Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Privacy Law (28)
- Science and Technology Law (26)
- Computer Law (24)
- National Security Law (18)
- International Law (17)
-
- Intellectual Property Law (11)
- Communications Law (8)
- Law and Society (8)
- Physical Sciences and Mathematics (8)
- Computer Sciences (7)
- Information Security (7)
- Consumer Protection Law (6)
- Social and Behavioral Sciences (6)
- Comparative and Foreign Law (5)
- Engineering (5)
- Human Rights Law (5)
- Law and Politics (5)
- Military, War, and Peace (5)
- Commercial Law (4)
- Computer Engineering (4)
- Criminal Law (4)
- First Amendment (4)
- Health Law and Policy (4)
- Legislation (4)
- Administrative Law (3)
- Banking and Finance Law (3)
- Business (3)
- Business Organizations Law (3)
- Institution
-
- Maurer School of Law: Indiana University (11)
- The Catholic University of America, Columbus School of Law (6)
- American University Washington College of Law (4)
- Boston University School of Law (3)
- University of Michigan Law School (3)
-
- City University of New York (CUNY) (2)
- Marquette University Law School (2)
- Penn State Dickinson Law (2)
- Roger Williams University (2)
- Singapore Management University (2)
- St. John's University School of Law (2)
- Texas A&M University School of Law (2)
- The University of Akron (2)
- University of Maryland Francis King Carey School of Law (2)
- University of Miami Law School (2)
- University of New Hampshire (2)
- Barry University School of Law (1)
- Brooklyn Law School (1)
- California Western School of Law (1)
- Cornell University Law School (1)
- DePaul University (1)
- Kennesaw State University (1)
- Liberty University (1)
- Loyola Marymount University and Loyola Law School (1)
- Mitchell Hamline School of Law (1)
- New York Law School (1)
- Northwestern Pritzker School of Law (1)
- Pace University (1)
- Pepperdine University (1)
- Purdue University (1)
- Publication Year
- Publication
-
- Catholic University Journal of Law and Technology (6)
- Faculty Scholarship (6)
- Articles by Maurer Faculty (4)
- Law Faculty Scholarship (4)
- Indiana Law Journal (3)
-
- University of Michigan Journal of Law Reform (3)
- Akron Law Review (2)
- Indiana Journal of Global Legal Studies (2)
- Marquette Law Review (2)
- St. John's Law Review (2)
- 2018–2019 Flyers (1)
- American University Business Law Review (1)
- American University International Law Review (1)
- Articles, Book Chapters, & Popular Press (1)
- Barry Law Review (1)
- Books and Book Chapters (1)
- Brooklyn Law Review (1)
- Centre for AI & Data Governance (2019-2025) (1)
- Christiana Ochoa (7/22-10/22 Acting; 11/2022-) (1)
- Cornell International Law Journal (1)
- Cybaris® (1)
- DePaul Magazine (1)
- Dickinson Law Review (2017-Present) (1)
- Faculty Publications (1)
- Georgia Journal of Law & Technology (1)
- Homeland Security Publications (1)
- Joint PIJIP/TLS Research Paper Series (1)
- Journal of Business & Technology Law (1)
- Journal of Cybersecurity Education, Research and Practice (1)
- Keep Up With the Latest News from the Law School (blog) (1)
- Publication Type
Articles 1 - 30 of 78
Full-Text Articles in Internet Law
Hacking With Uncle Sam: Imagining A Public-Private Partnership For Active Cyber Defense, Jonathan Coleman
Hacking With Uncle Sam: Imagining A Public-Private Partnership For Active Cyber Defense, Jonathan Coleman
Catholic University Journal of Law and Technology
Federal law makes no distinction between "good" and "bad" hackers—the Computer Fraud and Abuse Act criminalizes hacking by a private citizen in any form. While an anti-hacking statute is necessary to deter and punish cybercrime, the current law prohibits private entities from "hacking back" or, more precisely, from engaging in active defensive measures in response to a cyberattack. If these measures were legalized, they could allow private entities to assist law enforcement and reduce the financial and reputational costs of a cyber incident. Absent a change in the law, private entities are dependent on law enforcement to provide active cyber …
A Proposed Tort To Address The Negligent Enablement Of Cloud Data Breaches, Michael L. Rustad
A Proposed Tort To Address The Negligent Enablement Of Cloud Data Breaches, Michael L. Rustad
American University Business Law Review
