G2TT
来源类型Report
规范类型报告
DOIhttps://doi.org/10.7249/RR557
来源IDRR-557-ME
Information Security and Data Protection Legal and Policy Frameworks Applicable to European Union Institutions and Agencies
Neil Robinson; Jan Gaspers
发表日期2014-04-01
出版年2014
页码71
语种英语
结论 Information Security and Data Protection Legal and Policy Frameworks Applicable to European Union Institutions and Agencies | RAND
摘要

This study reviews the legal and policy frameworks that govern the use of information and communications technology by European Union institutions and agencies in terms of the extent to which they account for information security and data privacy.

,

The first set of findings is presented in Chapter 2, which suggests that legacy equipment, path dependency when it comes to law and policymaking, and the natural conservativeness of a large and complex administrative machine may act as inhibitors to building greater information security in EU institutions and agencies.

,

Examining legal and policy frameworks that govern and regulate the use of ICT across EU institutions and agencies, Chapter 3 finds that the overall tone of EU policy and legal frameworks governing and regulating information security resonates with a model of security based on an internally secure organisation and insecure external environment, which appears to be inconsistent with the latest evolving canon of best practice concerning inter-organisational security. Moreover, key EU information security and data protection frameworks would appear poorly aligned with many modern models of technology service delivery and use, and the potential for security and privacy requirements to be built in from the start through Security Engineering or Privacy by Design principles appears to have little visibility in many EU legal and policy frameworks.

,

Mapping legal and policy frameworks, which cover policy domains that are unique to EU institutions and agencies, Chapter 4 reveals that there is a complex landscape of very specific information security and data protection requirements for different EU policy domains. The unique nature of some of these policy domains and their attendant security or privacy considerations seem difficult to reconcile with the appetite for more innovative types of technology provision. The Chapter concluded by highlighting that information security governance and data protection remains a challenge within many EU frameworks, which are often managed in a federated fashion through obligatory standards and rules set at a strategic EU level and implementation at the national level.

目录
  • Chapter One

    Introduction

  • Chapter Two

    European Union ICT requirements and infrastructure

  • Chapter Three

    Cross-cutting legal and policy frameworks applicable to EU institutions and agencies

  • Chapter Four

    Legal and policy frameworks covering policy domains unique to EU institutions and agencies

  • Chapter Five

    Conclusions

主题Cybersecurity ; European Union ; Science ; Technology ; and Innovation Policy
URLhttps://www.rand.org/pubs/research_reports/RR557.html
来源智库RAND Corporation (United States)
引用统计
资源类型智库出版物
条目标识符http://119.78.100.153/handle/2XGU8XDN/522447
推荐引用方式
GB/T 7714
Neil Robinson,Jan Gaspers. Information Security and Data Protection Legal and Policy Frameworks Applicable to European Union Institutions and Agencies. 2014.
条目包含的文件
文件名称/大小 资源类型 版本类型 开放类型 使用许可
RAND_RR557.pdf(881KB)智库出版物 限制开放CC BY-NC-SA浏览
1596651469457.jpg(8KB)智库出版物 限制开放CC BY-NC-SA缩略图
浏览
个性服务
推荐该条目
保存到收藏夹
导出为Endnote文件
谷歌学术
谷歌学术中相似的文章
[Neil Robinson]的文章
[Jan Gaspers]的文章
百度学术
百度学术中相似的文章
[Neil Robinson]的文章
[Jan Gaspers]的文章
必应学术
必应学术中相似的文章
[Neil Robinson]的文章
[Jan Gaspers]的文章
相关权益政策
暂无数据
收藏/分享
文件名: RAND_RR557.pdf
格式: Adobe PDF
文件名: 1596651469457.jpg
格式: JPEG

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。