The Legal Aspects of Cybersecurity Vulnerability Disclosure: To the NIS 2 and Beyond

Logo poskytovatele

Varování

Publikace nespadá pod Pedagogickou fakultu, ale pod Právnickou fakultu. Oficiální stránka publikace je na webu muni.cz.
Autoři

VOSTOUPAL Jakub STUPKA Václav HARAŠTA Jakub KASL František LOUTOCKÝ Pavel MALINKA Kamil

Rok publikování 2024
Druh Článek v odborném periodiku
Časopis / Zdroj Computer Law & Security Review
Fakulta / Pracoviště MU

Právnická fakulta

Citace
www Odkaz na publikovaný text výsledku
Doi http://dx.doi.org/10.1016/j.clsr.2024.105988
Klíčová slova Bug bounty; Liability; Vulnerability disclosure; Ethical hacking; Penetration testing; Criminal law
Popis This paper focuses on the legal aspects of responsible vulnerability disclosure, bug bounty programs and legal risks associated with their implementation in the Czech Republic. Firstly, the authors introduce the basics of vulnerability disclosure procedures, identify different organisational models, and identify risks that may arise on the part of the organisation launching the bug bounty program or the hackers participating in it. The identified risks are divided into those arising from civil law, administrative law, and criminal law. For each identified risk, the authors then propose appropriate technical, organisation or legal solutions that can be applied to eliminate or reduce these risks. Nevertheless, the authors identified two areas that cannot be sufficiently mitigated through existing tools and laws and are likely to require legislative intervention – the matter of safeguarding the anonymity of reporters through confidentiality and the problematic ability to consent to the testing procedures by the public bodies.
Související projekty:

Používáte starou verzi internetového prohlížeče. Doporučujeme aktualizovat Váš prohlížeč na nejnovější verzi.