[INTRODUCTION] The term “cloud computing” means the remote storage of software applications, tools, and data accessed through the internet. Cloud customers enter into subscription agreements with providers who give 24/7, on-demand, as-needed access to software, storage, and networking services owned and managed by providers through a web browser. “Many businesses are transitioning to the cloud for data storage, remote work, and collaboration.” Cloud providers operate their software as a software-as-a-service (“SaaS”) model, under which customers pay a subscription fee to access the software. Netflix and Amazon Prime Video are examples of subscription services that deliver television programs and videos through …
The Sec Proposed Cybersecurity Infrastructure Rules And New Disclosure Requirements, Neal F. Newman, Lawrence J. Trautman, Brian Elzweig
The Sec Proposed Cybersecurity Infrastructure Rules And New Disclosure Requirements, Neal F. Newman, Lawrence J. Trautman, Brian Elzweig
Faculty Scholarship
In addition to regulation of securities market issuers, the Securities & Exchange Commission (SEC) is also responsible for regulation of those entities that provide the networks, either electronic or physical, that enable the functioning of our securities markets. On February 9, 2022, the Commission published a Release for Cybersecurity Risk Management for Investment Advisers, Registered Investment Companies, and Business Development Companies containing proposals that, if adopted, would establish a new cybersecurity incident reporting and disclosure regime and require registered investment advisers (“advisers”) and investment companies (“funds”) to implement policies and procedures designed to address cyber risks. The comment period for …
The Legal Cybersecurity Crisis: Potential Resolutions And Artificial Intelligence Implications, Ava R. Warrick
The Legal Cybersecurity Crisis: Potential Resolutions And Artificial Intelligence Implications, Ava R. Warrick
Senior Honors Theses
As cybersecurity becomes more relevant in the digital age, law firms have overlooked protections from cyberattacks, and this neglect has led to irreversible client data breaches. This thesis sought to investigate cybersecurity vulnerabilities in law firms and to theorize potential solutions using a literature review methodology. The research questions for this project are: What are the most effective cybersecurity protections for United States law firms, and should those cybersecurity protections utilize AI-based systems? In response, this thesis posits three claims. First, the central factors that contribute to inadequate law firm cybersecurity are as follows: lack of governmental oversight over legal …
Gendering The New International Convention On Cybercrimes And New Norms On Artificial Intelligence And Emerging Technologies, Rangita De Silva De Alwis
Gendering The New International Convention On Cybercrimes And New Norms On Artificial Intelligence And Emerging Technologies, Rangita De Silva De Alwis
Washington Journal of Law, Technology & Arts
The trifecta of the Digital Global Compact (2024), the UN General Assembly Resolution on AI for Sustainable Development (2024) and the new Cyber Crime Convention (2025) come at a time of what seems to be an inexorable march of new technology. It is also at a time of transborder disruption caused by data breaches and cyber threats, that binding international norms can respond to global challenge. However, it must be emphasized that digital violence, developer bias, and data bias are not new phenomena, they have existed since the origins of the internet. Data that is used to train machine-learning algorithms …
Dean's Desk: Finding New Ways To Help Diminish Cybersecurity Threats, Christiana Ochoa
Dean's Desk: Finding New Ways To Help Diminish Cybersecurity Threats, Christiana Ochoa
Christiana Ochoa (7/22-10/22 Acting; 11/2022-)
In an era when cyberattacks can paralyze hospitals, disrupt elections, and compromise the privacy of millions, the need for innovative cybersecurity and privacy protections has never been more urgent. But it is not just a question of new technologies; strong data protection depends as much on motivating people and organizations to use those technologies and make wise choices to diminish data risk.
