Ruslan Rakhmetov, Security Vision
We continue the series of publications devoted to the body of knowledge on cybersecurity - Cybersecurity Body of Knowledge (CyBOK). Chapter 3 of this body of knowledge describes the main regulatory norms and principles of international law that are relevant to cybersecurity and can be applied in assessing cyber risks, managing information security, and investigating cyber incidents. Today is the eighth part of the review of Chapter 3 of CyBOK, which discusses the issues of the legal significance of electronic signatures and the responsibility of certificate publishers, some industry requirements for information security and export restrictions for cybersecurity technologies.
3.10. Electronic documents and identity authentication services
With the increasing level of digitalization, it has become necessary to transfer traditional methods of ensuring the authenticity and integrity of paper documents, such as signatures, seals, and indelible ink, to electronic form. The answer was security technologies, often based on PKI (Public Key Infrastructure), the use of which gave rise to a number of new legal issues: the legal significance of electronic documents, legal support for digital communications, rights and obligations in the provision and use of electronic services.
3.10.1. The permissibility of using electronic documents as evidence
The acceptability of electronic documents as evidence in court proceedings is now ubiquitous. Courts and legislators allow the use of surveillance tools designed to verify the authenticity and integrity of data. The legislation of various countries may require special procedures for the recognition of evidence in electronic form, but the rules generally coincide with the requirements for documented evidence of other types.
3.10.2. Form requirements and the risk of non-applicability of legal norms
The legal requirement for the form is expressed in the fact that some communication can be the object of law enforcement only if it had a predetermined form. Failure to comply with the applicable legal requirements for the form creates the risk that the subject (substance) of the communication will lose its legal force. Different countries apply different form requirements, which may include following the following approximate rules for recognizing documents as legally binding:
· Some legal notices must be sent in writing (in the form of a paper document);
· Certain contracts must be personally signed.;
· Some appeals to government agencies can only be issued in a special form.;
· Some clauses of contracts that affect the responsibility of one of the parties must be visually highlighted (for example, using capital letters, noticeable font, etc.) and signed by one of the parties.;
· The will must be drawn up in writing and signed in the presence of witnesses.;
· The document on the transfer of property rights must be signed in the presence of a government official, who then stamps the document.
Electronic trading systems that appeared in the 1960s circumvented some of the formal requirements for paperwork by signing a paper-based framework agreement that contained a list of rules for an electronic trading platform and their relationship to legal obligations. As a result, structured text messages in an electronic trading system became legally significant communications between trading participants. However, modern trading platforms impose much fewer formal requirements on trading participants (individuals and legal entities - sellers and buyers). In 1996, the UNCITRAL Model Law on Electronic Commerce was signed at the United Nations to facilitate the use of Internet sites for commercial purposes and eliminate legal obstacles by adopting a rule on the equivalence of paper and electronic documents. In turn, individual States have begun to enact laws providing a legal framework for online interaction, including trading, financial information and reporting, rules of court proceedings, etc. However, certain sensitive issues in many countries have not yet been translated into electronic format, including, for example, the transfer of property rights or inheritance of property. In Russia, however, most issues can be resolved through the portal of Public Services, which generates certain material risks and legal consequences for citizens: for example, through Public Services you can apply for a loan or sell real estate, which is why it is important to know about the possibility of self-prohibition of loans and a ban on actions with real estate without the personal participation of the owner.
3.10.3. Electronic signature and identity authentication services
The development of the e-commerce sector took place simultaneously with the proliferation of identity trust services, including those that issue digital certificates linking a certain person with his public key within the framework of a PKI infrastructure. With the development of such authentication services, two subjects of discussion have emerged: firstly, to what extent the legal significance of a handwritten signature on paper corresponds to a digital signature; secondly, what is the scope of the rights and obligations of persons serving and using such services. The first issue has been resolved in most countries where, under the agreed conditions, a digital signature is equivalent to a handwritten one: for example, in Russia, in accordance with the norms of the Federal Law "On Electronic Signatures" No. 63-FZ dated 04/06/2011, simple electronic signatures (PEP, a login-password pair, or a one-time SMS/application code) are used, unqualified electronic signatures (NEP, a pair of public-private keys and a certificate), as well as enhanced qualified electronic signatures (UKEP/CEP, issued by accredited certification centers, using certified SCSI). The issue of the rights and obligations of identity authentication services is already more complicated: it is necessary to determine the extent of the publisher's responsibility for incorrectly issued digital certificates and for failures in the verification system for their validity, for compromising the private key of the root certification authority, for violating the availability of the service and cyber incidents. In addition, it is important to define the rules of responsibility of the signatory, who may compromise his private key or lose access to the device for creating the signature. These issues are regulated by the industry legislation of a particular country and are considered for each specific use case (for example, when using electronic payment systems). When using certificate issuance systems, information exchange tasks arise between the entity receiving the certificate and the party trusting it, the signatory user and the certification authority issuing and confirming the validity of the certificate. The following standards have become general rules, which are presented in various legislative acts of some countries:
· the obligation to recognize digital signatures as legal evidence;
· mandatory recognition of digital signatures as the equivalent of a handwritten signature, provided that a number of technical requirements are met to ensure authenticity and integrity;
· Judges are advised not to refuse to recognize digital signatures as legally significant just because they have an electronic form.;
· the obligation of the certificate publisher to ensure due reliability and caution in relation to third parties who trust the issued certificate;
· assigning responsibility to the certificate publisher in the matter of confirming the reliability of operations (instead of the obligation of the injured party, who trusted the issued certificate, to independently prove the publisher's negligence);
· implementation of frameworks to improve technical and non-technical quality standards when issuing certificates;
· providing certificate publishers with the opportunity to limit their financial liability by specifying the applicable restrictions in text form in the body of the certificate itself;
· providing certificate publishers with the opportunity to exclude their liability by specifying exceptions in text form in the body of the certificate itself.
