From insight to compliance: Appropriate technical and organisational security measures through the lens of cybersecurity maturity models

被引:0
|
作者
Koolen, Christof [1 ,3 ]
Wuyts, Kim [2 ]
Joosen, Wouter [2 ]
Valcke, Peggy [1 ]
机构
[1] Katholieke Univ Leuven, Ctr IT & IP Law, Leuven, Belgium
[2] Katholieke Univ Leuven, Dept Comp Sci, Leuven, Belgium
[3] Katholieke Univ Leuven, Fac Law, Tiensestr 41, B-3000 Leuven, Belgium
关键词
Cybersecurity; Appropriate technical and organisational; measures; IT systems; GDPR; Risk assessment; Compliance obligations; INTERNET; SOFTWARE;
D O I
10.1016/j.clsr.2023.105914
中图分类号
D9 [法律]; DF [法律];
学科分类号
0301 ;
摘要
Cybersecurity is a much-debated topic in both technical and legal scholarship. With contemporary business models hinging on highly performant information systems, there is increased awareness among entrepreneurs that security incidents often have devastating consequences on undertakings' revenue streams, intellectual property, and brand reputation. As a result, there is an increased focus on the obligation to implement cybersecurity measures. In the context of the GDPR, cybersecurity obligations seem to converge on the requirement to deploy 'appropriate technical and organisational measures' in order to ensure a level of security commensurate with the risks posed to an organisation. Yet, given the complex and rapidly evolving nature of the subject matter, the precise meaning and scope of these obligations remain unclear. This contribution offers guidance on how to assess the concept of 'appropriate technical and organisational measures' by considering it through the lens of cybersecurity maturity models. Accordingly, this article provides anchorage to scholarly audiences when scrutinizing the extent to which privacy and security measures qualify as 'appropriate' in the context of liability claims and actions for damages, thereby creating an opportunity to move from technical insight to legal compliance.
引用
收藏
页数:10
相关论文
共 1 条
  • [1] From insight to compliance: Appropriate technical and organisational security measures through the lens of cybersecurity maturity models
    Koolen, Christof
    Wuyts, Kim
    Joosen, Wouter
    Valcke, Peggy
    [J]. Computer Law and Security Review, 2024, 52