuous and secure provision of electronic communications across countries;

− baseline requirements for the security and resilience of electronic communications; − coordination and co-operation needs and mechanisms to prepare for and respond to

large-scale disruptions affecting electronic communications (European Commission 2011b, 10).

Critique of public-private partnerships in network and information security policy

EP3R is the first attempt to introduce a NIS partnership between public and private stakeholders at the EU level. The context that has led to the flourishing of PPPs in many countries, i.e. the distribution of responsibilities between the public and private sectors in the area of NIS prevails also at the EU level: While characterized by private ownership of ICT infrastructure, governments “remain ultimately responsible for defining and leading public policies for the security and resilience” of critical infrastructure protection (European

13

Commission 2009b, 18). In an ideal scenario, societies “approach critical infrastructure protection through a common-good public–private partnership, both sectors working in harmony to achieve a common goal" (Shore et al 2011, 4).

In practice, however, these ideal partnerships have yet to be actualized and it appears that PPPs are more of a projection of an efficient governance model than that there is empirical evidence that would support this claim at the level of implementation. Andersson and Malm caution that "such partnerships may instead become a Pandora’s box for many governments — an unreliable and unpredictable solution to the problem of under-provision of governance in deregulated sectors of society, particularly in the areas of national emergency preparedness and crisis management" (2006, 140). The mounting criticism of the inflationary use of PPPs at national level is summarized by Dunn-Cavelty and Suter:

The core problems are, first of all, that the term “PPP” can only describe the nature of existing partnerships in a very rudimentary way, and that the majority of so-called PPP in CIP are not really PPP at all; second, that the interests of private business and of the state are often not convergent when it comes to CIP and that PPP are therefore hardly suitable as solutions; and third, that the existing forms of cooperation are too limited (2009, 180f.)

The authors have identified some structural problems with the concept of PPPs that

would require “PPPs to exploit synergies in the joint innovative use of resources and in the application of management knowledge, with optimal attainment of the goals of all parties involved, where these goals could not be attained to the same extent without the other parties” (Ibid., 180). The required complementarity of goals may be absent in a PPP that has been set up with the primary object of promoting the national security of ICT network and information systems which according to the prevailing reading of incentives exceed what private sector stakeholders are willing to achieve. They conclude that “[n]early all of the problems that arise where PPP are formed for the purpose of [critical infrastructure protection] can be reduced to the fact that they are primarily intended to enhance security rather than efficiency” (ibid, 185). The natural tension between efficiency and security in ICT infrastructure has been affirmed earlier which is bound to ultimately impinge on the effectiveness of any PPP if incentives are not attuned to better value security.

That the European Commission is well aware of the critique shows the assessment of

national PPPs’ actual performance according to which "ownership and implementation by stakeholders appear insufficient", not least because the involvement of the private sector is often inadequate (European Commission 2009a, 6; 2009b, 8). The 2009 impact assessments discuss governance in PPPs in some detail (European Commission 2009b, 8f.). It holds that:

PPPs are quite challenging to implement in practice, as information exchange mechanisms between governments and the private sector basically become a trust issue. Private companies will share their sensitive information, about critical assets and the problems they have faced, with other stakeholders (including governments) only if such information is treated confidentially (Ibid.).

Nonetheless, this raises the question whether the European Commission consider PPPs an effective instrument at the national level and transplant this assumption to the European level (ibid.).

Besides overcoming PPPs’ known deficits, the pan-European dimension adds additional complexity (ENISA 2010, 7).11 The official impact assessments recognize the impact of the degree of institutionalization of the process, the nature of information to be exchanged, as well as the incentives to facilitate PPPs, all of which has to be understood in order to build a successful partnership (European Commission 2009b, 8f.). The CEPS Task Force on Protecting Critical Infrastructure in the EU lists several critical factors for the implementation of EP3R:

14

In particular, the size of the expected PPP, the need to accommodate several diverging interests at the same table, the sectoral specificities that would have to be merged into a single platform, and the difficulty of allocating responsibility in what is still chiefly a national prerogative may prove very difficult issues to address, and could potentially undermine the success of this very welcome initiative (Hämmerli and Renda 2010, 80).

Now that EP3R has been launched, it is possible to advance this discussion against the background of the Non-paper that provides for the establishment of EP3R (EP3R 2010) and using governance theory as a nexus of analysis.

Governance of critical information infrastructure protection

The security of ICT networks and information systems, within which CIIP policies belong, provides an excellent case study for the transformation from top-down government to new modes of governance nation states have learnt to accept and work with. It ticks all the boxes listed by the literature that would trigger a shift towards the increased reliance on governance in public management. Recent EU CIIP initiatives render the question on the appropriate European-wide governance framework highly relevant. This section shortly revisits theories of governance, networked governance and incentive-based governance in order to interrogate their relevance for CIIP. In a next step, the investigation focuses on CIIP governance in the EU context and the governance framework of EP3R will be assessed in the light of governance theory in order to deduce key aspects of a suitable European-wide governance framework for CIIP.

CIIP modes of governance  This section offers an overview of the literature on governance models for CIIP policies. Most literature focuses on the national context and here on the operational side of co- operations between public and private actors such as information sharing (Andersson and Malm 2007; Assaf 2008, 2009; Dunn Cavelty and Suter 2009; ENISA 2010, Shore, Du, and Zeadally 2011). National experiences, however, have only limited model character for supranational CIIP governance at the EU level given the different objectives and scope of these policies. Dan Assaf (2008) has conceptualized CIIP models as a regulatory continuum between more and less interventionist governance models as illustrated in Figure 1 below. His model offers a good entry point to classify the options along a spectrum of intervention intensity, but it falls short of addressing multi-pronged strategies which Bauer and van Eeten identified as the currently best approach in national efforts to combat cybercrime and enhance information security (2009, 717).

