REVIEW 2 major objections 5 minor 1 cited by
Risks and Compliance with the EU's Core Cyber Security Legislation
T0 review · 2 major / 5 minor · reviewed 2026-08-05 · deepseek-v4-flash
Pith's one-line read Across the CSA, GDPR, CRA, CER, and NIS2, the EU's core cyber security laws all frame risk as probability times impact and cover technical, organizational, human, and national security — but none acknowledges acceptable, residual, or non-pr
desk verdict Useful map of how five EU cyber laws frame risk; trust the positive taxonomy, treat the absence claims as hypotheses until a full-text check. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The paper's carrying object is a six-dimension taxonomy of risk framings, built from the conventional risk-analysis vocabulary: the formula 'risk = probability of occurrence of a threat × impact of a threat', and the paired definitions of acceptable risk (a risk understood and tolerated by a system's user, operator, owner, or accreditor) and residual risk (the portion of an original risk that remains after countermeasures have been applied). The taxonomy's six dimensions — viewpoint, man-made versus other origins, probabilistic versus non-probabilistic, acceptable/residual recognition, security concept, and development versus operations — do the analytical work: each act is mapped onto the c
What would settle it
Search the full text of the five acts and their recitals for 'residual risk', 'acceptable risk', 'risk tolerance', 'risk appetite', or equivalent formulations in EU languages; a single provision instructing that a risk analysis document what risk remains after mitigation, or setting a tolerable risk threshold, falsifies the claimed gap. Separately, the all-probabilistic claim falls if any act defines or uses risk without reference to likelihood — for instance, a threshold- or impact-only definition such as the CER's 'significant disruptive effect' criteria applied without probability, or a saf
Extended reading notes
Core claim
On the paper's own terms, the central claim is that the EU's five core cyber security acts form a convergent, risk-based regulatory regime with specific missing pieces. Interpreting each act against six taxonomy dimensions — risk viewpoint (threat-, asset-, or system-centric), man-made versus other risks, probabilistic versus non-probabilistic framing, recognition of acceptable/residual risks, security concept (technical, organizational, human, national), and development versus operations — the paper finds that all five laws share the conventional probabilistic understanding of risk, that their coverage spans all four security concepts, and that three risk notions are absent everywhere: acce
Load-bearing premise
The gap findings (no acceptable, residual, or non-probabilistic risks anywhere) rest on the authors' selective reading of only 'notable risk-based aspects' of each act; if a provision they did not single out, or an interpretation via recitals, case law, or contextual reading (all excluded), acknowledges these concepts, the claimed gaps would be artifacts of the selection.
Editorial extensions
If this is right
- Probability/impact risk matrices are a defensible common method across all five acts, since each law operates with the same probabilistic risk formula.
- Organizations covered by several acts (e.g., a networked product processing personal data for a critical-sector customer) can legally consolidate overlapping obligations into a single risk analysis spanning the GDPR, CRA, CER, and NIS2.
- Because no act recognizes acceptable or residual risk, nothing in the legislation itself says how much risk may remain after countermeasures; this will be settled by enforcement, standards, and future delegated acts.
- The paper's taxonomy is explicitly provisional: new implementing and delegated acts may shift where each law maps, so the convergence-and-gap picture should be revisited as the regime develops.
- The shared gaps count as a form of convergence: the five acts collectively decline to legislate non-probabilistic, acceptable, and residual risks, which is itself a structural feature of the regime.
Reading between the lines
- A full-text, corpus-level search of the five acts and their recitals for residual-risk and acceptable-risk vocabulary (including equivalents in other EU languages) would test whether the paper's qualitative absence findings hold at scale; its method deliberately reads only 'notable' provisions, so a systematic scan could either confirm the gaps or reveal mentions the selection missed.
- If the gaps are real, a small regulatory fix suggests itself: an implementing or delegated act under the CRA or NIS2 could require documenting residual risk after applying the essential security requirements, filling the gap without new primary legislation.
