Information Security

Technology allows individuals and organizations access to more comprehensive and diverse information, but this access requires that electronic information, networks, data repositories, and data transmissions be adequately safeguarded. RAND has developed a large body of research focused on recognizing the potential threats to information security and data integrity, as well as implications for personal and institutional privacy.

Research conducted by: RAND Justice, Infrastructure, and Environment; RAND National Security Research Division; RAND Labor and Population; RAND Europe; RAND Arroyo Center; RAND Project AIR FORCE

Featured at RAND

Cybersecurity: Examining Challenges for the Future

Cyberspace is increasingly important for economic growth, openness, and democracy, but poor cybersecurity can make governments, businesses, and individuals open to cyber attack and cyber crime. RAND Europe conducts a range of research on the topic to advise policymakers.

All Items (62)

Report

Evaluation of DG SANCO data management practices: Final report — Sep 8, 2011

The EC Health and Consumer Protection Directorate-General commissioned RAND Europe to provide support in developing a comprehensive data strategy for DG SANCO that meets the needs of increasingly evidence-based policymaking in the future.

Journal Article

Toward a U.S. Army Cyber Security Culture — Sep 1, 2011

This article defines and explores the concept of cyber security culture within the context of the U.S. Army.

Report

Understanding the Security, Privacy, and Trust Aspects of Cloud Computing — Apr 6, 2011

Cloud computing is a model for enabling on-demand network access to a shared pool of computing resources—such as storage and applications—that can be rapidly provisioned with minimal management effort or service provider interaction. RAND Europe explored the security, privacy, and trust challenges that cloud computing poses.

Journal Article

Encryption and the Loss of Patient Data — Jan 1, 2011

Encryption is seen as a way to prevent malicious use of patient data, but there is no empirical evidence that it does.

Commentary

Stuxnet Is the World's Problem — Dec 9, 2010

The highly sophisticated Stuxnet computer worm suspected of sending Iran's nuclear centrifuges into self-destruction mode forces a difficult debate on whether longstanding firewalls in our country's democracy should be breached for the sake of national security, writes Isaac Porche.

Journal Article

Incentives and Challenges for Information Sharing in the Context of Network and Information Security — Sep 8, 2010

This report sets out findings from a research project into the barriers to and incentives for information sharing in the field of network and information security, in the context of peer-to-peer groups such as Information Exchanges (IE) and Information Sharing Analysis Centres (ISACs).

Report

Chaos or Control? — Mar 11, 2010

What is the role of government in a borderless internet world? RAND Europe assesses the implications for policy makers.

Journal Article

Security, at What Cost? — Jan 1, 2010

Much of the current debate concerning civil liberties and security is adversarial, and little robust research data informs these arguments.This paper outlines the results of a study that attempts to objectively understand the real privacy, liberty and security trade-offs made by individuals, so that policymakers can be better informed about the preferences of individuals with regard to these important issues.

News Release

U.S. Must Focus on Protecting Critical Computer Networks from Cyber Attack — Oct 8, 2009

Because it will be difficult to prevent cyber attacks on critical civilian and military computer networks by threatening to punish attackers, the United States must focus its efforts on defending these networks from cyber attack.

Commentary

The Cracks in Data Privacy — May 19, 2009

In the future, the EU will inevitably have to adjust its system of rules to cope with the evolving uses of personal data, globalization and international data flows, write Neil Robinson and Lorenzo Valeri.

Research Brief

Cybersecurity Economic Issues: Corporate Approaches and Challenges to Decisionmaking — Nov 18, 2008

This research brief addresses key cybersecurity concerns, such as protecting critical products and services and ensuring that software will work. It identifies how organizations perceive the importance of cybersecurity in making investment decisions.

Report

Network Technologies for Networked Terrorists: Assessing the Value of Information and Communication Technologies to Modern Terrorist Organizations — Sep 16, 2007

Terrorists use network technologies as they plan and stage attacks. This book explores the purpose and manner of the use of these technologies, their net effect, and security forces' possible responses.

News Release

Computer-Based Crime to Be Focus of Silicon Valley Forum with Industry, Law Enforcement and Research Leaders — Sep 13, 2007

Security experts from the technology industry, law enforcement and academia will outline what is needed to better measure and understand the effect of computer-based crime in the United States during a public forum Sept. 25 in Silicon Valley.

Commentary

RFID Security in the Workplace: Perk or Privacy? — Jun 1, 2007

RFID Security in the Workplace: Perk or Privacy?, in the Security World International.

Report

Conquest in Cyberspace: National Security and Information Warfare — May 12, 2007

Explores the potential for and limitations to information warfare, including its use in weapons systems and in command-and-control operations as well as in the generation of ''noise'' and how far ''friendly conquest'' in cyberspace extends.

News Release

RAND Launches National Computer Security Survey for Departments of Justice and Homeland Security — May 2, 2006

On behalf of the U.S. Departments of Justice and Homeland Security, the RAND Corporation is fielding the first national survey to measure the impact of cybercrime on American businesses.

Report

Handbook of Legal Procedures of Computer and Network Misuse in EU Countries — Mar 24, 2006

A comprehensive and up-to-date collection of information on rules, regulations and laws concerning computer misuse in all 25 European Union (EU) countries.

Commentary

President Obscured the Case for Spying — Feb 5, 2006

Published commentary by RAND staff: President Obscured the Case for Spying, in the San Francisco Chronicle.

Report

Dissuading Terror: Strategic Influence and the Struggle Against Terrorism — Jan 21, 2005

Analyzes past U.S. strategic influence campaigns and looks at how and in what circumstances such campaigns can best be applied to today’s struggle against terrorism.

Report

Engaging the Board: Corporate Governance and Information Assurance — Jan 1, 2004

Analyzes the relationship between corporate governance and information assurance

My RAND ?

Saved Items

Recommended