Figure 1: The regulatory continuum of critical infrastructure protection Source: Reproduction from Dan Assaf 2008, 7.12

15

Countries’ liberalization and privatization of ICT infrastructure rendered the most

interventionist mode A obsolete. As was explained earlier, the merits of mode B, on the one side of the spectrum, which epitomizes command and control regulation are limited because it is likely to be inefficient, inflexible and slow when it comes to the implementation and enforcement of top-down CIIP policies. A purely market based approach as in mode G and even the voluntary self-regulation in mode F, on the other side of the spectrum, are unlikely to produce adequate levels of security given the prevailing economic disincentives for private operators of ICT infrastructure. Bauer and van Eeten argue for a stronger role of regulatory agencies corresponding to modes C or D because they may be “an efficient intervention point” (2009, 716). National regulatory agencies typically have jurisdiction over the critical ICT infrastructure and powers to demand information from the operators are embedded in administrative procedures and sector-specific policy making experience to name just a few (Ibid). Modes D and E have a co-regulatory component as championed by Dan Assaf who also stresses the need for transparency and public accountability in any such arrangement (2009, 81).

The literature unanimously emphasizes the need for co-operation between public and

private sector stakeholders who work in partnership to enhance the security of ICT networks and information systems critical for society. PPPs in this area would correspond to modes D to F in Asaaf’s concept implying different degrees of possible state intervention (Asaaf 2009, 68). Already the variations in the definition of PPPs result in a conceptual ambiguity that would prevent them from becoming a point of reference. Observing in their international survey that all countries recognize PPPs’ importance, Brunner and Suter (2008, 15) identify different types of such partnerships, such as government-led partnerships, business-led partnerships, and joint public-private initiatives. This epitomizes once again that referring to a PPP is a euphemism which does not resolve the main challenge to identify and implement an effective governance framework. Consequently, literature has nurtured the expectation that governance (network) theory and analyses can provide a concrete recommendations for a multi-stakeholder governance framework (Dunn-Cavelty and Suter 2009, 183; Shore et al 2011, 6).

Governance (network) theory and analyses  By invoking governance theory this paper explores an, in theory, very successful conceptual framework that seeks to identify governance mechanisms for the joint delivery of a public service by public and private stakeholders. Governance theory took hold in social science at a time when governments are losing their ability to govern exclusively by coercion due to the progressing fragmentation of political power. Causes for this fragmentation are that tasks and authorities are moving beyond the control of central government due to privatization, decentralization and supra-nationalization effects which Rhodes refers to as the hollowing- out of central government (2000, 71). This coincides with the paradigm shift to new public management that is used to describe a range of state reforms, such as privatization of state functions, aimed at modernizing the public sector towards better management of public resources that emphasizes outcomes and efficiency (Hood 1991, 3). It also links to the internationalization of public concerns that require supranational and joined-up policies beyond what a nation state can realistically achieve on its own.

Hence, according to one of its most influential proponents, Rhodes, governance is an emergent property of interactions rather than the imposition of control from above. Governance is conceptually so amorphous that it can be used to describe the process of governance, the actors and institutions involved in it and the policy instruments used to achieve a particular public policy objective (Rhodes 2000, 55). It revolves around the notion that public and private institutions “are linked by reciprocal connections and more complex network relationships” (Hill 2005, 68). Governments therefore have to use alternative means

16

to shape public policy that may involve re-regulation, soft law but also soft forms of intervention such as network steering, coalition building, moral suasion and networked governance. As a caveat and not surprisingly, governance and governance network theory have both been criticized for their conceptual ambiguity and lack of explanatory power.

The idea that governance by networks can considerably enhance public management

because it is based on a partnership between public and private sectors that share an interest in a given public service has been very successful (Lane 2009, 64). Lane holds that governance networks’ salience must be seen against the background of other popular notions of social capital and trust (Ibid.). Well conceived governance networks are capable of internalizing the knowledge requirement and incentivizing through rewards certain wanted behavior. Other advantages cited in connection with this approach are that participants from different backgrounds collaborating in the delivery of a specific service share their variety of experiences in a framework which levels out hierarchies and compartmentalization (Ibid.; Rhodes 2000, 63). Accordingly, such a setting is believed to motivate participants to perform well and seek out new knowledge and solutions. Thus, networks are likely to “be successful, comparatively speaking, when technology is ill-defined and there is a strong interdependency among the actors at the same time.” (Lane 2009, 64)

Networked governance takes place in a variety of possible constellations and PPPs are just one way to refer to networks. In an attempt to come up with a taxonomy of networks the literature discusses “policy networks’ (also referred to as “issue networks”) and “policy communities” respectively. In both cases the state has a vested interest to foster them, which helps to distinguish them from other purely private interest driven organizations. The differences between policy communities and policy networks in terms of size, cohesiveness, resources and power which evident from Table 2 (below) can be expected to require different governance schemes in order to work effectively for a given model. In addition, the influence on the policy agenda of policy communities is likely to be higher compared to policy networks because of the more homogenous setting. However, many of these propositions have been derived by observation and there is little that explains why a network develops either way (Hill 2005, 74f.). Another caveat which must be made is that these are not static models, but change can be engendered by changing interests, or from endogenous factors because policy communities and policy networks operate in their specific context. Table 2: Juxtaposing policy communities and policy networks Policy communities Policy networks Size Comparatively limited memberships

often with economic and professional interests, can be used to exclude others

Large and diverse

Cohesiveness Shared values and frequent interaction

Fluctuating levels of contacts and comparatively less shared values

Resources Exchange of resources, with group leaders able to regulate this

Varying resources and an inability to regulate their use on a collective basis

Power A relative balance of powers amongst members

Unequal power

Source: Own table based on overviews in Hill 2005, 69.

The theory is becoming less determined when it comes to the management of networks, rewards for engagement and policy implementation in general, but these are the crucial questions that ultimately decide the success of any such approach. In the context of

17

cybersecurity, some authors see an increased reliance on “meta-governance” as the crucial new role of governments, i.e. indirect control as a means to the organization of self- organization (Dunn-Cavelty and Suter 2009, 183; Shore et al 2011, 6). By the same logic, governments continue to attempt top-down network steering in spite of constraints imposed by networks to exercise authority (Rhodes 2000, 72). Rhodes, however, argues that self- organizing networks tend to resist government steering (2000, 61), which would result in a significant degree of autonomy from the state. Rather, key characteristics of networks are diplomacy, reciprocity and interdependence (Ibid, 61) but to the avail of all network participants. From the point of view of network management, this ultimately carries the risks of increasing the costs of cooperation, the blurring of objectives and suboptimal outcomes. Size too matters from the point of view of effective network management.