- The paper's reading of the CSA's attacker-skill tiers as an implicit residual-risk scale suggests a bridge between certification assurance levels and the CRA's essential requirements that the paper does not itself build: an assurance level could serve as a rough measure of how much residual risk remains for a certified product.
- Applying the same six-dimension taxonomy to neighbouring acts (DORA, the Digital Services Act, the AI Act), which the paper names only as overlaps, would show whether the convergent probabilistic risk concept extends beyond the five core acts into sectoral and technology-specific legislation.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper interprets the risk concepts in five EU cyber security legislative acts (CSA, GDPR, CRA, CER, NIS2) using a six-dimensional taxonomy derived from risk-management literature. It reports that the acts converge on a probabilistic, asset/system-centric framing of risk, cover technical, organizational, human, and national security to varying degrees, and contain two notable gaps: acceptable/residual risks and non-probabilistic risks. It also analyzes qualifying words that tighten or relax legal obligations and concludes with practical compliance recommendations. The main evidence is a qualitative reading of selected articles, summarized in Table 2.
Significance. If the results are correct, the paper provides a useful mapping for requirements and compliance engineering and contributes to the literature on risk-based regulation in the EU. Its positive classifications are often grounded in quoted provisions, and the authors are transparent about the qualitative, selective nature of the analysis. However, the paper's most novel negative findings — the absence of acceptable/residual risks and of non-probabilistic risks — are not supported by the corpus actually analyzed. This is a correctable but currently load-bearing weakness.
major comments (2)
- [Section 3 / Table 2 / Section 4.1] The negative claims in Table 2 (Dimensions 3b and 4a) and Section 4.1 ('none of the laws mention or otherwise discuss explicitly'; 'All laws rely on the conventional probabilistic understanding') assert absence across entire legal instruments. However, the analysis is explicitly selective: Section 3 states that only 'notable risk-based aspects' are considered and 'not everything about the laws is covered'; Section 2.2 excludes contextual interpretation and case law; footnote 3 lists further excluded risk-based details. Because no full-text search for 'acceptable risk', 'residual risk', 'remaining risk', or 'non-probabilistic risk' equivalents is reported, the P=0 entries may be artifacts of the selection. This is load-bearing because the abstract and conclusion present these gaps as the main novel finding. The authors should either perform a systematic corpus check (at least for English
- [Section 2.2.3 / Table 2] The convergence result is partly an artifact of the coding design. The six taxonomy dimensions are imported from the risk-management literature, the categories are coarse, and each law is allowed to map to multiple categories in dimensions (1), (5), and (6). The check-mark table therefore summarizes the authors' classifications, but the table alone does not let a reader verify each cell. I recommend a supplementary table with representative quotations per cell, or an explicit caveat that the convergence claim is descriptive of the authors' interpretive mapping rather than an independent property of the legal texts. This would align the strength of the claim with the evidence.
minor comments (5)
- [Section 3.3.3] Typo: 'ENISA will nothing other national authoritative CSIRTs' should read 'ENISA will notify other national authoritative CSIRTs'.
- [References] Reference [71] gives the year as '201'; this should be '2021'.
- [Figure 1] The figure contains the misspelling 'inreases'; it should be 'increases'.
- [Section 3.4.2 / Table 2] Article 13(1) CER explicitly requires 'technical, security and organisational measures', yet Table 2 does not mark CER under 'Technical security' (5a). If the coding criterion is the presence of concrete technical requirements rather than the mere mention of technical measures, this should be stated in Section 2.2.1 and applied consistently; otherwise the table conflicts with the text.
- [Section 3.5.1] Minor grammar issue: 'the NIS2 directive have already involved' should be 'the NIS2 directive has already involved'.
