
doi: 10.2139/ssrn.2835126
Cybersecurity policy currently is views security as an exercise in risk prevention. Questions such as "how do we stop attackers" pervade the discourse both in technical cybersecurity planning and legal and organizational policymaking. This view of security – which departs from centuries of accepted practices in other areas of security – is beneficial to exactly one group: attackers.This is an extremely rough draft of what will become a book proposal I tentatively am calling "Redefining Cybersecurity." The central thesis is about cybersecurity policymaking and the technical practices those policies drive "on the ground." It argues that those policies drive these practices toward risk "prevention" styles of management when cybersecurity practice is more effective as risk management exercises (for efficiency, efficacy, and possibly normative reasons).What follows is a draft table of contents of the book project, and an early working draft of a chapter which focuses the thesis above. This draft chapter, Redefining Cybersecurity Policy, attempts to articulate much of the argument of the larger book. This work follows on from my PLSC paper in 2015, Cybersecurity Stovepiping, which provides an example case study of the failure of rigid risk prevention-based policymaking.
| selected citations These citations are derived from selected sources. This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | 0 | |
| popularity This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network. | Average | |
| influence This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | Average | |
| impulse This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network. | Average |
