漏洞管理作为产品安全法规的合规要求——改变物联网中生产者责任和安全水平的游戏规则?

Roman Dickmann
{"title":"漏洞管理作为产品安全法规的合规要求——改变物联网中生产者责任和安全水平的游戏规则?","authors":"Roman Dickmann","doi":"10.1365/s43439-022-00064-9","DOIUrl":null,"url":null,"abstract":"<p><p>The article outlines the European Union (EU) regulation of information technology (IT) security in Internet of Things products from a consumer and end user perspective. It starts with civil law and the necessity to address security requirements and specifications in individual contractual terms. Data and consumer protection laws have not helped much, mainly because of missing definitions and levels of applicable security. Two new EU directives reforming the law of obligations may improve the situation for consumers since security is now a named quality requirement, especially for the sale of (digital) goods. Also introduced is the provision of security updates as a contractual duty. But both rule sets address only the traders, not the producers. This is different with the activation of clauses in the radio equipment directive, which sets IT security measures as requirements to be compliant for CE labeling. An important element is the introduction of a vulnerability management system. Details can be found in the draft of technical standard ETSI/EN 303645. The work concludes with a look at the EU's efforts regarding certification schemes and the interaction of all regulation elements, with more liability for insecure products plus the hope for effectiveness.</p>","PeriodicalId":73412,"journal":{"name":"International cybersecurity law review","volume":"4 1","pages":"21-37"},"PeriodicalIF":0.0000,"publicationDate":"2023-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9483465/pdf/","citationCount":"0","resultStr":"{\"title\":\"Vulnerability management as compliance requirement in product security regulation-a game changer for producers' liability and consequential improvement of the level of security in the Internet of Things?\",\"authors\":\"Roman Dickmann\",\"doi\":\"10.1365/s43439-022-00064-9\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<p><p>The article outlines the European Union (EU) regulation of information technology (IT) security in Internet of Things products from a consumer and end user perspective. It starts with civil law and the necessity to address security requirements and specifications in individual contractual terms. Data and consumer protection laws have not helped much, mainly because of missing definitions and levels of applicable security. Two new EU directives reforming the law of obligations may improve the situation for consumers since security is now a named quality requirement, especially for the sale of (digital) goods. Also introduced is the provision of security updates as a contractual duty. But both rule sets address only the traders, not the producers. This is different with the activation of clauses in the radio equipment directive, which sets IT security measures as requirements to be compliant for CE labeling. An important element is the introduction of a vulnerability management system. Details can be found in the draft of technical standard ETSI/EN 303645. The work concludes with a look at the EU's efforts regarding certification schemes and the interaction of all regulation elements, with more liability for insecure products plus the hope for effectiveness.</p>\",\"PeriodicalId\":73412,\"journal\":{\"name\":\"International cybersecurity law review\",\"volume\":\"4 1\",\"pages\":\"21-37\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2023-01-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9483465/pdf/\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"International cybersecurity law review\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1365/s43439-022-00064-9\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"International cybersecurity law review","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1365/s43439-022-00064-9","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

本文从消费者和最终用户的角度概述了欧盟(EU)对物联网产品中信息技术(IT)安全的监管。它从民法和在个别合同条款中解决安全要求和规范的必要性开始。数据和消费者保护法并没有起到多大作用,主要是因为缺乏适用的安全定义和级别。欧盟改革义务法的两项新指令可能会改善消费者的处境,因为安全现在是一项明确的质量要求,特别是对于(数字)商品的销售。还引入了作为合同义务提供安全更新的规定。但这两套规则都只针对贸易商,而不是生产者。这与无线电设备指令中的激活条款不同,该指令将IT安全措施设置为符合CE标签的要求。一个重要的因素是引入脆弱性管理系统。详细信息可参见技术标准ETSI/EN 303645草案。最后,研究了欧盟在认证计划方面的努力,以及所有监管要素之间的相互作用,对不安全产品承担更多责任,并希望提高有效性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Vulnerability management as compliance requirement in product security regulation-a game changer for producers' liability and consequential improvement of the level of security in the Internet of Things?

The article outlines the European Union (EU) regulation of information technology (IT) security in Internet of Things products from a consumer and end user perspective. It starts with civil law and the necessity to address security requirements and specifications in individual contractual terms. Data and consumer protection laws have not helped much, mainly because of missing definitions and levels of applicable security. Two new EU directives reforming the law of obligations may improve the situation for consumers since security is now a named quality requirement, especially for the sale of (digital) goods. Also introduced is the provision of security updates as a contractual duty. But both rule sets address only the traders, not the producers. This is different with the activation of clauses in the radio equipment directive, which sets IT security measures as requirements to be compliant for CE labeling. An important element is the introduction of a vulnerability management system. Details can be found in the draft of technical standard ETSI/EN 303645. The work concludes with a look at the EU's efforts regarding certification schemes and the interaction of all regulation elements, with more liability for insecure products plus the hope for effectiveness.

求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信