Information Security

Technology allows individuals and organizations access to more comprehensive and diverse information, but this access requires that electronic information, networks, data repositories, and data transmissions be adequately safeguarded. RAND has developed a large body of research focused on recognizing the potential threats to information security and data integrity, as well as implications for personal and institutional privacy.

Research conducted by: RAND Justice, Infrastructure, and Environment; RAND National Security Research Division; RAND Labor and Population; RAND Europe; RAND Arroyo Center; RAND Project AIR FORCE

Featured at RAND

Cybersecurity: Examining Challenges for the Future

Cyberspace is increasingly important for economic growth, openness, and democracy, but poor cybersecurity can make governments, businesses, and individuals open to cyber attack and cyber crime. RAND Europe conducts a range of research on the topic to advise policymakers.

All Items (63)

Report

Stocktaking study of military cyber defence capabilities in the European Union (milCyberCAP): Unclassified Summary — Jun 3, 2013

The objective of this study was to establish a high level understanding of cyber defence capabilities across EDA's participating Member States (pMS) to support progress toward a more consistent level of cyber defence capability across the EU.

Commentary

The Real Cyber Threat — May 21, 2013

close up of person using an ATM

The fact is that the United States needs to gear up for the coming era of cyber threats — and start by ensuring its financial flank is not catastrophically compromised, writes Mark Sparkman.

Report

Managing September 12th in Cyberspace: Presented before the House Foreign Affairs Committee, Subcommittee on Europe, Eurasia, and Emerging Threats — Mar 21, 2013

Testimony presented before the House Foreign Affairs Committee, Subcommittee on Europe, Eurasia, and Emerging Threats on March 21, 2013.

Report

Managing September 12th in Cyberspace — Mar 20, 2013

Red network cables

The U.S., while worried about a "9/11 in cyberspace," also ought to worry about what a "9/12 in cyberspace" would look like. The consequences of the reaction to a cyberattack could be more serious than the consequences of the original action itself.

Commentary

The European Cyber Security Strategy: Too Big to Fail? — Feb 8, 2013

The European Cyber Security Strategy is remarkable because it tries to co-ordinate policy across three areas whose competences and mandates were formerly very separate: law enforcement, the 'Digital Agenda', and defence, security, and foreign policy, writes Neil Robinson.

Report

Cyber-security threat characterisation: A rapid comparative analysis — Feb 5, 2013

The Swedish Center for Asymmetric Threat Studies asked RAND to investigate cyber-security within national defence and security strategies. The report presents research findings and is of interest to cyber-security practitioners and policymakers.

Commentary

Opening of the European Cybercrime Centre — a Journey Begins — Jan 11, 2013

While the opening of the EC3 at Europol, in line with our first-choice scenario, is very welcome, our study uncovered a range of risks that the EC3 will need to confront if it is to tackle cybercrime in a more coordinated and effective manner, writes Neil Robinson.

Blog

A Cybercrisis Is Inevitable — and Manageable — Jan 9, 2013

The United States can manage a cybercrisis by taking steps to reduce the incentives for other states to step into crisis, by controlling the narrative, understanding the stability parameters of the crises, and trying to manage escalation if conflicts arise.

Report

Cybercrises Can Be Managed with Multiple Strategies — Jan 4, 2013

The chances are growing that the United States will find itself in a crisis in cyberspace. Such crises can be managed by taking steps to reduce the incentives for other states to step into crisis, by controlling the narrative, understanding the stability parameters of the crises, and trying to manage escalation if conflicts arise from crises.

Report

Rapid Acquisition and Fielding for Information Assurance and Cyber Security in the Navy — Dec 21, 2012

The U.S. Navy requires an agile, adaptable acquisition process that can field new IT capabilities and services quickly. Successful rapid acquisition programs in the Army, Air Force, and Marine Corps offer lessons for the Navy as it develops its own streamlined processes for computer network defense and similar program areas.

Multimedia

Threats: Cyber Warfare — Dec 6, 2012

In this conference call, RAND senior management scientist Martin Libicki discusses cyber threats—including the declaration of cyber war by "hacktivist" group Anonymous against Israel—with RAND media relations director Jeffrey Hiday.

Journal Article

Data Protection Review: Impact on EU Innovation and Competitiveness — Dec 1, 2012

This document presents a rapid assessment of the innovation and competitiveness impacts of the measures affecting: automated processing; control of data processing; and data transfers.

Journal Article

Give and Take: Good Practice Guide for Addressing Network and Information Security Aspects of Cybercrime — Nov 1, 2012

A snapshot of the current status of ENISAs support for CERTs and LEAs, and includes good practice and recommendations for both communities.

Journal Article

Incentives and Barriers of the Cyber Insurance Market in Europe — Jun 28, 2012

ENISA conducted a study identifying possible causes inhibiting the cyber-insurance market in Europe and investigating incentives to kick-start its development.

Commentary

The Case for a Cyber-Security Safety Board: A Global View on Risk — Jun 18, 2012

Innovative approaches are needed to break the current stalemate of information sharing and to build a solid and reliable evidence base on the state of cyber-security, writes Neil Robinson.

Past Event

Information Sharing for Cyber-Security: Evidence from Europe — May 7, 2012

The U.S. House and Senate have numerous cyber-security proposals on the agenda to consider in the coming months. In this briefing, Neil Robinson presents evidence from empirical studies conducted in Europe regarding cyber-security and information exchange.

Report

Exploring How the EU Should Establish a Cybercrime Centre — Mar 28, 2012

After visiting EU high tech crime units, conducting interviews with stakeholders, and holding a scenario-based workshop, RAND Europe researchers determined that a European Cybercrime Centre hosted by Europol would bring together input from several different entities and drive a common approach to tackling cybercrime.

Journal Article

Cyber Policy: Institutional Struggle in a Transformed World — Jan 1, 2012

When it comes to cyber security, the world today is not the future that U.S. policy promised when cyber security first appeared on the national agenda well over a decade ago.

Report

The Characteristics of Cyberspace Pose Challenges to Those Who Seek to Defend It — Dec 22, 2011

It has become clear that Stuxnet-like worms pose a serious threat even to critical U.S. infrastructure and computer systems that are not connected to the Internet. However, defending against such attacks involves complex technological and legal issues.

My RAND ?

Saved Items

Recommended