The Indiana University Maurer School of Law has spent more than 30 years answering cybersecurity and privacy challenges with a distinctive, holistic approach: an interdisciplinary, human-centered legal education that equips students to lead at the intersection of technology, …
"Reasonable [Cybersecurity] Measures" For Digital Trade Secrets: Lessons From Marketing, Raj Sachdev
"Reasonable [Cybersecurity] Measures" For Digital Trade Secrets: Lessons From Marketing, Raj Sachdev
Law Faculty Scholarship
The loss of digital trade secrets in marketing and beyond, often the source of competitive advantage, can have disastrous impacts on brands and companies. Bad actors want to get their digital hands on digital trade secrets, and other actors and factors may also cause a risk to their secrecy. The Defend Trade Secrets Act (DTSA) makes clear that “reasonable measures” must be taken to maintain the secrecy of a trade secret. Likewise, the Uniform Trade Secrets Act (UTSA) requires “reasonable steps.” However, in a digital age, the definition of what is “reasonable” is even more unclear than in offline settings. …
Understanding Cyber Risk: Unpacking And Responding To Cyber Threats Facing The Public And Private Sectors, Lawrence J. Trautman, Scott Shackelford, Brian Elzweig, Peter Ormerod
Understanding Cyber Risk: Unpacking And Responding To Cyber Threats Facing The Public And Private Sectors, Lawrence J. Trautman, Scott Shackelford, Brian Elzweig, Peter Ormerod
University of Miami Law Review
Cyberattacks, data breaches, and ransomware continue to pose major threats to businesses, governments, and health and educational institutions worldwide. Ongoing successful instances of cybercrime involve sophisticated attacks from diverse sources such as organized crime syndicates, actors engaged in industrial espionage, nation-states, and even lone wolf actors having relatively few resources. Technological innovation continues to outpace the ability of U.S. law to keep pace, though other jurisdictions including the European Union have been more proactive. Nation-state and international criminal group ransomware attacks continue; Sony’s systems were hacked by a ransomware group; MGM Resorts disclosed that recovery from their September 2023 hack …
Zero Progress On Zero-Days: How The Last Ten Years Created The Modern Spyware Market, Mailyn Fidler
Zero Progress On Zero-Days: How The Last Ten Years Created The Modern Spyware Market, Mailyn Fidler
Law Faculty Scholarship
Spyware makes surveillance simple. The last ten years have seen a global market emerge for ready-made software that lets governments surveil their citizens and foreign adversaries alike and to do so more easily than when such work required tradecraft. The last ten years have also been marked by stark failures to control spyware and its precursors and components. This Article accounts for and critiques these failures, providing a socio-technical history since 2014, particularly focusing on the conversation about trade in zero-day vulnerabilities and exploits. Second, this Article applies lessons from these failures to guide regulatory efforts going forward. While recognizing …
Cybercrime Scenarios, Thomas E. Kadri, Samuel Won
Cybercrime Scenarios, Thomas E. Kadri, Samuel Won
Books and Book Chapters
Technological innovation alters the commission, definition, and conception of crime. In some cases, computers, social media, and the internet have made existing criminal activity harder to detect or easier to commit. In other cases, they’ve created new forms of criminal activity that challenge longstanding views about the permissibility and punishment of human behavior. Through a range of cybercrime scenarios, this book will address topics such as digital privacy, free speech, terrorism, cybersecurity, image-based sexual abuse, stalking, harassment, doxing, and identity theft.
Navigating The Intersection Of Regulation And Vulnerability: The Evolving Landscape Of Cybersecurity In Investment Management And The Imperative For Comprehensive Safeguards, Giezi Rios
Catholic University Journal of Law and Technology
No abstract provided.
Link Tank
DePaul Magazine
A new JD certificate program in information technology, cybersecurity and data privacy provides DePaul University students with proficiency in both law and tech.
Integrating Nist And Iso Cybersecurity Audit And Risk Assessment Frameworks Into Cameroonian Law, Bernard Ngalim
Integrating Nist And Iso Cybersecurity Audit And Risk Assessment Frameworks Into Cameroonian Law, Bernard Ngalim
Journal of Cybersecurity Education, Research and Practice
This paper reviews cybersecurity laws and regulations in Cameroon, focusing on cybersecurity and information security audits and risk assessments. The importance of cybersecurity risk assessment and the implementation of security controls to cure deficiencies noted during risk assessments or audits is a critical step in developing cybersecurity resilience. Cameroon's cybersecurity legal framework provides for audits but does not explicitly enumerate controls. Consequently, integrating relevant controls from the NIST frameworks and ISO Standards can improve the cybersecurity posture in Cameroon while waiting for a comprehensive revision of the legal framework. NIST and ISO are internationally recognized as best practices in information …
Ohio's Data Protection Act And/As A Process-Based Approach To "Reasonable" Security, Brian Ray
Ohio's Data Protection Act And/As A Process-Based Approach To "Reasonable" Security, Brian Ray
Akron Law Review
This essay argues that the ODPA [Ohio Data Protection Act], which has become a model for similar laws and legislative proposals in several other states, in effect creates a process-based standard for cybersecurity. It does so by incorporating the risk-based approach used by the listed cybersecurity frameworks as the defacto standard for reasonable security for organizations seeking to qualify for the Act’s affirmative defense. This article summarizes the ODPA and then explains the risk-based approach of the cybersecurity frameworks it incorporates. It then argues that this risk-based approach in effect establishes a process-based definition of reasonable security and explains why …
Security In The Digital Age, Michael Gentithes
Security In The Digital Age, Michael Gentithes
Akron Law Review
Rapidly evolving technology allows governments and businesses to elevate our collective well-being in ways we could not have imagined just decades ago. Data is now a resource that governments and businesses alike can mine to address the world’s needs with greater efficiency, accuracy, and flexibility. But evolving technology and advanced data analytics also come with risk. New digital capabilities also create new means for nefarious actors to infiltrate the complex technological systems at the heart of nearly all of our daily activities. Just as new digital tools emerge to offer unique goods and services, new tools allow wrongdoers to invade …
Two Visions Of Digital Sovereignty, Sujit Raman
Two Visions Of Digital Sovereignty, Sujit Raman
Joint PIJIP/TLS Research Paper Series
No abstract provided.