Circularity Check
No significant circularity; the taxonomy is an interpretive classification of primary legal texts, and self-citations are ancillary rather than load-bearing.
full rationale
The paper's central claims are qualitative classifications of EU legal provisions against a six-dimension taxonomy adapted from risk-management literature. The convergence claim ('All laws rely on the conventional probabilistic understanding'; 'the five acts have an encompassing coverage') is a summary of Table 2, which is constructed from quoted provisions and the authors' interpretations. This is not a derivation that reduces to its inputs: the dimensions come from external literature, the mappings are grounded in specific articles/recitals, and the authors explicitly allow overlaps. No fitted parameters are renamed as predictions, no uniqueness theorem is imported, and no central claim is defined in terms of itself. Self-citations are present ([56], [58], [60], [61]) and [58] is used when asserting that residual/acceptable risks remain unacknowledged in the CRA. However, this citation supports a qualitative interpretive conclusion that the paper also reaches through its own analysis of CRA Articles 3, 13, 14–20, 54, and 56; it is not the sole or formal basis for the claim. The paper is self-contained against the primary legal texts, and the taxonomy could in principle have revealed different mappings or gaps. The main weakness is not circularity but an evidentiary/scope mismatch: Section 3 states 'only considering notable risk-based aspects... not everything about the laws is covered', and Section 2.2 excludes contextual interpretation and case law. Yet Section 4.1 claims that acceptable/residual and non-probabilistic risks are aspects 'none of the laws mention or otherwise discuss explicitly'. Negative gap claims are broader than the deliberately selective sample and could be artifacts of selection. This is a correctness risk, not a circular reduction: the absence is not forced by the taxonomy's definitions or by a self-citation chain. For that reason, the circularity score is low.
Assumptions & free parameters
assumptions (4)
- domain assumption The conventional probabilistic definition of risk (probability of a threat times impact) is the reference standard for determining whether a law's risk concept is probabilistic.
- ad hoc to paper The six taxonomy dimensions and their categories are sufficient to capture the relevant differences between the laws.
- ad hoc to paper The asset concept can be stretched to include natural persons, the EU internal market, and critical infrastructures.
- domain assumption The analysis of selected provisions without contextual interpretation or case law is adequate to answer the research questions.
Cite this review
Pith. "Pith review of Risks and Compliance with the EU's Core Cyber Security Legislation." pith.science (2026). https://pith.science/paper/7ZSVET63
@misc{pith2026250821386,
author = {Pith},
title = {Pith review of: Risks and Compliance with the EU's Core Cyber Security Legislation},
year = {2026},
howpublished = {\url{https://pith.science/paper/7ZSVET63}},
note = {Machine review of arXiv:2508.21386}
}
read the original abstract
The European Union (EU) has long favored a risk-based approach to regulation. Such an approach is also used in recent cyber security legislation enacted in the EU. Risks are also inherently related to compliance with the new legislation. Objective: The paper investigates how risks are framed in the EU's five core cyber security legislative acts, whether the framings indicate convergence or divergence between the acts and their risk concepts, and what qualifying words and terms are used when describing the legal notions of risks. Method : The paper's methodology is based on qualitative legal interpretation and taxonomy-building. Results: The five acts have an encompassing coverage of different cyber security risks, including but not limited to risks related to technical, organizational, and human security as well as those not originating from man-made actions. Both technical aspects and assets are used to frame the legal risk notions in many of the legislative acts. A threat-centric viewpoint is also present in one of the acts. Notable gaps are related to acceptable risks, non-probabilistic risks, and residual risks. Conclusion: The EU's new cyber security legislation has significantly extended the risk-based approach to regulations. At the same time, complexity and compliance burden have increased. With this point in mind, the paper concludes with a few practical takeaways about means to deal with compliance and research it.
Figures
Forward citations
Cited by 1 Pith paper
-
A Rapid Review Regarding the Concept of Legal Requirements in Requirements Engineering
A rapid review finds that requirements engineering research lacks a shared definition of legal requirements and that common claims about them are not backed by empirical evidence.
