<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://cyber.harvard.edu/cybersecurity/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=David</id>
	<title>Cybersecurity Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://cyber.harvard.edu/cybersecurity/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=David"/>
	<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/Special:Contributions/David"/>
	<updated>2026-08-14T20:02:40Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.43.6</generator>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Template:Filtered_Table&amp;diff=6852</id>
		<title>Template:Filtered Table</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Template:Filtered_Table&amp;diff=6852"/>
		<updated>2013-01-25T21:03:19Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;dt_types&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|U.S. Government Report&lt;br /&gt;
|-&lt;br /&gt;
|U.S. Government Hearing&lt;br /&gt;
|-&lt;br /&gt;
|Non-U.S. Government Report&lt;br /&gt;
|-&lt;br /&gt;
|Independent Report&lt;br /&gt;
|-&lt;br /&gt;
|Industry Report&lt;br /&gt;
|-&lt;br /&gt;
|Book&lt;br /&gt;
|-&lt;br /&gt;
|Journal Article&lt;br /&gt;
|-&lt;br /&gt;
|Article&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;dt_categories&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|1. Overview&lt;br /&gt;
|-&lt;br /&gt;
|3. Threats and Actors&lt;br /&gt;
|-&lt;br /&gt;
|3.1 The Threat and Skeptics&lt;br /&gt;
|-&lt;br /&gt;
|3.2 Actors and Incentives&lt;br /&gt;
|-&lt;br /&gt;
|3.2.1 States&lt;br /&gt;
|-&lt;br /&gt;
|3.2.2 Groups&lt;br /&gt;
|-&lt;br /&gt;
|3.2.3 Hacktivists&lt;br /&gt;
|-&lt;br /&gt;
|3.2.4 Terrorists&lt;br /&gt;
|-&lt;br /&gt;
|3.2.5 Criminals and Criminal Organizations&lt;br /&gt;
|-&lt;br /&gt;
|3.3 Security Targets&lt;br /&gt;
|-&lt;br /&gt;
|3.3.1 Public Critical Infrastructure&lt;br /&gt;
|-&lt;br /&gt;
|3.3.1.1 Government Networks (.gov)&lt;br /&gt;
|-&lt;br /&gt;
|3.3.1.2 Military Networks (.mil)&lt;br /&gt;
|-&lt;br /&gt;
|3.3.2 Private Critical Infrastructure&lt;br /&gt;
|-&lt;br /&gt;
|3.3.2.1 Electricity, Oil and Natural Gas&lt;br /&gt;
|-&lt;br /&gt;
|3.3.2.2 Financial Institutions and Networks&lt;br /&gt;
|-&lt;br /&gt;
|3.3.2.3 Transportation&lt;br /&gt;
|-&lt;br /&gt;
|3.3.2.4 Water, Sewer, etc.&lt;br /&gt;
|-&lt;br /&gt;
|3.3.3 Communications&lt;br /&gt;
|-&lt;br /&gt;
|3.3.3.1 Telephone&lt;br /&gt;
|-&lt;br /&gt;
|3.3.3.2 Public Data Networks&lt;br /&gt;
|-&lt;br /&gt;
|3.3.3.3 Cloud Computing&lt;br /&gt;
|-&lt;br /&gt;
|4. Issues&lt;br /&gt;
|-&lt;br /&gt;
|4.1 Metrics&lt;br /&gt;
|-&lt;br /&gt;
|4.2 Economics of Cybersecurity&lt;br /&gt;
|-&lt;br /&gt;
|4.2.1 Risk Management and Investment&lt;br /&gt;
|-&lt;br /&gt;
|4.2.2 Incentives&lt;br /&gt;
|-&lt;br /&gt;
|4.2.3 Insurance&lt;br /&gt;
|-&lt;br /&gt;
|4.2.4 Behavioral Economics&lt;br /&gt;
|-&lt;br /&gt;
|4.2.5 Market Failure&lt;br /&gt;
|-&lt;br /&gt;
|4.3 Supply Chain Issues&lt;br /&gt;
|-&lt;br /&gt;
|4.4 Usability/Human Factors&lt;br /&gt;
|-&lt;br /&gt;
|4.5 Psychology and Politics&lt;br /&gt;
|-&lt;br /&gt;
|4.6 Information Sharing/Disclosure&lt;br /&gt;
|-&lt;br /&gt;
|4.7 Public-Private Cooperation&lt;br /&gt;
|-&lt;br /&gt;
|4.8 Attribution&lt;br /&gt;
|-&lt;br /&gt;
|4.9 Identity Management&lt;br /&gt;
|-&lt;br /&gt;
|4.10 Privacy&lt;br /&gt;
|-&lt;br /&gt;
|4.11 Cybercrime&lt;br /&gt;
|-&lt;br /&gt;
|4.12 Cyberwar&lt;br /&gt;
|-&lt;br /&gt;
|4.13 Espionage&lt;br /&gt;
|-&lt;br /&gt;
|4.13.1 Government to Government&lt;br /&gt;
|-&lt;br /&gt;
|4.13.2 Industrial&lt;br /&gt;
|-&lt;br /&gt;
|4.13.3 Media Perceptions&lt;br /&gt;
|-&lt;br /&gt;
|5. Approaches&lt;br /&gt;
|-&lt;br /&gt;
|5.1 Regulation/Liability&lt;br /&gt;
|-&lt;br /&gt;
|5.2 Private Efforts/Organizations&lt;br /&gt;
|-&lt;br /&gt;
|5.3 Government Organizations&lt;br /&gt;
|-&lt;br /&gt;
|5.4 International Cooperation&lt;br /&gt;
|-&lt;br /&gt;
|5.5 International Law (including Laws of War)&lt;br /&gt;
|-&lt;br /&gt;
|5.6 Deterrence&lt;br /&gt;
|-&lt;br /&gt;
|5.7 Technology&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable datatable&amp;quot; data-type-filter=&amp;quot;{{{1}}}&amp;quot; data-category-filter=&amp;quot;{{{2}}}&amp;quot; data-search-filter=&amp;quot;{{{3}}}&amp;quot; border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;1&amp;quot; cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;border: 1px solid LightGrey;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background-color:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Author/Agency&#039;&#039;&#039;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background-color:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Date&#039;&#039;&#039;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background-color:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Title&#039;&#039;&#039;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Wiki Entry&#039;&#039;&#039;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Type&#039;&#039;&#039;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Category&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| Aloise, Gene et al.||2008||[[Nuclear_Security|Nuclear Security]]||Yes||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]]&lt;br /&gt;
|-&lt;br /&gt;
| Anderson, Ross ||2001||[[Why_Information_Security_is_Hard|Why Information Security is Hard ]]||Yes||Independent Report ||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Anderson, Ross ||2006||[[The_Economics_of_Information_Security|The Economics of Information Security ]]||Yes||Journal Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Anderson, Ross J. ||2008||[[Security_Engineering|Security Engineering ]]||Yes||Book ||3.2 [[Security Targets]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Anderson, Ross, et. al ||2008||[[Security_Economics_and_the_Internal_Market|Security Economics and the Internal Market ]]||Yes||Article||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Arora et al. ||2006||[[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure|Does Information Security Attack Frequency Increase With Vulnerability Disclosure ]]||Yes||Journal Article ||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]]&lt;br /&gt;
|-&lt;br /&gt;
| Aviram, Amitai ||2004||[[Overcoming_Impediments_to_Information_Sharing|Overcoming Impediments to Information Sharing ]]||Yes||Journal Article ||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Barkham, Jason ||2001||[[Information_Warfare_and_International_Law_on_the_Use_of_Force|Information Warfare and International Law on the Use of Force ]]||Yes||Journal Article ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Bauer, Johannes M. and van Eeten, Michel J. G.||2009||[[Cybersecurity|Cybersecurity: Stakeholder Incentives, Externalities, and Policy Options]]||Yes||Journal Article||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Beard, Jack M. ||2009||[[Law_and_War_in_the_Virtual_Era|Law and War in the Virtual Era ]]||Yes||Journal Article ||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Bellovin, Steven M.||2009||[[The_Government_and_Cybersecurity|The Government and Cybersecurity]]||Yes||Journal Article||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;4.7[[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Besunder, Allison A.||2009||[[Best_Practices_for_Data_Protection_and_Privacy|Best Practices for Data Protection and Privacy]]||Yes||Book||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Boebert, W. Earl||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059366.pdf A Survey of Challenges in Attribution]||No||Journal Article||4.8 [[Attribution]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Bohme, Rainer ||2005||[[Cyber-Insurance_Revisited|Cyber-Insurance Revisited ]]||Yes||Independent Report ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.2.3 [[Insurance]],&amp;lt;br&amp;gt;,4.2.5 [[Market Failure]]&lt;br /&gt;
|-&lt;br /&gt;
| Bohme, Rainer ||2006||[[Models_and_Measures_for_Correlation_in_Cyber-Insurance|Models and Measures for Correlation in Cyber-Insurance ]]||Yes||Independent Report ||4.2.3 [[Insurance]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Bohme, Rainer ||2010||[[Modeling_Cyber-Insurance|Modeling Cyber-Insurance ]]||Yes||Independent Report ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.2.3 [[Insurance]],&amp;lt;br&amp;gt;,5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Booz Allen Hamilton and the Economist Intelligence Unit ||2012-01-15||[http://www.cyberhub.com/CyberPowerIndex Cyber Power Index ]||No||Industry Report||4. [[Issues]],&amp;lt;br&amp;gt;4.1 [[Metrics]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Bradley, Curtis A. and Goldsmith, Jack L.||2011||[[Overview_of_International_Law_and_Institutions|Overview of International Law and Institutions]]||Yes||Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Brown, Davis ||2006||[[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict|A Proposal for an International Convention To Regulate the Use of Information Systems in Armed Conflict ]]||Yes||Journal Article ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Burstein, Aaron J.||2008||[[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research|Amending the ECPA to Enable a Culture of Cybersecurity Research]]||Yes||Journal Article||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Business Roundtable||2011-10-11||[http://businessroundtable.org/uploads/studies-reports/downloads/2011_10_Mission_Critical_A_Public-Private_Strategy_for_Effective_Cybersecurity.pdf Mission Critical: A Public-Private Strategy for Effective Cybersecurity ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| Business Software Alliance ||2012-02-02||Global Cloud Computing Scorecard a Blueprint for Economic Opportunity||No||Industry Report||3.3.3.3 [[Cloud Computing]]&lt;br /&gt;
|-&lt;br /&gt;
| Business Software Alliance, Center for Democracy &amp;amp; Technology, U.S. Chamber of Commerce, Internet Security Alliance, Tech America ||2011-03-08||[http://www.cdt.org/files/pdfs/20110308_cbyersec_paper.pdf Improving our Nation’s Cybersecurity through the Public-Private Partnership: a White Paper ]||No||Industry Report||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Cabinet Office (United Kingdom) ||2011-11-11||[http://www.cabinetoffice.gov.uk/sites/default/files/resources/uk-cyber-security-strategy-final.pdf The UK Cyber Security Strategy: Protecting and promoting the UK in a digital world ]||No||Non-U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Camp, L. Jean ||2004||[[Economics_of_Information_Security|Economics of Information Security ]]||Yes||Book ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Camp, L. Jean ||2004||[[Pricing_Security|Pricing Security ]]||Yes||Book ||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Center for a New American Security||2012-06-11||[http://www.cnas.org/node/6405 America’s Cyber Future: Security and Prosperity in the Information Age ]||No||Independent Report||1. [[Overview]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Center for Strategic and International Studies ||2008||[[Securing_Cyberspace_for_the_44th_Presidency|Securing Cyberspace for the 44th Presidency ]]||Yes||Independent Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Centre for Secure Information Technologies||2011||[http://www.csit.qub.ac.uk/sites/CSIT/InnovationatCSIT/Reports/Filetoupload,295594,en.pdf World Cybersecurity Technology Research Summit (Belfast 2011) ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| Cetron, Marvin J. and Davies, Owen||2009||[[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity|World War 3.0: Ten Critical Trends for Cybersecurity]]||Yes||Journal Article||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Clark, David and Landau, Susan||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059365.pdf Untangling Attribution]||No||Journal Article||4.8 [[Attribution]],&amp;lt;br&amp;gt;5.6 [[Deterrence]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Clarke, Richard A. ||2010||[[Cyber_War|Cyber War ]]||Yes||Book ||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Clinton, Larry ||Undated ||[[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security|Cyber-Insurance Metrics and Impact on Cyber-Security ]]||Yes||Independent Report ||4.2.3 [[Insurance]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Cloud Security Alliance ||2009-12||[http://www.cloudsecurityalliance.org/csaguide.pdf Security Guidance for Critical Areas of Focus in Cloud Computing V2.1 ]||No||Independent Report||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Cohen, Geoff||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059445.pdf Targeting Third Party Collaboration]||No||Journal Article||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| Computer Economics, Inc. ||2007||[[2007_Malware_Report|2007 Malware Report ]]||Yes||Industry Report ||4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| Computing Research Association ||2003-||[[Four_Grand_Challenges_in_Trustworthy_Computing|Four Grand Challenges in Trustworthy Computing ]]||Yes||Independent Report ||4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.9 [[Identity Management]]&lt;br /&gt;
|-&lt;br /&gt;
| Cornish, Paul||2009||[[Cyber_Security_and_Politically,_Socially_and_Religiously_Motivated_Cyber_Attacks|Cyber Security and Politically, Socially and Religiously Motivated Cyber Attacks]]||Yes||Non-U.S. Government Report||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Cornish, Paul et al.||2009||[[Cyberspace_and_the_National_Security_of_the_United_Kingdom|Cyberspace and the National Security of the United Kingdom - Threats and Responses]]||Yes||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Council on Foreign Relations ||2010-07-15||[http://i.cfr.org/content/publications/attachments/Knake%20-Testimony%20071510.pdf Untangling Attribution: Moving to Accountability in Cyberspace [Testimony]]||No||Independent Report||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;4.8 [[Attribution]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| CSIS Commission on Cybersecurity for the 44th Presidency, Center for Strategic and International Studies ||2011-01||[http://csis.org/files/publication/110128_Lewis_CybersecurityTwoYearsLater_Web.pdf Cybersecurity Two Years Later ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5. [[Approaches]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Cyber Security Forum Initiative ||2011-05-09||[http://www.unveillance.com/wp-content/uploads/2011/05/Project_Cyber_Dawn_Public.pdf Cyber Dawn: Libya ]||No||Industry Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Commerce ||2011-06-14||[http://www.nist.gov/nstic/2012-nstic-governance-recs.pdf Models for a Governance Structure for the National Strategy for Trusted Identities in Cyberspace ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Commerce ||2010||[[Defense_Industrial_Base_Assessment|Defense Industrial Base Assessment ]]||Yes||U.S. Government Report ||3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Commerce, Internet Policy Task Force||2011-06||[http://www.nist.gov/itl/upload/Cybersecurity_Green-Paper_FinalVersion.pdf Cybersecurity, Innovation and the Internet Economy]||No||U.S. Government Report||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2011-07-14||[http://www.defense.gov/news/d20110714cyber.pdf Department of Defense Strategy for Operating in Cyberspace ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2011-11-15||[http://www.defense.gov/home/features/2011/0411_cyberstrategy/docs/NDAA%20Section%20934%20Report_For%20webpage.pdf Department of Defense Cyberspace Policy Report : A Report to Congress Pursuant to the National Defense Authorization Act for Fiscal Year 2011, Section 934 ]||No||U.S. Government Report||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2012-02-16||[http://www.fas.org/sgp/othergov/dod/5200_01v1.pdf DOD Information Security Program: Overview, Classification, and Declassification ]||No||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2012-04-11||[http://www.nsci-va.org/CyberReferenceLib/2011-04-Cyber%20Ops%20Personnel.pdf Cyber Operations Personnel Report (DoD) ]||No||U.S. Government Report||&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||1999||[[An_Assessment_of_International_Legal_Issues_in_Information_Operations|An Assessment of International Legal Issues in Information Operations ]]||Yes||U.S. Government Report ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2005-||[[Strategy_for_Homeland_Defense_and_Civil_Support|Strategy for Homeland Defense and Civil Support ]]||Yes||U.S. Government Report ||3.2.4 [[Terrorists]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2007||[[Mission_Impact_of_Foreign_Influence_on_DoD_Software|Mission Impact of Foreign Influence on DoD Software ]]||Yes||U.S. Government Report ||3.2.4 [[Terrorists]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2011-04||[http://www.nsci-va.org/CyberReferenceLib/2011-04-Cyber%20Ops%20Personnel.pdf Cyber Operations Personnel Report (DOD) ]||No||U.S. Government Report ||&lt;br /&gt;
|-&lt;br /&gt;
| Department of Energy||2012-04||[http://energy.gov/sites/prod/files/OAS-RA-12-04.pdf The Department&#039;s Management of the Smart Grid Investment Grant Program]||No||U.S. Government Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Energy (DOE) Inspector General ||2012-01-01||[http://energy.gov/ig/downloads/departments-management-smart-grid-investment-grant-program-oas-ra-12-04 The Department’s Management of the Smart Grid Investment Grant Program ]||No||U.S. Government Report ||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Energy, Idaho National Laboratory ||2010-05-01||[http://www.fas.org/sgp/eprint/nstb.pdf NSTB Assessments Summary Report: Common Industrial Control System Cyber Security Weaknesses ]||No||U.S. Government Report||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Energy, Office of Electricity Delivery &amp;amp; Energy Reliability ||Undated||[http://energy.gov/oe/technology-development/energy-delivery-systems-cybersecurity Cybersecurity for Energy Delivery Systems Program ]||No||U.S. Government Report ||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2009-09-16||[http://www.cyber.st.dhs.gov/docs/National_Cyber_Leap_Year_Summit_2009_Co-Chairs_Report.pdf National Cyber Leap Year Summit 2009: Co-Chairs&#039; Report]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.8 [[Attribution]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2007-06||[http://www.oig.dhs.gov/assets/Mgmt/OIG_07-48_Jun07.pdf Challenges Remain in Securing the Nation’s Cyber Infrastructure]||No||U.S. Government Report||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2009-11||[http://www.cyber.st.dhs.gov/docs/DHS-Cybersecurity-Roadmap.pdf A Roadmap for Cybersecurity Research]||No||U.S. Government Report||1. [[Overview]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2010-08||[http://www.dhs.gov/xoig/assets/mgmtrpts/OIG_10-111_Aug10.pdf DHS Needs to Improve the Security Posture of Its Cybersecurity Program Systems]||No||U.S. Government Report||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2010-09||[http://www.federalnewsradio.com/pdfs/NCIRP_Interim_Version_September_2010.pdf National Cyber Incident Response Plan]||No||U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2011-11||[http://www.dhs.gov/xlibrary/assets/nppd/blueprint-for-a-secure-cyber-future.pdf Blueprint for a Secure Cyber Future: The Cybersecurity Strategy for the Homeland Security Enterprise]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security ||2003||[[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets|The National Strategy for the Physical Protection of Critical Infrastructures and Key Assets ]]||Yes||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security ||2009||[[A_Roadmap_for_Cybersecurity_Research|A Roadmap for Cybersecurity Research ]]||Yes||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Justice||2011-04||[http://www.justice.gov/oig/reports/FBI/a1122r.pdf The Federal Bureau of Investigation&#039;s Ability to Address the National Security Cyber Intrusion Threat]||No||U.S. Government Report||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Deputy Chief of Staff for Intelligence ||2006||[[Critical_Infrastructure_Threats_and_Terrorism|Critical Infrastructure Threats and Terrorism ]]||Yes||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Dörmann, Knut ||2004||[[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks|Applicability of the Additional Protocols to Computer Network Attacks ]]||Yes||Independent Report ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Douglas Maughan||2010||[[The_Need_for_a_National_Cybersecurity_Research_and_Development_Agenda|The Need for a National Cybersecurity Research and Development Agenda]]||Yes||Article||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Dunlap Charles J, Jr   ||2011||[[Perspectives_for_Cyber_Strategists_on_Law_for_Cyberwar|Perspectives for Cyber Strategists on Law for Cyberwar]]||Yes||Journal Article||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Dunlap, Charles J. Jr. ||2009||[[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century|Towards a Cyberspace Legal Regime in the Twenty-First Century ]]||Yes||Article||4.5 [[Psychology and Politics]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| EastWest Institute ||2011-02-03||[http://vialardi.org/nastrazzuro/pdf/US-Russia.pdf Working Towards Rules for Governing Cyber Conflict: Rendering the Geneva and Hague Conventions in Cyberspace ]||No||Independent Report||3.2.1 [[States]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Energetics Inc. ||2006||[[Roadmap_to_Secure_Control_Systems_in_the_Energy_Sector|Roadmap to Secure Control Systems in the Energy Sector ]]||Yes||Independent Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Energy Sector Control Systems Working Group||2011-09||[http://www.cyber.st.dhs.gov/wp-content/uploads/2011/09/Energy_Roadmap.pdf Roadmap to Achieve Energy Delivery Systems Cybersecurity]||No||U.S. Government Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| ENISA||2010||[[Introduction_to_Country_Reports|Introduction to Country Reports]]||Yes||Non-U.S. Government Report||3.2.1 [[States]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Epstein, Richard A. ||2008||[[Cybersecurity_in_the_Payment_Card_Industry|Cybersecurity in the Payment Card Industry ]]||Yes||Journal Article ||3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| European Network and Information Security Agency ||2010-10-07||[http://www.enisa.europa.eu/media/press-releases/stuxnet-analysis Stuxnet Analysis ]||No||Non-U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| European Network and Information Security Agency (ENISA) ||2011-04-11||[http://www.enisa.europa.eu/act/res/other-areas/inter-x/report/interx-report Resilience of the Internet Interconnection Ecosystem, at: ]||No||Non-U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Federal CIO Council ||2012-01-04||[http://www.gsa.gov/portal/category/102371 Federal Risk and Authorization Management Program (FedRAMP) ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Federal Communications Commission (FCC) ||2010-04-21||[http://hraunfoss.fcc.gov/edocs_public/attachmatch/DOC-305618A1.doc Explore the reliability and resiliency of commercial broadband communications networks ]||No||U.S. Government Report||3.3.3 [[Communications]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Federal Communications Commission (FCC) ||2011-06-03||[ftp://ftp.fcc.gov/pub/Daily_Releases/Daily_Business/2011/db0610/DOC-307454A1.txt FCC&#039;s Plan for Ensuring the Security of Telecommunications Networks ]||No||U.S. Government Report||&lt;br /&gt;
|-&lt;br /&gt;
| Financial Services Sector Coordinating Council for Critical Infrastructure Protection ||2008||[[Research_Agenda_for_the_Banking_and_Finance_Sector|Research Agenda for the Banking and Finance Sector ]]||Yes||Independent Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.1 [[Metrics]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| Fischer, Eric A.&amp;lt;br /&amp;gt;CRS||2012-04-23||[http://www.fas.org/sgp/crs/natsec/R42114.pdf Federal Laws Relating to Cybersecurity: Discussion of Proposed Revisions]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Franklin, Jason, et. al ||2007||[[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants|An Inquiry into the Nature and Causes of the Wealth of Internet Miscreants ]]||Yes||Independent Report ||3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| Gandal, Neil ||2008||[[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security|An Introduction to Key Themes in the Economics of Cyber Security ]]||Yes||Book ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2003-08-27||[http://www.gao.gov/products/GAO-03-760 Efforts to Improve Information sharing Need to Be Strengthened ]||No||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2004-05-28||[http://www.gao.gov/assets/160/157541.pdf Technology Assessment: Cybersecurity for Critical Infrastructure Protection]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2008-07-31||[http://www.gao.gov/assets/280/279084.pdf Cyber Analysis And Warning: DHS Faces Challenges in Establishing a Comprehensive National Capability]||No||U.S. Government Report||5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2009-09-24||[http://www.gao.gov/new.items/d09969.pdf Critical Infrastructure Protection: Current Cyber Sector-Specific Planning Approach Needs Reassessment]||No||U.S. Government Report||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2009-11-17||[http://www.gao.gov/products/GAO-10-230t Continued Efforts Are Needed to Protect Information Systems from Evolving Threats ]||No||U.S. Government Report ||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-03-05||[http://www.gao.gov/products/GAO-10-338 Cybersecurity: Progress Made But Challenges Remain in Defining and Coordinating the Comprehensive National Initiative ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-03-16||[http://www.gao.gov/products/GAO-11-463T Cybersecurity: Continued Attention Is Needed to Protect Federal Information Systems from Evolving Threats ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-03-24||[http://www.gao.gov/products/GAO-10-536t Information Security: Concerted Response Needed to Resolve Persistent Weaknesses, at: ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-04-12||[http://www.gao.gov/products/GAO-10-237 Concerted Effort Needed to Consolidate and Secure Internet Connections at Federal Agencies ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-06-03||[http://www.gao.gov/assets/310/305208.pdf Cybersecurity: Key Challenges Need to Be Addressed to Improve Research and Development]||No||U.S. Government Report||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-06-16||[http://www.gao.gov/products/GAO-10-834t Continued Attention Is Needed to Protect Federal Information Systems from Evolving Threats ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-07-01||[http://www.gao.gov/products/GAO-10-513 Federal Guidance Needed to Address Control Issues With Implementing Cloud Computing ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-07-15||[http://www.gao.gov/products/GAO-10-628 Critical Infrastructure Protection: Key Private and Public Cyber Expectations Need to Be Consistently Addressed ]||No||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-08-02||[http://www.gao.gov/products/GAO-10-606 United States Faces Challenges in Addressing Global Cybersecurity and Governance ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-09-15||[http://www.gao.gov/products/GAO-10-916 Information Security: Progress Made on Harmonizing Policies and Guidance for National Security and Non-National Security Systems ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-09-23||[http://www.gao.gov/products/GAO-10-772 DHS Efforts to Assess and Promote Resiliency Are Evolving but Program Management Could Be Strengthened ]||No||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-10-06||[http://www.gao.gov/products/GAO-11-24 Cyberspace Policy: Executive Branch Is Making Progress Implementing 2009 Policy Review Recommendations, but Sustained Leadership Is Needed ]||No||U.S. Government Report ||5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-11-30||[http://www.gao.gov/products/GAO-11-43 Information Security: Federal Agencies Have Taken Steps to Secure Wireless Networks, but Further Actions Can Mitigate Risk ]||No||U.S. Government Report ||3.3.3 [[Communications]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-01-12||[http://www.gao.gov/products/GAO-11-117 Electricity Grid Modernization: Progress Being Made on Cybersecurity Guidelines, but Key Challenges Remain to be Addressed ]||No||U.S. Government Report ||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-03-16||[http://www.gao.gov/products/GAO-11-463T Cybersecurity: Continued Attention Needed to Protect Our Nation&#039;s Critical Infrastructure and Federal Information Systems ]||No||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-07-08||[http://www.gao.gov/products/GAO-11-149 Information Security: State Has Taken Steps to Implement a Continuous Monitoring Application, but Key Challenges Remain ]||No||U.S. Government Report ||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-07-25||[http://www.gao.gov/products/GAO-11-75 Defense Department Cyber Efforts: DoD Faces Challenges in Its Cyber Activities ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-07-26||[http://www.gao.gov/products/GAO-11-463T Continued Attention Needed to Protect Our Nation’s Critical Infrastructure ]||No||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-07-29||[http://www.gao.gov/products/GAO-11-695R Defense Department Cyber Efforts: Definitions, Focal Point, and Methodology Needed for DoD to Develop Full-Spectrum Cyberspace Budget Estimates ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-10-03||[http://www.gao.gov/products/GAO-12-137 Information Security: Weaknesses Continue Amid New Federal Efforts to Implement Requirements ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-10-05||[http://www.gao.gov/products/GAO-12-130T Information Security: Additional Guidance Needed to Address Cloud Computing Concerns ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-10-17||[http://www.gao.gov/products/GAO-11-634 Federal Chief Information Officers: Opportunities Exist to Improve Role in Information Technology Management ]||No||U.S. Government Report ||5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-11-29||[http://www.gao.gov/products/GAO-12-8 Cybersecurity Human Capital: Initiatives Need Better Planning and Coordination, at: ]||No||U.S. Government Report ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-12-09||[http://www.gao.gov/products/GAO-12-92 Critical Infrastructure Protection: Cybersecurity Guidance Is Available, but More Can Be Done to Promote Its Use ]||No||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2012-01-13||[http://www.gao.gov/assets/590/587681.pdf Defense Contracting: Improved Policies and Tools Could Help Increase Competition on DOD&#039;s National Security Exception Procurements]||No||U.S. Government Report||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2012-02-28||[http://www.csit.qub.ac.uk/media/pdf/Filetoupload,252359,en.pdf Cybersecurity: Challenges to Securing the Modernized Electricity Grid ]||No||Non-U.S. Government Report ||&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2009||[[Critical_Infrastructure_Protection|Critical Infrastructure Protection - Current Cyber Sector-Specific Planning Approach Needs Reassessment]]||Yes||U.S. Government Report||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2009-07||[http://www.gao.gov/new.items/d09546.pdf Information Security: Agencies Continue to Report Progress, but Need to. Mitigate Persistent Weaknesses]||No||U.S. Government Report||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2009-09||[http://www.gao.gov/new.items/d09617.pdf Information Security: Concerted Effort Needed to Improve Federal Performance Measures]||No||U.S. Government Report||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010||[[Information_Security|Information Security - Concerted Effort Needed to Consolidate and Secure Internet Connections at Federal Agencies]]||Yes||U.S. Government Report||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO ||2011-10-05||[http://www.gao.gov/products/GAO-12-130T Information Security: Additional Guidance Needed to Address Cloud Computing Concerns ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Geer, Daniel E. and Conway, Daniel G.||2010||[[Nothing_Ventured,_Nothing_Gained|Nothing Ventured, Nothing Gained]]||Yes||Journal Article||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Gellman, Robert||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059444.pdf Civil Liberties and Privacy Implications of Policies to Prevent Cyberattacks ]||No||Journal Article||4.8 [[Attribution]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2010-07-15||[http://www.gao.gov/products/GAO-10-628 Critical Infrastructure Protection: Key Private and Public Cyber Expectations Need to Be Consistently Addressed ]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2011-01-12||[http://www.gao.gov/products/GAO-11-117 Electricity Grid Modernization: Progress Being Made on Cybersecurity Guidelines, but Key Challenges Remain to be Addressed ]||No||U.S. Government Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2011-03-16||[http://www.gao.gov/products/GAO-11-463T Cybersecurity: Continued Attention Needed to Protect Our Nation&#039;s Critical Infrastructure and Federal Information Systems ]||No||U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2011-07-29||[http://www.gao.gov/products/GAO-11-695R Defense Department Cyber Efforts: Definitions, Focal Point, and Methodology Needed for DOD to Develop Full-Spectrum Cyberspace Budget Estimates ]||No||U.S. Government Report ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2011-11-29||[http://www.gao.gov/products/GAO-12-8 Cybersecurity Human Capital: Initiatives Need Better Planning and Coordination ]||No||U.S. Government Report||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2011-12-09||[http://www.gao.gov/products/GAO-12-92 Critical Infrastructure Protection: Cybersecurity Guidance Is Available, but More Can Be Done to Promote Its Use ]||No||U.S. Government Report ||&lt;br /&gt;
|-&lt;br /&gt;
