Cybersecurity Regulation: It’s Not ‘Performance-Based’ If Outcomes Can’t Be Measured

In a commentary for Lawfare, Jim Dempsey, a lecturer at the UC Berkeley Law School and a senior policy advisor at the Stanford Cyber Policy Center, says the Transportation Security Administration's cybersecurity directive for pipeline operators addresses risk, but fails to hold covered entities accountable for performance.

🔒 Members Only · Cyber & AI BriefYou’ve reached the member portion of this brief.Members read the full analysis and the source documents in every Brief, six days a week.