Reference graph
Works this paper leans on
-
[1]
M., Woody, C., Bandor, M., and Merendino, T
Alberts, C., Wallen, C. M., Woody, C., Bandor, M., and Merendino, T. (2023). Security Engineering Frame- work (SEF): Managing Security and Resilience Risks Across the Systems Lifecycle. CMU/SEI-2024-SR-022, Carnegie Mel- lon University, Software Engineering Institute (SEI), avail- able online in July: https://www.sei.cmu.edu/documents/6121/ security-engin...
work page 2023
-
[2]
Almada, M. and Petit, N. (2025). The EU AI Act: Between the Rock of Product Safety and the Hard Place of Fundamental Rights. Common Market Law Review, 62:85–120
work page 2025
-
[3]
Anderson, R. and Moore, T. (2009). Information Security: Where Computer Science, Economics and Psychology Meet. Philosophical Transactions of the Royal Society A: Mathemati- cal, Physical and Engineering Sciences, 367:2717–2727
work page 2009
-
[4]
Backman, S. (2023). Risk vs. Threat-Based Cybersecurity: The Case of the EU. European Security, 32(1):85–103
work page 2023
-
[5]
Bernhard, J. and Knoll, A. (2021). Risk-Constrained Interac- tive Safety Under Behavior Uncertainty for Autonomous Driving. In Proceedings of the IEEE Intelligent Vehicles Symposium (IV 2021), pages 63–70, Nagoya
work page 2021
-
[6]
Bertoldi, A. and Chishman, R. (2007). Improving Legal On- tologies Through Semantic Representation of Adjectives. In Pro- ceedings of the International Conference on Semantic Computing (ICSC 2007), pages 767–774, Irvine. IEEE
work page 2007
-
[7]
Bygrave, L. A. (2017). Data Protection by Design and by Default: Deciphering the EU’s Legislative Requirements. Oslo Law Review, 4(2):105–120
work page 2017
-
[8]
Carroll, T. E., Greitzer, F. L., and Roberts, A. D. (2014). Security Informatics Research Challenges for Mitigating Cyber Friendly Fire. Security Informatics, 13:1–14
work page 2014
Show all 78 references
-
[9]
and Larouche, P
Chirico, F. and Larouche, P. (2013). Convergence and Diver- gence, in Law and Economics and Comparative Law. In Larouche, P. and Cserne, P., editors, National Legal Systems and Globaliza- tion: New Role, Continuing Relevance, pages 9–33. Asser Press, Berlin
2013
-
[10]
Chockalingam, S., Nystad, E., and Esnoul, C. (2023). Capa- bility Maturity Models for Targeted Cyber Security Training. In Proceedings of the 5th International Conference on HCI for Cy- bersecurity, Privacy and Trust (HCI-CPT 2023), pages 576–590, Copenhagen. Springer
2023
-
[11]
and Daniel, E
Crotty, J. and Daniel, E. (2022). Cyber Threat: Its Origins and Consequence and the Use of Qualitative and Quantitative Methods in Cyber Risk Assessment. Applied Computing and In- formatics, pages 1–12
2022
-
[12]
H., and Pieters, W
de Bruijne, M., van Eeten, M., Ga˜ n´ an, C. H., and Pieters, W. (2017). Towards a New Cyber Threat Ac- tor Typology: A Hybrid Method for the NCSC Cyber Security Assessment. TU Delft, available online in July 2025: https://repository.wodc.nl/bitstream/handle/20.500. 12832/2299...
2017
-
[13]
Interoperable EU Risk Management Toolbox
ENISA (2023). Interoperable EU Risk Management Toolbox. The European Union Agency for Cyberse- curity (ENISA), available online in July 2025: https: //www.enisa.europa.eu/sites/default/files/publications/ Interoperable%20EU%20RM%20Toolbox.pdf
2023
-
[14]
Best Practices for Cyber Crisis Management
ENISA (2024). Best Practices for Cyber Crisis Management. The European Union Agency for Cybersecurity (ENISA), avail- able online in January 2025: https://enisa.europa.eu/sites/ default/files/2024-11/ENISA%20Study%20Best%20Practices% 20Cyber%20Crisis%20Management.pdf
2024
-
[15]
European Union Vulnerability Database
ENISA (2025). European Union Vulnerability Database. The European Union Agency for Cybersecurity (ENISA). Available online in March 2025: https://euvd.enisa.europa.eu/
2025
-
[16]
EU (2008). Decision No 768/2008/EC of the European Parlia- ment and of the Council of 9 July 2008 on a Common Framework for the Marketing of Products, and Repealing Council Decision 93/465/EEC (Text With EEA Relevance). The European Union (EU), available online in July 2025: h...
