论文标题

变得批评:了解云提供商的欧盟网络安全框架

Getting Critical: Making Sense of the EU Cybersecurity Framework for Cloud Providers

论文作者

Walden, Ian, Michels, Johan David

论文摘要

在本章中,我们回顾了欧盟网络安全监管框架如何影响云计算服务的提供商。我们将云服务的不断发展的监管处理作为欧盟数字经济的推动者,并质疑是否应将所有云服务视为关键基础设施。此外,我们研究了一般数据保护法规('GDPR')以及网络和信息系统指令('NISD')的保护和事件通知义务如何适用于云提供商。我们还考虑了NISD的拟议修订,并查看针对云提供商的新开发的自愿保证机制,包括行为和认证方案。我们得出的结论是,由于云提供商通常受到NISD和GDPR的约束以及多个监管机构的管辖权,因此他们面临不同的监管方法,这可能导致意外的结果和高遵守成本。

In this chapter, we review how the EU cybersecurity regulatory framework impacts providers of cloud computing services. We examine the evolving regulatory treatment of cloud services as an enabler of the EU's digital economy and question whether all cloud services should be treated as critical infrastructure. Further, we look at how the safeguarding and incident notification obligations under the General Data Protection Regulation ('GDPR') and the Network and Information Systems Directive ('NISD') apply to cloud providers. We also consider the proposed revision of the NISD and look at newly developed voluntary assurance mechanisms for cloud providers, including codes of conduct and certification schemes. We conclude that, since cloud providers are typically subject to both NISD and GDPR and to the jurisdiction of multiple regulators, they face divergent regulatory approaches, which can lead to unintended outcomes and high compliance costs.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源