Blockchain Safe Harbor? Applying The Lessons Learned From Early Internet Regulation, Amy Cyphert, Sam Perl
Blockchain Safe Harbor? Applying The Lessons Learned From Early Internet Regulation, Amy Cyphert, Sam Perl
Marquette Law Review
It has been more than a quarter century since Congress enacted twin safe harbor provisions to help protect and encourage the growth of a nascent internet by removing some liability and regulatory uncertainty. Today, there are calls for a similar safe harbor provision for blockchain, the technology behind cryptocurrencies and smart contracts. What lessons have we learned from the implementation of the internet safe harbor provisions, Section 230 of the Communications Decency Act, and Section 512 of the Digital Millennium Copyright Act? This Article charts the history of those provisions and their judicial construction over the decades. It also examines …
Cyberattacks: An Underlying Condition Exacerbated By The Covid-19 Pandemic, Kaitlyn Palmeter
Cyberattacks: An Underlying Condition Exacerbated By The Covid-19 Pandemic, Kaitlyn Palmeter
The Journal of Business, Entrepreneurship & the Law
COVID-19 continues to change the world in unforeseen ways triggering a new era of corporate data breaches. This article will illustrate how cyberattacks have increased in severity during the pandemic, how current laws and government officials are trying to evolve with the current threats and technology, how victims of cyberattacks risk sanctions and potential lawsuits, and concludes by suggesting solutions throughout to increase Cybersecurity.
Legal Implications Of A Ubiquitous Metaverse And A Web3 Future, Jon M. Garon
Legal Implications Of A Ubiquitous Metaverse And A Web3 Future, Jon M. Garon
Marquette Law Review
The metaverse is understood to be an immersive virtual world serving as the locus for all forms of work, education, and entertainment experiences. Depicted in books, movies, and games, the metaverse has the potential not just to supplement real-world experiences but to substantially supplant them. This Article explores the rapid emergence and evolution of the Web3 technologies at the heart of the metaverse movement. Web3 itself is a paradigmatic shift in internet commerce.
Small Business Cybersecurity: A Loophole To Consumer Data, Matthew R. Espinosa
Small Business Cybersecurity: A Loophole To Consumer Data, Matthew R. Espinosa
The Scholar: St. Mary's Law Review on Race and Social Justice
Small businesses and small minority owned businesses are vital to our nation’s economy; therefore legislation, regulation, and policy has been created in order to assist them in overcoming their economic stability issues and ensure they continue to serve the communities that rely on them. However, there is not a focus on regulating nor assisting small businesses to ensure their cybersecurity standards are up to par despite them increasingly becoming a victim of cyberattacks that yield high consequences. The external oversight and assistance is necessary for small businesses due to their lack of knowledge in implementing effective cybersecurity policies, the fiscal …
The Rise Of 5g Technology: How Internet Privacy And Protection Of Personal Data Is A Must In An Evolving Digital Landscape, Justin Rabine
The Rise Of 5g Technology: How Internet Privacy And Protection Of Personal Data Is A Must In An Evolving Digital Landscape, Justin Rabine
Catholic University Journal of Law and Technology
No abstract provided.
Book Review: This Is How They Tell Me The World Ends: The Cyberweapons Arms Race (2020) By Nicole Perlroth, Amy C. Gaudion
Book Review: This Is How They Tell Me The World Ends: The Cyberweapons Arms Race (2020) By Nicole Perlroth, Amy C. Gaudion
Dickinson Law Review (2017-Present)
No abstract provided.