| General Services Administration (GSA) ||2012-02-07||[http://www.gsa.gov/graphics/staffoffices/FedRAMP_CONOPS.pdf Concept of Operations: FedRAMP ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Grady, Mark F. ||2006||[[The_Law_and_Economics_of_Cybersecurity|The Law and Economics of Cybersecurity ]]||Yes||Book ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Graham David E   ||2010||[[Cyber_Threats_and_the_Law_of_War| Cyber Threats and the Law of War]]||Yes||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Granick, Jennifer Stisa ||2005||[[The_Price_of_Restricting_Vulnerability_Publications|The Price of Restricting Vulnerability Publications ]]||Yes||Journal Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Hollis, Duncan B. ||2007||[[Why_States_Need_an_International_Law_for_Information_Operations|Why States Need an International Law for Information Operations ]]||Yes||Journal Article ||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;4.13.1 [[Government to Government|Government to Government Espionage]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| HP TippingPoint DVLabs ||2010||[[2010_Top_Cyber_Security_Risks_Report|2010 Top Cyber Security Risks Report ]]||Yes||Industry report ||4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| IEEE/EastWest Institute ||2010-05-26||[http://www.ieee-rogucci.org/files/The%20ROGUCCI%20Report.pdf The Reliability of Global Undersea Communications Cable Infrastructure (The Rogucci Report) ]||No||Independent Report||3.3.3 [[Communications]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Institute for Information Infrastructure Protection ||2003||[[Cyber_Security_Research_and_Development_Agenda|Cyber Security Research and Development Agenda ]]||Yes||Independent Report ||4.1 [[Metrics]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Institute for Science and International Security ||2010-12-22||[http://isis-online.org/isis-reports/detail/did-stuxnet-take-out-1000-centrifuges-at-the-natanz-enrichment-plant/ Did Stuxnet Take Out 1,000 Centrifuges at the Natanz Enrichment Plant? Preliminary Assessment ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| International Instrument Users Association (WIB) ||2010-11-10||[http://www.isssource.com/wib/ WIB Security Standard Released ]||No||Industry Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| International Telecommunications Union ||2012-02-10||[http://www.itu.int/ITU-D/cyb/cybersecurity/docs/itu-toolkit-cybercrime-legislation.pdf ITU Toolkit for Cybercrime Legislation ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| James Clapper, Director of National Intelligence ||2011-02-10||[http://www.dni.gov/testimonies/20110210_testimony_clapper.pdf Worldwide Threat Assessment of the U.S. Intelligence Community (Testimony) ]||No||U.S. Government Report||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.2 [[Actors and Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Johnson, Eric M. ||2008||[[Managing_Information_Risk_and_the_Economics_of_Security|Managing Information Risk and the Economics of Security ]]||Yes||Book ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Johnson, Vincent R. ||2005||[[Cybersecurity,_Identity_Theft,_and_the_Limits_of_Tort_Liability|Cybersecurity, Identity Theft, and the Limits of Tort Liability ]]||Yes||Journal Article ||4.9 [[Identity Management]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Joint Workshop of the National Security Threats in Cyberspace and the National Strategy Forum ||2009-09-15||[http://nationalstrategy.com/Portals/0/National%20Security%20Threats%20in%20Cyberspace%20FINAL%2009-15-09.pdf National Security Threats in Cyberspace ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| Joseph S. Nye||2010||[[Cyber_Power|Cyber Power]]||Yes||Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Journal of Strategic Studies ||2011-10-05||[http://www.tandfonline.com/doi/abs/10.1080/01402390.2011.6089393 Cyber War Will Not Take Place ]||No||Journal Article||&lt;br /&gt;
|-&lt;br /&gt;
| Kelly A. Gable||2010||[[Cyber-Apocalypse_Now|Cyber-Apocalypse Now - Securing the Internet Against Cyberterrorism and Using Universal Jurisdiction as a Deterrent]]||Yes||Journal Article||3.2.4 [[Terrorists]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Kerr, Paul K. et al.&amp;lt;br /&amp;gt;CRS||2010-12-09||[http://www.fas.org/sgp/crs/natsec/R41524.pdf The Stuxnet Computer Worm: Harbinger of an Emerging Warfare Capability]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.4 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Kesan, Jay P. and Hayes, Carol M.||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059446.pdf Thinking Through Active Defense in Cyberspace ]||No||Journal Article||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Kobayashi, Bruce H.||2005||[[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods|An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and other Public Security Goods]]||Yes||Journal Article||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Kobayashi, Bruce H. ||2006||[[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods|An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and Other Public Security Goods ]]||Yes||Journal Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Korns, Stephen W. ||2009||[[Cyber_Operations|Cyber Operations ]]||Yes||Journal Article ||4.8 [[Attribution]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Kramer, Franklin D., et. al ||2009||[[Cyberpower_and_National_Security|Cyberpower and National Security ]]||Yes||Book ||1. [[Overview]]&lt;br /&gt;
|-&lt;br /&gt;
| Kundra, Vivek||2010-12-09||[http://www.cio.gov/documents/25-point-implementation-plan-to-reform-federal%20it.pdf 25 Point Implementation Plan to Reform Federal Information Technology Management]||No||U.S. Government Report||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Kundra, Vivek||2011-02-08||[http://www.cio.gov/documents/federal-cloud-computing-strategy.pdf Federal Cloud Computing Strategy]||No||U.S. Government Report||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Lan, Tang et al.||2010||[[Global_Cyber_Deterrence|Global Cyber Deterrence: Views from China, the U.S., Russia, India, and Norway]]||Yes||Independent Report||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Lernard, Thomas M. ||2005||[[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches|An Economic Analysis of Notification Requirements for Data Security Breaches ]]||Yes||Independent Report ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Lernard, Thomas M. ||2006||[[Much_Ado_About_Notification|Much Ado About Notification ]]||Yes||Journal Article ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Lewis, James Andrews||2005||[[Cyber_Security_and_Regulation_in_the_United_States|Aux armes, citoyens: Cyber Security and Regulation in the United States]]||Yes||Journal Article||3.3.1 [[Public Critical Infrastructure,&amp;lt;br&amp;gt;3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;3.3.2.3 [[Transportation]]&lt;br /&gt;
|-&lt;br /&gt;
| Libicki, Martin||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059490.pdf Pulling Punches in Cyberspace]||No||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
|Lin, Herbert||2012||[[Media:Lin-Cyber_Conflict_and_National_Security_2012.pdf|Cyber Conflict and National Security]]||No||Article||&lt;br /&gt;
|-&lt;br /&gt;
| Lukasik, Stephen J.||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059438.pdf A Framework for Thinking about Cyber Conflict and Cyber Deterrence with Possible Declatory Policies for these Domain]||No||Journal Article||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Massachusetts Institute of Technology (MIT) ||2011-12-05||[http://web.mit.edu/mitei/research/studies/the-electric-grid-2011.shtml The Future of the Electric Grid ]||No||Independent Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| McAfee ||2011-08-02||[http://www.mcafee.com/us/resources/white-papers/wp-operation-shady-rat.pdf Revealed: Operation Shady RAT: an Investigation Of Targeted Intrusions Into 70+ Global Companies, Governments, and Non-Profit Organizations During the Last 5 Years ]||No||Industry Report||3.2.1 [[States]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.13 [[Espionage]]&lt;br /&gt;
|-&lt;br /&gt;
| McAfee ||2012-02-01||[http://www.mcafee.com/us/resources/reports/rp-sda-cyber-security.pdf?cid=WBB048 Cyber-security: The Vexed Question of Global Rules: An Independent Report on Cyber-Preparedness Around the World ]||No||Industry Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| McAfee and Center for Strategic and International Studies (CSIS) ||2011-04-21||[http://www.mcafee.com/us/resources/reports/rp-critical-infrastructure-protection.pdf In the Dark: Crucial Industries Confront Cyberattacks ]||No||Industry Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt; 4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| McAfee and the Security Defense Agenda||2012-02-12||[http://www.mcafee.com/us/resources/reports/rp-sda-cyber-security.pdf Cyber-security: The Vexed Question of Global Rules: An Independent Report on Cyber-Preparedness Around the World]||No||Industry Report||1. [[Overview]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| McAfee, Inc. ||2010||[[McAfee_Threats_Report|McAfee Threats Report ]]||Yes||Industry Report ||3.2.3 [[Hacktivists]],&amp;lt;br&amp;gt;3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| McDermott, Rose||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059442.pdf Decision Making Under Uncertainty]||No||Journal Article||4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;4.5 [[Psychology and Politics]],&amp;lt;br&amp;gt;4.8 [[Attribution]]&lt;br /&gt;
|-&lt;br /&gt;
| Microsoft||2010-11||[http://cdn.globalfoundationservices.com/documents/InformationSecurityMangSysforMSCloudInfrastructure.pdf Information Security Management System for Microsoft Cloud Infrastructure ]||No||Industry Report||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Mitre Corp (JASON Program Office) ||2010-11||[http://www.fas.org/irp/agency/dod/jason/cyber.pdf Science of Cyber-Security ]||No||Independent Report||1. [[Overview]],&amp;lt;br&amp;gt;4. [[Issues]]&lt;br /&gt;
|-&lt;br /&gt;
| Moore, Tyler||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059364.pdf Introducing the Economics of Cybersecurity: Principles and Policy Options]||No||Journal Article||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Moore, Tyler ||2007||[[Examining_the_Impact_of_Website_Take-down_on_Phishing|Examining the Impact of Website Take-down on Phishing ]]||Yes||Independent Report ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Moore, Tyler ||2008||[[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing|The Consequence of Non-Cooperation in the Fight Against Phishing ]]||Yes||Independent Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]]&lt;br /&gt;
|-&lt;br /&gt;
| Moore, Tyler ||2009||[[The_Impact_of_Incentives_on_Notice_and_Take-down|The Impact of Incentives on Notice and Take-down ]]||Yes||Book ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Moore, Tyler, et. al ||2009||[[The_Economics_of_Online_Crime|The Economics of Online Crime ]]||Yes||Journal Article ||3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| Morgan, Patrick M. ||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059436.pdf Applicability of Traditional Deterrence Concepts and Theory to the Cyber Realm ]||No||Journal Article||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]],&amp;lt;br&amp;gt;5.6 [[Deterrence ]]&lt;br /&gt;
|-&lt;br /&gt;
| National Association of Secretaries of State ||2012-01-12||[http://www.nass.org/index.php?option=com_docman&amp;amp;task=doc_download&amp;amp;gid=1257 Developing State Solutions to Business Identity Theft: Assistance, Prevention and Detection Efforts by Secretary of State Offices ]||No||Independent Report||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Cyber Defense Initiative ||2009||[[National_Cyber_Defense_Financial_Services_Workshop_Report|National Cyber Defense Financial Services Workshop Report ]]||Yes||Independent Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Cyber Security Alliance and Microsoft ||2011-05-13||[http://www.staysafeonline.org/sites/default/files/resource_documents/2011%20National%20K-12%20Study%20Final_0.pdf 2011 State of Cyberethics, Cybersafety and Cybersecurity Curriculum in the U.S. Survey ]||No||Industry Report||4.4 [[Usability/Human Factors]]&lt;br /&gt;
|-&lt;br /&gt;
| National Cyber Security Summit Task Force ||2004||[[Information_Security_Governance|Information Security Governance ]]||Yes||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]],&amp;lt;br&amp;gt;5.3 [[government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Infrastructure Advisory Council ||2004||[[Hardening_The_Internet|Hardening The Internet ]]||Yes||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Initiative for Cybersecurity Education||2011-08-11||[http://csrc.nist.gov/nice/documents/nicestratplan/Draft_NICE-Strategic-Plan_Aug2011.pdf National Initiative for Cybersecurity Education Strategic Plan: Building a Digital Nation]||No||U.S. Government Report||1. [[Overview]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Initiative for Cybersecurity Education (NICE) ||2011-11-21||[http://csrc.nist.gov/nice/framework/documents/NICE-Cybersecurity-Workforce-Framework-printable.pdf NICE Cybersecurity Workforce Framework ]||No||U.S. Government Report||4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Institute of Standards and Technology ||2006||[[SP_800-82:_Guide_to_Supervisory_Control_and_Data_Acquisition_(SCADA)_and_Industrial_Control_Systems_Security|SP 800-82: Guide to Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems Security ]]||Yes||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Institute of Standards and Technology (NIST) ||2010-09-02||[http://www.nist.gov/public_affairs/releases/nist-finalizes-initial-set-of-smart-grid-cyber-security-guidelines.cfm NIST Finalizes Initial Set of Smart Grid Cyber Security Guidelines ]||No||U.S. Government Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council ||2009||[[Media:NRC-Cyberattack_Capabilities-2009.pdf|Technology, Policy, Law, and Ethics Regarding U.S. Acquisition and Use of Cyberattack Capabilities]]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council ||2010-09-21||[http://www.nap.edu/catalog.php?record_id=12998 Toward Better Usability, Security, and Privacy of Information Technology: Report of a Workshop ]||No||Independent Report||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;4.10 [[Privacy]]&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council ||2010-10-05||[http://www.nap.edu/catalog.php?record_id=12997#description Proceedings of a Workshop on Deterring Cyberattacks: Informing Strategies and Developing Options for U.S. Policy ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council ||1999||[[Trust_in_Cyberspace|Trust in Cyberspace ]]||Yes||Independent Report ||3.3.3.2 [[Public Data Networks]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council ||2007||[[Toward_a_Safer_and_More_Secure_Cyberspace|Toward a Safer and More Secure Cyberspace ]]||Yes||Independent Report ||1. [[Overview]],&amp;lt;br&amp;gt;4.8 [[Attribution]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council, Committee for Advancing Software-Intensive Systems Producibility ||2010-10-20||[http://www.nap.edu/catalog.php?record_id=12979 Critical Code: Software Producibility for Defense ]||No||Independent Reprot ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| National Science and Technology Council ||2006||[[Federal_Plan_for_Cyber_Security_and_Information_Assurance_Research_and_Development|Federal Plan for Cyber Security and Information Assurance Research and Development ]]||Yes||U.S. Government Report ||4.1 [[Metrics]],&amp;lt;br&amp;gt;4.7 [[Attribution]],&amp;lt;br&amp;gt;4.8 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| National Science Foundation||2011-08-11||[http://www.livescience.com/15423-forefront-cyber-security-research-nsf-bts.html At the Forefront of Cyber Security Research ]||No||U.S. Government Report||5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| National Science Foundation||2012-01-17||[http://www.nsf.gov/awardsearch/showAward.do?AwardNumber=1127185 Information Security Risk Taking ]||No||U.S. Government Report||4.1 [[Metrics]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Security Cyberspace Institute||2012-07-11||[http://www.nsci-va.org/WhitePapers/2011-07-22-Cyber Analogies Whitepaper-K McKee.pdf A Review of Frequently Used Cyber Analogies ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| National Security Initiative ||2010-10-18||[http://www.americansecuritychallenge.com/ American Security Challenge ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| Networking and Information Technology Research and Development ||2009||[[National_Cyber_Leap_Year_Summit_2009,_Co-Chairs%27_Report|National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report ]]||Yes||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| NIST ||2011-09-01||[http://www.nist.gov/customcf/get_pdf.cfm?pub_id=909505 Cloud Computing Reference Architecture ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]]&lt;br /&gt;
|-&lt;br /&gt;
| NIST ||2011-12-01||[http://www.nist.gov/itl/cloud/upload/SP_500_293_volumeII.pdf U.S. Government Cloud Computing Technology Roadmap, Release 1.0 (Draft), Volume II Useful Information for Cloud Adopters ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| NIST ||2012-02-17||[http://www.nist.gov/nstic/2012-nstic-governance-recs.pdf Recommendations for Establishing an Identity Ecosystem Governance Structure for the National Strategy for Trusted Identities in Cyberspace ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Nojeim, Gregory T.||2009||[[Cybersecurity:_Preventing_Terrorist_Attacks_and_Protecting_Privacy_in_Cyberspace|Cybersecurity: Preventing Terrorist Attacks and Protecting Privacy in Cyberspace]]||Yes||U.S. Government Hearing||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| North American Electric Reliability Corp. (NERC) ||2011-01-26||[http://www.wired.com/images_blogs/threatlevel/2011/02/DoE-IG-Report-on-Grid-Security.pdf Federal Energy Regulatory Commission&#039;s Monitoring of Power Grid Cyber Security ]||No||U.S. Government Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| NSTC||2011-12||[http://www.whitehouse.gov/sites/default/files/microsites/ostp/fed_cybersecurity_rd_strategic_plan_2011.pdf Trustworthy Cyberspace: Strategic Plan for the Federal Cybersecurity Research and Development Program]||No||U.S. Government Report||5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Nye, Joseph ||2010||[[Cyber_Power|Cyber Power ]]||Yes||Book ||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;4.13 [[Espionage]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| OECD||2009||[[Cybersecurity_and_Economic_Incentives|Cybersecurity and Economic Incentives]]||Yes||Non-U.S. Government Report||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| OECD||2009||[[The_Market_Consequences_of_Cybersecurity|The Market Consequences of Cybersecurity]]||Yes||Non-U.S. Government Report||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Office of the National Counterintelligence Executive ||2011-11-03||[http://www.ncix.gov/publications/reports/fecie_all/Foreign_Economic_Collection_2011.pdf Foreign Spies Stealing US Economic Secrets in Cyberspace ]||No||U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;4.13 [[Espionage]]&lt;br /&gt;
|-&lt;br /&gt;
| Organisation for Economic Co-operation and Development (OECD) ||2010-11-12||[http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.165.2211&amp;amp;rep=rep1&amp;amp;type=pdf The Role of Internet Service Providers in Botnet Mitigation: an Empirical Analysis Bases on Spam Data ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Organization for Economic Co-operation and Development (OECD) ||2012-01-10||[http://www.oecd-ilibrary.org/docserver/download/fulltext/5k9h2q8v9bln.pdf?expires=1330527950&amp;amp;id=id&amp;amp;accname=guest&amp;amp;checksum=F4470043AC638BE19D5131C3D5CE5EA4 ICT Applications for the Smart Grid: Opportunities and Policy Implications ]||No||Independent Report ||&lt;br /&gt;
|-&lt;br /&gt;
| PCAST||2010-12||[http://www.whitehouse.gov/sites/default/files/microsites/ostp/pcast-nitrd-report-2010.pdf Designing a Digital Future: Federally Funded Research and Development in Networking and Information Technology]||No||U.S. Government Report||4.3 [[Supply Chain Issues]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| PCAST||2011-06||[http://www.whitehouse.gov/sites/default/files/microsites/ostp/pcast-advanced-manufacturing-june2011.pdf Report to the President on Ensuring American Leadership in Advanced Manufacturing]||No||U.S. Government Report||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Perkins, Earl||2009||[[Evolving_Cybersecurity_Issues_in_the_Utility_Industry|Evolving Cybersecurity Issues in the Utility Industry]]||Yes||Independent Report||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.2.4 [[Water, Sewer, etc.]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Pew Research Center’s Internet &amp;amp; American Life Project ||2010-06-11||[http://pewinternet.org/Reports/2010/The-future-of-cloud-computing.aspx The future of cloud computing ]||No||Independent Report||3.3.3.3 [[Cloud Computing]]&lt;br /&gt;
|-&lt;br /&gt;
| Powell, Benjamin ||2005||[[Is_Cybersecurity_a_Public_Good|Is Cybersecurity a Public Good ]]||Yes||Journal Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.5 [[Market Failure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| President&#039;s Commission on Critical Infrastructure Protection ||1997||[[Critical_Foundations|Critical Foundations ]]||Yes||U.S. Government Report ||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.3 [[Communications]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| President&#039;s Information Technology Advisory Council ||2005||[[Cyber_Security:_A_Crisis_of_Prioritization|Cyber Security: A Crisis of Prioritization ]]||Yes||U.S. Government Report ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Project on National Security Reform (PNSR) ||2010-11||[http://www.pnsr.org/data/images/pnsr_the_power_of_people_report.pdf The Power of People: Building an Integrated National Security Professional System for the 21st Century ]||No||U.S. Government Report||4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Quadrennial Defense Review ||2010-07-30||[http://www.usip.org/quadrennial-defense-review-independent-panel-/view-the-report The QDR in Perspective: Meeting AmericaÅfs National Security Needs In the 21st Century (QDR Final Report) ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| RAND||2011-12-21||[http://www.rand.org/content/dam/rand/pubs/occasional_papers/2011/RAND_OP342.pdf A Cyberworm that Knows No Boundaries ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Rattray, Gregory and Healey, Jason||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059437.pdf Categorizing and Understanding Offensive Cyber Capabilities and Their Use ]||No||Journal Article||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Rollins, John and Wilson, Clay||2007||[[Terrorist_Capabilities_for_Cyberattack|Terrorist Capabilities for Cyberattack]]||Yes||U.S. Government Report||3.2.4 [[Terrorists]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Romanosky et al. ||2008||[[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft|Do Data Breach Disclosure Laws Reduce Identity Theft ]]||Yes||Independent Report ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Rosenzweig, Paul||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059443.pdf The Organization of the United States Government and Private Sector for Achieving Cyber Deterrence ]||No||Journal Article||4.3 [[Supply Chain Issues]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Rotenberg et. al. ||2010||[[The_Cyber_War_Threat_Has_Been_Grossly_Exaggerated|The Cyber War Threat Has Been Grossly Exaggerated ]]||Yes||Article||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Rue, Rachel and Pfleeger, Shari Lawrence||2009||[[Making_the_Best_Use_of_Cybersecurity_Economic_Models|Making the Best Use of Cybersecurity Economic Models]]||Yes||Journal Article||4.1 [[Metrics]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| Santos, Joost R., et. al||2007||[[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies|A Framework for Linking Cybersecurity Metrics to the Modeling of Macroeconomic Interdependencies]]||Yes||Journal Article||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;4.1 [[Metrics]]&lt;br /&gt;
|-&lt;br /&gt;
| Schmitt Michael N   ||2002||[[Wired_Warfare| Wired warfare: Computer network attack and jus in bello]]||Yes||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Schmitt Michael N   ||2004||[[Direct_Participation_in_Hostilities|Direct Participation in Hostilities and 21st Century Armed Conflict]]||Yes||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Schmitt, Michael N. ||1999||[[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law|Computer Network Attack and the Use of Force in International Law ]]||Yes||Journal Article ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Schmitt, Michael N. ||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059439.pdf Cyber Operations in International Law: The Use of Force, Collective Security, Self-Defense, and Armed Conflicts]||No||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Schmitt, Michael N., et. al ||2004||[[Computers_and_War|Computers and War ]]||Yes||Independent Report ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Schneidewind, Norman||2010||[[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks|Metrics for Mitigating Cybersecurity Threats to Networks]]||Yes||Journal Article||4.1 [[Metrics]]&lt;br /&gt;
|-&lt;br /&gt;
| Schneier, Bruce ||2003||[[Beyond_Fear|Beyond Fear ]]||Yes||Book ||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;4.5 [[Psychology and Politics]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Schneier, Bruce ||2008||[[Schneier_on_Security|Schneier on Security ]]||Yes||Book ||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Schwartz, Paul ||2007||[[Notification_of_Data_Security_Breaches|Notification of Data Security Breaches ]]||Yes||Journal Article ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Secretary of the Air Force ||2011-07-27||[http://www.e-publishing.af.mil/shared/media/epubs/AFI51-402.pdf Legal Reviews of Weapons and Cyber Capabilities ]||No||U.S. Government Report ||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Shackelford, Scott J.||2010||[[Estonia_Three_Years_Later|Estonia Three Years Later]]||Yes||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Shah, Shashi K.||2004||[[The_Evolving_Landscape_of_Maritime_Cybersecurity|The Evolving Landscape of Maritime Cybersecurity]]||Yes||Journal Article||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.2.3 [[Transportation]]&lt;br /&gt;
|-&lt;br /&gt;
| Sklerov, Matthew J. ||2009||[[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks|Solving the Dilemma of State Responses to Cyberattacks ]]||Yes||Journal Article ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.8 [[Attribution]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Sofaer, Abraham; Clark, David; and Diffie, Whitfield||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059440.pdf Cyber Security and International Cooperation ]||No||Journal Article||5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Software and Information Industry Association (SAII) ||2011-07-26||[http://www.siia.net/index.php?option=com_docman&amp;amp;task=doc_download&amp;amp;gid=3040&amp;amp;Itemid=318 Guide to Cloud Computing for Policy Makers ]||No||Independent Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Stohl, Michael ||2006||[[Cyber_Terrorism|Cyber Terrorism ]]||Yes||Journal Article ||3.2.3 [[Hacktivists]],&amp;lt;br&amp;gt;3.2.4 [[Terrorists]],&amp;lt;br&amp;gt;4.5 [[Psychology and Politics]]&lt;br /&gt;
|-&lt;br /&gt;
| Stuart Madnick et al.||2009||[[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security|Experiences and Challenges with Using CERT Data to Analyze International Cyber Security]]||Yes||Journal Article||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Swire, Peter P. ||2004||[[A_Model_for_When_Disclosure_Helps_Security|A Model for When Disclosure Helps Security ]]||Yes||Journal Article ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Swire, Peter P. ||2006||[[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons|A Theory of Disclosure for Security and Competitive Reasons ]]||Yes||Journal Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Symantec||2011-10-24||[http://www.symantec.com/connect/w32_duqu_precursor_next_stuxnet W32.Duqu: The Precursor to the Next Stuxnet ]||No||Industry Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Symantec Corporation ||2010||[[Symantec_Global_Internet_Security_Threat_Report|Symantec Global Internet Security Threat Report ]]||Yes||Industry Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| Telang, Rahul ||2007||[[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors|Impact of Software Vulnerability Announcements on the Market Value of Software Vendors ]]||Yes||Journal Article ||4.1 [[Metrics]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]]&lt;br /&gt;
|-&lt;br /&gt;
| Theohary, Catherine A. and Rollins, John||2010||[[Cybersecurity:_Current_Legislation,_Executive_Branch_Initiatives,_and_Options_for_Congress|Cybersecurity: Current Legislation, Executive Branch Initiatives, and Options for Congress]]||Yes||U.S. Government Report||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Thom, Maxie    ||2006||[[Information_Warfare_Arms_Control| Information Warfare Arms Control: Risks and Costs]]||Yes||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Thomas, Rob ||2006||[[The_Underground_Economy|The Underground Economy ]]||Yes||Journal Article ||3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| Threat Level Blog (Wired) ||2010-12-27||[http://www.wired.com/threatlevel/2010/12/a-four-day-dive-into-stuxnets-heart/ A Four-Day Dive Into Stuxnet’s Heart ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Todd, Graham H. ||2009||[[Armed_Attack_in_Cyberspace|Armed Attack in Cyberspace ]]||Yes||Journal Article ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.8 [[Attribution]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Trend Micro Incorporated ||2010||[[Trend_Micro_Annual_Report|Trend Micro Annual Report ]]||Yes||Industry Report ||4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Air Force ||2010-07-15||[http://www.e-publishing.af.mil/shared/media/epubs/afdd3-12.pdf Cyberspace Operations: Air Force Doctrine Document 3-12 ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Army War College ||2011-05-09||[http://www.strategicstudiesinstitute.army.mil/pubs/display.cfm?pubid=10670 Cyber Infrastructure Protection ]||No||U.S. Government Report||&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Army War College, Strategy Research Project ||2011-03-24||[http://www.dtic.mil/dtic/tr/fulltext/u2/a552990.pdf China’s Cyber Power and America’s National Security ]||No||U.S. Government Report||3.2.1 [[States]],&amp;lt;br&amp;gt;4.13 [[Espionage]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Department of Energy, Infrastructure Security and Energy Restoration ||2007-01-01||[http://www.oe.netl.doe.gov/docs/prepare/21stepsbooklet.pdf 21 Steps to Improve Cyber Security of SCADA Networks ]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Deputy Secretary of Defense, William J. Lynn (Foreign Affairs) ||2010-009||[http://www.foreignaffairs.com/articles/66552/william-j-lynn-iii/defending-a-new-domain Defending a New Domain ]||No||U.S. Government Report ||&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Appropriations (closed/classified) (Subcommittee on Energy and Power)||2011-03-31||[http://www.dhs.gov/ynews/testimony/testimony_1301595025263.shtm Budget Hearing - National Protection and Programs Directorate, Cybersecurity and Infrastructure Protection Programs  ]||No||U.S. Government Hearing||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2011-02-11||[http://armedservices.house.gov/index.cfm/hearings-display?ContentRecord_id=90d8a16a-23b7-4b9c-a732-cb10ab20e579&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=64562e79-731a-4ac6-aab0-7bd8d1b7e890&amp;amp;MonthDisplay=2&amp;amp;YearDisplay=2011 What Should the Department of Defense’s Role in Cyber Be?]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2011-03-16||[http://armedservices.house.gov/index.cfm/hearings-display?ContentRecord_id=79ce7b4c-f88b-40bf-9540-efdb3a2d26b2&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=64562e79-731a-4ac6-aab0-7bd8d1b7e890&amp;amp;MonthDisplay=3&amp;amp;YearDisplay=2011 2012 Budget Request from U.S. Cyber Command]||No||U.S. Government Hearing||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2011-11-03||[http://armedservices.house.gov/index.cfm/hearings-display?ContentRecord_id=42c170fb-8e0c-453a-81a2-f4ee3fa89283&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=64562e79-731a-4ac6-aab0-7bd8d1b7e890&amp;amp;MonthDisplay=11&amp;amp;YearDisplay=2011 Institutionalizing Irregular Warfare Capabilities]||No||U.S. Government Hearing||4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2012-03-20||[http://armedservices.house.gov/index.cfm/hearings-display?ContentRecord_id=92823c77-38f0-4c20-a3ee-36729e8e19a3&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=64562e79-731a-4ac6-aab0-7bd8d1b7e890&amp;amp;MonthDisplay=3&amp;amp;YearDisplay=2012 Fiscal 2013 Defense Authorization: IT and Cyber Operations]||No||U.S. Government Hearing||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce||2011-05-31||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=8639 Protecting the Electric Grid: the Grid Reliability and Infrastructure Defense Act]||No||U.S. Government Hearing||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Commerce, Manufacturing, and Trade)||2011-06-02||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=8653 Sony and Epsilon: Lessons for Data Security Legislation]||No||U.S. Government Hearing||4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Commerce,Trade and Manufacturing)||2011-06-15||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=8693 Discussion Draft of H.R. ___, a bill to require greater protection for sensitive consumer data and timely notification in case of breach]||No||U.S. Government Hearing||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Communications and Technology)||2012-03-07||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=9342 Cybersecurity:Networks     The Pivotal Role of Communications]||No||U.S. Government Hearing||3.3.3 [[Communications]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Communications and Technology)||2012-03-28||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=9397 Cybersecurity:Threats to Communications Networks and Public-Sector Responses]||No||U.S. Government Hearing||3.3.3 [[Communications]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Oversight and Investigations)||2011-07-26||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=8824 Cybersecurity: Infrastructure An Overview of Risks to Critical]||No||U.S. Government Hearing||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Oversight and Investigations)||2012-02-28||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=9318 Critical Infrastructure Cybersecurity: Assessments of Smart Grid Security]||No||U.S. Government Hearing||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Oversight and Investigations)||2012-03-27||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=9393 IT Supply Chain Security: Review of Government and Industry Efforts]||No||U.S. Government Hearing||4.3 [[Supply Chain Issues]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Financial Services (field hearing in Hoover, AL)||2011-06-29||[http://financialservices.house.gov/Calendar/EventSingle.aspx?EventID=246611 Field Hearing: Hacked Off: Helping Law Enforcement Protect Private Financial Information]||No||U.S. Government Hearing||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Financial Services (Subcommittee on Financial Institutions and Consumer Credit)||2011-09-14||[http://financialservices.house.gov/Calendar/EventSingle.aspx?EventID=258792 Combating Cybercriminals]||No||U.S. Government Hearing||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;5.7 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Foreign Affairs (Subcommittee on Oversight and Investigations)||2011-04-15||[http://foreignaffairs.house.gov/hearing_notice.asp?id=1279 Communist Chinese Cyber-Attacks, Cyber-Espionage and Theft of American Technology]||No||U.S. Government Hearing||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;4.13 [[Espionage]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies and Counterterrorism and Intelligence)||2012-04-19||[http://homeland.house.gov/hearing/subcommittee-hearing-dhs-and-doe-national-labs-finding-efficiencies-and-optimizing-outputs The DHS and DOE National Labs: Finding Efficiencies and Optimizing Outputs in Homeland Security Research and Development]||No||U.S. Government Hearing||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies and Counterterrorism and Intelligence)||2012-04-26||[http://homeland.house.gov/hearing/joint-subcommittee-hearing-iranian-cyber-threat-us-homeland Iranian Cyber Threat to U.S. Homeland]||No||U.S. Government Hearing||3.2.1 [[States]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2011-02-11||[http://homeland.house.gov/hearing/subcommittee-hearing-%E2%80%9Cpreventing-chemical-terrorism-building-foundation-security-our-nation Preventing Chemical Terrorism: Building a Foundation of Security at Our Nation’s Chemical Facilities]||No||U.S. Government Hearing||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2011-03-16||[http://homeland.house.gov/hearing/subcommittee-hearing-examining-cyber-threat-critical-infrastructure-and-american-economy Examining the Cyber Threat to Critical Infrastructure and the American Economy]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2011-04-15||[http://homeland.house.gov/hearing/subcommittee-hearing-%E2%80%9C-dhs-cybersecurity-mission-promoting-innovation-and-securing-critical DHS Cybersecurity Mission: Promoting Innovation and Securing Critical Infrastructure]||No||U.S. Government Hearing||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2011-06-24||[http://homeland.house.gov/hearing/subcommittee-hearing-examining-homeland-security-impact-obamaadministrations-cybersecurity Examining the Homeland Security Impact of the Obama Administration’s Cybersecurity Proposal]||No||U.S. Government Hearing||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2011-12-06||[http://homeland.house.gov/hearing/subcommittee-hearing-hearing-draft-legislative-proposal-cybersecurity Hearing on Draft Legislative Proposal on Cybersecurity]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2012-02-01||[http://homeland.house.gov/markup/subcommittee-markup-hr-3674 Consideration and Markup of H.R. 3674]||No||U.S. Government Hearing||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technology)||2011-10-06||[http://homeland.house.gov/hearing/cloud-computing-what-are-security-implications Cloud Computing: What are the Security Implications?]