In addition to these principles, it is important to take into account the legal issue of trust in certificate publishers on the part of end users, including Internet browser users and employers who install corporate root certificates on employees' devices that provide authorized inspection of encrypted traffic.
3.10.4. Conflict of laws in the use of electronic signatures and identity authentication services
Legal conflicts arise when cross-border certificates are used, for example, if the certificate publisher is located in one State, the signatory is in another, and the person relying on the authenticity of the certificate is in a third. If we are talking about the transfer of rights to property that may already be physically located in the fourth State, then the norms of the law of this state will apply. In accordance with the EU law "Rome I" (Regulation 593/2008), a single enforcement mechanism for contractual obligations has been developed, which presupposes a preliminary choice of jurisdiction by the parties to the contract to resolve disputes, and in the case of claims from the buyer, a cross-border contract with the seller can be recognized as valid only if it is valid in the consumer's country of residence. Equally complex cases may arise, for example, in cases where the certificate publisher has used the principles of limiting his own liability in accordance with the rules of his country of residence, and a person who has suffered from the publisher's negligence or insecurity files a claim in another country (in which he is registered).
3.11. Other regulatory issues
3.11.1. Industry requirements and the NIS Directive
In addition to government agencies, various industry regulators are also developing their own requirements for cybersecurity. For example, standards on reporting and notification of incidents of unauthorized access to data may be applied in the financial sector, legal practice, and healthcare. The increasing level of cyber risks, especially for national critical infrastructures, has led to the development of various government requirements in the field of cybersecurity. For example, the EU has Directive 2016/1148 ("NIS") and Directive 2022/2555 ("NIS 2") on cybersecurity measures for network and information systems (abbreviated NIS). The requirements of the NIS 2 Directive apply to 18 sectors of critical infrastructure - energy, transport, water supply, healthcare, science, chemical and food industries, financial and digital sectors, and public administration. The provisions of the NIS 2 Directive include:
· responsibility of the direct managers of organizations for the fulfillment of the requirements of the Directive;
· the need to implement cyber risk management processes, cyber incidents, business continuity, and supply chain security (including service providers);
· sending notifications to the CSIRT regional center (Computer Security Incident Response Team, cyber Incident response team) within 24 hours after the incident was detected and within 72 hours after the initial incident analysis (indicating the danger and damage, listing indicators of compromise), with the provision of a final incident report no later than 1 month later;
· Penalties for non-compliance with the requirements of the NIS 2 Directive amount to 10 million euros or up to 2% of the violating company's annual turnover.
In the United States, the key regulations in the field of cybersecurity are:
· Federal Information Security Management Act (FISMA - Federal Information Security Management Act) of 2002 as amended in 2014;
· The Cybersecurity Information Exchange Act (CISA - Cybersecurity Information Sharing Act) of 2015;
· The Strengthening American Cybersecurity Act of 2022;
· The Law on the Procedure for Reporting Cyber Incidents in Critical Infrastructure (CIRCIA - Cyber Incident Reporting for Critical Infrastructure Act) of 2022.
3.11.2. Improving the cybersecurity of goods and services
The development of the Internet of Things and cloud services creates increased risks of violating the confidentiality of data of private buyers and companies, and regulatory authorities in various countries are developing legal rules for certifying compliance with information security standards for products and services. For example, the EU has a Cybersecurity Law (EU Cybersecurity Act, Regulation 2019/881), which is designed to improve the cybersecurity of the digital market and is a framework for voluntary certification for IT products, services, processes and assigning them one of three levels of reliability assessment. The United States has the Internet of Things Cybersecurity Improvement Act of 2020, under which the American NIST Institute is working on standardization to ensure key requirements of the law (vulnerability management and updates of IoT devices, prohibition of the use of hard-coded credentials, manufacturers' compliance with basic information security requirements).
3.11.3. Export restrictions for cybersecurity technologies
The export restriction regime applies to various dual-use products, including cryptographic functions as part of software and hardware. Until 2000, the United States applied fairly strict restrictions to products exported to other countries with built-in cryptographic functions. For example, the first stable releases of the Netscape Navigator Internet browser in 1995 were distributed in the United States and Canada in versions with full support for 1024-bit asymmetric RSA keys and the RC4 symmetric streaming encryption algorithm with 128-bit keys. The export versions supported only 512-bit RSA keys and 40-bit RC4 keys, which meant their low cryptographic strength. Finally, in 2000, a US court decision found that the ban on distributing the source code of programs and algorithms violated the principle of freedom of speech (the First Amendment to the US Constitution), and the government updated export requirements, which began to impose significantly less extensive restrictions on cryptographic functionality. However, at present, control over the export and import of cryptographic equipment remains in place: for example, the Center for Licensing, Certification and Protection of State Secrets The FSB of Russia registers notifications about the characteristics of products containing encryption (cryptographic) tools. Such permission must be obtained when importing various imported devices into the Russian Federation that implement certain cryptographic functions (for example, encrypting traffic). Export control of Russian dual-use goods and technologies, including cryptographic tools, is already carried out by the FSTEC of Russia.
3.11.4. Issues of protection of state secrets
Information security specialists working in government agencies may face the application of legal requirements for the protection of classified data or state secrets. Most often, these types of information are related to the defense capability of the state, the conduct of investigations and the work of law enforcement agencies, the safety of individuals, etc. Laws on the protection of state secrets can be used to classify research and development work of third parties, and information security specialists may be subject to these laws when working with certain cyber threat analytics (cyber intelligence) data. Violation of the requirements of the legislation on the protection of state secrets can have very serious consequences.