week 9 assim

profilemid908
week_9_reading.docx

Build Cybersecurity Incentives: Why Should I Do What You Want?

 

This starts with one of the key problems in cybersecurity policy – that cyberattacks often have effects outside of the organization being attacked. This is known as a negative externality – a cost paid by someone else or by society as a whole. Without outside incentives (positive or negative), businesses will not spend money to remove negative externalities.

 

I don't know about you, but I find the first sentence of the last paragraph to be completely out of place. They say

 

The market can be a powerful force for cybersecurity when it functions properly.”

 

While there may be some truth to this sentence, it's placed in a strange place in the book, immediately after spending pages talking about all of the ways in which the market fails. I really wish they had elaborated on this statement (e.g., what do they mean by “properly”), and included something to justify it!

 

Learn to Share: How Can We Better Collaborate on Information?

 

And they change topics to another one of the big ones. Without a doubt, information sharing can improve cybersecurity. Attackers do as little work as possible – if an attack works well against one target, they will certainly try the same attack against others. The more information that is shared about attacks, the harder attackers will have to work.

 

But there are few incentives to share information when you are attacked, and many incentives not to. The authors mention two of these disincentives, the potential of releasing potentially sensitive information, and the potential of letting the attackers know what you know about them. I have no doubt that with a little thought, you can come up with several more reasons why businesses would be reluctant to talk any more than absolutely necessary about a cyber attack.

 

There's a few pages of descriptions of a variety of different ways in which cyber attack information is shared, followed by a discussion of the key question “is there enough?”

 

On the top of page 227, they state that “Industry groups have asked Congress to provide legal protection before they participate in widespread programs.” This is a reference to the Cybersecurity Information Sharing Act, which was passed by Congress and signed into law by Obama in December of 2015. It's important to recognize that the law is completely voluntary – it doesn't require organizations to share information about attacks, nor does it require organizations to pay attention to information that is shared by others. Whether the law advances cybersecurity at all will not be clear for at least a few years.

 

Demand Disclosure: What is the Role of Transparency?

 

This section is basically a continuation of the previous. Under what circumstances should organizations be required to disclose breaches, and how much information should they be required to disclose?

 

 

Get “Vigorous” About Responsibility: How Can We Create Accountability for Security?

 

The previous three sections talk about what types of cybersecurity responsibilities we might place on organizations. But what if they don't meet those responsibilities? How are they held accountability for their failures?