Image Database Export Citations


Unpacking the International Law on Cybersecurity Due Diligence: Lessons from the Public and Private Sectors

Show full item record

Type: Journal Article
Author: Shackelford, Scott; Russell, Scott; Kuehn, Andreas
Journal: Chicago Journal of International Law
Volume: 17
Date: 2016
URI: https://hdl.handle.net/10535/10243
Sector: Information & Knowledge
Subject(s): cybersecurity
international law
Abstract: "Although there has been a relative abundance of work done on exploring the contours of the law of cyber war, far less attention has been paid to defining a law of cyber peace applicable below the armed attack threshold. Among the most important unanswered questions is what exactly nations’ due diligence obligations are to one another and to their respective private sectors. The International Court of Justice (ICJ) has not yet explicitly considered this topic, though it has ruled in the Corfu Channel case that one country’s territory should not be 'used for acts that unlawfully harm other States.' But what steps exactly do nations and companies under their jurisdiction have to take under international law to secure their networks, and what of the rights and responsibilities of transit states? This Article reviews the arguments surrounding the creation of a cybersecurity due diligence norm and argues for a proactive regime that takes into account the common but differentiated responsibilities of public and private sector actors in cyberspace. The analogy is drawn to cybersecurity due diligence in the private sector and the experience of the 2014 National Institute of Standards and Technology (NIST) Framework to help guide and broaden the discussion."

Files in this item

Files Size Format View
SSRN-id2652446.pdf 620.3Kb PDF View/Open

This item appears in the following document type(s)

Show full item record