||No||U.S. Government Hearing||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;4.13 [[Espionage]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection, and Security Technologies)||2011-05-26||[http://homeland.house.gov/hearing/subcommittee-hearing-%E2%80%9Cunlocking-safety-act%E2%80%99s-potential-promote-technology-and-combat Unlocking the SAFETY Act’s Potential to Promote Technology and Combat Terrorism ]||No||U.S. Government Hearing||4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Oversight, Investigations and Management)||2012-04-24||[http://homeland.house.gov/hearing/subcommittee-hearing-america-under-cyber-attack-why-urgent-action-needed America is Under Cyber Attack: Why Urgent Action is Needed]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.2 [[Actors and Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Oversight and Government Reform||2011-07-07||[http://oversight.house.gov/hearing/cybersecurity-assessing-the-nations-ability-to-address-the-growing-cyber-threat/ Cybersecurity: Assessing the Nation’s Ability to Address the Growing Cyber Threat]||No||U.S. Government Hearing||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Oversight and Government Reform (Subcommittee on National Security, Homeland Defense and Foreign Operations)||2011-05-25||[http://oversight.house.gov/hearing/cybersecurity-assessing-the-immediate-threat-to-the-united-states/ Cybersecurity: Assessing the Immediate Threat to the United States]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Science, Space and Technology||2011-07-21||[http://science.house.gov/markup/full-committee-%E2%80%93-markup Markup on H.R. 2096, Cybersecurity Enhancement Act of 2011]||No||U.S. Government Hearing||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Science, Space and Technology (Subcommittee on Research and Science Education)||2011-05-25||[http://science.house.gov/hearing/subcommittee-research-and-science-education-subcommittee-technology-and-innovation-%E2%80%93-joint Protecting Information in the Digital Age: Federal Cybersecurity Research and Development Efforts]||No||U.S. Government Hearing||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Science, Space, and Technology (Subcommittee on Investigations and Oversight)||2012-02-29||[http://science.house.gov/hearing/subcommittee-investigations-and-oversight-hearing-nasa-cybersecurity-examination-agency%E2%80%99s NASA Cybersecurity: An Examination of the Agency’s Information Security]||No||U.S. Government Hearing||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Science, Space, and Technology (Subcommittee on Technology and Innovation)||2011-09-21||[http://science.house.gov/hearing/technology-and-innovation-subcommittee-hearing-cloud-computing The Cloud Computing Outlook]||No||U.S. Government Hearing||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Small Business (Subcommittee on Healthcare and Technology)||2011-12-01||[http://smallbusiness.house.gov/Calendar/EventSingle.aspx?EventID=270278 Cyber Security: Protecting Your Small Business]||No||U.S. Government Hearing||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on the Judiciary||2011-11-16||[http://judiciary.house.gov/hearings/hear_11162011.html Combating Online Piracy (H.R. 3261, Stop the Online Piracy Act)]||No||U.S. Government Hearing||4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on the Judiciary (Subcommittee on Crime, Terrorism and Homeland Security)||2011-11-15||[http://judiciary.house.gov/hearings/hear_11152011.html Cybersecurity: Protecting America’s New Frontier]||No||U.S. Government Hearing||4.10 [[Privacy]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on the Judiciary (Subcommittee on Intellectual Property, Competition and the Internet)||2011-05-25||[http://judiciary.house.gov/hearings/hear_05252011.html Cybersecurity: Problems Innovative Solutions to Challenging]||No||U.S. Government Hearing||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Permenant Select Committee on Intelligence||2011-02-10||[https://intelligence.house.gov/hearing/full-committee-world-wide-threats-hearing World Wide Threats]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Permenant Select Committee on Intelligence||2011-10-04||[https://intelligence.house.gov/hearing/cyber-threats-and-ongoing-efforts-protect-nation Cyber Threats and Ongoing Efforts to Protect the Nation]||No||U.S. Government Hearing||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.13.2 [[Industrial|Industrial Espionage]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Permenant Select Committee on Intelligence||2011-12-01||[https://intelligence.house.gov/markup/mark-hr-xxxx-%E2%80%9Ccyber-intelligence-sharing-and-protection-act-2011%E2%80%9D Markup: Draft Bill: Cyber Intelligence Sharing and Protection Act of 2011]||No||U.S. Government Hearing||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Navy ||2010-06-17||[http://www.doncio.navy.mil/PolicyView.aspx?ID=1804 DON (Department of the Navy) Cybersecurity/Information Assurance Workforce Management, Oversight and Compliance ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Armed Services||2012-03-27||[http://armed-services.senate.gov/e_witnesslist.cfm?id=5283 To receive testimony on U.S. Strategic Command and U.S. Cyber Command in review of the Defense Authorization Request for Fiscal Year 2013 and the Future Years Defense Program.]||No||U.S. Government Hearing||3.2.1 [[States]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2011-05-03||[http://www.armed-services.senate.gov/Transcripts/2011/05%20May/11-31%20-%205-3-11.pdf To receive testimony on the health and status of the defense industrial base and its science and technology-related elements]||No||U.S. Government Hearing||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.3 [[Supply Chain Issues]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2012-03-20||[http://www.armed-services.senate.gov/Transcripts/2012/03%20March/12-14%20-%203-20-12.pdf To receive testimony on cybersecurity research and development in review of the Defense Authorization Request for Fiscal Year 2013 and the Future Years Defense Program]||No||U.S. Government Hearing||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Banking, Housing and Urban Affairs||2011-06-21||[http://banking.senate.gov/public/index.cfm?FuseAction=Hearings.Hearing&amp;amp;Hearing_ID=87487cb2-4710-4c09-a1b0-a9e12cda88f1 Cybersecurity and Data Protection in the Financial Sector]||No||U.S. Government Hearing||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Commerce, Science and Transportation||2011-06-29||[http://commerce.senate.gov/public/index.cfm?p=Hearings&amp;amp;ContentRecord_id=e2c2a2ca-91d6-48a2-b5ea-b5c4104bdb97&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=b06c39af-e033-4cba-9221-de668ca1978a&amp;amp;MonthDisplay=6&amp;amp;YearDisplay=2011 Privacy and Data Security: Protecting Consumers in the Modern World]||No||U.S. Government Hearing||4.9 [[Identity Management]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Energy and Natural Resources||2011-03-15||[ Cybersecurity and Critical Electric Infrastructure (closed)]||No||U.S. Government Hearing||3.3.2.1 [[Electricity, Oil and Natural Gas]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Energy and Natural Resources||2011-05-05||[http://www.energy.senate.gov/public/index.cfm/hearings-and-business-meetings?ID=929c1441-da25-c99d-3e27-af20c29e3b4b Cybersecurity of the Bulk-Power System and Electric Infrastructure]||No||U.S. Government Hearing||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Homeland Security and Governmental Affairs||2011-02-17||[http://www.hsgac.senate.gov/hearings/the-homeland-security-departments-budget-submission-for-fiscal-year-2012 Homeland Security Department’s Budget Submission for Fiscal Year 2012]||No||U.S. Government Hearing||&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Homeland Security and Governmental Affairs||2011-03-10||[http://www.hsgac.senate.gov/hearings/information-sharing-in-the-era-of-wikileaks-balancing-security-and-collaboration Information Sharing in the Era of WikiLeaks: Balancing Security and Collaboration]||No||U.S. Government Hearing||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Homeland Security and Governmental Affairs||2011-05-23||[http://www.hsgac.senate.gov/hearings/protecting-cyberspace-assessing-the-white-house-proposal Protecting Cyberspace: Assessing the White House Proposal]||No||U.S. Government Hearing||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Homeland Security and Governmental Affairs||2012-02-16||[http://www.hsgac.senate.gov/hearings/securing-americas-future-the-cybersecurity-act-of-2012 Securing America’s Future: The Cybersecurity Act of 2012]||No||U.S. Government Hearing||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Judiciary||2011-03-30||[http://www.judiciary.senate.gov/hearings/hearing.cfm?id=e655f9e2809e5476862f735da1697f72 Oversight of the Federal Bureau of Investigation]||No||U.S. Government Hearing||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Judiciary||2011-09-07||[http://www.judiciary.senate.gov/hearings/hearing.cfm?id=3d9031b47812de2592c3baeba629084b Cybercrime: Updating the Computer Fraud and Abuse Act to Protect Cyberspace and Combat Emerging Threats]||No||U.S. Government Hearing||3.11 [[Cybercrime]],&amp;lt;br&amp;gt;4.13.2 [[Industrial|Industrial Espionage]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Judiciary||2012-03-13||[http://www.judiciary.senate.gov/hearings/hearing.cfm?id=8b30fa475a5089d793576cd947089793 The Freedom of Information Act: Safeguarding Critical Infrastructure Information and the Public’s Right to Know]||No||U.S. Government Hearing||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Judiciary (Subcommittee on Crime and Terrorism)||2011-04-12||[http://www.judiciary.senate.gov/hearings/hearing.cfm?id=e655f9e2809e5476862f735da16a9959 Cyber Security: Responding to the Threat of Cyber Crime and Terrorism]||No||U.S. Government Hearing||4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Judiciary (Subcommittee on Crime and Terrorism)||2011-06-21||[http://www.judiciary.senate.gov/hearings/hearing.cfm?id=e655f9e2809e5476862f735da16e1bbe Cybersecurity: Evaluating the Administration’s Proposals]||No||U.S. Government Hearing||1. [[Overview]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Small Business and Entrepreneurship||2011-07-25||[http://www.sbc.senate.gov/public/index.cfm?p=Hearings&amp;amp;ContentRecord_id=6b4d51de-dd67-434b-869f-a717b315e6c2&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=43eb5e02-e987-4077-b9a7-1e5a9cf28964&amp;amp;MonthDisplay=7&amp;amp;YearDisplay=2011 Role of Small Business in Strengthening Cybersecurity Efforts in the United States]||No||U.S. Government Hearing||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.7 [[public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| United States Secret Service ||2004||[[Insider_Threat_Study|Insider Threat Study ]]||Yes||U.S. Government Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]]&lt;br /&gt;
|-&lt;br /&gt;
| University of Southern California (USC) Information Sciences Institute, University of California Berkeley (UCB), McAfee Research ||2011-01-13||[http://www.isi.edu/deter/news/news.php?story=20 Design of the DETER Security Testbed ]||No||Independent Report||5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| van Eeten, Michael and Bauer, Johannes M.||2009||[[Emerging_Threats_to_Internet_Security|Emerging Threats to Internet Security: Incentives, Externalities and Policy Implications]]||Yes||Journal Article||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| van Eeten, Michel J. G. ||2008||[[Economics_of_Malware|Economics of Malware ]]||Yes||Non-U.S. Government Report ||4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| Varian, Hal ||2000||[[Managing_Online_Security_Risks|Managing Online Security Risks ]]||Yes||Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| Varian, Hal ||2004||[[System_Reliability_and_Free_Riding|System Reliability and Free Riding ]]||Yes||Book ||4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| Vatis, Michael A.||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059441.pdf The Council of Europe Convention on Cybercrime]||No||Journal Article||4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Verizon ||2010||[[2010_Data_Breach_Investigations_Report|2010 Data Breach Investigations Report ]]||Yes||Industry Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Watts, Sean ||2010||[[Combatant_Status_and_Computer_Network_Attack|Combatant Status and Computer Network Attack ]]||Yes||Journal Article ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| White House||2009||[http://www.whitehouse.gov/assets/documents/Cyberspace_Policy_Review_final.pdf Cyberspace Policy Review: Assuring a Trusted and Resilient Information and Communications Infrastructure]||No||U.S. Government Report||1. [[Overview]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| White House||2011-04||[http://www.whitehouse.gov/sites/default/files/rss_viewer/NSTICstrategy_041511.pdf National Strategy for Trusted Identities in Cyberspace: Enhancing Online Choice, Efficiency, Security, and Privacy]||No||U.S. Government Report||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]]&lt;br /&gt;
|-&lt;br /&gt;
| White House||2011-05||[http://www.whitehouse.gov/sites/default/files/rss_viewer/international_strategy_for_cyberspace.pdf International Strategy for Cyberspace: Prosperity, Security, and Openness in a Networked World]||No||U.S. Government Report||1. [[Overview]]&lt;br /&gt;
|-&lt;br /&gt;
| White House||2012-01||[http://www.whitehouse.gov/sites/default/files/national_strategy_for_global_supply_chain_security.pdf National Strategy for Global Supply Chain Security]||No||U.S. Government Report||4.3 [[Supply Chain Issues]]&lt;br /&gt;
|-&lt;br /&gt;
| White House||2012-02||[http://www.whitehouse.gov/sites/default/files/privacy-final.pdf Consumer Data Privacy in a Networked World: A Framework for Protecting Privacy and Promoting Innovation in the Global Digital Economy]||No||U.S. Government Report||4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2010-12-16||[http://www.whitehouse.gov/sites/default/files/microsites/ostp/pcast-nitrd-report-2010.pdf Designing A Digital Future: Federally Funded Research And Development In Networking And Information Technology ]||No||U.S. Government Report||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2011-02-13||[http://www.cio.gov/documents/Federal-Cloud-Computing-Strategy.pdf Federal Cloud Computing Strategy ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2011-04-15||[http://www.whitehouse.gov/the-press-office/2011/04/15/administration-releases-strategy-protect-online-consumers-and-support-in Administration Releases Strategy to Protect Online Consumers and Support Innovation and Fact Sheet on National Strategy for Trusted Identities in Cyberspace ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2011-04-15||[http://www.whitehouse.gov/sites/default/files/rss_viewer/NSTICstrategy_041511.pdf National Strategy for Trusted Identities in Cyberspace ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2003||[[The_National_Strategy_to_Secure_Cyberspace|The National Strategy to Secure Cyberspace ]]||Yes||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2009||[[Cyberspace_Policy_Review|Cyberspace Policy Review ]]||Yes||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2010||[[The_Comprehensive_National_Cybersecurity_Initiative|The Comprehensive National Cybersecurity Initiative ]]||Yes||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House (Office of Science &amp;amp; Technology Policy) ||2010-12-06||[http://www.whitehouse.gov/blog/2010/12/06/partnership-cybersecurity-innovation Partnership for Cybersecurity Innovation ]||No||U.S. Government Report||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/Office of Management and Budget (OMB) ||2011-12-08||[http://www.cio.gov/fedrampmemo.pdf Security Authorization of Information Systems in Cloud Computing Environments (FedRAMP) ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2009-05-29||[http://www.whitehouse.gov/assets/documents/Cyberspace_Policy_Review_final.pdf Cyberspace Policy Review: Assuring a Trusted and Resilient Communications Infrastructure ]||No||U.S. Government Report ||4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2010-03-02||[http://www.whitehouse.gov/cybersecurity/comprehensive-national-cybersecurity-initiative Comprehensive National Cybersecurity Initiative (CNCI) ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2010-06-25||[http://www.dhs.gov/xlibrary/assets/ns_tic.pdf The National Strategy for Trusted Identities in Cyberspace: Creating Options for Enhanced Online Security and Privacy ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2010-07-06||[http://www.whitehouse.gov/sites/default/files/omb/assets/memoranda_2010/m10-28.pdf Clarifying Cybersecurity Responsibilities ]||No||U.S. Government Report ||5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2010-12-09||[http://www.cio.gov/documents/25-Point-Implementation-Plan-to-Reform-Federal%20IT.pdf 25 Point Implementation Plan to Reform Federal Information Technology Management ]||No||U.S. Government Report ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-02-13||[http://www.cio.gov/documents/Federal-Cloud-Computing-Strategy.pdf Federal Cloud Computing Strategy ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-05-12||[http://www.whitehouse.gov/the-press-office/2011/05/12/fact-sheet-cybersecurity-legislative-proposal Cybersecurity Legislative Proposal (Fact Sheet) ]||No||U.S. Government Report ||4. [[Issues]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-05-16||[http://www.whitehouse.gov/sites/default/files/rss_viewer/international_strategy_for_cyberspace.pdf International Strategy for Cyberspace ]||No||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-09-14||[http://www.whitehouse.gov/sites/default/files/omb/memoranda/2011/m11-33.pdf FY 2012 Reporting Instructions for the Federal Information Security Management Act and Agency Privacy Managementa ]||No||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-10-07||[http://www.whitehouse.gov/the-press-office/2011/10/07/executive-order-structural-reforms-improve-security-classified-networks- Structural Reforms to Improve the Security of Classified Networks and the Responsible Sharing and Safeguarding of Classified Information ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-12-06||[http://www.whitehouse.gov/sites/default/files/microsites/ostp/fed_cybersecurity_rd_strategic_plan_2011.pdf Trustworthy Cyberspace: Strategic Plan for the Federal Cybersecurity Research and Development Program ]||No||U.S. Government Report ||5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Wilshusen, Gregory C. and Powner, David A.||2009||[[Continued_Efforts_are_Needed_to_Protect_Information_Systems_from_Evolving_Threats|Continued Efforts Are Needed to Protect Information Systems from Evolving Threats]]||Yes||U.S. Government Hearing||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Wilson, Clay||2007-03-20||[http://www.fas.org/sgp/crs/natsec/RL31787.pdf Information Operations, Electronic Warfare, and Cyberwar: Capabilities and Related Policy Issues]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Zittrain, Jonathan L. ||2008||[[The_Future_of_the_Internet_and_How_To_Stop_It|The Future of the Internet and How To Stop It ]]||Yes||Book ||4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Centre for Secure Information Technologies||2012||[http://www.csit.qub.ac.uk/sites/CSIT/InnovationatCSIT/Reports/Filetoupload,295595,en.pdf 2nd World Cyber security Technology Research Summit (Belfast 2012)]||No||Independent Report||&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Template:Filtered_Table&amp;diff=6851</id>
		<title>Template:Filtered Table</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Template:Filtered_Table&amp;diff=6851"/>
		<updated>2013-01-25T21:01:33Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;dt_types&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|U.S. Government Report&lt;br /&gt;
|-&lt;br /&gt;
|U.S. Government Hearing&lt;br /&gt;
|-&lt;br /&gt;
|Non-U.S. Government Report&lt;br /&gt;
|-&lt;br /&gt;
|Independent Report&lt;br /&gt;
|-&lt;br /&gt;
|Industry Report&lt;br /&gt;
|-&lt;br /&gt;
|Book&lt;br /&gt;
|-&lt;br /&gt;
|Journal Article&lt;br /&gt;
|-&lt;br /&gt;
|Article&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;dt_categories&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|1. Overview&lt;br /&gt;
|-&lt;br /&gt;
|3. Threats and Actors&lt;br /&gt;
|-&lt;br /&gt;
|3.1 The Threat and Skeptics&lt;br /&gt;
|-&lt;br /&gt;
|3.2 Actors and Incentives&lt;br /&gt;
|-&lt;br /&gt;
|3.2.1 States&lt;br /&gt;
|-&lt;br /&gt;
|3.2.2 Groups&lt;br /&gt;
|-&lt;br /&gt;
|3.2.3 Hacktivists&lt;br /&gt;
|-&lt;br /&gt;
|3.2.4 Terrorists&lt;br /&gt;
|-&lt;br /&gt;
|3.2.5 Criminals and Criminal Organizations&lt;br /&gt;
|-&lt;br /&gt;
|3.3 Security Targets&lt;br /&gt;
|-&lt;br /&gt;
|3.3.1 Public Critical Infrastructure&lt;br /&gt;
|-&lt;br /&gt;
|3.3.1.1 Government Networks (.gov)&lt;br /&gt;
|-&lt;br /&gt;
|3.3.1.2 Military Networks (.mil)&lt;br /&gt;
|-&lt;br /&gt;
|3.3.2 Private Critical Infrastructure&lt;br /&gt;
|-&lt;br /&gt;
|3.3.2.1 Electricity, Oil and Natural Gas&lt;br /&gt;
|-&lt;br /&gt;
|3.3.2.2 Financial Institutions and Networks&lt;br /&gt;
|-&lt;br /&gt;
|3.3.2.3 Transportation&lt;br /&gt;
|-&lt;br /&gt;
|3.3.2.4 Water, Sewer, etc.&lt;br /&gt;
|-&lt;br /&gt;
|3.3.3 Communications&lt;br /&gt;
|-&lt;br /&gt;
|3.3.3.1 Telephone&lt;br /&gt;
|-&lt;br /&gt;
|3.3.3.2 Public Data Networks&lt;br /&gt;
|-&lt;br /&gt;
|3.3.3.3 Cloud Computing&lt;br /&gt;
|-&lt;br /&gt;
|4. Issues&lt;br /&gt;
|-&lt;br /&gt;
|4.1 Metrics&lt;br /&gt;
|-&lt;br /&gt;
|4.2 Economics of Cybersecurity&lt;br /&gt;
|-&lt;br /&gt;
|4.2.1 Risk Management and Investment&lt;br /&gt;
|-&lt;br /&gt;
|4.2.2 Incentives&lt;br /&gt;
|-&lt;br /&gt;
|4.2.3 Insurance&lt;br /&gt;
|-&lt;br /&gt;
|4.2.4 Behavioral Economics&lt;br /&gt;
|-&lt;br /&gt;
|4.2.5 Market Failure&lt;br /&gt;
|-&lt;br /&gt;
|4.3 Supply Chain Issues&lt;br /&gt;
|-&lt;br /&gt;
|4.4 Usability/Human Factors&lt;br /&gt;
|-&lt;br /&gt;
|4.5 Psychology and Politics&lt;br /&gt;
|-&lt;br /&gt;
|4.6 Information Sharing/Disclosure&lt;br /&gt;
|-&lt;br /&gt;
|4.7 Public-Private Cooperation&lt;br /&gt;
|-&lt;br /&gt;
|4.8 Attribution&lt;br /&gt;
|-&lt;br /&gt;
|4.9 Identity Management&lt;br /&gt;
|-&lt;br /&gt;
|4.10 Privacy&lt;br /&gt;
|-&lt;br /&gt;
|4.11 Cybercrime&lt;br /&gt;
|-&lt;br /&gt;
|4.12 Cyberwar&lt;br /&gt;
|-&lt;br /&gt;
|4.13 Espionage&lt;br /&gt;
|-&lt;br /&gt;
|4.13.1 Government to Government&lt;br /&gt;
|-&lt;br /&gt;
|4.13.2 Industrial&lt;br /&gt;
|-&lt;br /&gt;
|4.13.3 Media Perceptions&lt;br /&gt;
|-&lt;br /&gt;
|5. Approaches&lt;br /&gt;
|-&lt;br /&gt;
|5.1 Regulation/Liability&lt;br /&gt;
|-&lt;br /&gt;
|5.2 Private Efforts/Organizations&lt;br /&gt;
|-&lt;br /&gt;
|5.3 Government Organizations&lt;br /&gt;
|-&lt;br /&gt;
|5.4 International Cooperation&lt;br /&gt;
|-&lt;br /&gt;
|5.5 International Law (including Laws of War)&lt;br /&gt;
|-&lt;br /&gt;
|5.6 Deterrence&lt;br /&gt;
|-&lt;br /&gt;
|5.7 Technology&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable datatable&amp;quot; data-type-filter=&amp;quot;{{{1}}}&amp;quot; data-category-filter=&amp;quot;{{{2}}}&amp;quot; data-search-filter=&amp;quot;{{{3}}}&amp;quot; border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;1&amp;quot; cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;border: 1px solid LightGrey;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background-color:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Author/Agency&#039;&#039;&#039;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background-color:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Date&#039;&#039;&#039;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background-color:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Title&#039;&#039;&#039;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Wiki Entry&#039;&#039;&#039;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Type&#039;&#039;&#039;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Category&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| Aloise, Gene et al.||2008||[[Nuclear_Security|Nuclear Security]]||Yes||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]]&lt;br /&gt;
|-&lt;br /&gt;
| Anderson, Ross ||2001||[[Why_Information_Security_is_Hard|Why Information Security is Hard ]]||Yes||Independent Report ||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Anderson, Ross ||2006||[[The_Economics_of_Information_Security|The Economics of Information Security ]]||Yes||Journal Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Anderson, Ross J. ||2008||[[Security_Engineering|Security Engineering ]]||Yes||Book ||3.2 [[Security Targets]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Anderson, Ross, et. al ||2008||[[Security_Economics_and_the_Internal_Market|Security Economics and the Internal Market ]]||Yes||Article||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Arora et al. ||2006||[[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure|Does Information Security Attack Frequency Increase With Vulnerability Disclosure ]]||Yes||Journal Article ||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]]&lt;br /&gt;
|-&lt;br /&gt;
| Aviram, Amitai ||2004||[[Overcoming_Impediments_to_Information_Sharing|Overcoming Impediments to Information Sharing ]]||Yes||Journal Article ||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Barkham, Jason ||2001||[[Information_Warfare_and_International_Law_on_the_Use_of_Force|Information Warfare and International Law on the Use of Force ]]||Yes||Journal Article ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Bauer, Johannes M. and van Eeten, Michel J. G.||2009||[[Cybersecurity|Cybersecurity: Stakeholder Incentives, Externalities, and Policy Options]]||Yes||Journal Article||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Beard, Jack M. ||2009||[[Law_and_War_in_the_Virtual_Era|Law and War in the Virtual Era ]]||Yes||Journal Article ||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Bellovin, Steven M.||2009||[[The_Government_and_Cybersecurity|The Government and Cybersecurity]]||Yes||Journal Article||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;4.7[[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Besunder, Allison A.||2009||[[Best_Practices_for_Data_Protection_and_Privacy|Best Practices for Data Protection and Privacy]]||Yes||Book||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Boebert, W. Earl||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059366.pdf A Survey of Challenges in Attribution]||No||Journal Article||4.8 [[Attribution]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Bohme, Rainer ||2005||[[Cyber-Insurance_Revisited|Cyber-Insurance Revisited ]]||Yes||Independent Report ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.2.3 [[Insurance]],&amp;lt;br&amp;gt;,4.2.5 [[Market Failure]]&lt;br /&gt;
|-&lt;br /&gt;
| Bohme, Rainer ||2006||[[Models_and_Measures_for_Correlation_in_Cyber-Insurance|Models and Measures for Correlation in Cyber-Insurance ]]||Yes||Independent Report ||4.2.3 [[Insurance]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Bohme, Rainer ||2010||[[Modeling_Cyber-Insurance|Modeling Cyber-Insurance ]]||Yes||Independent Report ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.2.3 [[Insurance]],&amp;lt;br&amp;gt;,5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Booz Allen Hamilton and the Economist Intelligence Unit ||2012-01-15||[http://www.cyberhub.com/CyberPowerIndex Cyber Power Index ]||No||Industry Report||4. [[Issues]],&amp;lt;br&amp;gt;4.1 [[Metrics]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Bradley, Curtis A. and Goldsmith, Jack L.||2011||[[Overview_of_International_Law_and_Institutions|Overview of International Law and Institutions]]||Yes||Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Brown, Davis ||2006||[[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict|A Proposal for an International Convention To Regulate the Use of Information Systems in Armed Conflict ]]||Yes||Journal Article ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Burstein, Aaron J.||2008||[[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research|Amending the ECPA to Enable a Culture of Cybersecurity Research]]||Yes||Journal Article||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Business Roundtable||2011-10-11||[http://businessroundtable.org/uploads/studies-reports/downloads/2011_10_Mission_Critical_A_Public-Private_Strategy_for_Effective_Cybersecurity.pdf Mission Critical: A Public-Private Strategy for Effective Cybersecurity ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| Business Software Alliance ||2012-02-02||Global Cloud Computing Scorecard a Blueprint for Economic Opportunity||No||Industry Report||3.3.3.3 [[Cloud Computing]]&lt;br /&gt;
|-&lt;br /&gt;
| Business Software Alliance, Center for Democracy &amp;amp; Technology, U.S. Chamber of Commerce, Internet Security Alliance, Tech America ||2011-03-08||[http://www.cdt.org/files/pdfs/20110308_cbyersec_paper.pdf Improving our Nation’s Cybersecurity through the Public-Private Partnership: a White Paper ]||No||Industry Report||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Cabinet Office (United Kingdom) ||2011-11-11||[http://www.cabinetoffice.gov.uk/sites/default/files/resources/uk-cyber-security-strategy-final.pdf The UK Cyber Security Strategy: Protecting and promoting the UK in a digital world ]||No||Non-U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Camp, L. Jean ||2004||[[Economics_of_Information_Security|Economics of Information Security ]]||Yes||Book ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Camp, L. Jean ||2004||[[Pricing_Security|Pricing Security ]]||Yes||Book ||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Center for a New American Security||2012-06-11||[http://www.cnas.org/node/6405 America’s Cyber Future: Security and Prosperity in the Information Age ]||No||Independent Report||1. [[Overview]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Center for Strategic and International Studies ||2008||[[Securing_Cyberspace_for_the_44th_Presidency|Securing Cyberspace for the 44th Presidency ]]||Yes||Independent Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Centre for Secure Information Technologies||2011||[http://www.csit.qub.ac.uk/sites/CSIT/InnovationatCSIT/Reports/Filetoupload,295594,en.pdf World Cybersecurity Technology Research Summit (Belfast 2011) ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| Cetron, Marvin J. and Davies, Owen||2009||[[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity|World War 3.0: Ten Critical Trends for Cybersecurity]]||Yes||Journal Article||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Clark, David and Landau, Susan||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059365.pdf Untangling Attribution]||No||Journal Article||4.8 [[Attribution]],&amp;lt;br&amp;gt;5.6 [[Deterrence]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Clarke, Richard A. ||2010||[[Cyber_War|Cyber War ]]||Yes||Book ||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Clinton, Larry ||Undated ||[[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security|Cyber-Insurance Metrics and Impact on Cyber-Security ]]||Yes||Independent Report ||4.2.3 [[Insurance]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Cloud Security Alliance ||2009-12||[http://www.cloudsecurityalliance.org/csaguide.pdf Security Guidance for Critical Areas of Focus in Cloud Computing V2.1 ]||No||Independent Report||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Cohen, Geoff||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059445.pdf Targeting Third Party Collaboration]||No||Journal Article||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| Computer Economics, Inc. ||2007||[[2007_Malware_Report|2007 Malware Report ]]||Yes||Industry Report ||4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| Computing Research Association ||2003-||[[Four_Grand_Challenges_in_Trustworthy_Computing|Four Grand Challenges in Trustworthy Computing ]]||Yes||Independent Report ||4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.9 [[Identity Management]]&lt;br /&gt;
|-&lt;br /&gt;