2008
-
[17]
Charter of Fundamental Rights of the Eu- ropean Union
EU (2016a). Charter of Fundamental Rights of the Eu- ropean Union. The European Union, available online in July 2025: https://eur-lex.europa.eu/legal-content/EN/TXT/ ?uri=celex%3A12016P%2FTXT
2025
-
[18]
EU (2016b). Consolidated Text: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the Protection of Natural Persons With Regard to the Process- ing of Personal Data and on the Free Movement of Such Data, and Repealing Directive 95/46/EC ...
2016
-
[19]
EU (2019). Regulation (EU) 2019/881 of the European Par- liament and of the Council of 17 April 2019 on ENISA (the Eu- ropean Union Agency for Cybersecurity) and on Information and Communications Technology Cybersecurity Certification and Re- pealing Regulation (EU) No 526/201...
2019
-
[20]
EU (2022a). Directive (EU) 2022/2555 of the European Parlia- ment and of the Council of 14 December 2022 on Measures for a High Common Level of Cybersecurity Across the Union, Amend- ing Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and Repealing Directive (EU) 201...
2022
-
[21]
EU (2022b). Directive (EU) 2022/2557 of the European Parlia- ment and of the Council of 14 December 2022 on the Resilience of Critical Entities and Repealing Council Directive 2008/114/EC (Text With EEA Relevance). The European Union (EU), avail- able online in March 2025: htt...
2022
-
[22]
EU (2022c). Regulation (EU) 2022/2065 of the European Par- liament and of the Council of 19 October 2022 on a Single Market for Digital Services and Amending Directive 2000/31/ec (Digital Services Act) (Text With EEA Relevance). The European Union (EU), available online in Mar...
2022
-
[23]
EU (2022d). Regulation (EU) 2022/2554 of the European Par- liament and of the Council of 14 December 2022 on Digital Oper- ational Resilience for the Financial Sector and Amending Regula- tions (EC) no 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 20...
2022
-
[24]
EU (2024). Regulation (EU) 2024/2847 of the European Parlia- ment and of the Council of 23 October 2024 on Horizontal Cyber- security Requirements for Products With Digital Elements and Amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cybe...
2024
-
[25]
Faisal, K. (2023). Applying the Purpose Limitation Principle in Smart-City Data-Processing Practices: A European Data Protec- tion Law Perspective. Communication Law and Policy, 28(1):67– 97
2023
-
[26]
Fridgen, G., Klier, J., Beer, M., and Wolf, T. (2014). Im- proving Business Value Assurance in Large-Scale IT Projects— A Quantitative Method Based on Founded Requirements Assess- ment. ACM Transactions on Management Information Systems, 5(3):1–17
2014
-
[27]
Gellert, R. (2016). We Have Always Managed Risks in Data Protection Law: Understanding the Similarities and Differ- ences Between the Rights-Based and the Risk-Based Approaches to Data Protection. European Data Protection Law Review, 2(4):481–492
2016
-
[28]
Guerra, G. (2018). An Interdisciplinary Approach for Compar- ative Lawyers: Insights from the Fast-Moving Field of Law and Technology. German Law Journal, 19(3):579–612
2018
-
[29]
Haelterman, H. (2022). Breaking Silos of Legal and Regulatory Risks to Outperform Traditional Compliance Approaches. Euro- pean Journal on Criminal Policy and Research, 28:19–36
2022
-
[30]
B., Moffett, J
