Patching security governance: an empirical view of emergent governance mechanisms for cybersecurity

11Citations
Citations of this article
143Readers
Mendeley users who have this article in their library.

Abstract

Purpose: The issue of cybersecurity has been cast as the focal point of a fight between two conflicting governance models: the nation-state model of national security and the global governance model of multi-stakeholder collaboration, as seen in forums like IGF, IETF, ICANN, etc. There is a strange disconnect, however, between this supposed fight and the actual control over cybersecurity “on the ground”. This paper aims to reconnect discourse and control via a property rights approach, where control is located first and foremost in ownership. Design/methodology/approach: This paper first conceptualizes current governance mechanisms through ownership and property rights. These concepts locate control over internet resources. They also help us understand ongoing shifts in control. Such shifts in governance are actually happening, security governance is being patched left and right, but these arrangements bear little resemblance to either the national security model of states or the global model of multi-stakeholder collaboration. With the conceptualization in hand, the paper then presents case studies of governance that have emerged around specific security externalities. Findings: While not all mechanisms are equally effective, in each of the studied areas, the author found evidence of private actors partially internalizing the externalities, mostly on a voluntary basis and through network governance mechanisms. No one thinks that this is enough, but it is a starting point. Future research is needed to identify how these mechanisms can be extended or supplemented to further improve the governance of cybersecurity. Originality/value: This paper bridges together the disconnected research communities on governance and (technical) cybersecurity.

Author supplied keywords

Cite

CITATION STYLE

APA

van Eeten, M. (2017). Patching security governance: an empirical view of emergent governance mechanisms for cybersecurity. Digital Policy, Regulation and Governance , 19(6), 429–448. https://doi.org/10.1108/DPRG-05-2017-0029

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free