Article (Périodiques scientifiques)
Defining the reporting threshold for a cybersecurity incident under the NIS Directive and the NIS 2 Directive
SCHMITZ-BERNDT, Sandra
2023In Journal of Cybersecurity, 9 (1)
Peer reviewed vérifié par ORBi Dataset
 

Documents


Texte intégral
NISDirective_Oxford_Cybersecurity2023.pdf
Postprint Auteur (957.66 kB) Licence Creative Commons - Attribution
Télécharger

Tous les documents dans ORBilu sont protégés par une licence d'utilisation.

Envoyer vers



Détails



Mots-clés :
cybersecurity; incident reporting; NIS 2 Directive; NIS Directive; Cyber security; Cyber threats; European Commission; Incident reporting; NIS 2 directive; NIS directive; Risk-based approach; Security elements; Security incident; Computer Networks and Communications
Résumé :
[en] The NIS Directive and sector-specific cybersecurity regulations require the reporting of (security) incidents to supervisory authorities. Following the risk-based approach adopted in the NIS Directive, the NIS 2 Directive enlists as a basic security element the reporting of significant incidents that (i) have caused or (ii) are capable to cause harm, as well as (iii) notifying the service recipients of cyber threats. Although during the interinstitutional negotiations between the European Commission, the European Parliament, and the Council of the European there was consensus that the NIS Directive’s reporting framework needs to be reformed, views on the determination of what needs to be reported varied. This paper outlines and analyses the different concepts of a report-worthy significant incident that have been proposed during the legislative procedure for the NIS 2 Directive from a legal and policy perspective. Irrespective of further motives that may inhibit reporting, legal compliance is difficult to achieve where legal requirements are vague. In that regard, the difficulties to determine the reporting thresholds in the past and in the future are addressed. In consideration of the increased attack surface and threat scenario, it is argued that incidents where no harm has materialized should not be treated any different than incidents that have actually resulted in harm in order to acquire the envisaged full picture of the threat landscape and create value for business and society.
Disciplines :
Droit, criminologie & sciences politiques: Multidisciplinaire, généralités & autres
Auteur, co-auteur :
SCHMITZ-BERNDT, Sandra  ;  University of Luxembourg > Faculty of Law, Economics and Finance (FDEF) > Department of Law (DL)
Co-auteurs externes :
no
Langue du document :
Anglais
Titre :
Defining the reporting threshold for a cybersecurity incident under the NIS Directive and the NIS 2 Directive
Date de publication/diffusion :
2023
Titre du périodique :
Journal of Cybersecurity
eISSN :
2057-2093
Maison d'édition :
Oxford University Press
Volume/Tome :
9
Fascicule/Saison :
1
Peer reviewed :
Peer reviewed vérifié par ORBi
Organisme subsidiant :
Luxembourg National Research Fund
Subventionnement (détails) :
This work was supported by the Luxembourg National Research Fund (FNR) [grant number C18/IS/12639666/EnCaViBS/Cole], https://www.fnr.lu/projects/the-eu-nis-directive-enhancing-cybersecurityacross-vital-business-sectors-encavibs/ .
Jeu de données :
Disponible sur ORBilu :
depuis le 06 décembre 2023

Statistiques


Nombre de vues
104 (dont 1 Unilu)
Nombre de téléchargements
71 (dont 1 Unilu)

citations Scopus®
 
25
citations Scopus®
sans auto-citations
24
OpenCitations
 
1
citations OpenAlex
 
23
citations WoS
 
16

Bibliographie


Publications similaires



Contacter ORBilu