Policy network analysis is the attempt to analyze networks’ ability to bring about

change and to influence public policy making. Several theories concurrently interrogate networks function in terms of participation, agenda setting and actors’ behavior but they cannot explain conclusively if, how and why change happens. The study of policy networks is highly circumstantial because its influence is a function of the network itself, its structure and the actors operating in it, all of which is embedded in a given context and a specific policy sub-system. One of the more influential concepts, the Advocacy Coalition Framework by Sabatier and Jenkins-Smith (1993), seeks to explain retroactively over a time perspective of a decade or longer the workings of a network (here: coalition) within a policy subsystems stressing the role of expert information. As a result, neither does policy network analysis offer a forward-looking perspective that could be used as a reference framework to model “successful” governance networks beyond what governance theory above already contributes. Nor does governance (network) theory help eradicate the conceptual ambiguities that have been pointed out in the critique of the PPP model earlier.

Principal‐agent theory and incentive‐based regulation  Borrowing from rational choice theory, the principal-agent framework is another way to conceptualise governance that derives explanations from participants’ incentives in a given context. For its representatives “governing involves the manipulation of incentives for the participants, and if those are adjusted properly governing becomes a relative simple exercise” (Pierre and Peters 2000, 43). However, principal-agent models are becoming less operational and more complex when there are many principals and multiple delegations. As an illustration, public and private sector members in such a partnership represent their organizations and are not automatically enlisted to the objectives for which the partnership has been formed. This is further complicated in the case of a delegation by an EU institution because here too the first instance of delegation has been from the member states to the EU which has then delegated to the agent. By way of incentives it is possible to align the preferences of the partners and their representatives, but any incentive scheme needs to be well conceived so as to produce the desired effects.

In the context of CIIP, Hämmerli and Renda (2010, 74) ask for “the possibility of establishing an effective principal-agent scheme that ties the actions of public and private players to clearly defined objectives, and establishes incentive schemes and sanction mechanisms." (see also Assaf 2009, 74) The details of what would constitute such an effective principal-agent scheme are neither obvious nor easy to conceive. Since precautionary measures and resilience meet uncertainty as regards to the nature of threats and magnitude of risks, a CIIP strategy’s only means is the best effort approach. The outcomes of the section on the economics of cybersecurity above suggests a mixed approach that would combine mitigating known disincentives with incentives to stimulate appropriate CIIP investments by operators. For example, a 2010 ENISA study investigates the incentives and barriers to information sharing in which it identifies, but also refutes, certain disincentives to the sharing of security relevant information (ENISA 2010).

18

Table 2 below provides an overview of policy instruments that are proposed in the

literature mainly in a national context to incentivize private actors to invest in security, resilience and emergency preparedness of ICT assets. This table distinguishes between relevant positive and negative incentives which are grouped under four categories: legal and regulatory, economic, technical and informational measures. Importantly, their individual effectiveness is not empirically proven and very controversially discussed (Bauer and van Eeten 2009, 715f.; see Hämmerli and Renda 2010, 49f.; Dunn-Cavelty and Suter 2009, 183; Moore 2010, 12f.), which is why there is no ranking among these instruments implied.

Table 2: Incentives to enhance network and information security of ICT networks Policy instruments

Positive incentives Negative incentives

Legal and regulatory measures

Public ICT security trustmark National legislation/regulation of information security

Setting-up national CERT functionality

Mandating best practices to enhance information security

Liabilities in case of failure to meet required standards

Security breach information duties Compulsory memberships in

professional organizations/ PPPs Economic measures

Tax credits and privileges for certain initiatives

Financial penalties for violations of legal/regulatory provisions (compensatory, punitive)

Public subsidies for certain investments in information security

Payments for access to valuable information

Insurance markets Technical measures

Technical guidance Information security standards Offering technical assistance Mandating security testing, audits

or peer-evaluation Education and training relevant to ICT security

Mandating participation in security exercises

Informational measures

National and international information sharing on information security

Publication of individual operator’s ICT security breach notifications

Source: Own adaptation based on Bauer and van Eeten (2009, 715)13, expanded

Co-regulation, enforced self-regulation or the “shadow of hierarchy” may be necessary to trigger private actors’ commitment and compliance. Assaf presents two scenarios from the US (which is traditionally taking a non-interventionist approach), which implies a move from self-regulation to enforced self-regulation with regards to chemical and energy security that has altered the incentive structure of private infrastructure owners to some extent. For New Zealand, Shore et al argue the case of enforced self-regulation in CIIP governance (2012, 8). In their survey, Bauer and van Eeten deduce from an Australian PPP case study on information security that a regulatory threat “seems to have boosted participation” and may have helped that the initiative continued to expand steadily (2009, 716). “Safe harbor” style regulation is another approach to manipulate operators’ incentive to contribute to and comply with private CIIP standard-setting in order to benefit from an exemption from a legislative default.

19

Less invasive isthe theory of a “shadow of hierarchy”, i.e. the possibility of governmental action, that may be necessary to provoke private policy initiatives such as co- and self-regulation. According to principal-agent-theory, a legislative threat can be perceived as an incentive and some authors would even argue that self-regulation does not exist at all because the motivation is induced endogenously by the possibility of legislative action and private policy making is a strategy to forego regulation. A different area exhibiting public good characteristics, complexity and interconnectedness is environmental policy which is why research in this field may be relevant to advance our understanding how to achieve private actors’ compliance and commitment. Empirical research by Héritier and Eckert (2008) covering a range of environmental initiatives by industry in Germany and the UK shows that in almost all investigated cases voluntary commitments from industry followed a legislative threat. For this investigation it is a relevant insight that in networks, which are said to resist authoritative steering, the “shadow of hierarchy” may be a necessary incentive to enlist the private sector to produce outcomes in the context of a multi-stakeholder policy network. The “shadow of hierarchy” can be direct or indirect, the first being a system of regulated self- regulation, the second referring to a real legislative threat (contrary to the general risk of some legislation to come). Governance network theory and the prospects of introducing a “shadow of hierarchy” are now applied to this investigation into a suitable European-wide governance framework for CIIP.