| Cornish, Paul||2009||[[Cyber_Security_and_Politically,_Socially_and_Religiously_Motivated_Cyber_Attacks|Cyber Security and Politically, Socially and Religiously Motivated Cyber Attacks]]||Yes||Non-U.S. Government Report||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Cornish, Paul et al.||2009||[[Cyberspace_and_the_National_Security_of_the_United_Kingdom|Cyberspace and the National Security of the United Kingdom - Threats and Responses]]||Yes||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Council on Foreign Relations ||2010-07-15||[http://i.cfr.org/content/publications/attachments/Knake%20-Testimony%20071510.pdf Untangling Attribution: Moving to Accountability in Cyberspace [Testimony]]||No||Independent Report||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;4.8 [[Attribution]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| CSIS Commission on Cybersecurity for the 44th Presidency, Center for Strategic and International Studies ||2011-01||[http://csis.org/files/publication/110128_Lewis_CybersecurityTwoYearsLater_Web.pdf Cybersecurity Two Years Later ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5. [[Approaches]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Cyber Security Forum Initiative ||2011-05-09||[http://www.unveillance.com/wp-content/uploads/2011/05/Project_Cyber_Dawn_Public.pdf Cyber Dawn: Libya ]||No||Industry Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Commerce ||2011-06-14||[http://www.nist.gov/nstic/2012-nstic-governance-recs.pdf Models for a Governance Structure for the National Strategy for Trusted Identities in Cyberspace ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Commerce ||2010||[[Defense_Industrial_Base_Assessment|Defense Industrial Base Assessment ]]||Yes||U.S. Government Report ||3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Commerce, Internet Policy Task Force||2011-06||[http://www.nist.gov/itl/upload/Cybersecurity_Green-Paper_FinalVersion.pdf Cybersecurity, Innovation and the Internet Economy]||No||U.S. Government Report||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2011-07-14||[http://www.defense.gov/news/d20110714cyber.pdf Department of Defense Strategy for Operating in Cyberspace ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2011-11-15||[http://www.defense.gov/home/features/2011/0411_cyberstrategy/docs/NDAA%20Section%20934%20Report_For%20webpage.pdf Department of Defense Cyberspace Policy Report : A Report to Congress Pursuant to the National Defense Authorization Act for Fiscal Year 2011, Section 934 ]||No||U.S. Government Report||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2012-02-16||[http://www.fas.org/sgp/othergov/dod/5200_01v1.pdf DOD Information Security Program: Overview, Classification, and Declassification ]||No||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2012-04-11||[http://www.nsci-va.org/CyberReferenceLib/2011-04-Cyber%20Ops%20Personnel.pdf Cyber Operations Personnel Report (DoD) ]||No||U.S. Government Report||&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||1999||[[An_Assessment_of_International_Legal_Issues_in_Information_Operations|An Assessment of International Legal Issues in Information Operations ]]||Yes||U.S. Government Report ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2005-||[[Strategy_for_Homeland_Defense_and_Civil_Support|Strategy for Homeland Defense and Civil Support ]]||Yes||U.S. Government Report ||3.2.4 [[Terrorists]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2007||[[Mission_Impact_of_Foreign_Influence_on_DoD_Software|Mission Impact of Foreign Influence on DoD Software ]]||Yes||U.S. Government Report ||3.2.4 [[Terrorists]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2011-04||[http://www.nsci-va.org/CyberReferenceLib/2011-04-Cyber%20Ops%20Personnel.pdf Cyber Operations Personnel Report (DOD) ]||No||U.S. Government Report ||&lt;br /&gt;
|-&lt;br /&gt;
| Department of Energy||2012-04||[http://energy.gov/sites/prod/files/OAS-RA-12-04.pdf The Department&#039;s Management of the Smart Grid Investment Grant Program]||No||U.S. Government Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Energy (DOE) Inspector General ||2012-01-01||[http://energy.gov/ig/downloads/departments-management-smart-grid-investment-grant-program-oas-ra-12-04 The Department’s Management of the Smart Grid Investment Grant Program ]||No||U.S. Government Report ||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Energy, Idaho National Laboratory ||2010-05-01||[http://www.fas.org/sgp/eprint/nstb.pdf NSTB Assessments Summary Report: Common Industrial Control System Cyber Security Weaknesses ]||No||U.S. Government Report||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Energy, Office of Electricity Delivery &amp;amp; Energy Reliability ||Undated||[http://energy.gov/oe/technology-development/energy-delivery-systems-cybersecurity Cybersecurity for Energy Delivery Systems Program ]||No||U.S. Government Report ||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2009-09-16||[http://www.cyber.st.dhs.gov/docs/National_Cyber_Leap_Year_Summit_2009_Co-Chairs_Report.pdf National Cyber Leap Year Summit 2009: Co-Chairs&#039; Report]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.8 [[Attribution]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2007-06||[http://www.oig.dhs.gov/assets/Mgmt/OIG_07-48_Jun07.pdf Challenges Remain in Securing the Nation’s Cyber Infrastructure]||No||U.S. Government Report||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2009-11||[http://www.cyber.st.dhs.gov/docs/DHS-Cybersecurity-Roadmap.pdf A Roadmap for Cybersecurity Research]||No||U.S. Government Report||1. [[Overview]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2010-08||[http://www.dhs.gov/xoig/assets/mgmtrpts/OIG_10-111_Aug10.pdf DHS Needs to Improve the Security Posture of Its Cybersecurity Program Systems]||No||U.S. Government Report||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2010-09||[http://www.federalnewsradio.com/pdfs/NCIRP_Interim_Version_September_2010.pdf National Cyber Incident Response Plan]||No||U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2011-11||[http://www.dhs.gov/xlibrary/assets/nppd/blueprint-for-a-secure-cyber-future.pdf Blueprint for a Secure Cyber Future: The Cybersecurity Strategy for the Homeland Security Enterprise]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security ||2003||[[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets|The National Strategy for the Physical Protection of Critical Infrastructures and Key Assets ]]||Yes||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security ||2009||[[A_Roadmap_for_Cybersecurity_Research|A Roadmap for Cybersecurity Research ]]||Yes||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Justice||2011-04||[http://www.justice.gov/oig/reports/FBI/a1122r.pdf The Federal Bureau of Investigation&#039;s Ability to Address the National Security Cyber Intrusion Threat]||No||U.S. Government Report||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Deputy Chief of Staff for Intelligence ||2006||[[Critical_Infrastructure_Threats_and_Terrorism|Critical Infrastructure Threats and Terrorism ]]||Yes||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Dörmann, Knut ||2004||[[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks|Applicability of the Additional Protocols to Computer Network Attacks ]]||Yes||Independent Report ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Douglas Maughan||2010||[[The_Need_for_a_National_Cybersecurity_Research_and_Development_Agenda|The Need for a National Cybersecurity Research and Development Agenda]]||Yes||Article||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Dunlap Charles J, Jr   ||2011||[[Perspectives_for_Cyber_Strategists_on_Law_for_Cyberwar|Perspectives for Cyber Strategists on Law for Cyberwar]]||Yes||Journal Article||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Dunlap, Charles J. Jr. ||2009||[[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century|Towards a Cyberspace Legal Regime in the Twenty-First Century ]]||Yes||Article||4.5 [[Psychology and Politics]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| EastWest Institute ||2011-02-03||[http://vialardi.org/nastrazzuro/pdf/US-Russia.pdf Working Towards Rules for Governing Cyber Conflict: Rendering the Geneva and Hague Conventions in Cyberspace ]||No||Independent Report||3.2.1 [[States]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Energetics Inc. ||2006||[[Roadmap_to_Secure_Control_Systems_in_the_Energy_Sector|Roadmap to Secure Control Systems in the Energy Sector ]]||Yes||Independent Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Energy Sector Control Systems Working Group||2011-09||[http://www.cyber.st.dhs.gov/wp-content/uploads/2011/09/Energy_Roadmap.pdf Roadmap to Achieve Energy Delivery Systems Cybersecurity]||No||U.S. Government Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| ENISA||2010||[[Introduction_to_Country_Reports|Introduction to Country Reports]]||Yes||Non-U.S. Government Report||3.2.1 [[States]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Epstein, Richard A. ||2008||[[Cybersecurity_in_the_Payment_Card_Industry|Cybersecurity in the Payment Card Industry ]]||Yes||Journal Article ||3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| European Network and Information Security Agency ||2010-10-07||[http://www.enisa.europa.eu/media/press-releases/stuxnet-analysis Stuxnet Analysis ]||No||Non-U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| European Network and Information Security Agency (ENISA) ||2011-04-11||[http://www.enisa.europa.eu/act/res/other-areas/inter-x/report/interx-report Resilience of the Internet Interconnection Ecosystem, at: ]||No||Non-U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Federal CIO Council ||2012-01-04||[http://www.gsa.gov/portal/category/102371 Federal Risk and Authorization Management Program (FedRAMP) ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Federal Communications Commission (FCC) ||2010-04-21||[http://hraunfoss.fcc.gov/edocs_public/attachmatch/DOC-305618A1.doc Explore the reliability and resiliency of commercial broadband communications networks ]||No||U.S. Government Report||3.3.3 [[Communications]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Federal Communications Commission (FCC) ||2011-06-03||[ftp://ftp.fcc.gov/pub/Daily_Releases/Daily_Business/2011/db0610/DOC-307454A1.txt FCC&#039;s Plan for Ensuring the Security of Telecommunications Networks ]||No||U.S. Government Report||&lt;br /&gt;
|-&lt;br /&gt;
| Financial Services Sector Coordinating Council for Critical Infrastructure Protection ||2008||[[Research_Agenda_for_the_Banking_and_Finance_Sector|Research Agenda for the Banking and Finance Sector ]]||Yes||Independent Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.1 [[Metrics]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| Fischer, Eric A.&amp;lt;br /&amp;gt;CRS||2012-04-23||[http://www.fas.org/sgp/crs/natsec/R42114.pdf Federal Laws Relating to Cybersecurity: Discussion of Proposed Revisions]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Franklin, Jason, et. al ||2007||[[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants|An Inquiry into the Nature and Causes of the Wealth of Internet Miscreants ]]||Yes||Independent Report ||3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| Gandal, Neil ||2008||[[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security|An Introduction to Key Themes in the Economics of Cyber Security ]]||Yes||Book ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2003-08-27||[http://www.gao.gov/products/GAO-03-760 Efforts to Improve Information sharing Need to Be Strengthened ]||No||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2004-05-28||[http://www.gao.gov/assets/160/157541.pdf Technology Assessment: Cybersecurity for Critical Infrastructure Protection]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2008-07-31||[http://www.gao.gov/assets/280/279084.pdf Cyber Analysis And Warning: DHS Faces Challenges in Establishing a Comprehensive National Capability]||No||U.S. Government Report||5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2009-09-24||[http://www.gao.gov/new.items/d09969.pdf Critical Infrastructure Protection: Current Cyber Sector-Specific Planning Approach Needs Reassessment]||No||U.S. Government Report||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2009-11-17||[http://www.gao.gov/products/GAO-10-230t Continued Efforts Are Needed to Protect Information Systems from Evolving Threats ]||No||U.S. Government Report ||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-03-05||[http://www.gao.gov/products/GAO-10-338 Cybersecurity: Progress Made But Challenges Remain in Defining and Coordinating the Comprehensive National Initiative ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-03-16||[http://www.gao.gov/products/GAO-11-463T Cybersecurity: Continued Attention Is Needed to Protect Federal Information Systems from Evolving Threats ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-03-24||[http://www.gao.gov/products/GAO-10-536t Information Security: Concerted Response Needed to Resolve Persistent Weaknesses, at: ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-04-12||[http://www.gao.gov/products/GAO-10-237 Concerted Effort Needed to Consolidate and Secure Internet Connections at Federal Agencies ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-06-03||[http://www.gao.gov/assets/310/305208.pdf Cybersecurity: Key Challenges Need to Be Addressed to Improve Research and Development]||No||U.S. Government Report||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-06-16||[http://www.gao.gov/products/GAO-10-834t Continued Attention Is Needed to Protect Federal Information Systems from Evolving Threats ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-07-01||[http://www.gao.gov/products/GAO-10-513 Federal Guidance Needed to Address Control Issues With Implementing Cloud Computing ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-07-15||[http://www.gao.gov/products/GAO-10-628 Critical Infrastructure Protection: Key Private and Public Cyber Expectations Need to Be Consistently Addressed ]||No||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-08-02||[http://www.gao.gov/products/GAO-10-606 United States Faces Challenges in Addressing Global Cybersecurity and Governance ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-09-15||[http://www.gao.gov/products/GAO-10-916 Information Security: Progress Made on Harmonizing Policies and Guidance for National Security and Non-National Security Systems ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-09-23||[http://www.gao.gov/products/GAO-10-772 DHS Efforts to Assess and Promote Resiliency Are Evolving but Program Management Could Be Strengthened ]||No||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-10-06||[http://www.gao.gov/products/GAO-11-24 Cyberspace Policy: Executive Branch Is Making Progress Implementing 2009 Policy Review Recommendations, but Sustained Leadership Is Needed ]||No||U.S. Government Report ||5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-11-30||[http://www.gao.gov/products/GAO-11-43 Information Security: Federal Agencies Have Taken Steps to Secure Wireless Networks, but Further Actions Can Mitigate Risk ]||No||U.S. Government Report ||3.3.3 [[Communications]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-01-12||[http://www.gao.gov/products/GAO-11-117 Electricity Grid Modernization: Progress Being Made on Cybersecurity Guidelines, but Key Challenges Remain to be Addressed ]||No||U.S. Government Report ||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-03-16||[http://www.gao.gov/products/GAO-11-463T Cybersecurity: Continued Attention Needed to Protect Our Nation&#039;s Critical Infrastructure and Federal Information Systems ]||No||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-07-08||[http://www.gao.gov/products/GAO-11-149 Information Security: State Has Taken Steps to Implement a Continuous Monitoring Application, but Key Challenges Remain ]||No||U.S. Government Report ||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-07-25||[http://www.gao.gov/products/GAO-11-75 Defense Department Cyber Efforts: DoD Faces Challenges in Its Cyber Activities ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-07-26||[http://www.gao.gov/products/GAO-11-463T Continued Attention Needed to Protect Our Nation’s Critical Infrastructure ]||No||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-07-29||[http://www.gao.gov/products/GAO-11-695R Defense Department Cyber Efforts: Definitions, Focal Point, and Methodology Needed for DoD to Develop Full-Spectrum Cyberspace Budget Estimates ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-10-03||[http://www.gao.gov/products/GAO-12-137 Information Security: Weaknesses Continue Amid New Federal Efforts to Implement Requirements ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-10-05||[http://www.gao.gov/products/GAO-12-130T Information Security: Additional Guidance Needed to Address Cloud Computing Concerns ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-10-17||[http://www.gao.gov/products/GAO-11-634 Federal Chief Information Officers: Opportunities Exist to Improve Role in Information Technology Management ]||No||U.S. Government Report ||5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-11-29||[http://www.gao.gov/products/GAO-12-8 Cybersecurity Human Capital: Initiatives Need Better Planning and Coordination, at: ]||No||U.S. Government Report ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-12-09||[http://www.gao.gov/products/GAO-12-92 Critical Infrastructure Protection: Cybersecurity Guidance Is Available, but More Can Be Done to Promote Its Use ]||No||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2012-01-13||[http://www.gao.gov/assets/590/587681.pdf Defense Contracting: Improved Policies and Tools Could Help Increase Competition on DOD&#039;s National Security Exception Procurements]||No||U.S. Government Report||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2012-02-28||[http://www.csit.qub.ac.uk/media/pdf/Filetoupload,252359,en.pdf Cybersecurity: Challenges to Securing the Modernized Electricity Grid ]||No||Non-U.S. Government Report ||&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2009||[[Critical_Infrastructure_Protection|Critical Infrastructure Protection - Current Cyber Sector-Specific Planning Approach Needs Reassessment]]||Yes||U.S. Government Report||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2009-07||[http://www.gao.gov/new.items/d09546.pdf Information Security: Agencies Continue to Report Progress, but Need to. Mitigate Persistent Weaknesses]||No||U.S. Government Report||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2009-09||[http://www.gao.gov/new.items/d09617.pdf Information Security: Concerted Effort Needed to Improve Federal Performance Measures]||No||U.S. Government Report||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010||[[Information_Security|Information Security - Concerted Effort Needed to Consolidate and Secure Internet Connections at Federal Agencies]]||Yes||U.S. Government Report||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO ||2011-10-05||[http://www.gao.gov/products/GAO-12-130T Information Security: Additional Guidance Needed to Address Cloud Computing Concerns ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Geer, Daniel E. and Conway, Daniel G.||2010||[[Nothing_Ventured,_Nothing_Gained|Nothing Ventured, Nothing Gained]]||Yes||Journal Article||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Gellman, Robert||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059444.pdf Civil Liberties and Privacy Implications of Policies to Prevent Cyberattacks ]||No||Journal Article||4.8 [[Attribution]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2010-07-15||[http://www.gao.gov/products/GAO-10-628 Critical Infrastructure Protection: Key Private and Public Cyber Expectations Need to Be Consistently Addressed ]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2011-01-12||[http://www.gao.gov/products/GAO-11-117 Electricity Grid Modernization: Progress Being Made on Cybersecurity Guidelines, but Key Challenges Remain to be Addressed ]||No||U.S. Government Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2011-03-16||[http://www.gao.gov/products/GAO-11-463T Cybersecurity: Continued Attention Needed to Protect Our Nation&#039;s Critical Infrastructure and Federal Information Systems ]||No||U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2011-07-29||[http://www.gao.gov/products/GAO-11-695R Defense Department Cyber Efforts: Definitions, Focal Point, and Methodology Needed for DOD to Develop Full-Spectrum Cyberspace Budget Estimates ]||No||U.S. Government Report ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2011-11-29||[http://www.gao.gov/products/GAO-12-8 Cybersecurity Human Capital: Initiatives Need Better Planning and Coordination ]||No||U.S. Government Report||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2011-12-09||[http://www.gao.gov/products/GAO-12-92 Critical Infrastructure Protection: Cybersecurity Guidance Is Available, but More Can Be Done to Promote Its Use ]||No||U.S. Government Report ||&lt;br /&gt;
|-&lt;br /&gt;
| General Services Administration (GSA) ||2012-02-07||[http://www.gsa.gov/graphics/staffoffices/FedRAMP_CONOPS.pdf Concept of Operations: FedRAMP ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Grady, Mark F. ||2006||[[The_Law_and_Economics_of_Cybersecurity|The Law and Economics of Cybersecurity ]]||Yes||Book ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Graham David E   ||2010||[[Cyber_Threats_and_the_Law_of_War| Cyber Threats and the Law of War]]||Yes||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Granick, Jennifer Stisa ||2005||[[The_Price_of_Restricting_Vulnerability_Publications|The Price of Restricting Vulnerability Publications ]]||Yes||Journal Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Hollis, Duncan B. ||2007||[[Why_States_Need_an_International_Law_for_Information_Operations|Why States Need an International Law for Information Operations ]]||Yes||Journal Article ||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;4.13.1 [[Government to Government|Government to Government Espionage]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| HP TippingPoint DVLabs ||2010||[[2010_Top_Cyber_Security_Risks_Report|2010 Top Cyber Security Risks Report ]]||Yes||Industry report ||4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| IEEE/EastWest Institute ||2010-05-26||[http://www.ieee-rogucci.org/files/The%20ROGUCCI%20Report.pdf The Reliability of Global Undersea Communications Cable Infrastructure (The Rogucci Report) ]||No||Independent Report||3.3.3 [[Communications]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Institute for Information Infrastructure Protection ||2003||[[Cyber_Security_Research_and_Development_Agenda|Cyber Security Research and Development Agenda ]]||Yes||Independent Report ||4.1 [[Metrics]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Institute for Science and International Security ||2010-12-22||[http://isis-online.org/isis-reports/detail/did-stuxnet-take-out-1000-centrifuges-at-the-natanz-enrichment-plant/ Did Stuxnet Take Out 1,000 Centrifuges at the Natanz Enrichment Plant? Preliminary Assessment ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| International Instrument Users Association (WIB) ||2010-11-10||[http://www.isssource.com/wib/ WIB Security Standard Released ]||No||Industry Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| International Telecommunications Union ||2012-02-10||[http://www.itu.int/ITU-D/cyb/cybersecurity/docs/itu-toolkit-cybercrime-legislation.pdf ITU Toolkit for Cybercrime Legislation ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| James Clapper, Director of National Intelligence ||2011-02-10||[http://www.dni.gov/testimonies/20110210_testimony_clapper.pdf Worldwide Threat Assessment of the U.S. Intelligence Community (Testimony) ]||No||U.S. Government Report||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.2 [[Actors and Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Johnson, Eric M. ||2008||[[Managing_Information_Risk_and_the_Economics_of_Security|Managing Information Risk and the Economics of Security ]]||Yes||Book ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Johnson, Vincent R. ||2005||[[Cybersecurity,_Identity_Theft,_and_the_Limits_of_Tort_Liability|Cybersecurity, Identity Theft, and the Limits of Tort Liability ]]||Yes||Journal Article ||4.9 [[Identity Management]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Joint Workshop of the National Security Threats in Cyberspace and the National Strategy Forum ||2009-09-15||[http://nationalstrategy.com/Portals/0/National%20Security%20Threats%20in%20Cyberspace%20FINAL%2009-15-09.pdf National Security Threats in Cyberspace ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| Joseph S. Nye||2010||[[Cyber_Power|Cyber Power]]||Yes||Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Journal of Strategic Studies ||2011-10-05||[http://www.tandfonline.com/doi/abs/10.1080/01402390.2011.6089393 Cyber War Will Not Take Place ]||No||Journal Article||&lt;br /&gt;
|-&lt;br /&gt;
| Kelly A. Gable||2010||[[Cyber-Apocalypse_Now|Cyber-Apocalypse Now - Securing the Internet Against Cyberterrorism and Using Universal Jurisdiction as a Deterrent]]||Yes||Journal Article||3.2.4 [[Terrorists]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Kerr, Paul K. et al.&amp;lt;br /&amp;gt;CRS||2010-12-09||[http://www.fas.org/sgp/crs/natsec/R41524.pdf The Stuxnet Computer Worm: Harbinger of an Emerging Warfare Capability]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.4 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Kesan, Jay P. and Hayes, Carol M.||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059446.pdf Thinking Through Active Defense in Cyberspace ]||No||Journal Article||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Kobayashi, Bruce H.||2005||[[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods|An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and other Public Security Goods]]||Yes||Journal Article||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Kobayashi, Bruce H. ||2006||[[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods|An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and Other Public Security Goods ]]||Yes||Journal Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Korns, Stephen W. ||2009||[[Cyber_Operations|Cyber Operations ]]||Yes||Journal Article ||4.8 [[Attribution]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Kramer, Franklin D., et. al ||2009||[[Cyberpower_and_National_Security|Cyberpower and National Security ]]||Yes||Book ||1. [[Overview]]&lt;br /&gt;
|-&lt;br /&gt;
| Kundra, Vivek||2010-12-09||[http://www.cio.gov/documents/25-point-implementation-plan-to-reform-federal%20it.pdf 25 Point Implementation Plan to Reform Federal Information Technology Management]||No||U.S. Government Report||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Kundra, Vivek||2011-02-08||[http://www.cio.gov/documents/federal-cloud-computing-strategy.pdf Federal Cloud Computing Strategy]||No||U.S. Government Report||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Lan, Tang et al.||2010||[[Global_Cyber_Deterrence|Global Cyber Deterrence: Views from China, the U.S., Russia, India, and Norway]]||Yes||Independent Report||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Lernard, Thomas M. ||2005||[[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches|An Economic Analysis of Notification Requirements for Data Security Breaches ]]||Yes||Independent Report ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Lernard, Thomas M. ||2006||[[Much_Ado_About_Notification|Much Ado About Notification ]]||Yes||Journal Article ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Lewis, James Andrews||2005||[[Cyber_Security_and_Regulation_in_the_United_States|Aux armes, citoyens: Cyber Security and Regulation in the United States]]||Yes||Journal Article||3.3.1 [[Public Critical Infrastructure,&amp;lt;br&amp;gt;3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;3.3.2.3 [[Transportation]]&lt;br /&gt;
|-&lt;br /&gt;
| Libicki, Martin||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059490.pdf Pulling Punches in Cyberspace]||No||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
|Lin, Herbert||2012||[[Media:Lin-Cyber_Conflict_and_National_Security_2012.pdf|Cyber Conflict and National Security]]||No||Article||&lt;br /&gt;
|-&lt;br /&gt;
| Lukasik, Stephen J.||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059438.pdf A Framework for Thinking about Cyber Conflict and Cyber Deterrence with Possible Declatory Policies for these Domain]||No||Journal Article||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Massachusetts Institute of Technology (MIT) ||2011-12-05||[http://web.mit.edu/mitei/research/studies/the-electric-grid-2011.shtml The Future of the Electric Grid ]||No||Independent Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| McAfee ||2011-08-02||[http://www.mcafee.com/us/resources/white-papers/wp-operation-shady-rat.pdf Revealed: Operation Shady RAT: an Investigation Of Targeted Intrusions Into 70+ Global Companies, Governments, and Non-Profit Organizations During the Last 5 Years ]||No||Industry Report||3.2.1 [[States]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.13 [[Espionage]]&lt;br /&gt;
|-&lt;br /&gt;
| McAfee ||2012-02-01||[http://www.mcafee.com/us/resources/reports/rp-sda-cyber-security.pdf?cid=WBB048 Cyber-security: The Vexed Question of Global Rules: An Independent Report on Cyber-Preparedness Around the World ]||No||Industry Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| McAfee and Center for Strategic and International Studies (CSIS) ||2011-04-21||[http://www.mcafee.com/us/resources/reports/rp-critical-infrastructure-protection.pdf In the Dark: Crucial Industries Confront Cyberattacks ]||No||Industry Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt; 4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| McAfee and the Security Defense Agenda||2012-02-12||[http://www.mcafee.com/us/resources/reports/rp-sda-cyber-security.pdf Cyber-security: The Vexed Question of Global Rules: An Independent Report on Cyber-Preparedness Around the World]||No||Industry Report||1. [[Overview]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| McAfee, Inc. ||2010||[[McAfee_Threats_Report|McAfee Threats Report ]]||Yes||Industry Report ||3.2.3 [[Hacktivists]],&amp;lt;br&amp;gt;3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| McDermott, Rose||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059442.pdf Decision Making Under Uncertainty]||No||Journal Article||4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;4.5 [[Psychology and Politics]],&amp;lt;br&amp;gt;4.8 [[Attribution]]&lt;br /&gt;
|-&lt;br /&gt;
| Microsoft||2010-11||[http://cdn.globalfoundationservices.com/documents/InformationSecurityMangSysforMSCloudInfrastructure.pdf Information Security Management System for Microsoft Cloud Infrastructure ]||No||Industry Report||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Mitre Corp (JASON Program Office) ||2010-11||[http://www.fas.org/irp/agency/dod/jason/cyber.pdf Science of Cyber-Security ]||No||Independent Report||1. [[Overview]],&amp;lt;br&amp;gt;4. [[Issues]]&lt;br /&gt;
|-&lt;br /&gt;
| Moore, Tyler||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059364.pdf Introducing the Economics of Cybersecurity: Principles and Policy Options]||No||Journal Article||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Moore, Tyler ||2007||[[Examining_the_Impact_of_Website_Take-down_on_Phishing|Examining the Impact of Website Take-down on Phishing ]]||Yes||Independent Report ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Moore, Tyler ||2008||[[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing|The Consequence of Non-Cooperation in the Fight Against Phishing ]]||Yes||Independent Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]]&lt;br /&gt;
|-&lt;br /&gt;
| Moore, Tyler ||2009||[[The_Impact_of_Incentives_on_Notice_and_Take-down|The Impact of Incentives on Notice and Take-down ]]||Yes||Book ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Moore, Tyler, et. al ||2009||[[The_Economics_of_Online_Crime|The Economics of Online Crime ]]||Yes||Journal Article ||3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| Morgan, Patrick M. ||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059436.pdf Applicability of Traditional Deterrence Concepts and Theory to the Cyber Realm ]||No||Journal Article||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]],&amp;lt;br&amp;gt;5.6 [[Deterrence ]]&lt;br /&gt;
|-&lt;br /&gt;
| National Association of Secretaries of State ||2012-01-12||[http://www.nass.org/index.php?option=com_docman&amp;amp;task=doc_download&amp;amp;gid=1257 Developing State Solutions to Business Identity Theft: Assistance, Prevention and Detection Efforts by Secretary of State Offices ]||No||Independent Report||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Cyber Defense Initiative ||2009||[[National_Cyber_Defense_Financial_Services_Workshop_Report|National Cyber Defense Financial Services Workshop Report ]]||Yes||Independent Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Cyber Security Alliance and Microsoft ||2011-05-13||[http://www.staysafeonline.org/sites/default/files/resource_documents/2011%20National%20K-12%20Study%20Final_0.pdf 2011 State of Cyberethics, Cybersafety and Cybersecurity Curriculum in the U.S. Survey ]||No||Industry Report||4.4 [[Usability/Human Factors]]&lt;br /&gt;
|-&lt;br /&gt;
| National Cyber Security Summit Task Force ||2004||[[Information_Security_Governance|Information Security Governance ]]||Yes||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]],&amp;lt;br&amp;gt;5.3 [[government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Infrastructure Advisory Council ||2004||[[Hardening_The_Internet|Hardening The Internet ]]||Yes||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Initiative for Cybersecurity Education||2011-08-11||[http://csrc.nist.gov/nice/documents/nicestratplan/Draft_NICE-Strategic-Plan_Aug2011.pdf National Initiative for Cybersecurity Education Strategic Plan: Building a Digital Nation]||No||U.S. Government Report||1. [[Overview]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Initiative for Cybersecurity Education (NICE) ||2011-11-21||[http://csrc.nist.gov/nice/framework/documents/NICE-Cybersecurity-Workforce-Framework-printable.pdf NICE Cybersecurity Workforce Framework ]||No||U.S. Government Report||4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Institute of Standards and Technology ||2006||[[SP_800-82:_Guide_to_Supervisory_Control_and_Data_Acquisition_(SCADA)_and_Industrial_Control_Systems_Security|SP 800-82: Guide to Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems Security ]]||Yes||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Institute of Standards and Technology (NIST) ||2010-09-02||[http://www.nist.gov/public_affairs/releases/nist-finalizes-initial-set-of-smart-grid-cyber-security-guidelines.cfm NIST Finalizes Initial Set of Smart Grid Cyber Security Guidelines ]||No||U.S. Government Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council ||2009||[http://www.nap.edu/catalog.php?record_id=12651 Technology, Policy, Law, and Ethics Regarding U.S. Acquisition and Use of Cyberattack Capabilities]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council ||2010-09-21||[http://www.nap.edu/catalog.php?record_id=12998 Toward Better Usability, Security, and Privacy of Information Technology: Report of a Workshop ]||No||Independent Report||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;4.10 [[Privacy]]&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council ||2010-10-05||[http://www.nap.edu/catalog.php?record_id=12997#description Proceedings of a Workshop on Deterring Cyberattacks: Informing Strategies and Developing Options for U.S. Policy ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council ||1999||[[Trust_in_Cyberspace|Trust in Cyberspace ]]||Yes||Independent Report ||3.3.3.2 [[Public Data Networks]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council ||2007||[[Toward_a_Safer_and_More_Secure_Cyberspace|Toward a Safer and More Secure Cyberspace ]]||Yes||Independent Report ||1. [[Overview]],&amp;lt;br&amp;gt;4.8 [[Attribution]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council, Committee for Advancing Software-Intensive Systems Producibility ||2010-10-20||[http://www.nap.edu/catalog.php?record_id=12979 Critical Code: Software Producibility for Defense ]||No||Independent Reprot ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| National Science and Technology Council ||2006||[[Federal_Plan_for_Cyber_Security_and_Information_Assurance_Research_and_Development|Federal Plan for Cyber Security and Information Assurance Research and Development ]]||Yes||U.S. Government Report ||4.1 [[Metrics]],&amp;lt;br&amp;gt;4.7 [[Attribution]],&amp;lt;br&amp;gt;4.8 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| National Science Foundation||2011-08-11||[http://www.livescience.com/15423-forefront-cyber-security-research-nsf-bts.html At the Forefront of Cyber Security Research ]||No||U.S. Government Report||5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| National Science Foundation||2012-01-17||[http://www.nsf.gov/awardsearch/showAward.do?AwardNumber=1127185 Information Security Risk Taking ]||No||U.S. Government Report||4.1 [[Metrics]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Security Cyberspace Institute||2012-07-11||[http://www.nsci-va.org/WhitePapers/2011-07-22-Cyber Analogies Whitepaper-K McKee.pdf A Review of Frequently Used Cyber Analogies ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| National Security Initiative ||2010-10-18||[http://www.americansecuritychallenge.com/ American Security Challenge ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| Networking and Information Technology Research and Development ||2009||[[National_Cyber_Leap_Year_Summit_2009,_Co-Chairs%27_Report|National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report ]]||Yes||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| NIST ||2011-09-01||[http://www.nist.gov/customcf/get_pdf.cfm?pub_id=909505 Cloud Computing Reference Architecture ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]]&lt;br /&gt;
