Risks and Compliance with the EU's Core Cyber Security Legislation

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Ruohonen, Jukka, Nielsen, Jesper Løffler, Skórczynski, Jakub
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866914013523214336
author Ruohonen, Jukka
Nielsen, Jesper Løffler
Skórczynski, Jakub
author_facet Ruohonen, Jukka
Nielsen, Jesper Løffler
Skórczynski, Jakub
contents The European Union (EU) has long favored a risk-based approach to regulation. Such an approach is also used in recent cyber security legislation enacted in the EU. Risks are also inherently related to compliance with the new legislation. Objective: The paper investigates how risks are framed in the EU's five core cyber security legislative acts, whether the framings indicate convergence or divergence between the acts and their risk concepts, and what qualifying words and terms are used when describing the legal notions of risks. Method : The paper's methodology is based on qualitative legal interpretation and taxonomy-building. Results: The five acts have an encompassing coverage of different cyber security risks, including but not limited to risks related to technical, organizational, and human security as well as those not originating from man-made actions. Both technical aspects and assets are used to frame the legal risk notions in many of the legislative acts. A threat-centric viewpoint is also present in one of the acts. Notable gaps are related to acceptable risks, non-probabilistic risks, and residual risks. Conclusion: The EU's new cyber security legislation has significantly extended the risk-based approach to regulations. At the same time, complexity and compliance burden have increased. With this point in mind, the paper concludes with a few practical takeaways about means to deal with compliance and research it.
format Preprint
id arxiv_https___arxiv_org_abs_2508_21386
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Risks and Compliance with the EU's Core Cyber Security Legislation
Ruohonen, Jukka
Nielsen, Jesper Løffler
Skórczynski, Jakub
Cryptography and Security
Computers and Society
Software Engineering
The European Union (EU) has long favored a risk-based approach to regulation. Such an approach is also used in recent cyber security legislation enacted in the EU. Risks are also inherently related to compliance with the new legislation. Objective: The paper investigates how risks are framed in the EU's five core cyber security legislative acts, whether the framings indicate convergence or divergence between the acts and their risk concepts, and what qualifying words and terms are used when describing the legal notions of risks. Method : The paper's methodology is based on qualitative legal interpretation and taxonomy-building. Results: The five acts have an encompassing coverage of different cyber security risks, including but not limited to risks related to technical, organizational, and human security as well as those not originating from man-made actions. Both technical aspects and assets are used to frame the legal risk notions in many of the legislative acts. A threat-centric viewpoint is also present in one of the acts. Notable gaps are related to acceptable risks, non-probabilistic risks, and residual risks. Conclusion: The EU's new cyber security legislation has significantly extended the risk-based approach to regulations. At the same time, complexity and compliance burden have increased. With this point in mind, the paper concludes with a few practical takeaways about means to deal with compliance and research it.
title Risks and Compliance with the EU's Core Cyber Security Legislation
topic Cryptography and Security
Computers and Society
Software Engineering
url https://arxiv.org/abs/2508.21386