The case for regulating computer security applications

Roksana Moore · ePrints Soton (University of Southampton) · 2013

Computer security applications (CSAs) are essential for ensuring information security across insecure mediums such as the Internet, however despite the widespread reliance placed upon them they appear to receive no greater focus on quality than that of the broader software industry. In identifying information asymmetry as a leading factor behind substandard software quality, and by highlighting how private law and compensation are unable to otherwise remedy the situation, this paper puts forward a case for the regulation of CSA quality. Justified through legal and economic analysis it proposes a regulatory model that draws upon industry expertise to mandate the use of standardised software engineering methods to achieve quality assurance and build trust within CSA quality, as well as leveraging the proposed European Network and Information Security Directive to mandate the disclosure of defects and vulnerabilities within CSAs sold on the European Single Market and thereby dissolving information asymmetry accordingly.

Read the paper · More papers on PaperTik