|-&lt;br /&gt;
| NIST ||2011-12-01||[http://www.nist.gov/itl/cloud/upload/SP_500_293_volumeII.pdf U.S. Government Cloud Computing Technology Roadmap, Release 1.0 (Draft), Volume II Useful Information for Cloud Adopters ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| NIST ||2012-02-17||[http://www.nist.gov/nstic/2012-nstic-governance-recs.pdf Recommendations for Establishing an Identity Ecosystem Governance Structure for the National Strategy for Trusted Identities in Cyberspace ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Nojeim, Gregory T.||2009||[[Cybersecurity:_Preventing_Terrorist_Attacks_and_Protecting_Privacy_in_Cyberspace|Cybersecurity: Preventing Terrorist Attacks and Protecting Privacy in Cyberspace]]||Yes||U.S. Government Hearing||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| North American Electric Reliability Corp. (NERC) ||2011-01-26||[http://www.wired.com/images_blogs/threatlevel/2011/02/DoE-IG-Report-on-Grid-Security.pdf Federal Energy Regulatory Commission&#039;s Monitoring of Power Grid Cyber Security ]||No||U.S. Government Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| NSTC||2011-12||[http://www.whitehouse.gov/sites/default/files/microsites/ostp/fed_cybersecurity_rd_strategic_plan_2011.pdf Trustworthy Cyberspace: Strategic Plan for the Federal Cybersecurity Research and Development Program]||No||U.S. Government Report||5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Nye, Joseph ||2010||[[Cyber_Power|Cyber Power ]]||Yes||Book ||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;4.13 [[Espionage]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| OECD||2009||[[Cybersecurity_and_Economic_Incentives|Cybersecurity and Economic Incentives]]||Yes||Non-U.S. Government Report||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| OECD||2009||[[The_Market_Consequences_of_Cybersecurity|The Market Consequences of Cybersecurity]]||Yes||Non-U.S. Government Report||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Office of the National Counterintelligence Executive ||2011-11-03||[http://www.ncix.gov/publications/reports/fecie_all/Foreign_Economic_Collection_2011.pdf Foreign Spies Stealing US Economic Secrets in Cyberspace ]||No||U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;4.13 [[Espionage]]&lt;br /&gt;
|-&lt;br /&gt;
| Organisation for Economic Co-operation and Development (OECD) ||2010-11-12||[http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.165.2211&amp;amp;rep=rep1&amp;amp;type=pdf The Role of Internet Service Providers in Botnet Mitigation: an Empirical Analysis Bases on Spam Data ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Organization for Economic Co-operation and Development (OECD) ||2012-01-10||[http://www.oecd-ilibrary.org/docserver/download/fulltext/5k9h2q8v9bln.pdf?expires=1330527950&amp;amp;id=id&amp;amp;accname=guest&amp;amp;checksum=F4470043AC638BE19D5131C3D5CE5EA4 ICT Applications for the Smart Grid: Opportunities and Policy Implications ]||No||Independent Report ||&lt;br /&gt;
|-&lt;br /&gt;
| PCAST||2010-12||[http://www.whitehouse.gov/sites/default/files/microsites/ostp/pcast-nitrd-report-2010.pdf Designing a Digital Future: Federally Funded Research and Development in Networking and Information Technology]||No||U.S. Government Report||4.3 [[Supply Chain Issues]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| PCAST||2011-06||[http://www.whitehouse.gov/sites/default/files/microsites/ostp/pcast-advanced-manufacturing-june2011.pdf Report to the President on Ensuring American Leadership in Advanced Manufacturing]||No||U.S. Government Report||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Perkins, Earl||2009||[[Evolving_Cybersecurity_Issues_in_the_Utility_Industry|Evolving Cybersecurity Issues in the Utility Industry]]||Yes||Independent Report||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.2.4 [[Water, Sewer, etc.]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Pew Research Center’s Internet &amp;amp; American Life Project ||2010-06-11||[http://pewinternet.org/Reports/2010/The-future-of-cloud-computing.aspx The future of cloud computing ]||No||Independent Report||3.3.3.3 [[Cloud Computing]]&lt;br /&gt;
|-&lt;br /&gt;
| Powell, Benjamin ||2005||[[Is_Cybersecurity_a_Public_Good|Is Cybersecurity a Public Good ]]||Yes||Journal Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.5 [[Market Failure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| President&#039;s Commission on Critical Infrastructure Protection ||1997||[[Critical_Foundations|Critical Foundations ]]||Yes||U.S. Government Report ||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.3 [[Communications]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| President&#039;s Information Technology Advisory Council ||2005||[[Cyber_Security:_A_Crisis_of_Prioritization|Cyber Security: A Crisis of Prioritization ]]||Yes||U.S. Government Report ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Project on National Security Reform (PNSR) ||2010-11||[http://www.pnsr.org/data/images/pnsr_the_power_of_people_report.pdf The Power of People: Building an Integrated National Security Professional System for the 21st Century ]||No||U.S. Government Report||4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Quadrennial Defense Review ||2010-07-30||[http://www.usip.org/quadrennial-defense-review-independent-panel-/view-the-report The QDR in Perspective: Meeting AmericaÅfs National Security Needs In the 21st Century (QDR Final Report) ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| RAND||2011-12-21||[http://www.rand.org/content/dam/rand/pubs/occasional_papers/2011/RAND_OP342.pdf A Cyberworm that Knows No Boundaries ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Rattray, Gregory and Healey, Jason||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059437.pdf Categorizing and Understanding Offensive Cyber Capabilities and Their Use ]||No||Journal Article||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Rollins, John and Wilson, Clay||2007||[[Terrorist_Capabilities_for_Cyberattack|Terrorist Capabilities for Cyberattack]]||Yes||U.S. Government Report||3.2.4 [[Terrorists]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Romanosky et al. ||2008||[[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft|Do Data Breach Disclosure Laws Reduce Identity Theft ]]||Yes||Independent Report ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Rosenzweig, Paul||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059443.pdf The Organization of the United States Government and Private Sector for Achieving Cyber Deterrence ]||No||Journal Article||4.3 [[Supply Chain Issues]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Rotenberg et. al. ||2010||[[The_Cyber_War_Threat_Has_Been_Grossly_Exaggerated|The Cyber War Threat Has Been Grossly Exaggerated ]]||Yes||Article||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Rue, Rachel and Pfleeger, Shari Lawrence||2009||[[Making_the_Best_Use_of_Cybersecurity_Economic_Models|Making the Best Use of Cybersecurity Economic Models]]||Yes||Journal Article||4.1 [[Metrics]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| Santos, Joost R., et. al||2007||[[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies|A Framework for Linking Cybersecurity Metrics to the Modeling of Macroeconomic Interdependencies]]||Yes||Journal Article||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;4.1 [[Metrics]]&lt;br /&gt;
|-&lt;br /&gt;
| Schmitt Michael N   ||2002||[[Wired_Warfare| Wired warfare: Computer network attack and jus in bello]]||Yes||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Schmitt Michael N   ||2004||[[Direct_Participation_in_Hostilities|Direct Participation in Hostilities and 21st Century Armed Conflict]]||Yes||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Schmitt, Michael N. ||1999||[[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law|Computer Network Attack and the Use of Force in International Law ]]||Yes||Journal Article ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Schmitt, Michael N. ||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059439.pdf Cyber Operations in International Law: The Use of Force, Collective Security, Self-Defense, and Armed Conflicts]||No||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Schmitt, Michael N., et. al ||2004||[[Computers_and_War|Computers and War ]]||Yes||Independent Report ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Schneidewind, Norman||2010||[[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks|Metrics for Mitigating Cybersecurity Threats to Networks]]||Yes||Journal Article||4.1 [[Metrics]]&lt;br /&gt;
|-&lt;br /&gt;
| Schneier, Bruce ||2003||[[Beyond_Fear|Beyond Fear ]]||Yes||Book ||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;4.5 [[Psychology and Politics]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Schneier, Bruce ||2008||[[Schneier_on_Security|Schneier on Security ]]||Yes||Book ||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Schwartz, Paul ||2007||[[Notification_of_Data_Security_Breaches|Notification of Data Security Breaches ]]||Yes||Journal Article ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Secretary of the Air Force ||2011-07-27||[http://www.e-publishing.af.mil/shared/media/epubs/AFI51-402.pdf Legal Reviews of Weapons and Cyber Capabilities ]||No||U.S. Government Report ||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Shackelford, Scott J.||2010||[[Estonia_Three_Years_Later|Estonia Three Years Later]]||Yes||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Shah, Shashi K.||2004||[[The_Evolving_Landscape_of_Maritime_Cybersecurity|The Evolving Landscape of Maritime Cybersecurity]]||Yes||Journal Article||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.2.3 [[Transportation]]&lt;br /&gt;
|-&lt;br /&gt;
| Sklerov, Matthew J. ||2009||[[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks|Solving the Dilemma of State Responses to Cyberattacks ]]||Yes||Journal Article ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.8 [[Attribution]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Sofaer, Abraham; Clark, David; and Diffie, Whitfield||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059440.pdf Cyber Security and International Cooperation ]||No||Journal Article||5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Software and Information Industry Association (SAII) ||2011-07-26||[http://www.siia.net/index.php?option=com_docman&amp;amp;task=doc_download&amp;amp;gid=3040&amp;amp;Itemid=318 Guide to Cloud Computing for Policy Makers ]||No||Independent Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Stohl, Michael ||2006||[[Cyber_Terrorism|Cyber Terrorism ]]||Yes||Journal Article ||3.2.3 [[Hacktivists]],&amp;lt;br&amp;gt;3.2.4 [[Terrorists]],&amp;lt;br&amp;gt;4.5 [[Psychology and Politics]]&lt;br /&gt;
|-&lt;br /&gt;
| Stuart Madnick et al.||2009||[[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security|Experiences and Challenges with Using CERT Data to Analyze International Cyber Security]]||Yes||Journal Article||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Swire, Peter P. ||2004||[[A_Model_for_When_Disclosure_Helps_Security|A Model for When Disclosure Helps Security ]]||Yes||Journal Article ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Swire, Peter P. ||2006||[[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons|A Theory of Disclosure for Security and Competitive Reasons ]]||Yes||Journal Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Symantec||2011-10-24||[http://www.symantec.com/connect/w32_duqu_precursor_next_stuxnet W32.Duqu: The Precursor to the Next Stuxnet ]||No||Industry Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Symantec Corporation ||2010||[[Symantec_Global_Internet_Security_Threat_Report|Symantec Global Internet Security Threat Report ]]||Yes||Industry Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| Telang, Rahul ||2007||[[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors|Impact of Software Vulnerability Announcements on the Market Value of Software Vendors ]]||Yes||Journal Article ||4.1 [[Metrics]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]]&lt;br /&gt;
|-&lt;br /&gt;
| Theohary, Catherine A. and Rollins, John||2010||[[Cybersecurity:_Current_Legislation,_Executive_Branch_Initiatives,_and_Options_for_Congress|Cybersecurity: Current Legislation, Executive Branch Initiatives, and Options for Congress]]||Yes||U.S. Government Report||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Thom, Maxie    ||2006||[[Information_Warfare_Arms_Control| Information Warfare Arms Control: Risks and Costs]]||Yes||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Thomas, Rob ||2006||[[The_Underground_Economy|The Underground Economy ]]||Yes||Journal Article ||3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| Threat Level Blog (Wired) ||2010-12-27||[http://www.wired.com/threatlevel/2010/12/a-four-day-dive-into-stuxnets-heart/ A Four-Day Dive Into Stuxnet’s Heart ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Todd, Graham H. ||2009||[[Armed_Attack_in_Cyberspace|Armed Attack in Cyberspace ]]||Yes||Journal Article ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.8 [[Attribution]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Trend Micro Incorporated ||2010||[[Trend_Micro_Annual_Report|Trend Micro Annual Report ]]||Yes||Industry Report ||4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Air Force ||2010-07-15||[http://www.e-publishing.af.mil/shared/media/epubs/afdd3-12.pdf Cyberspace Operations: Air Force Doctrine Document 3-12 ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Army War College ||2011-05-09||[http://www.strategicstudiesinstitute.army.mil/pubs/display.cfm?pubid=10670 Cyber Infrastructure Protection ]||No||U.S. Government Report||&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Army War College, Strategy Research Project ||2011-03-24||[http://www.dtic.mil/dtic/tr/fulltext/u2/a552990.pdf China’s Cyber Power and America’s National Security ]||No||U.S. Government Report||3.2.1 [[States]],&amp;lt;br&amp;gt;4.13 [[Espionage]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Department of Energy, Infrastructure Security and Energy Restoration ||2007-01-01||[http://www.oe.netl.doe.gov/docs/prepare/21stepsbooklet.pdf 21 Steps to Improve Cyber Security of SCADA Networks ]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Deputy Secretary of Defense, William J. Lynn (Foreign Affairs) ||2010-009||[http://www.foreignaffairs.com/articles/66552/william-j-lynn-iii/defending-a-new-domain Defending a New Domain ]||No||U.S. Government Report ||&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Appropriations (closed/classified) (Subcommittee on Energy and Power)||2011-03-31||[http://www.dhs.gov/ynews/testimony/testimony_1301595025263.shtm Budget Hearing - National Protection and Programs Directorate, Cybersecurity and Infrastructure Protection Programs  ]||No||U.S. Government Hearing||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2011-02-11||[http://armedservices.house.gov/index.cfm/hearings-display?ContentRecord_id=90d8a16a-23b7-4b9c-a732-cb10ab20e579&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=64562e79-731a-4ac6-aab0-7bd8d1b7e890&amp;amp;MonthDisplay=2&amp;amp;YearDisplay=2011 What Should the Department of Defense’s Role in Cyber Be?]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2011-03-16||[http://armedservices.house.gov/index.cfm/hearings-display?ContentRecord_id=79ce7b4c-f88b-40bf-9540-efdb3a2d26b2&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=64562e79-731a-4ac6-aab0-7bd8d1b7e890&amp;amp;MonthDisplay=3&amp;amp;YearDisplay=2011 2012 Budget Request from U.S. Cyber Command]||No||U.S. Government Hearing||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2011-11-03||[http://armedservices.house.gov/index.cfm/hearings-display?ContentRecord_id=42c170fb-8e0c-453a-81a2-f4ee3fa89283&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=64562e79-731a-4ac6-aab0-7bd8d1b7e890&amp;amp;MonthDisplay=11&amp;amp;YearDisplay=2011 Institutionalizing Irregular Warfare Capabilities]||No||U.S. Government Hearing||4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2012-03-20||[http://armedservices.house.gov/index.cfm/hearings-display?ContentRecord_id=92823c77-38f0-4c20-a3ee-36729e8e19a3&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=64562e79-731a-4ac6-aab0-7bd8d1b7e890&amp;amp;MonthDisplay=3&amp;amp;YearDisplay=2012 Fiscal 2013 Defense Authorization: IT and Cyber Operations]||No||U.S. Government Hearing||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce||2011-05-31||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=8639 Protecting the Electric Grid: the Grid Reliability and Infrastructure Defense Act]||No||U.S. Government Hearing||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Commerce, Manufacturing, and Trade)||2011-06-02||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=8653 Sony and Epsilon: Lessons for Data Security Legislation]||No||U.S. Government Hearing||4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Commerce,Trade and Manufacturing)||2011-06-15||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=8693 Discussion Draft of H.R. ___, a bill to require greater protection for sensitive consumer data and timely notification in case of breach]||No||U.S. Government Hearing||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Communications and Technology)||2012-03-07||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=9342 Cybersecurity:Networks     The Pivotal Role of Communications]||No||U.S. Government Hearing||3.3.3 [[Communications]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Communications and Technology)||2012-03-28||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=9397 Cybersecurity:Threats to Communications Networks and Public-Sector Responses]||No||U.S. Government Hearing||3.3.3 [[Communications]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Oversight and Investigations)||2011-07-26||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=8824 Cybersecurity: Infrastructure An Overview of Risks to Critical]||No||U.S. Government Hearing||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Oversight and Investigations)||2012-02-28||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=9318 Critical Infrastructure Cybersecurity: Assessments of Smart Grid Security]||No||U.S. Government Hearing||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Oversight and Investigations)||2012-03-27||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=9393 IT Supply Chain Security: Review of Government and Industry Efforts]||No||U.S. Government Hearing||4.3 [[Supply Chain Issues]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Financial Services (field hearing in Hoover, AL)||2011-06-29||[http://financialservices.house.gov/Calendar/EventSingle.aspx?EventID=246611 Field Hearing: Hacked Off: Helping Law Enforcement Protect Private Financial Information]||No||U.S. Government Hearing||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Financial Services (Subcommittee on Financial Institutions and Consumer Credit)||2011-09-14||[http://financialservices.house.gov/Calendar/EventSingle.aspx?EventID=258792 Combating Cybercriminals]||No||U.S. Government Hearing||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;5.7 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Foreign Affairs (Subcommittee on Oversight and Investigations)||2011-04-15||[http://foreignaffairs.house.gov/hearing_notice.asp?id=1279 Communist Chinese Cyber-Attacks, Cyber-Espionage and Theft of American Technology]||No||U.S. Government Hearing||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;4.13 [[Espionage]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies and Counterterrorism and Intelligence)||2012-04-19||[http://homeland.house.gov/hearing/subcommittee-hearing-dhs-and-doe-national-labs-finding-efficiencies-and-optimizing-outputs The DHS and DOE National Labs: Finding Efficiencies and Optimizing Outputs in Homeland Security Research and Development]||No||U.S. Government Hearing||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies and Counterterrorism and Intelligence)||2012-04-26||[http://homeland.house.gov/hearing/joint-subcommittee-hearing-iranian-cyber-threat-us-homeland Iranian Cyber Threat to U.S. Homeland]||No||U.S. Government Hearing||3.2.1 [[States]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2011-02-11||[http://homeland.house.gov/hearing/subcommittee-hearing-%E2%80%9Cpreventing-chemical-terrorism-building-foundation-security-our-nation Preventing Chemical Terrorism: Building a Foundation of Security at Our Nation’s Chemical Facilities]||No||U.S. Government Hearing||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2011-03-16||[http://homeland.house.gov/hearing/subcommittee-hearing-examining-cyber-threat-critical-infrastructure-and-american-economy Examining the Cyber Threat to Critical Infrastructure and the American Economy]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2011-04-15||[http://homeland.house.gov/hearing/subcommittee-hearing-%E2%80%9C-dhs-cybersecurity-mission-promoting-innovation-and-securing-critical DHS Cybersecurity Mission: Promoting Innovation and Securing Critical Infrastructure]||No||U.S. Government Hearing||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2011-06-24||[http://homeland.house.gov/hearing/subcommittee-hearing-examining-homeland-security-impact-obamaadministrations-cybersecurity Examining the Homeland Security Impact of the Obama Administration’s Cybersecurity Proposal]||No||U.S. Government Hearing||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2011-12-06||[http://homeland.house.gov/hearing/subcommittee-hearing-hearing-draft-legislative-proposal-cybersecurity Hearing on Draft Legislative Proposal on Cybersecurity]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2012-02-01||[http://homeland.house.gov/markup/subcommittee-markup-hr-3674 Consideration and Markup of H.R. 3674]||No||U.S. Government Hearing||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technology)||2011-10-06||[http://homeland.house.gov/hearing/cloud-computing-what-are-security-implications Cloud Computing: What are the Security Implications?]||No||U.S. Government Hearing||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;4.13 [[Espionage]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection, and Security Technologies)||2011-05-26||[http://homeland.house.gov/hearing/subcommittee-hearing-%E2%80%9Cunlocking-safety-act%E2%80%99s-potential-promote-technology-and-combat Unlocking the SAFETY Act’s Potential to Promote Technology and Combat Terrorism ]||No||U.S. Government Hearing||4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Oversight, Investigations and Management)||2012-04-24||[http://homeland.house.gov/hearing/subcommittee-hearing-america-under-cyber-attack-why-urgent-action-needed America is Under Cyber Attack: Why Urgent Action is Needed]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.2 [[Actors and Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Oversight and Government Reform||2011-07-07||[http://oversight.house.gov/hearing/cybersecurity-assessing-the-nations-ability-to-address-the-growing-cyber-threat/ Cybersecurity: Assessing the Nation’s Ability to Address the Growing Cyber Threat]||No||U.S. Government Hearing||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Oversight and Government Reform (Subcommittee on National Security, Homeland Defense and Foreign Operations)||2011-05-25||[http://oversight.house.gov/hearing/cybersecurity-assessing-the-immediate-threat-to-the-united-states/ Cybersecurity: Assessing the Immediate Threat to the United States]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Science, Space and Technology||2011-07-21||[http://science.house.gov/markup/full-committee-%E2%80%93-markup Markup on H.R. 2096, Cybersecurity Enhancement Act of 2011]||No||U.S. Government Hearing||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Science, Space and Technology (Subcommittee on Research and Science Education)||2011-05-25||[http://science.house.gov/hearing/subcommittee-research-and-science-education-subcommittee-technology-and-innovation-%E2%80%93-joint Protecting Information in the Digital Age: Federal Cybersecurity Research and Development Efforts]||No||U.S. Government Hearing||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Science, Space, and Technology (Subcommittee on Investigations and Oversight)||2012-02-29||[http://science.house.gov/hearing/subcommittee-investigations-and-oversight-hearing-nasa-cybersecurity-examination-agency%E2%80%99s NASA Cybersecurity: An Examination of the Agency’s Information Security]||No||U.S. Government Hearing||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Science, Space, and Technology (Subcommittee on Technology and Innovation)||2011-09-21||[http://science.house.gov/hearing/technology-and-innovation-subcommittee-hearing-cloud-computing The Cloud Computing Outlook]||No||U.S. Government Hearing||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Small Business (Subcommittee on Healthcare and Technology)||2011-12-01||[http://smallbusiness.house.gov/Calendar/EventSingle.aspx?EventID=270278 Cyber Security: Protecting Your Small Business]||No||U.S. Government Hearing||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on the Judiciary||2011-11-16||[http://judiciary.house.gov/hearings/hear_11162011.html Combating Online Piracy (H.R. 3261, Stop the Online Piracy Act)]||No||U.S. Government Hearing||4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on the Judiciary (Subcommittee on Crime, Terrorism and Homeland Security)||2011-11-15||[http://judiciary.house.gov/hearings/hear_11152011.html Cybersecurity: Protecting America’s New Frontier]||No||U.S. Government Hearing||4.10 [[Privacy]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on the Judiciary (Subcommittee on Intellectual Property, Competition and the Internet)||2011-05-25||[http://judiciary.house.gov/hearings/hear_05252011.html Cybersecurity: Problems Innovative Solutions to Challenging]||No||U.S. Government Hearing||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Permenant Select Committee on Intelligence||2011-02-10||[https://intelligence.house.gov/hearing/full-committee-world-wide-threats-hearing World Wide Threats]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Permenant Select Committee on Intelligence||2011-10-04||[https://intelligence.house.gov/hearing/cyber-threats-and-ongoing-efforts-protect-nation Cyber Threats and Ongoing Efforts to Protect the Nation]||No||U.S. Government Hearing||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.13.2 [[Industrial|Industrial Espionage]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Permenant Select Committee on Intelligence||2011-12-01||[https://intelligence.house.gov/markup/mark-hr-xxxx-%E2%80%9Ccyber-intelligence-sharing-and-protection-act-2011%E2%80%9D Markup: Draft Bill: Cyber Intelligence Sharing and Protection Act of 2011]||No||U.S. Government Hearing||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Navy ||2010-06-17||[http://www.doncio.navy.mil/PolicyView.aspx?ID=1804 DON (Department of the Navy) Cybersecurity/Information Assurance Workforce Management, Oversight and Compliance ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Armed Services||2012-03-27||[http://armed-services.senate.gov/e_witnesslist.cfm?id=5283 To receive testimony on U.S. Strategic Command and U.S. Cyber Command in review of the Defense Authorization Request for Fiscal Year 2013 and the Future Years Defense Program.]||No||U.S. Government Hearing||3.2.1 [[States]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2011-05-03||[http://www.armed-services.senate.gov/Transcripts/2011/05%20May/11-31%20-%205-3-11.pdf To receive testimony on the health and status of the defense industrial base and its science and technology-related elements]||No||U.S. Government Hearing||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.3 [[Supply Chain Issues]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2012-03-20||[http://www.armed-services.senate.gov/Transcripts/2012/03%20March/12-14%20-%203-20-12.pdf To receive testimony on cybersecurity research and development in review of the Defense Authorization Request for Fiscal Year 2013 and the Future Years Defense Program]||No||U.S. Government Hearing||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Banking, Housing and Urban Affairs||2011-06-21||[http://banking.senate.gov/public/index.cfm?FuseAction=Hearings.Hearing&amp;amp;Hearing_ID=87487cb2-4710-4c09-a1b0-a9e12cda88f1 Cybersecurity and Data Protection in the Financial Sector]||No||U.S. Government Hearing||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Commerce, Science and Transportation||2011-06-29||[http://commerce.senate.gov/public/index.cfm?p=Hearings&amp;amp;ContentRecord_id=e2c2a2ca-91d6-48a2-b5ea-b5c4104bdb97&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=b06c39af-e033-4cba-9221-de668ca1978a&amp;amp;MonthDisplay=6&amp;amp;YearDisplay=2011 Privacy and Data Security: Protecting Consumers in the Modern World]||No||U.S. Government Hearing||4.9 [[Identity Management]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Energy and Natural Resources||2011-03-15||[ Cybersecurity and Critical Electric Infrastructure (closed)]||No||U.S. Government Hearing||3.3.2.1 [[Electricity, Oil and Natural Gas]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Energy and Natural Resources||2011-05-05||[http://www.energy.senate.gov/public/index.cfm/hearings-and-business-meetings?ID=929c1441-da25-c99d-3e27-af20c29e3b4b Cybersecurity of the Bulk-Power System and Electric Infrastructure]||No||U.S. Government Hearing||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Homeland Security and Governmental Affairs||2011-02-17||[http://www.hsgac.senate.gov/hearings/the-homeland-security-departments-budget-submission-for-fiscal-year-2012 Homeland Security Department’s Budget Submission for Fiscal Year 2012]||No||U.S. Government Hearing||&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Homeland Security and Governmental Affairs||2011-03-10||[http://www.hsgac.senate.gov/hearings/information-sharing-in-the-era-of-wikileaks-balancing-security-and-collaboration Information Sharing in the Era of WikiLeaks: Balancing Security and Collaboration]||No||U.S. Government Hearing||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Homeland Security and Governmental Affairs||2011-05-23||[http://www.hsgac.senate.gov/hearings/protecting-cyberspace-assessing-the-white-house-proposal Protecting Cyberspace: Assessing the White House Proposal]||No||U.S. Government Hearing||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Homeland Security and Governmental Affairs||2012-02-16||[http://www.hsgac.senate.gov/hearings/securing-americas-future-the-cybersecurity-act-of-2012 Securing America’s Future: The Cybersecurity Act of 2012]||No||U.S. Government Hearing||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Judiciary||2011-03-30||[http://www.judiciary.senate.gov/hearings/hearing.cfm?id=e655f9e2809e5476862f735da1697f72 Oversight of the Federal Bureau of Investigation]||No||U.S. Government Hearing||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Judiciary||2011-09-07||[http://www.judiciary.senate.gov/hearings/hearing.cfm?id=3d9031b47812de2592c3baeba629084b Cybercrime: Updating the Computer Fraud and Abuse Act to Protect Cyberspace and Combat Emerging Threats]||No||U.S. Government Hearing||3.11 [[Cybercrime]],&amp;lt;br&amp;gt;4.13.2 [[Industrial|Industrial Espionage]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Judiciary||2012-03-13||[http://www.judiciary.senate.gov/hearings/hearing.cfm?id=8b30fa475a5089d793576cd947089793 The Freedom of Information Act: Safeguarding Critical Infrastructure Information and the Public’s Right to Know]||No||U.S. Government Hearing||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Judiciary (Subcommittee on Crime and Terrorism)||2011-04-12||[http://www.judiciary.senate.gov/hearings/hearing.cfm?id=e655f9e2809e5476862f735da16a9959 Cyber Security: Responding to the Threat of Cyber Crime and Terrorism]||No||U.S. Government Hearing||4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Judiciary (Subcommittee on Crime and Terrorism)||2011-06-21||[http://www.judiciary.senate.gov/hearings/hearing.cfm?id=e655f9e2809e5476862f735da16e1bbe Cybersecurity: Evaluating the Administration’s Proposals]||No||U.S. Government Hearing||1. [[Overview]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Small Business and Entrepreneurship||2011-07-25||[http://www.sbc.senate.gov/public/index.cfm?p=Hearings&amp;amp;ContentRecord_id=6b4d51de-dd67-434b-869f-a717b315e6c2&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=43eb5e02-e987-4077-b9a7-1e5a9cf28964&amp;amp;MonthDisplay=7&amp;amp;YearDisplay=2011 Role of Small Business in Strengthening Cybersecurity Efforts in the United States]||No||U.S. Government Hearing||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.7 [[public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| United States Secret Service ||2004||[[Insider_Threat_Study|Insider Threat Study ]]||Yes||U.S. Government Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]]&lt;br /&gt;
|-&lt;br /&gt;
| University of Southern California (USC) Information Sciences Institute, University of California Berkeley (UCB), McAfee Research ||2011-01-13||[http://www.isi.edu/deter/news/news.php?story=20 Design of the DETER Security Testbed ]||No||Independent Report||5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| van Eeten, Michael and Bauer, Johannes M.||2009||[[Emerging_Threats_to_Internet_Security|Emerging Threats to Internet Security: Incentives, Externalities and Policy Implications]]||Yes||Journal Article||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| van Eeten, Michel J. G. ||2008||[[Economics_of_Malware|Economics of Malware ]]||Yes||Non-U.S. Government Report ||4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| Varian, Hal ||2000||[[Managing_Online_Security_Risks|Managing Online Security Risks ]]||Yes||Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| Varian, Hal ||2004||[[System_Reliability_and_Free_Riding|System Reliability and Free Riding ]]||Yes||Book ||4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| Vatis, Michael A.||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059441.pdf The Council of Europe Convention on Cybercrime]||No||Journal Article||4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Verizon ||2010||[[2010_Data_Breach_Investigations_Report|2010 Data Breach Investigations Report ]]||Yes||Industry Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Watts, Sean ||2010||[[Combatant_Status_and_Computer_Network_Attack|Combatant Status and Computer Network Attack ]]||Yes||Journal Article ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| White House||2009||[http://www.whitehouse.gov/assets/documents/Cyberspace_Policy_Review_final.pdf Cyberspace Policy Review: Assuring a Trusted and Resilient Information and Communications Infrastructure]||No||U.S. Government Report||1. [[Overview]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| White House||2011-04||[http://www.whitehouse.gov/sites/default/files/rss_viewer/NSTICstrategy_041511.pdf National Strategy for Trusted Identities in Cyberspace: Enhancing Online Choice, Efficiency, Security, and Privacy]||No||U.S. Government Report||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]]&lt;br /&gt;