Haley, C. B., Moffett, J. D., Laney, R., and Nuseibeh, B. (2006). A Framework for Security Requirements Engineering. In Proceed- ings of the International Workshop on Software Engineering for Secure Systems (SESS 2006), pages 35–42, Shanghai. ACM
2006
-
[31]
Hall´ e, S. (2024). Column: Is Theory (Still) Welcome in Software Engineering Research? ACM SIGSOFT Software Engineering Notes, 49(2):19–21
2024
-
[32]
Hanif, H., Constantino, J., Sekwenz, M.-T., van Eeten, M., Ubacht, J., Wagner, B., and Zhauniarovich, Y. (2024). Navigat- ing the EU AI Act Maze Using a Decision-Tree Approach. ACM Journal on Responsible Computing, 1(3):1–16
2024
-
[33]
Hildebrandt, M. (2020). Law for Computer Scientists and Other Folk. Oxford University Press, Oxford
2020
-
[34]
Hildebrandt, M. (2024). The Future of Computational Law in the Context of the Rule of Law. Journal of Cross-Disciplinary Research in Computational Law, 2(2):1–11
2024
-
[35]
B., and Glinz, M
Hotomski, S., Charrada, E. B., and Glinz, M. (2016). An Ex- ploratory Study on Handling Requirements and Acceptance Test Documentation in Industry. In Proceedings of the IEEE 24th International Requirements Engineering Conference (RE 2016), pages 116–125, Beijing. IEEE
2016
-
[36]
M., Liebel, G., de Souza Santos, R., and Baltes, S
Hyrynsalmi, S. M., Liebel, G., de Souza Santos, R., and Baltes, S. (2025). Not Real or too Soft? On the Challenges of Publishing Interdisciplinary Software Engineering Research. InProceedings of the IEEE/ACM 47th International Conference on Software En- gineering: Software Eng...
2025
-
[37]
Jasmontaite, L., Kamara, I., Zanfir-Fortuna, G., and Leucci, S. (2018). Data Protection by Design and by Default: Framing Guiding Principles into Legal Obligations in the GDPR. European Data Protection Law Review, 4:168–189
2018
-
[38]
and Farhadi, S
Kalatpour, O. and Farhadi, S. (2017). The Content Analysis of Emergency Scenarios: Thematic Survey of the Context in the Process Industries. Safety Science, 92:257–261
2017
-
[39]
V., and Tanas, A
Kloza, D., Van Dijk, N., Casiraghi, S., Maymir, S. V., and Tanas, A. (2021). The Concept of Impact Assessment. In Burgess, J. P. and Kloza, D., editors, Border Control and New Technolo- gies: Addressing Integrated Impact Assessment, pages 31–48. ASP Academic and Scientific Pub...
2021
-
[40]
Kosenkov, O., Elahidoost, P., Gorschek, T., Fischbach, J., Mendez, D., Unterkalmsteiner, M., Fucci, D., and Mohanani, R. (2025). Systematic Mapping Study on Requirements Engineering for Regulatory Compliance of Software Systems. Information and Software Technology, 178:107622
2025
-
[41]
Labaka, L., Hernantes, J., and Sarriegi, J. M. (2016). A Holistic Framework for Building Critical Infrastructure Resilience. Tech- nological Forecasting & Social Change, 103:21–33
2016
-
[42]
S., Werner, C., Ernst, N., and Damian, D
Li, Z. S., Werner, C., Ernst, N., and Damian, D. (2022). To- wards Privacy Compliance: A Design Science Study in a Small Organization. Information and Software Technology, 146:106868
2022
-
[43]
and Dhirani, L
Meagher, H. and Dhirani, L. L. (2024). Cyber-Resilience, Prin- ciples, and Practices. In Qureshi, K. N., Newe, T., Jeon, G., and Chehri, A., editors, Cybersecurity Vigilance and Security Engi- neering of Internet of Everything, pages 57–74. Springer, Cham
2024
-
[44]
Mendes, J. P. (2023). Model-Based Risk Analysis for System Design. Systems Engineering, 27(1):5–20