Implications for the European‐wide governance framework for CIIP  Returning to the focus of this paper, the EP3R is just one component of the European-wide governance framework for CIIP that is complemented by ENISA, EFMS, and BEREC. However, as the designated platform for public and private actor collaboration, it is arguably one of the most ambitious initiatives at the European level. As has been previewed, EP3R differs in scope and objectives from its national counterparts (ENISA 2010, 7; European Commission 2009b, 8f.; Hämmerli and Renda 2010, 80). The following assessment relates governance network theory to this partnership, which is then found to conflate a number of concepts discussed in the literature. The argument discusses implications for a European-wide governance framework for CIIP and argues incentive-based governance inspired by principal- agent theory.

In contrast to the comparatively homogeneous policy community, EP3R bears arguably more characteristics of a policy network that is bigger in size and rather diverse. Once EP3R has reached its envisaged constituency it is bound to become rather large, in terms of membership, and diverse as EP3R gives preference to cooperating with the highest ranking executives responsible for NIS from the following organizations: National PPPs and national public authorities in the field of NIS, ICT network infrastructure operators with a European-wide relevance in terms of size or cross-border coverage, and European associations representing ICT infrastructure operators (EP3R 2010, 9f.). Even if the partnership succeeds in attracting only the types of organizations enumerated in the founding non-paper (EP3R 2010, 9), diversity emanates from different national and cultural backgrounds and the relative involvement of public and private sector stakeholders.14In the national context, PPP are likely composed by a majority of private stakeholders, but this is not the case with EP3R which reaches out to NIS authorities and national PPPs.

For the desired European-wide governance framework for CIIP this has a number of

consequences. There are no regulatory mechanisms at work that would coerce private actors to participate in EP3R. To the contrary, the founding non-paper of EP3R emphasizes a bottom-up approach to CIIP collaboration. At the formal level this organization should preclude direct interventions by EU officials and attempt to exercise indirect control (albeit the European Commission and ENISA facilitate and administer the partnership, EP3R 2010, 9). Governance literature reflects the governability of policy networks which some authors

20

describe as resisting attempts of government (here EU) steering (notably Rhodes 2000, 61). It is important to interrogate the motivations of stakeholders to actively participate and be firmly committed to EP3R’s objectives.

At the national level, information sharing has been identified as one of the core

motivations in engaging in PPP where the relationship is built on trust among its participants. Trust and credibility cannot be mandated or replaced by binding information frameworks because they are intangible (European Commission 2009b, 34). Diversity and participation can actually become deterrents for sharing sensitive business information (ENISA 2010, 37; see also Dunn-Cavelty and Suter 2009, 182). It is clear that when it comes to creating a trusted environment “[s]upranational PPPs may face a problem of size” (Hämmerli and Renda 2010, 78). In other words, diversity and participation at the European level can actually become deterrents for sharing sensitive business information (7; ENISA 2010, 37; see also Dunn-Cavelty and Suter 2009, 182). Against this backdrop, it is straightforward not to include operational information sharing in EP3R's mandate and refer to its activities being complementary to existing national PPPs information sharing activities.

In fact, EP3R pursues strategic CIIP policy objectives with a view on best practices,

statistical frameworks and policy recommendations (EP3R 2010). EP3R’s deliberative nature and the interaction with European Commission officials, where the competence for EU policy initiatives rests, may actually explain a fair share of private actors’ incentive to participate in EP3R. High-level representation from the European Commission ensures the desired level of executive participation from the private sector and vice versa. EP3R offers an exclusive venue to influence EU policy making at an early stage when it is likely to be most effective. For example, EP3R is involved in discussing a legislative proposal that defines the features that would lead to specific ICT networks being designated critical information infrastructure and trigger regulatory obligations. This and the involvement with similar high-level policy initiatives is what private stakeholders are likely to derive from participating in EP3R.

This leads to the follow-up question whether in the light of its objectives and

principles the issues of trust and size are, indeed, such important organizational imperatives for EP3R that they can justify the limitations in representation, accountability and transparency. Since EP3R is effectively a policy network and pursues by and large high-level public policy objectives instead of low-level information exchange, the issues with representativeness and procedural legitimacy are becoming more pronounced. Expressions of interest for participation in the working groups have to be mailed to the European Commission and access to the High Level Steering Group is by invitation only (EP3R 2011, 10). Thus, inclusiveness and participation of EP3R is fairly regulated, which would require a very strong justification in order to counterbalance the inherent legitimacy deficit, which is also a concern of governance theory. Further, it must be noted that apart from the European Commission and ENISA there is no public information about which organizations have endorsed the Non-paper establishing EP3R and that the European Commission’s website for EP3R does not feature a list of members in either the High Level Steering Group or the existing three working groups. Since the 2010 non-paper establishing EP3R there is no more recent documentation about its functioning and subsequent activities.

Regulation and governance research, however, stress the importance of principles of

procedural legitimacy in co- and self-regulation for the sake of effective and sustainable co- regulation or self-regulation. With regards to PPPs as a governance mechanism to the protection of critical infrastructure protection, Assaf calls for regulatory arrangements to be restructured in order to enhance the accountability to public values (2009, 78). Transparency crucially accompanies public accountability (Ibid, 77). The 2003 inter-institutional agreement on better law-making (European Parliament et al 2003), which recognizes alternative regulation mechanisms, among other issues, carries also the commitment that the European Commission:

21

will ensure that any use of co-regulation or self-regulation is always consistent with Community law and that it meets the criteria of transparency (in particular the publicizing of agreements) and representativeness of the parties involved. It must also represent added value for the general interest. These mechanisms will not be applicable where fundamental rights or important political options are at stake or in situations where the rules must be applied in a uniform fashion in all Member States (Ibid., para. 17).

Strictly speaking EP3R has not yet made use of co-regulation or self-regulation but it

is meant to lead to some sort of commitment of private actors and must adhere to principals of procedural legitimacy. EP3R does not comply with the self-adopted standards of the European institutions in terms of transparency and possibly also representativeness. It clearly infringes aspects of procedural legitimacy whenever EP3R is involved in negotiating important political options of CIIP. Although the EP3R non-paper broadly defines objectives, principles and even expected outcomes, there are no mechanisms that would render the activities of EP3R accountably to the public, let alone to the public good NIS it seeks to promote. Admittedly, any PPP governance arrangement is a delicate maneuver along the spectrum of possible interventions, yet EP3R appears to replicate known deficits of national PPP in the field of network and information security.