|-&lt;br /&gt;
| White House||2011-05||[http://www.whitehouse.gov/sites/default/files/rss_viewer/international_strategy_for_cyberspace.pdf International Strategy for Cyberspace: Prosperity, Security, and Openness in a Networked World]||No||U.S. Government Report||1. [[Overview]]&lt;br /&gt;
|-&lt;br /&gt;
| White House||2012-01||[http://www.whitehouse.gov/sites/default/files/national_strategy_for_global_supply_chain_security.pdf National Strategy for Global Supply Chain Security]||No||U.S. Government Report||4.3 [[Supply Chain Issues]]&lt;br /&gt;
|-&lt;br /&gt;
| White House||2012-02||[http://www.whitehouse.gov/sites/default/files/privacy-final.pdf Consumer Data Privacy in a Networked World: A Framework for Protecting Privacy and Promoting Innovation in the Global Digital Economy]||No||U.S. Government Report||4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2010-12-16||[http://www.whitehouse.gov/sites/default/files/microsites/ostp/pcast-nitrd-report-2010.pdf Designing A Digital Future: Federally Funded Research And Development In Networking And Information Technology ]||No||U.S. Government Report||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2011-02-13||[http://www.cio.gov/documents/Federal-Cloud-Computing-Strategy.pdf Federal Cloud Computing Strategy ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2011-04-15||[http://www.whitehouse.gov/the-press-office/2011/04/15/administration-releases-strategy-protect-online-consumers-and-support-in Administration Releases Strategy to Protect Online Consumers and Support Innovation and Fact Sheet on National Strategy for Trusted Identities in Cyberspace ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2011-04-15||[http://www.whitehouse.gov/sites/default/files/rss_viewer/NSTICstrategy_041511.pdf National Strategy for Trusted Identities in Cyberspace ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2003||[[The_National_Strategy_to_Secure_Cyberspace|The National Strategy to Secure Cyberspace ]]||Yes||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2009||[[Cyberspace_Policy_Review|Cyberspace Policy Review ]]||Yes||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2010||[[The_Comprehensive_National_Cybersecurity_Initiative|The Comprehensive National Cybersecurity Initiative ]]||Yes||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House (Office of Science &amp;amp; Technology Policy) ||2010-12-06||[http://www.whitehouse.gov/blog/2010/12/06/partnership-cybersecurity-innovation Partnership for Cybersecurity Innovation ]||No||U.S. Government Report||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/Office of Management and Budget (OMB) ||2011-12-08||[http://www.cio.gov/fedrampmemo.pdf Security Authorization of Information Systems in Cloud Computing Environments (FedRAMP) ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2009-05-29||[http://www.whitehouse.gov/assets/documents/Cyberspace_Policy_Review_final.pdf Cyberspace Policy Review: Assuring a Trusted and Resilient Communications Infrastructure ]||No||U.S. Government Report ||4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2010-03-02||[http://www.whitehouse.gov/cybersecurity/comprehensive-national-cybersecurity-initiative Comprehensive National Cybersecurity Initiative (CNCI) ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2010-06-25||[http://www.dhs.gov/xlibrary/assets/ns_tic.pdf The National Strategy for Trusted Identities in Cyberspace: Creating Options for Enhanced Online Security and Privacy ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2010-07-06||[http://www.whitehouse.gov/sites/default/files/omb/assets/memoranda_2010/m10-28.pdf Clarifying Cybersecurity Responsibilities ]||No||U.S. Government Report ||5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2010-12-09||[http://www.cio.gov/documents/25-Point-Implementation-Plan-to-Reform-Federal%20IT.pdf 25 Point Implementation Plan to Reform Federal Information Technology Management ]||No||U.S. Government Report ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-02-13||[http://www.cio.gov/documents/Federal-Cloud-Computing-Strategy.pdf Federal Cloud Computing Strategy ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-05-12||[http://www.whitehouse.gov/the-press-office/2011/05/12/fact-sheet-cybersecurity-legislative-proposal Cybersecurity Legislative Proposal (Fact Sheet) ]||No||U.S. Government Report ||4. [[Issues]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-05-16||[http://www.whitehouse.gov/sites/default/files/rss_viewer/international_strategy_for_cyberspace.pdf International Strategy for Cyberspace ]||No||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-09-14||[http://www.whitehouse.gov/sites/default/files/omb/memoranda/2011/m11-33.pdf FY 2012 Reporting Instructions for the Federal Information Security Management Act and Agency Privacy Managementa ]||No||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-10-07||[http://www.whitehouse.gov/the-press-office/2011/10/07/executive-order-structural-reforms-improve-security-classified-networks- Structural Reforms to Improve the Security of Classified Networks and the Responsible Sharing and Safeguarding of Classified Information ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-12-06||[http://www.whitehouse.gov/sites/default/files/microsites/ostp/fed_cybersecurity_rd_strategic_plan_2011.pdf Trustworthy Cyberspace: Strategic Plan for the Federal Cybersecurity Research and Development Program ]||No||U.S. Government Report ||5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Wilshusen, Gregory C. and Powner, David A.||2009||[[Continued_Efforts_are_Needed_to_Protect_Information_Systems_from_Evolving_Threats|Continued Efforts Are Needed to Protect Information Systems from Evolving Threats]]||Yes||U.S. Government Hearing||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Wilson, Clay||2007-03-20||[http://www.fas.org/sgp/crs/natsec/RL31787.pdf Information Operations, Electronic Warfare, and Cyberwar: Capabilities and Related Policy Issues]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Zittrain, Jonathan L. ||2008||[[The_Future_of_the_Internet_and_How_To_Stop_It|The Future of the Internet and How To Stop It ]]||Yes||Book ||4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Centre for Secure Information Technologies||2012||[http://www.csit.qub.ac.uk/sites/CSIT/InnovationatCSIT/Reports/Filetoupload,295595,en.pdf 2nd World Cyber security Technology Research Summit (Belfast 2012)]||No||Independent Report||&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Template:Filtered_Table&amp;diff=6850</id>
		<title>Template:Filtered Table</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Template:Filtered_Table&amp;diff=6850"/>
		<updated>2013-01-25T21:00:32Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;dt_types&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|U.S. Government Report&lt;br /&gt;
|-&lt;br /&gt;
|U.S. Government Hearing&lt;br /&gt;
|-&lt;br /&gt;
|Non-U.S. Government Report&lt;br /&gt;
|-&lt;br /&gt;
|Independent Report&lt;br /&gt;
|-&lt;br /&gt;
|Industry Report&lt;br /&gt;
|-&lt;br /&gt;
|Book&lt;br /&gt;
|-&lt;br /&gt;
|Journal Article&lt;br /&gt;
|-&lt;br /&gt;
|Article&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;dt_categories&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|1. Overview&lt;br /&gt;
|-&lt;br /&gt;
|3. Threats and Actors&lt;br /&gt;
|-&lt;br /&gt;
|3.1 The Threat and Skeptics&lt;br /&gt;
|-&lt;br /&gt;
|3.2 Actors and Incentives&lt;br /&gt;
|-&lt;br /&gt;
|3.2.1 States&lt;br /&gt;
|-&lt;br /&gt;
|3.2.2 Groups&lt;br /&gt;
|-&lt;br /&gt;
|3.2.3 Hacktivists&lt;br /&gt;
|-&lt;br /&gt;
|3.2.4 Terrorists&lt;br /&gt;
|-&lt;br /&gt;
|3.2.5 Criminals and Criminal Organizations&lt;br /&gt;
|-&lt;br /&gt;
|3.3 Security Targets&lt;br /&gt;
|-&lt;br /&gt;
|3.3.1 Public Critical Infrastructure&lt;br /&gt;
|-&lt;br /&gt;
|3.3.1.1 Government Networks (.gov)&lt;br /&gt;
|-&lt;br /&gt;
|3.3.1.2 Military Networks (.mil)&lt;br /&gt;
|-&lt;br /&gt;
|3.3.2 Private Critical Infrastructure&lt;br /&gt;
|-&lt;br /&gt;
|3.3.2.1 Electricity, Oil and Natural Gas&lt;br /&gt;
|-&lt;br /&gt;
|3.3.2.2 Financial Institutions and Networks&lt;br /&gt;
|-&lt;br /&gt;
|3.3.2.3 Transportation&lt;br /&gt;
|-&lt;br /&gt;
|3.3.2.4 Water, Sewer, etc.&lt;br /&gt;
|-&lt;br /&gt;
|3.3.3 Communications&lt;br /&gt;
|-&lt;br /&gt;
|3.3.3.1 Telephone&lt;br /&gt;
|-&lt;br /&gt;
|3.3.3.2 Public Data Networks&lt;br /&gt;
|-&lt;br /&gt;
|3.3.3.3 Cloud Computing&lt;br /&gt;
|-&lt;br /&gt;
|4. Issues&lt;br /&gt;
|-&lt;br /&gt;
|4.1 Metrics&lt;br /&gt;
|-&lt;br /&gt;
|4.2 Economics of Cybersecurity&lt;br /&gt;
|-&lt;br /&gt;
|4.2.1 Risk Management and Investment&lt;br /&gt;
|-&lt;br /&gt;
|4.2.2 Incentives&lt;br /&gt;
|-&lt;br /&gt;
|4.2.3 Insurance&lt;br /&gt;
|-&lt;br /&gt;
|4.2.4 Behavioral Economics&lt;br /&gt;
|-&lt;br /&gt;
|4.2.5 Market Failure&lt;br /&gt;
|-&lt;br /&gt;
|4.3 Supply Chain Issues&lt;br /&gt;
|-&lt;br /&gt;
|4.4 Usability/Human Factors&lt;br /&gt;
|-&lt;br /&gt;
|4.5 Psychology and Politics&lt;br /&gt;
|-&lt;br /&gt;
|4.6 Information Sharing/Disclosure&lt;br /&gt;
|-&lt;br /&gt;
|4.7 Public-Private Cooperation&lt;br /&gt;
|-&lt;br /&gt;
|4.8 Attribution&lt;br /&gt;
|-&lt;br /&gt;
|4.9 Identity Management&lt;br /&gt;
|-&lt;br /&gt;
|4.10 Privacy&lt;br /&gt;
|-&lt;br /&gt;
|4.11 Cybercrime&lt;br /&gt;
|-&lt;br /&gt;
|4.12 Cyberwar&lt;br /&gt;
|-&lt;br /&gt;
|4.13 Espionage&lt;br /&gt;
|-&lt;br /&gt;
|4.13.1 Government to Government&lt;br /&gt;
|-&lt;br /&gt;
|4.13.2 Industrial&lt;br /&gt;
|-&lt;br /&gt;
|4.13.3 Media Perceptions&lt;br /&gt;
|-&lt;br /&gt;
|5. Approaches&lt;br /&gt;
|-&lt;br /&gt;
|5.1 Regulation/Liability&lt;br /&gt;
|-&lt;br /&gt;
|5.2 Private Efforts/Organizations&lt;br /&gt;
|-&lt;br /&gt;
|5.3 Government Organizations&lt;br /&gt;
|-&lt;br /&gt;
|5.4 International Cooperation&lt;br /&gt;
|-&lt;br /&gt;
|5.5 International Law (including Laws of War)&lt;br /&gt;
|-&lt;br /&gt;
|5.6 Deterrence&lt;br /&gt;
|-&lt;br /&gt;
|5.7 Technology&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable datatable&amp;quot; data-type-filter=&amp;quot;{{{1}}}&amp;quot; data-category-filter=&amp;quot;{{{2}}}&amp;quot; data-search-filter=&amp;quot;{{{3}}}&amp;quot; border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;1&amp;quot; cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;border: 1px solid LightGrey;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background-color:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Author/Agency&#039;&#039;&#039;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background-color:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Date&#039;&#039;&#039;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background-color:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Title&#039;&#039;&#039;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Wiki Entry&#039;&#039;&#039;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Type&#039;&#039;&#039;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Category&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| Aloise, Gene et al.||2008||[[Nuclear_Security|Nuclear Security]]||Yes||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]]&lt;br /&gt;
|-&lt;br /&gt;
| Anderson, Ross ||2001||[[Why_Information_Security_is_Hard|Why Information Security is Hard ]]||Yes||Independent Report ||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Anderson, Ross ||2006||[[The_Economics_of_Information_Security|The Economics of Information Security ]]||Yes||Journal Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Anderson, Ross J. ||2008||[[Security_Engineering|Security Engineering ]]||Yes||Book ||3.2 [[Security Targets]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Anderson, Ross, et. al ||2008||[[Security_Economics_and_the_Internal_Market|Security Economics and the Internal Market ]]||Yes||Article||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Arora et al. ||2006||[[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure|Does Information Security Attack Frequency Increase With Vulnerability Disclosure ]]||Yes||Journal Article ||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]]&lt;br /&gt;
|-&lt;br /&gt;
| Aviram, Amitai ||2004||[[Overcoming_Impediments_to_Information_Sharing|Overcoming Impediments to Information Sharing ]]||Yes||Journal Article ||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Barkham, Jason ||2001||[[Information_Warfare_and_International_Law_on_the_Use_of_Force|Information Warfare and International Law on the Use of Force ]]||Yes||Journal Article ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Bauer, Johannes M. and van Eeten, Michel J. G.||2009||[[Cybersecurity|Cybersecurity: Stakeholder Incentives, Externalities, and Policy Options]]||Yes||Journal Article||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Beard, Jack M. ||2009||[[Law_and_War_in_the_Virtual_Era|Law and War in the Virtual Era ]]||Yes||Journal Article ||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Bellovin, Steven M.||2009||[[The_Government_and_Cybersecurity|The Government and Cybersecurity]]||Yes||Journal Article||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;4.7[[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Besunder, Allison A.||2009||[[Best_Practices_for_Data_Protection_and_Privacy|Best Practices for Data Protection and Privacy]]||Yes||Book||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Boebert, W. Earl||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059366.pdf A Survey of Challenges in Attribution]||No||Journal Article||4.8 [[Attribution]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Bohme, Rainer ||2005||[[Cyber-Insurance_Revisited|Cyber-Insurance Revisited ]]||Yes||Independent Report ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.2.3 [[Insurance]],&amp;lt;br&amp;gt;,4.2.5 [[Market Failure]]&lt;br /&gt;
|-&lt;br /&gt;
| Bohme, Rainer ||2006||[[Models_and_Measures_for_Correlation_in_Cyber-Insurance|Models and Measures for Correlation in Cyber-Insurance ]]||Yes||Independent Report ||4.2.3 [[Insurance]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Bohme, Rainer ||2010||[[Modeling_Cyber-Insurance|Modeling Cyber-Insurance ]]||Yes||Independent Report ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.2.3 [[Insurance]],&amp;lt;br&amp;gt;,5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Booz Allen Hamilton and the Economist Intelligence Unit ||2012-01-15||[http://www.cyberhub.com/CyberPowerIndex Cyber Power Index ]||No||Industry Report||4. [[Issues]],&amp;lt;br&amp;gt;4.1 [[Metrics]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Bradley, Curtis A. and Goldsmith, Jack L.||2011||[[Overview_of_International_Law_and_Institutions|Overview of International Law and Institutions]]||Yes||Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Brown, Davis ||2006||[[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict|A Proposal for an International Convention To Regulate the Use of Information Systems in Armed Conflict ]]||Yes||Journal Article ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Burstein, Aaron J.||2008||[[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research|Amending the ECPA to Enable a Culture of Cybersecurity Research]]||Yes||Journal Article||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Business Roundtable||2011-10-11||[http://businessroundtable.org/uploads/studies-reports/downloads/2011_10_Mission_Critical_A_Public-Private_Strategy_for_Effective_Cybersecurity.pdf Mission Critical: A Public-Private Strategy for Effective Cybersecurity ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| Business Software Alliance ||2012-02-02||Global Cloud Computing Scorecard a Blueprint for Economic Opportunity||No||Industry Report||3.3.3.3 [[Cloud Computing]]&lt;br /&gt;
|-&lt;br /&gt;
| Business Software Alliance, Center for Democracy &amp;amp; Technology, U.S. Chamber of Commerce, Internet Security Alliance, Tech America ||2011-03-08||[http://www.cdt.org/files/pdfs/20110308_cbyersec_paper.pdf Improving our Nation’s Cybersecurity through the Public-Private Partnership: a White Paper ]||No||Industry Report||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Cabinet Office (United Kingdom) ||2011-11-11||[http://www.cabinetoffice.gov.uk/sites/default/files/resources/uk-cyber-security-strategy-final.pdf The UK Cyber Security Strategy: Protecting and promoting the UK in a digital world ]||No||Non-U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Camp, L. Jean ||2004||[[Economics_of_Information_Security|Economics of Information Security ]]||Yes||Book ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Camp, L. Jean ||2004||[[Pricing_Security|Pricing Security ]]||Yes||Book ||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Center for a New American Security||2012-06-11||[http://www.cnas.org/node/6405 America’s Cyber Future: Security and Prosperity in the Information Age ]||No||Independent Report||1. [[Overview]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Center for Strategic and International Studies ||2008||[[Securing_Cyberspace_for_the_44th_Presidency|Securing Cyberspace for the 44th Presidency ]]||Yes||Independent Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Centre for Secure Information Technologies||2011||[http://www.csit.qub.ac.uk/sites/CSIT/InnovationatCSIT/Reports/Filetoupload,295594,en.pdf World Cybersecurity Technology Research Summit (Belfast 2011) ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| Cetron, Marvin J. and Davies, Owen||2009||[[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity|World War 3.0: Ten Critical Trends for Cybersecurity]]||Yes||Journal Article||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Clark, David and Landau, Susan||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059365.pdf Untangling Attribution]||No||Journal Article||4.8 [[Attribution]],&amp;lt;br&amp;gt;5.6 [[Deterrence]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Clarke, Richard A. ||2010||[[Cyber_War|Cyber War ]]||Yes||Book ||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Clinton, Larry ||Undated ||[[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security|Cyber-Insurance Metrics and Impact on Cyber-Security ]]||Yes||Independent Report ||4.2.3 [[Insurance]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Cloud Security Alliance ||2009-12||[http://www.cloudsecurityalliance.org/csaguide.pdf Security Guidance for Critical Areas of Focus in Cloud Computing V2.1 ]||No||Independent Report||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Cohen, Geoff||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059445.pdf Targeting Third Party Collaboration]||No||Journal Article||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| Computer Economics, Inc. ||2007||[[2007_Malware_Report|2007 Malware Report ]]||Yes||Industry Report ||4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| Computing Research Association ||2003-||[[Four_Grand_Challenges_in_Trustworthy_Computing|Four Grand Challenges in Trustworthy Computing ]]||Yes||Independent Report ||4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.9 [[Identity Management]]&lt;br /&gt;
|-&lt;br /&gt;
| Cornish, Paul||2009||[[Cyber_Security_and_Politically,_Socially_and_Religiously_Motivated_Cyber_Attacks|Cyber Security and Politically, Socially and Religiously Motivated Cyber Attacks]]||Yes||Non-U.S. Government Report||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Cornish, Paul et al.||2009||[[Cyberspace_and_the_National_Security_of_the_United_Kingdom|Cyberspace and the National Security of the United Kingdom - Threats and Responses]]||Yes||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Council on Foreign Relations ||2010-07-15||[http://i.cfr.org/content/publications/attachments/Knake%20-Testimony%20071510.pdf Untangling Attribution: Moving to Accountability in Cyberspace [Testimony]]||No||Independent Report||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;4.8 [[Attribution]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| CSIS Commission on Cybersecurity for the 44th Presidency, Center for Strategic and International Studies ||2011-01||[http://csis.org/files/publication/110128_Lewis_CybersecurityTwoYearsLater_Web.pdf Cybersecurity Two Years Later ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5. [[Approaches]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Cyber Security Forum Initiative ||2011-05-09||[http://www.unveillance.com/wp-content/uploads/2011/05/Project_Cyber_Dawn_Public.pdf Cyber Dawn: Libya ]||No||Industry Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Commerce ||2011-06-14||[http://www.nist.gov/nstic/2012-nstic-governance-recs.pdf Models for a Governance Structure for the National Strategy for Trusted Identities in Cyberspace ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Commerce ||2010||[[Defense_Industrial_Base_Assessment|Defense Industrial Base Assessment ]]||Yes||U.S. Government Report ||3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Commerce, Internet Policy Task Force||2011-06||[http://www.nist.gov/itl/upload/Cybersecurity_Green-Paper_FinalVersion.pdf Cybersecurity, Innovation and the Internet Economy]||No||U.S. Government Report||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2011-07-14||[http://www.defense.gov/news/d20110714cyber.pdf Department of Defense Strategy for Operating in Cyberspace ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2011-11-15||[http://www.defense.gov/home/features/2011/0411_cyberstrategy/docs/NDAA%20Section%20934%20Report_For%20webpage.pdf Department of Defense Cyberspace Policy Report : A Report to Congress Pursuant to the National Defense Authorization Act for Fiscal Year 2011, Section 934 ]||No||U.S. Government Report||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2012-02-16||[http://www.fas.org/sgp/othergov/dod/5200_01v1.pdf DOD Information Security Program: Overview, Classification, and Declassification ]||No||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2012-04-11||[http://www.nsci-va.org/CyberReferenceLib/2011-04-Cyber%20Ops%20Personnel.pdf Cyber Operations Personnel Report (DoD) ]||No||U.S. Government Report||&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||1999||[[An_Assessment_of_International_Legal_Issues_in_Information_Operations|An Assessment of International Legal Issues in Information Operations ]]||Yes||U.S. Government Report ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2005-||[[Strategy_for_Homeland_Defense_and_Civil_Support|Strategy for Homeland Defense and Civil Support ]]||Yes||U.S. Government Report ||3.2.4 [[Terrorists]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2007||[[Mission_Impact_of_Foreign_Influence_on_DoD_Software|Mission Impact of Foreign Influence on DoD Software ]]||Yes||U.S. Government Report ||3.2.4 [[Terrorists]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2011-04||[http://www.nsci-va.org/CyberReferenceLib/2011-04-Cyber%20Ops%20Personnel.pdf Cyber Operations Personnel Report (DOD) ]||No||U.S. Government Report ||&lt;br /&gt;
|-&lt;br /&gt;
| Department of Energy||2012-04||[http://energy.gov/sites/prod/files/OAS-RA-12-04.pdf The Department&#039;s Management of the Smart Grid Investment Grant Program]||No||U.S. Government Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Energy (DOE) Inspector General ||2012-01-01||[http://energy.gov/ig/downloads/departments-management-smart-grid-investment-grant-program-oas-ra-12-04 The Department’s Management of the Smart Grid Investment Grant Program ]||No||U.S. Government Report ||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Energy, Idaho National Laboratory ||2010-05-01||[http://www.fas.org/sgp/eprint/nstb.pdf NSTB Assessments Summary Report: Common Industrial Control System Cyber Security Weaknesses ]||No||U.S. Government Report||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Energy, Office of Electricity Delivery &amp;amp; Energy Reliability ||Undated||[http://energy.gov/oe/technology-development/energy-delivery-systems-cybersecurity Cybersecurity for Energy Delivery Systems Program ]||No||U.S. Government Report ||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2009-09-16||[http://www.cyber.st.dhs.gov/docs/National_Cyber_Leap_Year_Summit_2009_Co-Chairs_Report.pdf National Cyber Leap Year Summit 2009: Co-Chairs&#039; Report]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.8 [[Attribution]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2007-06||[http://www.oig.dhs.gov/assets/Mgmt/OIG_07-48_Jun07.pdf Challenges Remain in Securing the Nation’s Cyber Infrastructure]||No||U.S. Government Report||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2009-11||[http://www.cyber.st.dhs.gov/docs/DHS-Cybersecurity-Roadmap.pdf A Roadmap for Cybersecurity Research]||No||U.S. Government Report||1. [[Overview]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2010-08||[http://www.dhs.gov/xoig/assets/mgmtrpts/OIG_10-111_Aug10.pdf DHS Needs to Improve the Security Posture of Its Cybersecurity Program Systems]||No||U.S. Government Report||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2010-09||[http://www.federalnewsradio.com/pdfs/NCIRP_Interim_Version_September_2010.pdf National Cyber Incident Response Plan]||No||U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2011-11||[http://www.dhs.gov/xlibrary/assets/nppd/blueprint-for-a-secure-cyber-future.pdf Blueprint for a Secure Cyber Future: The Cybersecurity Strategy for the Homeland Security Enterprise]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security ||2003||[[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets|The National Strategy for the Physical Protection of Critical Infrastructures and Key Assets ]]||Yes||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security ||2009||[[A_Roadmap_for_Cybersecurity_Research|A Roadmap for Cybersecurity Research ]]||Yes||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Justice||2011-04||[http://www.justice.gov/oig/reports/FBI/a1122r.pdf The Federal Bureau of Investigation&#039;s Ability to Address the National Security Cyber Intrusion Threat]||No||U.S. Government Report||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Deputy Chief of Staff for Intelligence ||2006||[[Critical_Infrastructure_Threats_and_Terrorism|Critical Infrastructure Threats and Terrorism ]]||Yes||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Dörmann, Knut ||2004||[[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks|Applicability of the Additional Protocols to Computer Network Attacks ]]||Yes||Independent Report ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Douglas Maughan||2010||[[The_Need_for_a_National_Cybersecurity_Research_and_Development_Agenda|The Need for a National Cybersecurity Research and Development Agenda]]||Yes||Article||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Dunlap Charles J, Jr   ||2011||[[Perspectives_for_Cyber_Strategists_on_Law_for_Cyberwar|Perspectives for Cyber Strategists on Law for Cyberwar]]||Yes||Journal Article||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Dunlap, Charles J. Jr. ||2009||[[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century|Towards a Cyberspace Legal Regime in the Twenty-First Century ]]||Yes||Article||4.5 [[Psychology and Politics]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| EastWest Institute ||2011-02-03||[http://vialardi.org/nastrazzuro/pdf/US-Russia.pdf Working Towards Rules for Governing Cyber Conflict: Rendering the Geneva and Hague Conventions in Cyberspace ]||No||Independent Report||3.2.1 [[States]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Energetics Inc. ||2006||[[Roadmap_to_Secure_Control_Systems_in_the_Energy_Sector|Roadmap to Secure Control Systems in the Energy Sector ]]||Yes||Independent Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Energy Sector Control Systems Working Group||2011-09||[http://www.cyber.st.dhs.gov/wp-content/uploads/2011/09/Energy_Roadmap.pdf Roadmap to Achieve Energy Delivery Systems Cybersecurity]||No||U.S. Government Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| ENISA||2010||[[Introduction_to_Country_Reports|Introduction to Country Reports]]||Yes||Non-U.S. Government Report||3.2.1 [[States]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Epstein, Richard A. ||2008||[[Cybersecurity_in_the_Payment_Card_Industry|Cybersecurity in the Payment Card Industry ]]||Yes||Journal Article ||3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| European Network and Information Security Agency ||2010-10-07||[http://www.enisa.europa.eu/media/press-releases/stuxnet-analysis Stuxnet Analysis ]||No||Non-U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| European Network and Information Security Agency (ENISA) ||2011-04-11||[http://www.enisa.europa.eu/act/res/other-areas/inter-x/report/interx-report Resilience of the Internet Interconnection Ecosystem, at: ]||No||Non-U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Federal CIO Council ||2012-01-04||[http://www.gsa.gov/portal/category/102371 Federal Risk and Authorization Management Program (FedRAMP) ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Federal Communications Commission (FCC) ||2010-04-21||[http://hraunfoss.fcc.gov/edocs_public/attachmatch/DOC-305618A1.doc Explore the reliability and resiliency of commercial broadband communications networks ]||No||U.S. Government Report||3.3.3 [[Communications]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Federal Communications Commission (FCC) ||2011-06-03||[ftp://ftp.fcc.gov/pub/Daily_Releases/Daily_Business/2011/db0610/DOC-307454A1.txt FCC&#039;s Plan for Ensuring the Security of Telecommunications Networks ]||No||U.S. Government Report||&lt;br /&gt;
|-&lt;br /&gt;
| Financial Services Sector Coordinating Council for Critical Infrastructure Protection ||2008||[[Research_Agenda_for_the_Banking_and_Finance_Sector|Research Agenda for the Banking and Finance Sector ]]||Yes||Independent Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.1 [[Metrics]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| Fischer, Eric A.&amp;lt;br /&amp;gt;CRS||2012-04-23||[http://www.fas.org/sgp/crs/natsec/R42114.pdf Federal Laws Relating to Cybersecurity: Discussion of Proposed Revisions]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Franklin, Jason, et. al ||2007||[[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants|An Inquiry into the Nature and Causes of the Wealth of Internet Miscreants ]]||Yes||Independent Report ||3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| Gandal, Neil ||2008||[[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security|An Introduction to Key Themes in the Economics of Cyber Security ]]||Yes||Book ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2003-08-27||[http://www.gao.gov/products/GAO-03-760 Efforts to Improve Information sharing Need to Be Strengthened ]||No||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2004-05-28||[http://www.gao.gov/assets/160/157541.pdf Technology Assessment: Cybersecurity for Critical Infrastructure Protection]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2008-07-31||[http://www.gao.gov/assets/280/279084.pdf Cyber Analysis And Warning: DHS Faces Challenges in Establishing a Comprehensive National Capability]||No||U.S. Government Report||5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2009-09-24||[http://www.gao.gov/new.items/d09969.pdf Critical Infrastructure Protection: Current Cyber Sector-Specific Planning Approach Needs Reassessment]||No||U.S. Government Report||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2009-11-17||[http://www.gao.gov/products/GAO-10-230t Continued Efforts Are Needed to Protect Information Systems from Evolving Threats ]||No||U.S. Government Report ||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-03-05||[http://www.gao.gov/products/GAO-10-338 Cybersecurity: Progress Made But Challenges Remain in Defining and Coordinating the Comprehensive National Initiative ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-03-16||[http://www.gao.gov/products/GAO-11-463T Cybersecurity: Continued Attention Is Needed to Protect Federal Information Systems from Evolving Threats ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-03-24||[http://www.gao.gov/products/GAO-10-536t Information Security: Concerted Response Needed to Resolve Persistent Weaknesses, at: ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-04-12||[http://www.gao.gov/products/GAO-10-237 Concerted Effort Needed to Consolidate and Secure Internet Connections at Federal Agencies ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-06-03||[http://www.gao.gov/assets/310/305208.pdf Cybersecurity: Key Challenges Need to Be Addressed to Improve Research and Development]||No||U.S. Government Report||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-06-16||[http://www.gao.gov/products/GAO-10-834t Continued Attention Is Needed to Protect Federal Information Systems from Evolving Threats ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-07-01||[http://www.gao.gov/products/GAO-10-513 Federal Guidance Needed to Address Control Issues With Implementing Cloud Computing ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-07-15||[http://www.gao.gov/products/GAO-10-628 Critical Infrastructure Protection: Key Private and Public Cyber Expectations Need to Be Consistently Addressed ]||No||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-08-02||[http://www.gao.gov/products/GAO-10-606 United States Faces Challenges in Addressing Global Cybersecurity and Governance ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-09-15||[http://www.gao.gov/products/GAO-10-916 Information Security: Progress Made on Harmonizing Policies and Guidance for National Security and Non-National Security Systems ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-09-23||[http://www.gao.gov/products/GAO-10-772 DHS Efforts to Assess and Promote Resiliency Are Evolving but Program Management Could Be Strengthened ]||No||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-10-06||[http://www.gao.gov/products/GAO-11-24 Cyberspace Policy: Executive Branch Is Making Progress Implementing 2009 Policy Review Recommendations, but Sustained Leadership Is Needed ]||No||U.S. Government Report ||5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-11-30||[http://www.gao.gov/products/GAO-11-43 Information Security: Federal Agencies Have Taken Steps to Secure Wireless Networks, but Further Actions Can Mitigate Risk ]||No||U.S. Government Report ||3.3.3 [[Communications]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-01-12||[http://www.gao.gov/products/GAO-11-117 Electricity Grid Modernization: Progress Being Made on Cybersecurity Guidelines, but Key Challenges Remain to be Addressed ]||No||U.S. Government Report ||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-03-16||[http://www.gao.gov/products/GAO-11-463T Cybersecurity: Continued Attention Needed to Protect Our Nation&#039;s Critical Infrastructure and Federal Information Systems ]||No||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-07-08||[http://www.gao.gov/products/GAO-11-149 Information Security: State Has Taken Steps to Implement a Continuous Monitoring Application, but Key Challenges Remain ]||No||U.S. Government Report ||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-07-25||[http://www.gao.gov/products/GAO-11-75 Defense Department Cyber Efforts: DoD Faces Challenges in Its Cyber Activities ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-07-26||[http://www.gao.gov/products/GAO-11-463T Continued Attention Needed to Protect Our Nation’s Critical Infrastructure ]||No||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-07-29||[http://www.gao.gov/products/GAO-11-695R Defense Department Cyber Efforts: Definitions, Focal Point, and Methodology Needed for DoD to Develop Full-Spectrum Cyberspace Budget Estimates ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-10-03||[http://www.gao.gov/products/GAO-12-137 Information Security: Weaknesses Continue Amid New Federal Efforts to Implement Requirements ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-10-05||[http://www.gao.gov/products/GAO-12-130T Information Security: Additional Guidance Needed to Address Cloud Computing Concerns ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-10-17||[http://www.gao.gov/products/GAO-11-634 Federal Chief Information Officers: Opportunities Exist to Improve Role in Information Technology Management ]||No||U.S. Government Report ||5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-11-29||[http://www.gao.gov/products/GAO-12-8 Cybersecurity Human Capital: Initiatives Need Better Planning and Coordination, at: ]||No||U.S. Government Report ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-12-09||[http://www.gao.gov/products/GAO-12-92 Critical Infrastructure Protection: Cybersecurity Guidance Is Available, but More Can Be Done to Promote Its Use ]||No||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2012-01-13||[http://www.gao.gov/assets/590/587681.pdf Defense Contracting: Improved Policies and Tools Could Help Increase Competition on DOD&#039;s National Security Exception Procurements]||No||U.S. Government Report||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2012-02-28||[http://www.csit.qub.ac.uk/media/pdf/Filetoupload,252359,en.pdf Cybersecurity: Challenges to Securing the Modernized Electricity Grid ]||No||Non-U.S. Government Report ||&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2009||[[Critical_Infrastructure_Protection|Critical Infrastructure Protection - Current Cyber Sector-Specific Planning Approach Needs Reassessment]]||Yes||U.S. Government Report||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2009-07||[http://www.gao.gov/new.items/d09546.pdf Information Security: Agencies Continue to Report Progress, but Need to. Mitigate Persistent Weaknesses]||No||U.S. Government Report||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2009-09||[http://www.gao.gov/new.items/d09617.pdf Information Security: Concerted Effort Needed to Improve Federal Performance Measures]||No||U.S. Government Report||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010||[[Information_Security|Information Security - Concerted Effort Needed to Consolidate and Secure Internet Connections at Federal Agencies]]||Yes||U.S. Government Report||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO ||2011-10-05||[http://www.gao.gov/products/GAO-12-130T Information Security: Additional Guidance Needed to Address Cloud Computing Concerns ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Geer, Daniel E. and Conway, Daniel G.||2010||[[Nothing_Ventured,_Nothing_Gained|Nothing Ventured, Nothing Gained]]||Yes||Journal Article||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Gellman, Robert||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059444.pdf Civil Liberties and Privacy Implications of Policies to Prevent Cyberattacks ]||No||Journal Article||4.8 [[Attribution]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2010-07-15||[http://www.gao.gov/products/GAO-10-628 Critical Infrastructure Protection: Key Private and Public Cyber Expectations Need to Be Consistently Addressed ]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2011-01-12||[http://www.gao.gov/products/GAO-11-117 Electricity Grid Modernization: Progress Being Made on Cybersecurity Guidelines, but Key Challenges Remain to be Addressed ]||No||U.S. Government Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2011-03-16||[http://www.gao.gov/products/GAO-11-463T Cybersecurity: Continued Attention Needed to Protect Our Nation&#039;s Critical Infrastructure and Federal Information Systems ]||No||U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2011-07-29||[http://www.gao.gov/products/GAO-11-695R Defense Department Cyber Efforts: Definitions, Focal Point, and Methodology Needed for DOD to Develop Full-Spectrum Cyberspace Budget Estimates ]||No||U.S. Government Report ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2011-11-29||[http://www.gao.gov/products/GAO-12-8 Cybersecurity Human Capital: Initiatives Need Better Planning and Coordination ]||No||U.S. Government Report||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2011-12-09||[http://www.gao.gov/products/GAO-12-92 Critical Infrastructure Protection: Cybersecurity Guidance Is Available, but More Can Be Done to Promote Its Use ]||No||U.S. Government Report ||&lt;br /&gt;