2023
-
[45]
Michalec, O., Milyaeva, S., and Rashid, A. (2022). When the Future Meets the Past: Can Safety and Cyber Security Coexist in Modern Critical Infrastructures? Big Data & Society, 9(1):1–13
2022
-
[46]
and Ranise, S
Mollaeefar, M. and Ranise, S. (2023). Identifying and Quantify- ing Trade-Offs in Multi-Stakeholder Risk Evaluation With Appli- cations to the Data Protection Impact Assessment of the GDPR. Computers & Security, 129:103206
2023
-
[47]
Onos´ e, C. (2020). Designing for Consumer Trust in a Data- Powered World. IEEE Consumer Electronics Magazine, 9(2):89– 93
2020
-
[48]
Purnhagen, K. (2003). The Politics of Systemization in EU Product Safety Regulation: Market, States, Collectivity, and In- tegration. Springer, Dordrecht
2003
-
[49]
K., Coyle, P., and Cohen, R
Rabitti, G., Chokami, A. K., Coyle, P., and Cohen, R. D. (2024). A Taxonomy of Cyber Risk Taxonomies.Risk Analysis, 45(2):376– 386
2024
-
[50]
Ralph, P. (2019). Toward Methodological Guidelines for Pro- cess Theories and Taxonomies in Software Engineering. IEEE Transactions on Software Engineering, 45(7):712–735
2019
-
[51]
S., Calvo-Manzano, J., and Sanchez- Garcia, I
Rea-Guaman, A., Feliu, T. S., Calvo-Manzano, J., and Sanchez- Garcia, I. (2017). Systematic Review: Cybersecurity Risk Taxon- omy. In Proceedings of the 6th International Conference on Soft- ware Process Improvement (CIMPS 2017), pages 137–146, Za- catecas. Springer
2017
-
[52]
and Malgieri, G
Rebrean, M.-L. and Malgieri, G. (2025). Vulnerability in the EU AI Act: Building an Interpretation. In Proceedings of the 2025 ACM Conference on Fairness, Accountability, and Transparency (F AccT 2025), pages 1985–1997, Athens. ACM
2025
-
[53]
Ruan, K. (2017). Introducing Cybernomics: A Unifying Eco- nomic Framework for Measuring Cyber Risk. Computers & Secu- rity, 65:77–89
2017
-
[54]
Ruohonen, J. (2022). A Review of Product Safety Regulations in the European Union. International Cybersecurity Law Review, 3:345–366
2022
-
[55]
Ruohonen, J. (2025). (Forthcoming) An Empirical Analysis of Policy Consultations on the European Union’s Cyber Security Laws. In Amoretti, F., Busetti, S., Righettini, M. S., and Vecchi, G., editors, Cybersecurity Policy in the European Union. Palgrave Macmillan, Cham
2025
-
[56]
Ruohonen, J., Hjerppe, K., and Kang, E.-Y. (2025a). A Map- ping Analysis of Requirements Between the CRA and the GDPR. In (Forthcoming) Proceedings of the IEEE 33rd International Re- quirements Engineering Conference Workshops (REW 2025), Va- lencia. IEEE
2025
-
[57]
Ruohonen, J., Hjerppe, K., and von Zastrow, M. (2024). An Ex- ploratory Case Study on Data Breach Journalism. In Proceedings of the 19th International Conference on Availability, Reliability and Security (ARES 2024), pages 1–9, Vienna. ACM
2024
-
[58]
Ruohonen, J., Kang, E.-Y., and Ramadan, Q. (2025b). An Alignment Between the CRA’s Essential Requirements and the ATT&CK®’s Mitigations. In (Forthcoming) Proceedings of the IEEE 33rd International Requirements Engineering Conference Workshops (REW 2025), Valencia. IEEE
2025
-
[59]
and Mickelsson, S
Ruohonen, J. and Mickelsson, S. (2023). Reflections on the Data Governance Act. Digital Society, 2:1–10
2023
-
[60]
Ruohonen, J., Rindell, K., and Busetti, S. (2025c). From Cy- ber Security Incident Management to Cyber Security Crisis Man- agement in the European Union. Archived manuscript, available online: https://doi.org/10.48550/arXiv.2504.14220