However, at the EU level the rationale for setting-up a PPP in the area of NIS follows

a path-dependent logic that has its basis in a national PPP, where operational information- sharing requires high levels of trust and confidentially. In the light of EP3Rs objectives and scope of activities, trust and size, which are used to justify limitations to the principles of representativeness, accountability and transparency, are overemphasized. Apart from considerations of procedural legitimacy, the risks are that EP3R will not produce significant and tangible commitments by private operators of ICT infrastructures. The mechanisms that would attune the security-efficiency trade-off and incentive European-wide NIS policy consistency, which is by and large the raison d'être of EU NIS policy intervention, are still at the drawing-board and EP3R is a venue to influence these new regulations to come.

Conclusions

The security of ICT networks and information systems poses a particular governance challenge for policy makers at all levels. The governance approach is imperative because it is the only means to public policy making under the impression of an international ICT ecosystem that is characterized by high (technical) complexity and requires multi-stakeholder co-operation. In the EU, member states have already accumulated a fair number of years of experience and existing comparative surveys reveal a range of commonalities in the approach and engagement with private sector stakeholders, in particular the creation of PPPs involving the operators of ICT (Brunner and Suter 2008; ENISA 2009b).

Aside from raising the overall level of preparedness and resilience against cyberthreats, a central EU NIS policy objective must be regional policy coherence in order to address transborder risks stemming from the ICT sector’s interconnectedness. For the EU there is a strong case to set up a dedicated structure with the objective to tackle CIIP in a European-wide context. Aside from the interaction with the private sector ENISA already facilitates, the founding of EP3R in 2010 manifests the first European-wide partnership between public and private stakeholders towards the protection of critical information infrastructure. For the EU, EP3R is the organizational vessel that should provide a Europe- wide governance framework to enhancing cybersecurity.

The national reliance on PPPs as a suitable governance model has clearly informed the EU’s NIS governance framework in the area of CIIP (EP3R 2010; European Commission

22

2009a, 6; 2009b, 8f.). EP3R, however, is in many ways bound to be different from similar initiatives at the national level, where often the same private stakeholders are already engaged. The non-paper establishing EP3R shows acute awareness of the need to observe subsidiarity and complementarity with national initiatives and of the overall context in which this partnership operates (EP3R 2010):

(1). The founding non-paper of EP3R emphasizes a bottom-up approach, the success of

which would depend on the active participation and strong commitment of all participants.

(2). EP3R does not engage in operational information sharing and exchange, which is believed to be the main motivation for private actors to engage in national PPPs.

(3). EP3R’s high-level objectives centre around “public policy and strategic decision making discussions to strengthen security and resilience in the context of CIIP” (EP3R 2010, 5).

(4). One design principle of EP3R is the creation of a “trusted collaboration” environment (EP3R 2010, 7), which is why participation is limited to NIS senior representatives from enumerated public and private sector organizations.

(5). EP3R pays little attention to procedural legitimacy, such as transparency and accountability to the public and to the public good security. This paper concludes that EP3R has adopted a restrictive governance structure which

can not be entirely justified in the light of its mandate and scope of activities. Deliberations in EP3R are moved up to such crucial tiers in European public policy formulation, that the wish to stay among peers (“trusted collaboration”) conflicts with the principles of representativeness, accountability and transparency, contrary to what EU institutions committed to under the 2003 inter-institutional agreement on better law-making (European Parliament et al 2003). EP3R’s selling point is the close engagement with senior representatives from the European Commission and member states’ authorities, which appears to be the major incentive for private ICT network operators’ motivation to participate. Apart from considerations of procedural legitimacy, the risks are that EP3R will not produce significant and tangible commitments by private operators of ICT infrastructures.

An investigation into a suitable European-wide multi-stakeholder governance

framework reveals that PPPs are no silver-bullet to NIS governance (Dunn-Caveltry and Suter 2009, 179) and that the take-aways from governance network theory and analysis are at best mundane. Governance literature does not support the engineering of a successful multi- stakeholder partnership aimed at the protection of the public good NIS, and the study of policy networks implies they tend to resist any attempts of government (here EU) steering where they exist. Thus, governance needs to manipulate the incentives of stakeholders in order for them to carry security preparedness and resilience beyond what efficiency dictates. This paper argues in favor of of safe harbor style regulation that would establish a system of enforced self-regulation in CIIP at the EU level.

The tensions created by the need to observe subsidiarity and complementarity with

national CIIP initiatives may preclude the adoption of a narrow PPP model for European- wide CIIP governance. The conclusion offers recommendations on an improved European- wide governance framework for CIIP that are informed by procedural legitimacy and incentive-based governance. It does not argue to abandon the notion of a partnership between public and private actors but it tries to untangle this notion from those considerations that are invoked in favor of non-transparent and clandestine arrangements in the context of operational information sharing in national PPPs.

23

Mixed policy approach to network and information security  Governance networks to which PPPs belong are formed with the objective to jointly deliver a public service. NIS is not a public service but a public good with the main difference that economic incentives may produce efficiency but not - from a societal point of view - adequate levels of security. Theory and national practice point towards a mixed approach that would combine mitigating known disincentives with incentives to stimulate appropriate CIIP investments by operators.

At the EU level this result holds true but the mix is different to what is done at the national level, not least because of the need to observe the principles of subsidiarity and complementarity. New regulation of security breach information and the introduction of the state-of-the-art-principle for appropriate technical and organizational measures, the cornerstones of the policy mix, are already in place. A European-wide CIIP governance framework needs to focus primarily on enhancing policy coherence, i.e. the systematic integration and coordination of all activities and actors at regional level.

Not scaling trust but the benefits of information‐sharing at the EU level  Trust is not a essential requirement of a European-wide CIIP governance framework that does not engage primarily in operational information sharing. Rather, the benefits of information- sharing should be scaled to European levels. The key to information sharing is to de-sensitize information from their originating context and repackage CIIP information in a way that would maintain the value of the information for other users. Existing operational information sharing platforms at the international level, e.g. the Forum of Incident Response and Security Teams (FIRST), mark a development towards preserving the benefits of information sharing across borders. Additionally, the EU follows a joined-up approach in which national CERTs exchange information via EISAS and national regulatory authorities in the electronic communications sector share security breach notifications when it is deemed appropriate and an annual summary report on security breach notifications.