|-&lt;br /&gt;
| General Services Administration (GSA) ||2012-02-07||[http://www.gsa.gov/graphics/staffoffices/FedRAMP_CONOPS.pdf Concept of Operations: FedRAMP ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Grady, Mark F. ||2006||[[The_Law_and_Economics_of_Cybersecurity|The Law and Economics of Cybersecurity ]]||Yes||Book ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Graham David E   ||2010||[[Cyber_Threats_and_the_Law_of_War| Cyber Threats and the Law of War]]||Yes||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Granick, Jennifer Stisa ||2005||[[The_Price_of_Restricting_Vulnerability_Publications|The Price of Restricting Vulnerability Publications ]]||Yes||Journal Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Hollis, Duncan B. ||2007||[[Why_States_Need_an_International_Law_for_Information_Operations|Why States Need an International Law for Information Operations ]]||Yes||Journal Article ||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;4.13.1 [[Government to Government|Government to Government Espionage]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| HP TippingPoint DVLabs ||2010||[[2010_Top_Cyber_Security_Risks_Report|2010 Top Cyber Security Risks Report ]]||Yes||Industry report ||4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| IEEE/EastWest Institute ||2010-05-26||[http://www.ieee-rogucci.org/files/The%20ROGUCCI%20Report.pdf The Reliability of Global Undersea Communications Cable Infrastructure (The Rogucci Report) ]||No||Independent Report||3.3.3 [[Communications]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Institute for Information Infrastructure Protection ||2003||[[Cyber_Security_Research_and_Development_Agenda|Cyber Security Research and Development Agenda ]]||Yes||Independent Report ||4.1 [[Metrics]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Institute for Science and International Security ||2010-12-22||[http://isis-online.org/isis-reports/detail/did-stuxnet-take-out-1000-centrifuges-at-the-natanz-enrichment-plant/ Did Stuxnet Take Out 1,000 Centrifuges at the Natanz Enrichment Plant? Preliminary Assessment ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| International Instrument Users Association (WIB) ||2010-11-10||[http://www.isssource.com/wib/ WIB Security Standard Released ]||No||Industry Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| International Telecommunications Union ||2012-02-10||[http://www.itu.int/ITU-D/cyb/cybersecurity/docs/itu-toolkit-cybercrime-legislation.pdf ITU Toolkit for Cybercrime Legislation ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| James Clapper, Director of National Intelligence ||2011-02-10||[http://www.dni.gov/testimonies/20110210_testimony_clapper.pdf Worldwide Threat Assessment of the U.S. Intelligence Community (Testimony) ]||No||U.S. Government Report||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.2 [[Actors and Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Johnson, Eric M. ||2008||[[Managing_Information_Risk_and_the_Economics_of_Security|Managing Information Risk and the Economics of Security ]]||Yes||Book ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Johnson, Vincent R. ||2005||[[Cybersecurity,_Identity_Theft,_and_the_Limits_of_Tort_Liability|Cybersecurity, Identity Theft, and the Limits of Tort Liability ]]||Yes||Journal Article ||4.9 [[Identity Management]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Joint Workshop of the National Security Threats in Cyberspace and the National Strategy Forum ||2009-09-15||[http://nationalstrategy.com/Portals/0/National%20Security%20Threats%20in%20Cyberspace%20FINAL%2009-15-09.pdf National Security Threats in Cyberspace ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| Joseph S. Nye||2010||[[Cyber_Power|Cyber Power]]||Yes||Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Journal of Strategic Studies ||2011-10-05||[http://www.tandfonline.com/doi/abs/10.1080/01402390.2011.6089393 Cyber War Will Not Take Place ]||No||Journal Article||&lt;br /&gt;
|-&lt;br /&gt;
| Kelly A. Gable||2010||[[Cyber-Apocalypse_Now|Cyber-Apocalypse Now - Securing the Internet Against Cyberterrorism and Using Universal Jurisdiction as a Deterrent]]||Yes||Journal Article||3.2.4 [[Terrorists]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Kerr, Paul K. et al.&amp;lt;br /&amp;gt;CRS||2010-12-09||[http://www.fas.org/sgp/crs/natsec/R41524.pdf The Stuxnet Computer Worm: Harbinger of an Emerging Warfare Capability]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.4 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Kesan, Jay P. and Hayes, Carol M.||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059446.pdf Thinking Through Active Defense in Cyberspace ]||No||Journal Article||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Kobayashi, Bruce H.||2005||[[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods|An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and other Public Security Goods]]||Yes||Journal Article||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Kobayashi, Bruce H. ||2006||[[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods|An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and Other Public Security Goods ]]||Yes||Journal Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Korns, Stephen W. ||2009||[[Cyber_Operations|Cyber Operations ]]||Yes||Journal Article ||4.8 [[Attribution]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Kramer, Franklin D., et. al ||2009||[[Cyberpower_and_National_Security|Cyberpower and National Security ]]||Yes||Book ||1. [[Overview]]&lt;br /&gt;
|-&lt;br /&gt;
| Kundra, Vivek||2010-12-09||[http://www.cio.gov/documents/25-point-implementation-plan-to-reform-federal%20it.pdf 25 Point Implementation Plan to Reform Federal Information Technology Management]||No||U.S. Government Report||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Kundra, Vivek||2011-02-08||[http://www.cio.gov/documents/federal-cloud-computing-strategy.pdf Federal Cloud Computing Strategy]||No||U.S. Government Report||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Lan, Tang et al.||2010||[[Global_Cyber_Deterrence|Global Cyber Deterrence: Views from China, the U.S., Russia, India, and Norway]]||Yes||Independent Report||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Lernard, Thomas M. ||2005||[[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches|An Economic Analysis of Notification Requirements for Data Security Breaches ]]||Yes||Independent Report ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Lernard, Thomas M. ||2006||[[Much_Ado_About_Notification|Much Ado About Notification ]]||Yes||Journal Article ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Lewis, James Andrews||2005||[[Cyber_Security_and_Regulation_in_the_United_States|Aux armes, citoyens: Cyber Security and Regulation in the United States]]||Yes||Journal Article||3.3.1 [[Public Critical Infrastructure,&amp;lt;br&amp;gt;3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;3.3.2.3 [[Transportation]]&lt;br /&gt;
|-&lt;br /&gt;
| Libicki, Martin||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059490.pdf Pulling Punches in Cyberspace]||No||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
|Lin, Herbert||2012||[[Image:Lin-Cyber_Conflict_and_National_Security_2012.pdf|Cyber Conflict and National Security]]||No||Article||&lt;br /&gt;
|-&lt;br /&gt;
| Lukasik, Stephen J.||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059438.pdf A Framework for Thinking about Cyber Conflict and Cyber Deterrence with Possible Declatory Policies for these Domain]||No||Journal Article||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Massachusetts Institute of Technology (MIT) ||2011-12-05||[http://web.mit.edu/mitei/research/studies/the-electric-grid-2011.shtml The Future of the Electric Grid ]||No||Independent Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| McAfee ||2011-08-02||[http://www.mcafee.com/us/resources/white-papers/wp-operation-shady-rat.pdf Revealed: Operation Shady RAT: an Investigation Of Targeted Intrusions Into 70+ Global Companies, Governments, and Non-Profit Organizations During the Last 5 Years ]||No||Industry Report||3.2.1 [[States]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.13 [[Espionage]]&lt;br /&gt;
|-&lt;br /&gt;
| McAfee ||2012-02-01||[http://www.mcafee.com/us/resources/reports/rp-sda-cyber-security.pdf?cid=WBB048 Cyber-security: The Vexed Question of Global Rules: An Independent Report on Cyber-Preparedness Around the World ]||No||Industry Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| McAfee and Center for Strategic and International Studies (CSIS) ||2011-04-21||[http://www.mcafee.com/us/resources/reports/rp-critical-infrastructure-protection.pdf In the Dark: Crucial Industries Confront Cyberattacks ]||No||Industry Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt; 4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| McAfee and the Security Defense Agenda||2012-02-12||[http://www.mcafee.com/us/resources/reports/rp-sda-cyber-security.pdf Cyber-security: The Vexed Question of Global Rules: An Independent Report on Cyber-Preparedness Around the World]||No||Industry Report||1. [[Overview]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| McAfee, Inc. ||2010||[[McAfee_Threats_Report|McAfee Threats Report ]]||Yes||Industry Report ||3.2.3 [[Hacktivists]],&amp;lt;br&amp;gt;3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| McDermott, Rose||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059442.pdf Decision Making Under Uncertainty]||No||Journal Article||4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;4.5 [[Psychology and Politics]],&amp;lt;br&amp;gt;4.8 [[Attribution]]&lt;br /&gt;
|-&lt;br /&gt;
| Microsoft||2010-11||[http://cdn.globalfoundationservices.com/documents/InformationSecurityMangSysforMSCloudInfrastructure.pdf Information Security Management System for Microsoft Cloud Infrastructure ]||No||Industry Report||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Mitre Corp (JASON Program Office) ||2010-11||[http://www.fas.org/irp/agency/dod/jason/cyber.pdf Science of Cyber-Security ]||No||Independent Report||1. [[Overview]],&amp;lt;br&amp;gt;4. [[Issues]]&lt;br /&gt;
|-&lt;br /&gt;
| Moore, Tyler||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059364.pdf Introducing the Economics of Cybersecurity: Principles and Policy Options]||No||Journal Article||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Moore, Tyler ||2007||[[Examining_the_Impact_of_Website_Take-down_on_Phishing|Examining the Impact of Website Take-down on Phishing ]]||Yes||Independent Report ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Moore, Tyler ||2008||[[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing|The Consequence of Non-Cooperation in the Fight Against Phishing ]]||Yes||Independent Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]]&lt;br /&gt;
|-&lt;br /&gt;
| Moore, Tyler ||2009||[[The_Impact_of_Incentives_on_Notice_and_Take-down|The Impact of Incentives on Notice and Take-down ]]||Yes||Book ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Moore, Tyler, et. al ||2009||[[The_Economics_of_Online_Crime|The Economics of Online Crime ]]||Yes||Journal Article ||3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| Morgan, Patrick M. ||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059436.pdf Applicability of Traditional Deterrence Concepts and Theory to the Cyber Realm ]||No||Journal Article||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]],&amp;lt;br&amp;gt;5.6 [[Deterrence ]]&lt;br /&gt;
|-&lt;br /&gt;
| National Association of Secretaries of State ||2012-01-12||[http://www.nass.org/index.php?option=com_docman&amp;amp;task=doc_download&amp;amp;gid=1257 Developing State Solutions to Business Identity Theft: Assistance, Prevention and Detection Efforts by Secretary of State Offices ]||No||Independent Report||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Cyber Defense Initiative ||2009||[[National_Cyber_Defense_Financial_Services_Workshop_Report|National Cyber Defense Financial Services Workshop Report ]]||Yes||Independent Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Cyber Security Alliance and Microsoft ||2011-05-13||[http://www.staysafeonline.org/sites/default/files/resource_documents/2011%20National%20K-12%20Study%20Final_0.pdf 2011 State of Cyberethics, Cybersafety and Cybersecurity Curriculum in the U.S. Survey ]||No||Industry Report||4.4 [[Usability/Human Factors]]&lt;br /&gt;
|-&lt;br /&gt;
| National Cyber Security Summit Task Force ||2004||[[Information_Security_Governance|Information Security Governance ]]||Yes||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]],&amp;lt;br&amp;gt;5.3 [[government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Infrastructure Advisory Council ||2004||[[Hardening_The_Internet|Hardening The Internet ]]||Yes||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Initiative for Cybersecurity Education||2011-08-11||[http://csrc.nist.gov/nice/documents/nicestratplan/Draft_NICE-Strategic-Plan_Aug2011.pdf National Initiative for Cybersecurity Education Strategic Plan: Building a Digital Nation]||No||U.S. Government Report||1. [[Overview]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Initiative for Cybersecurity Education (NICE) ||2011-11-21||[http://csrc.nist.gov/nice/framework/documents/NICE-Cybersecurity-Workforce-Framework-printable.pdf NICE Cybersecurity Workforce Framework ]||No||U.S. Government Report||4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Institute of Standards and Technology ||2006||[[SP_800-82:_Guide_to_Supervisory_Control_and_Data_Acquisition_(SCADA)_and_Industrial_Control_Systems_Security|SP 800-82: Guide to Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems Security ]]||Yes||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Institute of Standards and Technology (NIST) ||2010-09-02||[http://www.nist.gov/public_affairs/releases/nist-finalizes-initial-set-of-smart-grid-cyber-security-guidelines.cfm NIST Finalizes Initial Set of Smart Grid Cyber Security Guidelines ]||No||U.S. Government Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council ||2009||[http://www.nap.edu/catalog.php?record_id=12651 Technology, Policy, Law, and Ethics Regarding U.S. Acquisition and Use of Cyberattack Capabilities]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council ||2010-09-21||[http://www.nap.edu/catalog.php?record_id=12998 Toward Better Usability, Security, and Privacy of Information Technology: Report of a Workshop ]||No||Independent Report||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;4.10 [[Privacy]]&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council ||2010-10-05||[http://www.nap.edu/catalog.php?record_id=12997#description Proceedings of a Workshop on Deterring Cyberattacks: Informing Strategies and Developing Options for U.S. Policy ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council ||1999||[[Trust_in_Cyberspace|Trust in Cyberspace ]]||Yes||Independent Report ||3.3.3.2 [[Public Data Networks]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council ||2007||[[Toward_a_Safer_and_More_Secure_Cyberspace|Toward a Safer and More Secure Cyberspace ]]||Yes||Independent Report ||1. [[Overview]],&amp;lt;br&amp;gt;4.8 [[Attribution]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council, Committee for Advancing Software-Intensive Systems Producibility ||2010-10-20||[http://www.nap.edu/catalog.php?record_id=12979 Critical Code: Software Producibility for Defense ]||No||Independent Reprot ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| National Science and Technology Council ||2006||[[Federal_Plan_for_Cyber_Security_and_Information_Assurance_Research_and_Development|Federal Plan for Cyber Security and Information Assurance Research and Development ]]||Yes||U.S. Government Report ||4.1 [[Metrics]],&amp;lt;br&amp;gt;4.7 [[Attribution]],&amp;lt;br&amp;gt;4.8 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| National Science Foundation||2011-08-11||[http://www.livescience.com/15423-forefront-cyber-security-research-nsf-bts.html At the Forefront of Cyber Security Research ]||No||U.S. Government Report||5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| National Science Foundation||2012-01-17||[http://www.nsf.gov/awardsearch/showAward.do?AwardNumber=1127185 Information Security Risk Taking ]||No||U.S. Government Report||4.1 [[Metrics]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Security Cyberspace Institute||2012-07-11||[http://www.nsci-va.org/WhitePapers/2011-07-22-Cyber Analogies Whitepaper-K McKee.pdf A Review of Frequently Used Cyber Analogies ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| National Security Initiative ||2010-10-18||[http://www.americansecuritychallenge.com/ American Security Challenge ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| Networking and Information Technology Research and Development ||2009||[[National_Cyber_Leap_Year_Summit_2009,_Co-Chairs%27_Report|National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report ]]||Yes||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| NIST ||2011-09-01||[http://www.nist.gov/customcf/get_pdf.cfm?pub_id=909505 Cloud Computing Reference Architecture ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]]&lt;br /&gt;
|-&lt;br /&gt;
| NIST ||2011-12-01||[http://www.nist.gov/itl/cloud/upload/SP_500_293_volumeII.pdf U.S. Government Cloud Computing Technology Roadmap, Release 1.0 (Draft), Volume II Useful Information for Cloud Adopters ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| NIST ||2012-02-17||[http://www.nist.gov/nstic/2012-nstic-governance-recs.pdf Recommendations for Establishing an Identity Ecosystem Governance Structure for the National Strategy for Trusted Identities in Cyberspace ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Nojeim, Gregory T.||2009||[[Cybersecurity:_Preventing_Terrorist_Attacks_and_Protecting_Privacy_in_Cyberspace|Cybersecurity: Preventing Terrorist Attacks and Protecting Privacy in Cyberspace]]||Yes||U.S. Government Hearing||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| North American Electric Reliability Corp. (NERC) ||2011-01-26||[http://www.wired.com/images_blogs/threatlevel/2011/02/DoE-IG-Report-on-Grid-Security.pdf Federal Energy Regulatory Commission&#039;s Monitoring of Power Grid Cyber Security ]||No||U.S. Government Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| NSTC||2011-12||[http://www.whitehouse.gov/sites/default/files/microsites/ostp/fed_cybersecurity_rd_strategic_plan_2011.pdf Trustworthy Cyberspace: Strategic Plan for the Federal Cybersecurity Research and Development Program]||No||U.S. Government Report||5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Nye, Joseph ||2010||[[Cyber_Power|Cyber Power ]]||Yes||Book ||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;4.13 [[Espionage]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| OECD||2009||[[Cybersecurity_and_Economic_Incentives|Cybersecurity and Economic Incentives]]||Yes||Non-U.S. Government Report||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| OECD||2009||[[The_Market_Consequences_of_Cybersecurity|The Market Consequences of Cybersecurity]]||Yes||Non-U.S. Government Report||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Office of the National Counterintelligence Executive ||2011-11-03||[http://www.ncix.gov/publications/reports/fecie_all/Foreign_Economic_Collection_2011.pdf Foreign Spies Stealing US Economic Secrets in Cyberspace ]||No||U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;4.13 [[Espionage]]&lt;br /&gt;
|-&lt;br /&gt;
| Organisation for Economic Co-operation and Development (OECD) ||2010-11-12||[http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.165.2211&amp;amp;rep=rep1&amp;amp;type=pdf The Role of Internet Service Providers in Botnet Mitigation: an Empirical Analysis Bases on Spam Data ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Organization for Economic Co-operation and Development (OECD) ||2012-01-10||[http://www.oecd-ilibrary.org/docserver/download/fulltext/5k9h2q8v9bln.pdf?expires=1330527950&amp;amp;id=id&amp;amp;accname=guest&amp;amp;checksum=F4470043AC638BE19D5131C3D5CE5EA4 ICT Applications for the Smart Grid: Opportunities and Policy Implications ]||No||Independent Report ||&lt;br /&gt;
|-&lt;br /&gt;
| PCAST||2010-12||[http://www.whitehouse.gov/sites/default/files/microsites/ostp/pcast-nitrd-report-2010.pdf Designing a Digital Future: Federally Funded Research and Development in Networking and Information Technology]||No||U.S. Government Report||4.3 [[Supply Chain Issues]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| PCAST||2011-06||[http://www.whitehouse.gov/sites/default/files/microsites/ostp/pcast-advanced-manufacturing-june2011.pdf Report to the President on Ensuring American Leadership in Advanced Manufacturing]||No||U.S. Government Report||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Perkins, Earl||2009||[[Evolving_Cybersecurity_Issues_in_the_Utility_Industry|Evolving Cybersecurity Issues in the Utility Industry]]||Yes||Independent Report||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.2.4 [[Water, Sewer, etc.]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Pew Research Center’s Internet &amp;amp; American Life Project ||2010-06-11||[http://pewinternet.org/Reports/2010/The-future-of-cloud-computing.aspx The future of cloud computing ]||No||Independent Report||3.3.3.3 [[Cloud Computing]]&lt;br /&gt;
|-&lt;br /&gt;
| Powell, Benjamin ||2005||[[Is_Cybersecurity_a_Public_Good|Is Cybersecurity a Public Good ]]||Yes||Journal Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.5 [[Market Failure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| President&#039;s Commission on Critical Infrastructure Protection ||1997||[[Critical_Foundations|Critical Foundations ]]||Yes||U.S. Government Report ||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.3 [[Communications]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| President&#039;s Information Technology Advisory Council ||2005||[[Cyber_Security:_A_Crisis_of_Prioritization|Cyber Security: A Crisis of Prioritization ]]||Yes||U.S. Government Report ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Project on National Security Reform (PNSR) ||2010-11||[http://www.pnsr.org/data/images/pnsr_the_power_of_people_report.pdf The Power of People: Building an Integrated National Security Professional System for the 21st Century ]||No||U.S. Government Report||4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Quadrennial Defense Review ||2010-07-30||[http://www.usip.org/quadrennial-defense-review-independent-panel-/view-the-report The QDR in Perspective: Meeting AmericaÅfs National Security Needs In the 21st Century (QDR Final Report) ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| RAND||2011-12-21||[http://www.rand.org/content/dam/rand/pubs/occasional_papers/2011/RAND_OP342.pdf A Cyberworm that Knows No Boundaries ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Rattray, Gregory and Healey, Jason||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059437.pdf Categorizing and Understanding Offensive Cyber Capabilities and Their Use ]||No||Journal Article||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Rollins, John and Wilson, Clay||2007||[[Terrorist_Capabilities_for_Cyberattack|Terrorist Capabilities for Cyberattack]]||Yes||U.S. Government Report||3.2.4 [[Terrorists]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Romanosky et al. ||2008||[[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft|Do Data Breach Disclosure Laws Reduce Identity Theft ]]||Yes||Independent Report ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Rosenzweig, Paul||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059443.pdf The Organization of the United States Government and Private Sector for Achieving Cyber Deterrence ]||No||Journal Article||4.3 [[Supply Chain Issues]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Rotenberg et. al. ||2010||[[The_Cyber_War_Threat_Has_Been_Grossly_Exaggerated|The Cyber War Threat Has Been Grossly Exaggerated ]]||Yes||Article||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Rue, Rachel and Pfleeger, Shari Lawrence||2009||[[Making_the_Best_Use_of_Cybersecurity_Economic_Models|Making the Best Use of Cybersecurity Economic Models]]||Yes||Journal Article||4.1 [[Metrics]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| Santos, Joost R., et. al||2007||[[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies|A Framework for Linking Cybersecurity Metrics to the Modeling of Macroeconomic Interdependencies]]||Yes||Journal Article||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;4.1 [[Metrics]]&lt;br /&gt;
|-&lt;br /&gt;
| Schmitt Michael N   ||2002||[[Wired_Warfare| Wired warfare: Computer network attack and jus in bello]]||Yes||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Schmitt Michael N   ||2004||[[Direct_Participation_in_Hostilities|Direct Participation in Hostilities and 21st Century Armed Conflict]]||Yes||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Schmitt, Michael N. ||1999||[[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law|Computer Network Attack and the Use of Force in International Law ]]||Yes||Journal Article ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Schmitt, Michael N. ||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059439.pdf Cyber Operations in International Law: The Use of Force, Collective Security, Self-Defense, and Armed Conflicts]||No||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Schmitt, Michael N., et. al ||2004||[[Computers_and_War|Computers and War ]]||Yes||Independent Report ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Schneidewind, Norman||2010||[[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks|Metrics for Mitigating Cybersecurity Threats to Networks]]||Yes||Journal Article||4.1 [[Metrics]]&lt;br /&gt;
|-&lt;br /&gt;
| Schneier, Bruce ||2003||[[Beyond_Fear|Beyond Fear ]]||Yes||Book ||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;4.5 [[Psychology and Politics]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Schneier, Bruce ||2008||[[Schneier_on_Security|Schneier on Security ]]||Yes||Book ||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Schwartz, Paul ||2007||[[Notification_of_Data_Security_Breaches|Notification of Data Security Breaches ]]||Yes||Journal Article ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Secretary of the Air Force ||2011-07-27||[http://www.e-publishing.af.mil/shared/media/epubs/AFI51-402.pdf Legal Reviews of Weapons and Cyber Capabilities ]||No||U.S. Government Report ||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Shackelford, Scott J.||2010||[[Estonia_Three_Years_Later|Estonia Three Years Later]]||Yes||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Shah, Shashi K.||2004||[[The_Evolving_Landscape_of_Maritime_Cybersecurity|The Evolving Landscape of Maritime Cybersecurity]]||Yes||Journal Article||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.2.3 [[Transportation]]&lt;br /&gt;
|-&lt;br /&gt;
| Sklerov, Matthew J. ||2009||[[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks|Solving the Dilemma of State Responses to Cyberattacks ]]||Yes||Journal Article ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.8 [[Attribution]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Sofaer, Abraham; Clark, David; and Diffie, Whitfield||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059440.pdf Cyber Security and International Cooperation ]||No||Journal Article||5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Software and Information Industry Association (SAII) ||2011-07-26||[http://www.siia.net/index.php?option=com_docman&amp;amp;task=doc_download&amp;amp;gid=3040&amp;amp;Itemid=318 Guide to Cloud Computing for Policy Makers ]||No||Independent Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Stohl, Michael ||2006||[[Cyber_Terrorism|Cyber Terrorism ]]||Yes||Journal Article ||3.2.3 [[Hacktivists]],&amp;lt;br&amp;gt;3.2.4 [[Terrorists]],&amp;lt;br&amp;gt;4.5 [[Psychology and Politics]]&lt;br /&gt;
|-&lt;br /&gt;
| Stuart Madnick et al.||2009||[[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security|Experiences and Challenges with Using CERT Data to Analyze International Cyber Security]]||Yes||Journal Article||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Swire, Peter P. ||2004||[[A_Model_for_When_Disclosure_Helps_Security|A Model for When Disclosure Helps Security ]]||Yes||Journal Article ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Swire, Peter P. ||2006||[[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons|A Theory of Disclosure for Security and Competitive Reasons ]]||Yes||Journal Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Symantec||2011-10-24||[http://www.symantec.com/connect/w32_duqu_precursor_next_stuxnet W32.Duqu: The Precursor to the Next Stuxnet ]||No||Industry Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Symantec Corporation ||2010||[[Symantec_Global_Internet_Security_Threat_Report|Symantec Global Internet Security Threat Report ]]||Yes||Industry Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| Telang, Rahul ||2007||[[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors|Impact of Software Vulnerability Announcements on the Market Value of Software Vendors ]]||Yes||Journal Article ||4.1 [[Metrics]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]]&lt;br /&gt;
|-&lt;br /&gt;