Platforms, Encryption, And The Cfaa: The Case Of Whatsapp V Nso Group, Jonathon Penney, Bruce Schneier
Platforms, Encryption, And The Cfaa: The Case Of Whatsapp V Nso Group, Jonathon Penney, Bruce Schneier
Articles, Book Chapters, & Popular Press
End-to-end encryption technology has gone mainstream. But this wider use has led hackers, cybercriminals, foreign governments, and other threat actors to employ creative and novel attacks to compromise or workaround these protections, raising important questions as to how the Computer Fraud and Abuse Act (CFAA), the primary federal anti-hacking statute, is best applied to these new encryption implementations. Now, after the Supreme Court recently narrowed the CFAA’s scope in Van Buren and suggested it favors a code-based approach to liability under the statute, understanding how best to theorize sophisticated code-based access barriers like end-to-end encryption, and their circumvention, is now …
Indiana Law’S Lubin, Sun Help Advise Kosovo Government On Country’S Cybersecurity Act, James Owsley Boyd
Indiana Law’S Lubin, Sun Help Advise Kosovo Government On Country’S Cybersecurity Act, James Owsley Boyd
Keep Up With the Latest News from the Law School (blog)
No abstract provided.
Securities Law: Overview And Contemporary Issues, Neal Newman, Lawrence J. Trautman
Securities Law: Overview And Contemporary Issues, Neal Newman, Lawrence J. Trautman
Faculty Scholarship
This is not your grandfather’s SEC anymore. Rapid technological change has resulted in novel regulatory issues and challenges, as law and policy struggles to keep pace. The U.S. Securities and Exchange Commission (SEC) reports that “the U.S. capital markets are the deepest, most dynamic, and most liquid in the world. They also have evolved to become increasingly fast and extraordinarily complex. It is our job to be responsive and innovative in the face of significant market developments and trends.” With global markets increasingly interdependent and interconnected and, “as technological advancements and commercial developments have changed how our securities markets operate, …
A Deep Dive Into Technical Encryption Concepts To Better Understand Cybersecurity & Data Privacy Legal & Policy Issues, Anthony Volini
A Deep Dive Into Technical Encryption Concepts To Better Understand Cybersecurity & Data Privacy Legal & Policy Issues, Anthony Volini
Georgia Journal of Law & Technology
Lawyers wishing to exercise a meaningful degree of leadership at the intersection of technology and the law could benefit greatly from a deep understanding of the use and application of encryption, considering it arises in so many legal scenarios. For example, in FTC v. Wyndham1 the defendant failed to implement nearly every conceivable cybersecurity control, including lack of encryption for stored data, resulting in multiple data breaches and a consequent FTC enforcement action for unfair and deceptive practices. Other examples of legal issues requiring use of encryption and other technology concepts include compliance with security requirements of GLBA & HIPAA, …
What's The Harm? Federalism, The Separation Of Powers, And Standing In Data Breach Litigation, Grayson Wells
What's The Harm? Federalism, The Separation Of Powers, And Standing In Data Breach Litigation, Grayson Wells
Indiana Law Journal
This Comment will argue that the Supreme Court should analyze standing in data breach litigation under a standard that is deferential to state statutory and common law. Specifically, federal standing analysis should look to state law when determining whether an injury is concrete such that the injury-in-fact requirement is met. Some argue that allowing more data breach cases to proceed to the merits could lead to an explosion of successful litigation and settlements, burdening the federal courts and causing economic losses for the breached businesses. These concerns may be valid. But if state law provides a remedy to the harm …
Eu Privacy Law And U.S. Surveillance: Solving The Problem Of Transatlantic Data Transfers, Peter Margulies
Eu Privacy Law And U.S. Surveillance: Solving The Problem Of Transatlantic Data Transfers, Peter Margulies
Law Faculty Scholarship
No abstract provided.
Self-Defense To Cyber Force: Combatting The Notion Of ‘Scale And Effect', Thomas Eaton
Self-Defense To Cyber Force: Combatting The Notion Of ‘Scale And Effect', Thomas Eaton
American University International Law Review
No abstract provided.
Cybersecurity-Cybercrime-The Legal Environment, Amy J. Ramson
Cybersecurity-Cybercrime-The Legal Environment, Amy J. Ramson
Open Educational Resources
This presentation covers the legal environment of cybercrime to date. It addresses: the challenges of law enforcement; federal government vs. sate jurisdiction of cybercrime; law enforcement department and agencies which handle cybercrime; criminal statutes and privacy statutes.