European‐wide CIIP governance pursues strategic and high‐level public policy objectives  Different to national PPPs in the field of network and information security, European-wide CIIP governance involving public and private actors pursues strategic and high-level public policy objectives. The deliberations must be open and transparent in order to prevent them from turning into an exclusive lobbying venue for private stakeholders with vested interests in CIIP policies. Instead CIIP governance requires sustained attention at the EU level and an annual conference could be a suitable venue for public deliberation. In order to collect sector- specific expertise, public consultations on EU policy and legislative proposals may be a suitable and procedurally legitimate alternative.

European‐wide CIIP governance has a large and diverse constituency  A European-wide engagement with public and private actors results inevitably in a large and diverse constituency. Any efforts to contain membership are most unlikely to make a difference on the commitment of the participants. Since in European-wide CIIP governance trust and confidentiality are less of a prerequisite, participation must be open to all stakeholders including representatives, who are not representing industry such as civil society organizations.

Co‐regulation of private CIIP standard‐setting activities likely to be most effective  Co-regulation or enforced self-regulation is likely to be the most effective CIIP governance mechanism to correct the underprovision of network and information security. It combines

24

the advantages of industry CIIP standard-setting, i.e. expertise, flexibility, compliance and monitoring, with EU-wide regulatory benchmarks geared towards efficient strategies, policy coherence and accountability. The EU policy maker should consider regulation that would trigger “safe harbor”-privileges for operators of ICT networks which adhere to industry best practices and which have been endorsed by the competent authorities.

Effective CIIP policy cooperation needs transparency and accountability  An effective CIIP policy cooperation between public and private actors at the European level needs transparency and accountability. According the 2003 inter-institutional agreement on better law-making, this would be already mandatory because the European-wide CIIP governance classifies as an alternative regulation mechanism. Beyond formal obligations, European-wide CIIP governance is best served by public scrutiny and accountability to the public interest, which helps to assess whether deliberations on high-level policy are not unduly influenced and private actors’ commitments hold strong.

At the EU level, efforts should be made to correct the EP3R governance model following

these recommendations. The corrected European-wide multi-stakeholder governance framework would become susceptible to the challenges of the protection of critical information infrastructure and reconcile it with the principles on procedural legitimacy. As a Conseqeunce EP3R is perhaps less exclusive and attractive for private actors but may prove more effective in the medium term because it holds ICT infrastructure operators accountable to the public good NIS.

***

Notes Kristina Irion is Assistant Professor at the Departments of Public Policy/ Legal Studies and Research Director in Public Policy at the Center for Media and Communications Studies (CMCS) at Central European University. I would like to thank Jean-Pierre Chamoux for his valuable comments on an earlier draft which was presented at the 27th European Communications Policy Research Conference (EuroCPR), 25-27 March 2012, Ghent, Belgium. I am alone responsible for any inaccuracies and interpretations. The paper will be published in Gaycken, Krueger, Nickolay (eds., 2012 forthcoming ). The Secure Information Society. Berlin: Springer Publ. The author can be contacted at [email protected].

Endnotes 1 In the example of illegal botnets, the virtual network of high jacked computers (or “zombies” as they

are referred to) can be enlisted for illegal activities against a fee the criminal controlling the botnet levies from their customers.

2 The 2008 OECD “Ministerial Meeting on the Future of the Internet Economy” in Seoul reinforced the attention paid to policies and international cooperation that aim for security and resilience of networked ICT systems (OECD 2008, 7f.).

3 For an inventory of CERT activities in Europe see http://www.enisa.europa.eu/activities/cert/ background/inv.

4 The OECD (2001, 104; 2003, 2) formulated this concept in the context of development policies, however, its principles are generalizable and can be flexibly adapted to fit other policy areas.

5 This very provision has long been criticised, however, for undermining national legislative processes because under this provision member states executives adopt EU measures.

6 Privacy in electronic communications also implies the security of communications services. Under the Directive on Privacy and Electronic Communications providers of communications services to the public have to meet specific security obligations which correspond to the general duty of data

25

processors in the European Union's Data Protection Directive concerning the secure processing personal data. Providers are required to safeguard the security of its electronic communications services by taking appropriate technical and organizational measures commensurate with the risks (Article 4 of the Directive on Privacy and Electronic Communications; Article 17 (1) of the Data Protection Directive). The 2009 Citizens' Rights Directive, which amended the Directive on Privacy and Electronic Communications, implemented the obligation to draw-up a security policy and to issue a notification in the event of a personal data breach to the users concerned.

7 The public consultation which had a turn-around of close to 600 contributions is archived at http://ec.europa.eu/information_society/policy/nis/nis_public_consultation/index_en.htm. (accessed 12 December 2012).

8 In September 2009, the EU’s new Computer Emergency Response Preconfiguration Team (CERT- EU) took up its work. See European Commission’s Press Release IP/11/694 of 10 June 2011 “Cyber security: EU prepares to set up Computer Emergency Response Team for EU Institutions.” Available at http://europa.eu/rapid/pressReleasesAction.do?reference=IP/11/694 (Accessed December 12, 2011).

9 In the Digital Agenda for Europe, one of the seven flagship projects of the Europe 2020 Strategy, key actions 6 and 28 set out the objective to modernize ENISA (European Commission 2010a, 17).

10 See Non-paper on the Establishment of a European Public-Private Partnership for resilience (EP3R) Version 2.0, 23 June 2010, available at http://ec.europa.eu/information_society/policy/nis/ docs/ep3r_workshops/3rd_june2010/2010_06_23_ep3r_nonpaper_v_2_0_final.pdf (Accessed 14 December 2011).

11 ENISA was tasked with investigating barriers and drivers for public and private actors to cooperate in the area of network and information security (see Preparatory Action 2: Identifying drivers, barriers and frameworks for EU sectoral NIS cooperation" in the Work Programme (ENISA 2010b, 8)), however, it appears this action has been abandoned.

12 Assaf’s taxonomy suffices for this argument; for an enhanced PPP taxonomy see Shore et al 2012, 8. 13 Note that Bauer and van Eeten’s survey takes the perspective that combines policy instruments to

combat cybercrime and promotes enhanced information security of stakeholders in the ICT ecosystem.

