Standardisation as a regulatory measure:

Security enhancement

Dag Wiese Schartum

Standardisation is seen as one of several regulatory measures which may be applied to enhance information security. After a brief overview of available measures and their interrelation, emphasis will be de jure standards and possible interplay between legislation and standards, in particular standards issued by international standardisation organisations. To what extent should national statutory law exploit international standards within the area of information security, and how should this be performed? Questions concerning effective, democratic regulation, rule of law and predictability, as well as slow/rapid and technology neutral/specific regulatory response will be part of the discussion.