Image Database Export Citations


Defining Cybersecurity Due Diligence Under International Law: Lessons from the Private Sector

Show full item record

Type: Working Paper
Author: Shackelford, Scott; Russell, Scott; Kuehn, Andreas
Date: 2015
Agency: Kelley School of Business, Indiana University
Series: Kelley School of Business Research Paper No. 15-41
URI: https://hdl.handle.net/10535/10253
Sector: Information & Knowledge
Subject(s): cybersecurity
Abstract: "Although there has been a relative abundance of work done on exploring the contours of the law of cyber war, far less attention has been paid to defining a law of cyber peace applicable below the armed attack threshold. Among the most important unanswered questions is what exactly nations’ due diligence obligations are to their respective private sectors and to one another. The International Court of Justice (ICJ) has not explicitly considered the legality of cyber weapons to this point, though it has ruled in the Corfu Channel case that one country’s territory should not be 'used for acts that unlawfully harm other States.' But what steps exactly do nations and companies under their jurisdiction have to take under international law to secure their networks, and what of the rights and responsibilities of transit states? This Article reviews the arguments surrounding the creation of a cybersecurity due diligence norm and argues for a proactive regime that takes into account the common but differentiated responsibilities of public- and private-sector actors in cyberspace. The analogy is drawn to cybersecurity due diligence in the private sector and the experience of the 2014 National Institute of Standards and Technology (NIST) Framework to help guide and broaden the discussion."

Files in this item

Files Size Format View
SSRN-id2594323.pdf 321.4Kb PDF View/Open

This item appears in the following document type(s)

Show full item record