14 The organization into different working groups clearly attempts to counterbalance this structural problem and to approximate more the setting of a policy community, but in remains a sub-structure which requires a mandate by the organization and does not produce EP3R-wide consensus.

26

References

Alderson, David and Kevin Soo Hoo. (2004). “The Role of Economic Incentives in Securing Cyberspace”. Stanford University’s Center for International Security and Cooperation

Andersson, Jan Joel, and Andreas Malm. (2007), "Public-private Partnerships and the Challenge of Critical Infrastructure Protection", in Isabelle Abele-Wigert and Myriam Dunn (eds.), International CIIP Handbook 2006 vol.2, Center for Security Studies, ETH Zurich, 2007.

Assaf, Dan (2008). “Models of Critical Information Infrastructure Protection.” International Journal of Critical Infrastructure Protection 1: 6-14.

--------- (2009). “Conceptualizing the use of Public-Private Partnerships as a regulatory arrangement in critical information infrastructure protection”, in: A.O. Peters, L. Koechlin, T. Förster, G.F. Zinker-nagel (Eds.), Non-State Actors as Standard Setters, Cambridge: Cambridge University Press, 2009.

Bauer, Johannes M. and Michel Van Eeten. 2009.”Cybersecurity: stakeholder incentives, externalities, and policy options”, Telecommunications Policy, 33(10-11): 706-719.

BBC. 2008. “Severed cables disrupt internet”. 31 January 2008. Available at http://news.bbc.co.uk/2/hi/technology/7218008.stm (accessed 14 February 2012).

Bell Labs and Professional Services Alcatel Lucent (2007). Availability and Robustness of Electronic Communications Infrastructure. “The ARECI Study”, Final Report. Study prepared for the European Commission. March 2007.

Brunner, Elgin M., and Manuel Suter (2008). International CIIP Handbook 2008/2009. Center for Security Studies (CSS), ETH Zurich, 2008.

EP3R (2010). Non-paper on the Establishment of a European Public-Private Partnership for resilience (EP3R). Version 2.0, 23 June 2010, available at http://ec.europa.eu/information_society/policy/nis/docs/ep3r_workshops/3rd_june201 0/2010_06_23_ep3r_nonpaper_v_2_0_final.pdf (Accessed 14 December 2011).

Gal-Or, Esther and Anindya Ghose (2004). “The Economic Consequences of Sharing Security Information”. Economics of Information Security: Advances in Information Security, 2004, Volume 12, 95-104.

Goldsmith, Stephen, and William D Eggers. (2004). Governing by Network: The New Shape of the Public Sector, Brookings Institution Press and John F Kennedy School of Government at Harvard University 2004.

Dunn-Cavelty, Myriam, and Manuel Suter (2009). “Public-Private Partnerships Are No Silver Bullet: an Expanded Governance Model for Critical Infrastructure Protection”. International Journal of Critical Infrastructure Protection Issue 2, Volume 4, 2009, pp. 179-187.

Dynes, Scott, Eric Goetz and Michael Freeman (2007). “Cyber Security: Are Economic Incentives Adequate?” IFIP International Federation for Information Processing, 2007, Volume 253/2007, 15-27.

Fieldes, Jonathan (2011). “Stuxnet virus targets and spread revealed”. 15 February 2011. Available at http://www.bbc.co.uk/news/technology-12465688 (accessed February 14, 2012)

Hämmerli, Bernard, and Andrea Renda (2010). Protecting Critical Infrastructure in the EU. Regulatory Policy, CEPS Task Force Reports, Centre for European Policy Studies (CEPS).

27

Hare, Forrest B. (2009). "Private Sector Contributions to National Cyber Security: A

Preliminary Analysis," Journal of Homeland Security and Emergency Management: Vol. 6: Iss. 1, Article 7.

Héritier, Adrienne, and Sandra Eckert (2008). "New Modes of Governance in the Shadow of Hierarchy: Self-regulation by Industry in Europe". Journal of Public Policy (2008), 28, 113-138.

Hill, Michael (2005). The Policy Process, 4th Edition, London: Longman. Hood, Christopher (1991). “A Public Management for All Seasons?”. Public Administration

69 (1), pp. 3-19. Intelligence and National Security Alliance (INSA). Addressing Cyber Security Through

Public-Private Partnership: An Analysis of Existing Models, November 2009. Available at http://www.insaonline.org/assets/files/CyberPaperNov09R3.pdf

ITU (2011). ITU National Cybersecurity Strategy Guide. September 2011. ITU: Geneva. Available at http://www.itu.int/ITU-D/cyb/cybersecurity/docs/ITUNational CybersecurityStrategyGuide.pdf (accessed December 11, 2011)

Lane, Jan-Erik (2009). State Management. London: Routledge Maurer, Tim (2011). “Cyber Norm Emergence at the United Nations – An Analysis of the

UN‘s Activities Regarding Cyber-security?”, Discussion Paper 2011-11,Cambridge, Mass.: Belfer Center for Science and International Affairs, Harvard Kennedy School, September 2011.

Menn, Joseph (2010). “Police shut down Mariposa hacker ring”, Financial Times, March 3, 2010. Available at http://www.ft.com/intl/cms/s/0/f6960e5a-2711-11df-b84e- 00144feabdc0.html#axzz1otZbvVuh (accessed February 14, 2012).

OECD (2001). The DAC Guidelines, Poverty Reduction, OECD. Paris. Available at http://www.oecd.org/dataoecd/47/14/2672735.pdf (accessed December 11, 2011)

OECD (2003). "Policy Coherence: Vital for Global Development". Policy Brief, OECD, Paris. Available at http://www.oecd.org/dataoecd/1/50/8879954.pdf (accessed December 11, 2011)

OECD (2002). OECD Guidelines for the Security of Information Systems and Networks: Towards a Culture of Security. Available at http://www.oecd.org/dataoecd/16/22/15582260.pdf (accessed at 14 February 2012).

OECD (2006). The Development of Policies for the Protection of Critical Information Infrastructures (CII): DSTI/ICCP/REG(2006)15/FINAL.OECD, Paris.

OECD (2008). The Seoul Declaration for the Future of the Internet Economy. Available at www.oecd.org/dataoecd/49/28/40839436.pdf (accessed 14 December 2011)

Pierre, Jon, and Guy B. Pieters (2000). Governance, Politics and the State. Hunts: Palgrave Macmillan.