-
[61]
and Timmers, P
Ruohonen, J. and Timmers, P. (2025). Vulnerability Coordi- nation Under the Cyber Resilience Act. Archived manuscript, available online: https://doi.org/10.48550/arXiv.2412.06261
2025 doi
-
[62]
Ryan, I., Roedig, U., and Stol, K.-J. (2023). Measuring Secure Coding Practice and Culture: A Finger Pointing at the Moon is not the Moon. In Proceedings of the IEEE/ACM 45th Interna- tional Conference on Software Engineering (ICSE 2023), pages 1622–1634, Melbourne. IEEE. 13
2023
-
[63]
Sarmah, T., Ghosh, K., Chatterjee, R., and Shaw, R. (2024). History of Risk Management Approach. In Izumi, T., Abe, M., Fujita, K., and Shaw, R., editors,All-Hazards Approach: Towards Resilience Building, pages 29–41. Springer, Singapore
2024
-
[64]
Shirey, R. W. (2007). Internet Security Glossary, Version
2007
-
[65]
Request for Comments (RFC) 4949, the Internet Engineer- ing Task Force (IETF), available online in July 2025: https: //datatracker.ietf.org/doc/html/rfc4949
2025
-
[66]
Sibony, A.-L. (2017). Returning to Risk Regulation After a Long Journey. European Journal of Risk Regulation, 8(1):112–114
2017
-
[67]
and Kocarev, L
Sokolovska, A. and Kocarev, L. (2018). Integrating Technical and Legal Concepts of Privacy. IEEE Access, 6:26543–26557
2018
-
[68]
Solove, D. J. (2002). Conceptualizing Privacy. California Law Review, 90(4):1087–1155
2002
-
[69]
Suslov, T. (2025). Rethinking Security: The Human Side of Risk Management. Palgrave Macmillan, Cham
2025
-
[70]
Tatam, M., Shanmugam, B., Azam, S., and Kannoorpatti, K. (2021). A Review of Threat Modelling Approaches for APT-Style Attacks. Heliyon, 7(1):e05969
2021
-
[71]
Usman, M., Britto, R., B¨ orstler, J., and Mendes, E. (2017). Tax- onomies in Software Engineering: A Systematic Mapping Study and a Revised Taxonomy Development Method. Information and Software Technology, 85:43–59
2017
-
[72]
van der Heijden, J. (201). Risk as an Approach to Regulatory Governance: An Evidence Synthesis and Research Agenda. SAGE Open, 11(3):1–12
-
[73]
Vielberth, M., Siepmann, R., Glas, M., and Pernul, G. (2025). Securing the Road Ahead: Supporting Decision Making in Auto- motive Cybersecurity Risk Treatment. In Proceedings of the 20th International Conference on Availability, Reliability and Security (ARES 2025), pages 269–...
2025
-
[74]
and Disparte, D
Wagner, D. and Disparte, D. (2016). Global Risk Agility and Decision Making: Organizational Resilience in the Era of Man- Made Risk. Palgrave Macmillan, London
2016
-
[75]
H., Fritsch, L., and Lindskog, S
Wairmu, S., Iwaya, L. H., Fritsch, L., and Lindskog, S. (2024). On the Evaluation of Privacy Impact Assessment and Privacy Risk Assessment Methodologies: A Systematic Literature Review. IEEE Access, 12:19625–19650
2024
-
[76]
Walley, P. (1991). Statistical Reasoning With Imprecise Proba- bilities. Chapman and Hall, London
1991
-
[77]
Waqdan, M., Louafi, H., and Mouhoub, M. (2025). Security Risk Assessment in IoT Environments: A Taxonomy and Survey. Computers & Security, 154:10446
2025
-
[78]
Woods, D. W. and B¨ ohme, R. (2016). SoK: Quantifying Cyber Risk. In Proceedings of the IEEE Symposium on Security and Privacy (S&P), pages 211–228, San Francisco. IEEE. 14
2016
Reviewed August 5, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.