Rhodes, Rod A.W. (2000). “Governance and Public Administration”. In Debating Governance: Authority, Steering, and Democracy (John Pierre ed.), Oxford: Oxford University Press, pp. 54-90.

Sabatier, Paul and Hank Jenkins-Smith, (eds) (1993) Policy Change and Learning: An Advocacy Coalition Approach, Boulder, CO: Westview Press.

Servida, Andrea (2010). “Towards a modernised Network and Information Security Policy for the European Union”. Presentation held at the Cybersecurity Workshop at Central European University and funded by the European Science Foundation, Budapest, 6/7 June 2010. (On file with the author).

Scott, Markus, et al (2001). The role of ENISA in contributing to a coherent and enhanced structure of network and information security in the EU and internationally. Study prepared for the European Parliament. Available at

28

http://www.europarl.europa.eu/activities/committees/studies/download.do?language= en&file=42251 (Accessed 14 December 2012).

Shore, Malcolm, Du, Yi, and Sherali Zeadally (2011). "A Public-Private Partnership Model for National Cybersecurity," Policy & Internet: Vol. 3: Iss. 2, Article 8. Available at: http://www.psocommons.org/policyandinternet/vol3/iss2/art8 (Accessed December 14, 2011).

U/FOUO. Project 12 Report: Improving Protection of Privately Owned Critical Network Infrastructure Through Public-Private Partnerships. 2011. Available at http://info.publicintelligence.net/NetworkInfrastructurePublicPrivate.pdf (accessed December 14, 2011)

Official documents

Council Resolution of 22 March 2007 on a Strategy for a Secure Information Society in Europe (2007/C 68/01). Official Journal of the European Union C 68/1 f 24.3.2007.

Council (2008). Council Directive 2008/114/EC of 8 December 2008 on the identification and designation of European critical infrastructures and the assessment of the need to improve their protection. Official Journal of the European Union L 345/75 of 23.12.2008.

ENISA. 2009a. Work Programme. ENISA. 2009b. Analysis of Member States’ Policies and Recommendation. ENISA: 2009. ENISA. 2010. Incentives and barriers to information sharing in the context of network and

information security. ENISA ENISA. 2011. Economics of Security: Facing the Challenges. A multidisciplinary assessment.

ENISA. European Commission (1994). Green Paper on the liberalisation of telecommunications

infrastructure and cable television networks. Part one, principle and timetable. COM (94) 440 final, 25 October 1994. http://aei.pitt.edu/1093/1/telecom_cable_gp_part_1_COM_94_440.pdf

European Commission (2001). Communication from the Commission to the European Parliament, the Council, the European Economic and Social Committee and the Committee of the Regions on Network and Information Security: Proposal for A European Policy Approach, COM(2001)298, Brussels, 6.6.2001.

European Commission (2004). Communication from the Commission to the Council and the European Parliament on Critical Infrastructure Protection in the fight against terrorism, (COM(2004) 702 final), Brussels, 20.10.2004.

European Commission (2005). Green Paper on a European Programme for Critical Infrastructure Protection, COM(2005) 576 final, Brussels, 17.11.2005.

European Commission (2006a). Communication from the Commission to the European Parliament, the Council, the European Economic and Social Committee and the Committee of the Regions on A strategy for a Secure Information Society – “Dialogue, partnership and empowerment”. COM(2006)251.

European Commission (2006b). Communication from the Commission of 12 December 2006 on a European Programme for Critical Infrastructure Protection, COM(2006) 786 final, Official Journal C 126 of 7.6.2007.

European Commission (2009a). Communication from the Commission to the European Parliament, the Council, the European Economic and Social Committee and the Committee of the Regions on Critical Information Infrastructure Protection -

29

"Protecting Europe from large scale cyber-attacks and disruptions: enhancing preparedness, security and resilience" {SEC(2009) 399} {SEC(2009) 400.

European Commission (2009b). Commission Staff Working Document Accompanying document to the Communication from the Commission to the European Parliament, the Council, the European Economic and Social Committee and the Committee of the Regions on Critical Information Infrastructure Protection - "Protecting Europe from large scale cyber-attacks and disruptions: enhancing preparedness, security and resilience." Impact Assessment (Part 1),{COM(2009) 149}{SEC(2009) 400}.

European Commission (2010a). Communication from the Commission to the European Parliament, the Council, the European Economic and Social Committee and the Committee of the Regions. A Digital Agenda for Europe. Brussels, 26.8.2010. COM(2010) 245 final/2.

European Commission (2010b). Communication from the Commission to the European Parliament, the Council, the European Economic and Social Committee and the Committee of the Regions on Critical Information Infrastructure Protection ‘Achievements and next steps: towards global cyber-security’. 31. March 2011, COM(2011) 163 final.

European Forum for Member States (2011). European principles and guidelines for Internet resilience and stability (Version of March 2011). http://ec.europa.eu/information_society/policy/nis/docs/principles_ciip/guidelines_int ernet_fin.pdf

European Parliament, the Council and the Commission of the European Union (2003), ‘Inter- institutional Agreement on better law-making’, adopted on 16 December, OJ 2003, C 321/01.

Directive 2002/21/EC of the European Parliament and of the Council of 7 March 2002 on a common regulatory framework for electronic communications networks and services (Framework Directive) as amended by Directive 2009/140/EC and Regulation 544/2009.

Directive 2002/22/EC of the European Parliament and of the Council of 7 March 2002 on the on universal service and users' rights relating to electronic communications networks and services (Universal Service Directive) as amended by Directive 2009/136/EC.

Directive 2002/58/ of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications) as amended by Directive 2006/24/EC and Directive 2009/136/EC

High-level Group on the Information Society. 1994. Report on Europe and the Global Information Society: Recommendations of the High-level Group on the Information Society to the Corfu European Council. Bulletin of the European Union, Supplement No. 2/94. (commonly called “the Bangemann Report”). Available at http://aei.pitt.edu/1199/1/info_society_bangeman_report.pdf (accessed 11 December 2011)

Regulation (EC) No 460/2004 of the European Parliament and of the Council of 10 March 2004 establishing the European Network and Information Security Agency. Official Journal L 77, 13/03/2004 P. 1 – 11.