| Theohary, Catherine A. and Rollins, John||2010||[[Cybersecurity:_Current_Legislation,_Executive_Branch_Initiatives,_and_Options_for_Congress|Cybersecurity: Current Legislation, Executive Branch Initiatives, and Options for Congress]]||Yes||U.S. Government Report||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Thom, Maxie    ||2006||[[Information_Warfare_Arms_Control| Information Warfare Arms Control: Risks and Costs]]||Yes||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Thomas, Rob ||2006||[[The_Underground_Economy|The Underground Economy ]]||Yes||Journal Article ||3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| Threat Level Blog (Wired) ||2010-12-27||[http://www.wired.com/threatlevel/2010/12/a-four-day-dive-into-stuxnets-heart/ A Four-Day Dive Into Stuxnet’s Heart ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Todd, Graham H. ||2009||[[Armed_Attack_in_Cyberspace|Armed Attack in Cyberspace ]]||Yes||Journal Article ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.8 [[Attribution]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Trend Micro Incorporated ||2010||[[Trend_Micro_Annual_Report|Trend Micro Annual Report ]]||Yes||Industry Report ||4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Air Force ||2010-07-15||[http://www.e-publishing.af.mil/shared/media/epubs/afdd3-12.pdf Cyberspace Operations: Air Force Doctrine Document 3-12 ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Army War College ||2011-05-09||[http://www.strategicstudiesinstitute.army.mil/pubs/display.cfm?pubid=10670 Cyber Infrastructure Protection ]||No||U.S. Government Report||&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Army War College, Strategy Research Project ||2011-03-24||[http://www.dtic.mil/dtic/tr/fulltext/u2/a552990.pdf China’s Cyber Power and America’s National Security ]||No||U.S. Government Report||3.2.1 [[States]],&amp;lt;br&amp;gt;4.13 [[Espionage]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Department of Energy, Infrastructure Security and Energy Restoration ||2007-01-01||[http://www.oe.netl.doe.gov/docs/prepare/21stepsbooklet.pdf 21 Steps to Improve Cyber Security of SCADA Networks ]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Deputy Secretary of Defense, William J. Lynn (Foreign Affairs) ||2010-009||[http://www.foreignaffairs.com/articles/66552/william-j-lynn-iii/defending-a-new-domain Defending a New Domain ]||No||U.S. Government Report ||&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Appropriations (closed/classified) (Subcommittee on Energy and Power)||2011-03-31||[http://www.dhs.gov/ynews/testimony/testimony_1301595025263.shtm Budget Hearing - National Protection and Programs Directorate, Cybersecurity and Infrastructure Protection Programs  ]||No||U.S. Government Hearing||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2011-02-11||[http://armedservices.house.gov/index.cfm/hearings-display?ContentRecord_id=90d8a16a-23b7-4b9c-a732-cb10ab20e579&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=64562e79-731a-4ac6-aab0-7bd8d1b7e890&amp;amp;MonthDisplay=2&amp;amp;YearDisplay=2011 What Should the Department of Defense’s Role in Cyber Be?]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2011-03-16||[http://armedservices.house.gov/index.cfm/hearings-display?ContentRecord_id=79ce7b4c-f88b-40bf-9540-efdb3a2d26b2&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=64562e79-731a-4ac6-aab0-7bd8d1b7e890&amp;amp;MonthDisplay=3&amp;amp;YearDisplay=2011 2012 Budget Request from U.S. Cyber Command]||No||U.S. Government Hearing||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2011-11-03||[http://armedservices.house.gov/index.cfm/hearings-display?ContentRecord_id=42c170fb-8e0c-453a-81a2-f4ee3fa89283&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=64562e79-731a-4ac6-aab0-7bd8d1b7e890&amp;amp;MonthDisplay=11&amp;amp;YearDisplay=2011 Institutionalizing Irregular Warfare Capabilities]||No||U.S. Government Hearing||4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2012-03-20||[http://armedservices.house.gov/index.cfm/hearings-display?ContentRecord_id=92823c77-38f0-4c20-a3ee-36729e8e19a3&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=64562e79-731a-4ac6-aab0-7bd8d1b7e890&amp;amp;MonthDisplay=3&amp;amp;YearDisplay=2012 Fiscal 2013 Defense Authorization: IT and Cyber Operations]||No||U.S. Government Hearing||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce||2011-05-31||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=8639 Protecting the Electric Grid: the Grid Reliability and Infrastructure Defense Act]||No||U.S. Government Hearing||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Commerce, Manufacturing, and Trade)||2011-06-02||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=8653 Sony and Epsilon: Lessons for Data Security Legislation]||No||U.S. Government Hearing||4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Commerce,Trade and Manufacturing)||2011-06-15||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=8693 Discussion Draft of H.R. ___, a bill to require greater protection for sensitive consumer data and timely notification in case of breach]||No||U.S. Government Hearing||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Communications and Technology)||2012-03-07||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=9342 Cybersecurity:Networks     The Pivotal Role of Communications]||No||U.S. Government Hearing||3.3.3 [[Communications]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Communications and Technology)||2012-03-28||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=9397 Cybersecurity:Threats to Communications Networks and Public-Sector Responses]||No||U.S. Government Hearing||3.3.3 [[Communications]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Oversight and Investigations)||2011-07-26||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=8824 Cybersecurity: Infrastructure An Overview of Risks to Critical]||No||U.S. Government Hearing||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Oversight and Investigations)||2012-02-28||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=9318 Critical Infrastructure Cybersecurity: Assessments of Smart Grid Security]||No||U.S. Government Hearing||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Oversight and Investigations)||2012-03-27||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=9393 IT Supply Chain Security: Review of Government and Industry Efforts]||No||U.S. Government Hearing||4.3 [[Supply Chain Issues]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Financial Services (field hearing in Hoover, AL)||2011-06-29||[http://financialservices.house.gov/Calendar/EventSingle.aspx?EventID=246611 Field Hearing: Hacked Off: Helping Law Enforcement Protect Private Financial Information]||No||U.S. Government Hearing||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Financial Services (Subcommittee on Financial Institutions and Consumer Credit)||2011-09-14||[http://financialservices.house.gov/Calendar/EventSingle.aspx?EventID=258792 Combating Cybercriminals]||No||U.S. Government Hearing||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;5.7 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Foreign Affairs (Subcommittee on Oversight and Investigations)||2011-04-15||[http://foreignaffairs.house.gov/hearing_notice.asp?id=1279 Communist Chinese Cyber-Attacks, Cyber-Espionage and Theft of American Technology]||No||U.S. Government Hearing||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;4.13 [[Espionage]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies and Counterterrorism and Intelligence)||2012-04-19||[http://homeland.house.gov/hearing/subcommittee-hearing-dhs-and-doe-national-labs-finding-efficiencies-and-optimizing-outputs The DHS and DOE National Labs: Finding Efficiencies and Optimizing Outputs in Homeland Security Research and Development]||No||U.S. Government Hearing||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies and Counterterrorism and Intelligence)||2012-04-26||[http://homeland.house.gov/hearing/joint-subcommittee-hearing-iranian-cyber-threat-us-homeland Iranian Cyber Threat to U.S. Homeland]||No||U.S. Government Hearing||3.2.1 [[States]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2011-02-11||[http://homeland.house.gov/hearing/subcommittee-hearing-%E2%80%9Cpreventing-chemical-terrorism-building-foundation-security-our-nation Preventing Chemical Terrorism: Building a Foundation of Security at Our Nation’s Chemical Facilities]||No||U.S. Government Hearing||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2011-03-16||[http://homeland.house.gov/hearing/subcommittee-hearing-examining-cyber-threat-critical-infrastructure-and-american-economy Examining the Cyber Threat to Critical Infrastructure and the American Economy]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2011-04-15||[http://homeland.house.gov/hearing/subcommittee-hearing-%E2%80%9C-dhs-cybersecurity-mission-promoting-innovation-and-securing-critical DHS Cybersecurity Mission: Promoting Innovation and Securing Critical Infrastructure]||No||U.S. Government Hearing||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2011-06-24||[http://homeland.house.gov/hearing/subcommittee-hearing-examining-homeland-security-impact-obamaadministrations-cybersecurity Examining the Homeland Security Impact of the Obama Administration’s Cybersecurity Proposal]||No||U.S. Government Hearing||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2011-12-06||[http://homeland.house.gov/hearing/subcommittee-hearing-hearing-draft-legislative-proposal-cybersecurity Hearing on Draft Legislative Proposal on Cybersecurity]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2012-02-01||[http://homeland.house.gov/markup/subcommittee-markup-hr-3674 Consideration and Markup of H.R. 3674]||No||U.S. Government Hearing||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technology)||2011-10-06||[http://homeland.house.gov/hearing/cloud-computing-what-are-security-implications Cloud Computing: What are the Security Implications?]||No||U.S. Government Hearing||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;4.13 [[Espionage]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection, and Security Technologies)||2011-05-26||[http://homeland.house.gov/hearing/subcommittee-hearing-%E2%80%9Cunlocking-safety-act%E2%80%99s-potential-promote-technology-and-combat Unlocking the SAFETY Act’s Potential to Promote Technology and Combat Terrorism ]||No||U.S. Government Hearing||4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Oversight, Investigations and Management)||2012-04-24||[http://homeland.house.gov/hearing/subcommittee-hearing-america-under-cyber-attack-why-urgent-action-needed America is Under Cyber Attack: Why Urgent Action is Needed]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.2 [[Actors and Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Oversight and Government Reform||2011-07-07||[http://oversight.house.gov/hearing/cybersecurity-assessing-the-nations-ability-to-address-the-growing-cyber-threat/ Cybersecurity: Assessing the Nation’s Ability to Address the Growing Cyber Threat]||No||U.S. Government Hearing||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Oversight and Government Reform (Subcommittee on National Security, Homeland Defense and Foreign Operations)||2011-05-25||[http://oversight.house.gov/hearing/cybersecurity-assessing-the-immediate-threat-to-the-united-states/ Cybersecurity: Assessing the Immediate Threat to the United States]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Science, Space and Technology||2011-07-21||[http://science.house.gov/markup/full-committee-%E2%80%93-markup Markup on H.R. 2096, Cybersecurity Enhancement Act of 2011]||No||U.S. Government Hearing||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Science, Space and Technology (Subcommittee on Research and Science Education)||2011-05-25||[http://science.house.gov/hearing/subcommittee-research-and-science-education-subcommittee-technology-and-innovation-%E2%80%93-joint Protecting Information in the Digital Age: Federal Cybersecurity Research and Development Efforts]||No||U.S. Government Hearing||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Science, Space, and Technology (Subcommittee on Investigations and Oversight)||2012-02-29||[http://science.house.gov/hearing/subcommittee-investigations-and-oversight-hearing-nasa-cybersecurity-examination-agency%E2%80%99s NASA Cybersecurity: An Examination of the Agency’s Information Security]||No||U.S. Government Hearing||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Science, Space, and Technology (Subcommittee on Technology and Innovation)||2011-09-21||[http://science.house.gov/hearing/technology-and-innovation-subcommittee-hearing-cloud-computing The Cloud Computing Outlook]||No||U.S. Government Hearing||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Small Business (Subcommittee on Healthcare and Technology)||2011-12-01||[http://smallbusiness.house.gov/Calendar/EventSingle.aspx?EventID=270278 Cyber Security: Protecting Your Small Business]||No||U.S. Government Hearing||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on the Judiciary||2011-11-16||[http://judiciary.house.gov/hearings/hear_11162011.html Combating Online Piracy (H.R. 3261, Stop the Online Piracy Act)]||No||U.S. Government Hearing||4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on the Judiciary (Subcommittee on Crime, Terrorism and Homeland Security)||2011-11-15||[http://judiciary.house.gov/hearings/hear_11152011.html Cybersecurity: Protecting America’s New Frontier]||No||U.S. Government Hearing||4.10 [[Privacy]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on the Judiciary (Subcommittee on Intellectual Property, Competition and the Internet)||2011-05-25||[http://judiciary.house.gov/hearings/hear_05252011.html Cybersecurity: Problems Innovative Solutions to Challenging]||No||U.S. Government Hearing||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Permenant Select Committee on Intelligence||2011-02-10||[https://intelligence.house.gov/hearing/full-committee-world-wide-threats-hearing World Wide Threats]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Permenant Select Committee on Intelligence||2011-10-04||[https://intelligence.house.gov/hearing/cyber-threats-and-ongoing-efforts-protect-nation Cyber Threats and Ongoing Efforts to Protect the Nation]||No||U.S. Government Hearing||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.13.2 [[Industrial|Industrial Espionage]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Permenant Select Committee on Intelligence||2011-12-01||[https://intelligence.house.gov/markup/mark-hr-xxxx-%E2%80%9Ccyber-intelligence-sharing-and-protection-act-2011%E2%80%9D Markup: Draft Bill: Cyber Intelligence Sharing and Protection Act of 2011]||No||U.S. Government Hearing||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Navy ||2010-06-17||[http://www.doncio.navy.mil/PolicyView.aspx?ID=1804 DON (Department of the Navy) Cybersecurity/Information Assurance Workforce Management, Oversight and Compliance ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Armed Services||2012-03-27||[http://armed-services.senate.gov/e_witnesslist.cfm?id=5283 To receive testimony on U.S. Strategic Command and U.S. Cyber Command in review of the Defense Authorization Request for Fiscal Year 2013 and the Future Years Defense Program.]||No||U.S. Government Hearing||3.2.1 [[States]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2011-05-03||[http://www.armed-services.senate.gov/Transcripts/2011/05%20May/11-31%20-%205-3-11.pdf To receive testimony on the health and status of the defense industrial base and its science and technology-related elements]||No||U.S. Government Hearing||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.3 [[Supply Chain Issues]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2012-03-20||[http://www.armed-services.senate.gov/Transcripts/2012/03%20March/12-14%20-%203-20-12.pdf To receive testimony on cybersecurity research and development in review of the Defense Authorization Request for Fiscal Year 2013 and the Future Years Defense Program]||No||U.S. Government Hearing||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Banking, Housing and Urban Affairs||2011-06-21||[http://banking.senate.gov/public/index.cfm?FuseAction=Hearings.Hearing&amp;amp;Hearing_ID=87487cb2-4710-4c09-a1b0-a9e12cda88f1 Cybersecurity and Data Protection in the Financial Sector]||No||U.S. Government Hearing||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Commerce, Science and Transportation||2011-06-29||[http://commerce.senate.gov/public/index.cfm?p=Hearings&amp;amp;ContentRecord_id=e2c2a2ca-91d6-48a2-b5ea-b5c4104bdb97&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=b06c39af-e033-4cba-9221-de668ca1978a&amp;amp;MonthDisplay=6&amp;amp;YearDisplay=2011 Privacy and Data Security: Protecting Consumers in the Modern World]||No||U.S. Government Hearing||4.9 [[Identity Management]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Energy and Natural Resources||2011-03-15||[ Cybersecurity and Critical Electric Infrastructure (closed)]||No||U.S. Government Hearing||3.3.2.1 [[Electricity, Oil and Natural Gas]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Energy and Natural Resources||2011-05-05||[http://www.energy.senate.gov/public/index.cfm/hearings-and-business-meetings?ID=929c1441-da25-c99d-3e27-af20c29e3b4b Cybersecurity of the Bulk-Power System and Electric Infrastructure]||No||U.S. Government Hearing||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Homeland Security and Governmental Affairs||2011-02-17||[http://www.hsgac.senate.gov/hearings/the-homeland-security-departments-budget-submission-for-fiscal-year-2012 Homeland Security Department’s Budget Submission for Fiscal Year 2012]||No||U.S. Government Hearing||&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Homeland Security and Governmental Affairs||2011-03-10||[http://www.hsgac.senate.gov/hearings/information-sharing-in-the-era-of-wikileaks-balancing-security-and-collaboration Information Sharing in the Era of WikiLeaks: Balancing Security and Collaboration]||No||U.S. Government Hearing||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Homeland Security and Governmental Affairs||2011-05-23||[http://www.hsgac.senate.gov/hearings/protecting-cyberspace-assessing-the-white-house-proposal Protecting Cyberspace: Assessing the White House Proposal]||No||U.S. Government Hearing||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Homeland Security and Governmental Affairs||2012-02-16||[http://www.hsgac.senate.gov/hearings/securing-americas-future-the-cybersecurity-act-of-2012 Securing America’s Future: The Cybersecurity Act of 2012]||No||U.S. Government Hearing||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Judiciary||2011-03-30||[http://www.judiciary.senate.gov/hearings/hearing.cfm?id=e655f9e2809e5476862f735da1697f72 Oversight of the Federal Bureau of Investigation]||No||U.S. Government Hearing||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Judiciary||2011-09-07||[http://www.judiciary.senate.gov/hearings/hearing.cfm?id=3d9031b47812de2592c3baeba629084b Cybercrime: Updating the Computer Fraud and Abuse Act to Protect Cyberspace and Combat Emerging Threats]||No||U.S. Government Hearing||3.11 [[Cybercrime]],&amp;lt;br&amp;gt;4.13.2 [[Industrial|Industrial Espionage]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Judiciary||2012-03-13||[http://www.judiciary.senate.gov/hearings/hearing.cfm?id=8b30fa475a5089d793576cd947089793 The Freedom of Information Act: Safeguarding Critical Infrastructure Information and the Public’s Right to Know]||No||U.S. Government Hearing||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Judiciary (Subcommittee on Crime and Terrorism)||2011-04-12||[http://www.judiciary.senate.gov/hearings/hearing.cfm?id=e655f9e2809e5476862f735da16a9959 Cyber Security: Responding to the Threat of Cyber Crime and Terrorism]||No||U.S. Government Hearing||4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Judiciary (Subcommittee on Crime and Terrorism)||2011-06-21||[http://www.judiciary.senate.gov/hearings/hearing.cfm?id=e655f9e2809e5476862f735da16e1bbe Cybersecurity: Evaluating the Administration’s Proposals]||No||U.S. Government Hearing||1. [[Overview]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Small Business and Entrepreneurship||2011-07-25||[http://www.sbc.senate.gov/public/index.cfm?p=Hearings&amp;amp;ContentRecord_id=6b4d51de-dd67-434b-869f-a717b315e6c2&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=43eb5e02-e987-4077-b9a7-1e5a9cf28964&amp;amp;MonthDisplay=7&amp;amp;YearDisplay=2011 Role of Small Business in Strengthening Cybersecurity Efforts in the United States]||No||U.S. Government Hearing||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.7 [[public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| United States Secret Service ||2004||[[Insider_Threat_Study|Insider Threat Study ]]||Yes||U.S. Government Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]]&lt;br /&gt;
|-&lt;br /&gt;
| University of Southern California (USC) Information Sciences Institute, University of California Berkeley (UCB), McAfee Research ||2011-01-13||[http://www.isi.edu/deter/news/news.php?story=20 Design of the DETER Security Testbed ]||No||Independent Report||5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| van Eeten, Michael and Bauer, Johannes M.||2009||[[Emerging_Threats_to_Internet_Security|Emerging Threats to Internet Security: Incentives, Externalities and Policy Implications]]||Yes||Journal Article||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| van Eeten, Michel J. G. ||2008||[[Economics_of_Malware|Economics of Malware ]]||Yes||Non-U.S. Government Report ||4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| Varian, Hal ||2000||[[Managing_Online_Security_Risks|Managing Online Security Risks ]]||Yes||Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| Varian, Hal ||2004||[[System_Reliability_and_Free_Riding|System Reliability and Free Riding ]]||Yes||Book ||4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| Vatis, Michael A.||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059441.pdf The Council of Europe Convention on Cybercrime]||No||Journal Article||4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Verizon ||2010||[[2010_Data_Breach_Investigations_Report|2010 Data Breach Investigations Report ]]||Yes||Industry Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Watts, Sean ||2010||[[Combatant_Status_and_Computer_Network_Attack|Combatant Status and Computer Network Attack ]]||Yes||Journal Article ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| White House||2009||[http://www.whitehouse.gov/assets/documents/Cyberspace_Policy_Review_final.pdf Cyberspace Policy Review: Assuring a Trusted and Resilient Information and Communications Infrastructure]||No||U.S. Government Report||1. [[Overview]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| White House||2011-04||[http://www.whitehouse.gov/sites/default/files/rss_viewer/NSTICstrategy_041511.pdf National Strategy for Trusted Identities in Cyberspace: Enhancing Online Choice, Efficiency, Security, and Privacy]||No||U.S. Government Report||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]]&lt;br /&gt;
|-&lt;br /&gt;
| White House||2011-05||[http://www.whitehouse.gov/sites/default/files/rss_viewer/international_strategy_for_cyberspace.pdf International Strategy for Cyberspace: Prosperity, Security, and Openness in a Networked World]||No||U.S. Government Report||1. [[Overview]]&lt;br /&gt;
|-&lt;br /&gt;
| White House||2012-01||[http://www.whitehouse.gov/sites/default/files/national_strategy_for_global_supply_chain_security.pdf National Strategy for Global Supply Chain Security]||No||U.S. Government Report||4.3 [[Supply Chain Issues]]&lt;br /&gt;
|-&lt;br /&gt;
| White House||2012-02||[http://www.whitehouse.gov/sites/default/files/privacy-final.pdf Consumer Data Privacy in a Networked World: A Framework for Protecting Privacy and Promoting Innovation in the Global Digital Economy]||No||U.S. Government Report||4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2010-12-16||[http://www.whitehouse.gov/sites/default/files/microsites/ostp/pcast-nitrd-report-2010.pdf Designing A Digital Future: Federally Funded Research And Development In Networking And Information Technology ]||No||U.S. Government Report||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2011-02-13||[http://www.cio.gov/documents/Federal-Cloud-Computing-Strategy.pdf Federal Cloud Computing Strategy ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2011-04-15||[http://www.whitehouse.gov/the-press-office/2011/04/15/administration-releases-strategy-protect-online-consumers-and-support-in Administration Releases Strategy to Protect Online Consumers and Support Innovation and Fact Sheet on National Strategy for Trusted Identities in Cyberspace ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2011-04-15||[http://www.whitehouse.gov/sites/default/files/rss_viewer/NSTICstrategy_041511.pdf National Strategy for Trusted Identities in Cyberspace ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2003||[[The_National_Strategy_to_Secure_Cyberspace|The National Strategy to Secure Cyberspace ]]||Yes||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2009||[[Cyberspace_Policy_Review|Cyberspace Policy Review ]]||Yes||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2010||[[The_Comprehensive_National_Cybersecurity_Initiative|The Comprehensive National Cybersecurity Initiative ]]||Yes||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House (Office of Science &amp;amp; Technology Policy) ||2010-12-06||[http://www.whitehouse.gov/blog/2010/12/06/partnership-cybersecurity-innovation Partnership for Cybersecurity Innovation ]||No||U.S. Government Report||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/Office of Management and Budget (OMB) ||2011-12-08||[http://www.cio.gov/fedrampmemo.pdf Security Authorization of Information Systems in Cloud Computing Environments (FedRAMP) ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2009-05-29||[http://www.whitehouse.gov/assets/documents/Cyberspace_Policy_Review_final.pdf Cyberspace Policy Review: Assuring a Trusted and Resilient Communications Infrastructure ]||No||U.S. Government Report ||4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2010-03-02||[http://www.whitehouse.gov/cybersecurity/comprehensive-national-cybersecurity-initiative Comprehensive National Cybersecurity Initiative (CNCI) ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2010-06-25||[http://www.dhs.gov/xlibrary/assets/ns_tic.pdf The National Strategy for Trusted Identities in Cyberspace: Creating Options for Enhanced Online Security and Privacy ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2010-07-06||[http://www.whitehouse.gov/sites/default/files/omb/assets/memoranda_2010/m10-28.pdf Clarifying Cybersecurity Responsibilities ]||No||U.S. Government Report ||5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2010-12-09||[http://www.cio.gov/documents/25-Point-Implementation-Plan-to-Reform-Federal%20IT.pdf 25 Point Implementation Plan to Reform Federal Information Technology Management ]||No||U.S. Government Report ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-02-13||[http://www.cio.gov/documents/Federal-Cloud-Computing-Strategy.pdf Federal Cloud Computing Strategy ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-05-12||[http://www.whitehouse.gov/the-press-office/2011/05/12/fact-sheet-cybersecurity-legislative-proposal Cybersecurity Legislative Proposal (Fact Sheet) ]||No||U.S. Government Report ||4. [[Issues]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-05-16||[http://www.whitehouse.gov/sites/default/files/rss_viewer/international_strategy_for_cyberspace.pdf International Strategy for Cyberspace ]||No||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-09-14||[http://www.whitehouse.gov/sites/default/files/omb/memoranda/2011/m11-33.pdf FY 2012 Reporting Instructions for the Federal Information Security Management Act and Agency Privacy Managementa ]||No||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-10-07||[http://www.whitehouse.gov/the-press-office/2011/10/07/executive-order-structural-reforms-improve-security-classified-networks- Structural Reforms to Improve the Security of Classified Networks and the Responsible Sharing and Safeguarding of Classified Information ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-12-06||[http://www.whitehouse.gov/sites/default/files/microsites/ostp/fed_cybersecurity_rd_strategic_plan_2011.pdf Trustworthy Cyberspace: Strategic Plan for the Federal Cybersecurity Research and Development Program ]||No||U.S. Government Report ||5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Wilshusen, Gregory C. and Powner, David A.||2009||[[Continued_Efforts_are_Needed_to_Protect_Information_Systems_from_Evolving_Threats|Continued Efforts Are Needed to Protect Information Systems from Evolving Threats]]||Yes||U.S. Government Hearing||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Wilson, Clay||2007-03-20||[http://www.fas.org/sgp/crs/natsec/RL31787.pdf Information Operations, Electronic Warfare, and Cyberwar: Capabilities and Related Policy Issues]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Zittrain, Jonathan L. ||2008||[[The_Future_of_the_Internet_and_How_To_Stop_It|The Future of the Internet and How To Stop It ]]||Yes||Book ||4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Centre for Secure Information Technologies||2012||[http://www.csit.qub.ac.uk/sites/CSIT/InnovationatCSIT/Reports/Filetoupload,295595,en.pdf 2nd World Cyber security Technology Research Summit (Belfast 2012)]||No||Independent Report||&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Template:Filtered_Table&amp;diff=6849</id>
		<title>Template:Filtered Table</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Template:Filtered_Table&amp;diff=6849"/>
		<updated>2013-01-25T20:59:29Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;dt_types&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|U.S. Government Report&lt;br /&gt;
|-&lt;br /&gt;
|U.S. Government Hearing&lt;br /&gt;
|-&lt;br /&gt;
|Non-U.S. Government Report&lt;br /&gt;
|-&lt;br /&gt;
|Independent Report&lt;br /&gt;
|-&lt;br /&gt;
|Industry Report&lt;br /&gt;
|-&lt;br /&gt;
|Book&lt;br /&gt;
|-&lt;br /&gt;
|Journal Article&lt;br /&gt;
|-&lt;br /&gt;
|Article&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;dt_categories&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|1. Overview&lt;br /&gt;
|-&lt;br /&gt;
|3. Threats and Actors&lt;br /&gt;
|-&lt;br /&gt;
|3.1 The Threat and Skeptics&lt;br /&gt;
|-&lt;br /&gt;
|3.2 Actors and Incentives&lt;br /&gt;
|-&lt;br /&gt;
|3.2.1 States&lt;br /&gt;
|-&lt;br /&gt;
|3.2.2 Groups&lt;br /&gt;
|-&lt;br /&gt;
|3.2.3 Hacktivists&lt;br /&gt;
|-&lt;br /&gt;
|3.2.4 Terrorists&lt;br /&gt;
|-&lt;br /&gt;
|3.2.5 Criminals and Criminal Organizations&lt;br /&gt;
|-&lt;br /&gt;
|3.3 Security Targets&lt;br /&gt;
|-&lt;br /&gt;
|3.3.1 Public Critical Infrastructure&lt;br /&gt;
|-&lt;br /&gt;
|3.3.1.1 Government Networks (.gov)&lt;br /&gt;
|-&lt;br /&gt;
|3.3.1.2 Military Networks (.mil)&lt;br /&gt;
|-&lt;br /&gt;
|3.3.2 Private Critical Infrastructure&lt;br /&gt;
|-&lt;br /&gt;
|3.3.2.1 Electricity, Oil and Natural Gas&lt;br /&gt;
|-&lt;br /&gt;
|3.3.2.2 Financial Institutions and Networks&lt;br /&gt;
|-&lt;br /&gt;
|3.3.2.3 Transportation&lt;br /&gt;
|-&lt;br /&gt;
|3.3.2.4 Water, Sewer, etc.&lt;br /&gt;
|-&lt;br /&gt;
|3.3.3 Communications&lt;br /&gt;
|-&lt;br /&gt;
|3.3.3.1 Telephone&lt;br /&gt;
|-&lt;br /&gt;
|3.3.3.2 Public Data Networks&lt;br /&gt;
|-&lt;br /&gt;
|3.3.3.3 Cloud Computing&lt;br /&gt;
|-&lt;br /&gt;
|4. Issues&lt;br /&gt;
|-&lt;br /&gt;
|4.1 Metrics&lt;br /&gt;
|-&lt;br /&gt;
|4.2 Economics of Cybersecurity&lt;br /&gt;
|-&lt;br /&gt;
|4.2.1 Risk Management and Investment&lt;br /&gt;
|-&lt;br /&gt;
|4.2.2 Incentives&lt;br /&gt;
|-&lt;br /&gt;
|4.2.3 Insurance&lt;br /&gt;
|-&lt;br /&gt;
|4.2.4 Behavioral Economics&lt;br /&gt;
|-&lt;br /&gt;
|4.2.5 Market Failure&lt;br /&gt;
|-&lt;br /&gt;
|4.3 Supply Chain Issues&lt;br /&gt;
|-&lt;br /&gt;
|4.4 Usability/Human Factors&lt;br /&gt;
|-&lt;br /&gt;
|4.5 Psychology and Politics&lt;br /&gt;
|-&lt;br /&gt;
|4.6 Information Sharing/Disclosure&lt;br /&gt;
|-&lt;br /&gt;
|4.7 Public-Private Cooperation&lt;br /&gt;
|-&lt;br /&gt;
|4.8 Attribution&lt;br /&gt;
|-&lt;br /&gt;
|4.9 Identity Management&lt;br /&gt;
|-&lt;br /&gt;
|4.10 Privacy&lt;br /&gt;
|-&lt;br /&gt;
|4.11 Cybercrime&lt;br /&gt;
|-&lt;br /&gt;
|4.12 Cyberwar&lt;br /&gt;
|-&lt;br /&gt;
|4.13 Espionage&lt;br /&gt;
|-&lt;br /&gt;
|4.13.1 Government to Government&lt;br /&gt;
|-&lt;br /&gt;
|4.13.2 Industrial&lt;br /&gt;
|-&lt;br /&gt;
|4.13.3 Media Perceptions&lt;br /&gt;
|-&lt;br /&gt;
|5. Approaches&lt;br /&gt;
|-&lt;br /&gt;
|5.1 Regulation/Liability&lt;br /&gt;
|-&lt;br /&gt;
|5.2 Private Efforts/Organizations&lt;br /&gt;
|-&lt;br /&gt;
|5.3 Government Organizations&lt;br /&gt;
|-&lt;br /&gt;
|5.4 International Cooperation&lt;br /&gt;
|-&lt;br /&gt;
|5.5 International Law (including Laws of War)&lt;br /&gt;
|-&lt;br /&gt;
|5.6 Deterrence&lt;br /&gt;
|-&lt;br /&gt;
|5.7 Technology&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable datatable&amp;quot; data-type-filter=&amp;quot;{{{1}}}&amp;quot; data-category-filter=&amp;quot;{{{2}}}&amp;quot; data-search-filter=&amp;quot;{{{3}}}&amp;quot; border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;1&amp;quot; cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;border: 1px solid LightGrey;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background-color:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Author/Agency&#039;&#039;&#039;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background-color:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Date&#039;&#039;&#039;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background-color:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Title&#039;&#039;&#039;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Wiki Entry&#039;&#039;&#039;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Type&#039;&#039;&#039;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Category&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| Aloise, Gene et al.||2008||[[Nuclear_Security|Nuclear Security]]||Yes||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]]&lt;br /&gt;
|-&lt;br /&gt;
| Anderson, Ross ||2001||[[Why_Information_Security_is_Hard|Why Information Security is Hard ]]||Yes||Independent Report ||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Anderson, Ross ||2006||[[The_Economics_of_Information_Security|The Economics of Information Security ]]||Yes||Journal Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Anderson, Ross J. ||2008||[[Security_Engineering|Security Engineering ]]||Yes||Book ||3.2 [[Security Targets]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Anderson, Ross, et. al ||2008||[[Security_Economics_and_the_Internal_Market|Security Economics and the Internal Market ]]||Yes||Article||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Arora et al. ||2006||[[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure|Does Information Security Attack Frequency Increase With Vulnerability Disclosure ]]||Yes||Journal Article ||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]]&lt;br /&gt;
|-&lt;br /&gt;
| Aviram, Amitai ||2004||[[Overcoming_Impediments_to_Information_Sharing|Overcoming Impediments to Information Sharing ]]||Yes||Journal Article ||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Barkham, Jason ||2001||[[Information_Warfare_and_International_Law_on_the_Use_of_Force|Information Warfare and International Law on the Use of Force ]]||Yes||Journal Article ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Bauer, Johannes M. and van Eeten, Michel J. G.||2009||[[Cybersecurity|Cybersecurity: Stakeholder Incentives, Externalities, and Policy Options]]||Yes||Journal Article||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Beard, Jack M. ||2009||[[Law_and_War_in_the_Virtual_Era|Law and War in the Virtual Era ]]||Yes||Journal Article ||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Bellovin, Steven M.||2009||[[The_Government_and_Cybersecurity|The Government and Cybersecurity]]||Yes||Journal Article||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;4.7[[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Besunder, Allison A.||2009||[[Best_Practices_for_Data_Protection_and_Privacy|Best Practices for Data Protection and Privacy]]||Yes||Book||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Boebert, W. Earl||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059366.pdf A Survey of Challenges in Attribution]||No||Journal Article||4.8 [[Attribution]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Bohme, Rainer ||2005||[[Cyber-Insurance_Revisited|Cyber-Insurance Revisited ]]||Yes||Independent Report ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.2.3 [[Insurance]],&amp;lt;br&amp;gt;,4.2.5 [[Market Failure]]&lt;br /&gt;
|-&lt;br /&gt;
| Bohme, Rainer ||2006||[[Models_and_Measures_for_Correlation_in_Cyber-Insurance|Models and Measures for Correlation in Cyber-Insurance ]]||Yes||Independent Report ||4.2.3 [[Insurance]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Bohme, Rainer ||2010||[[Modeling_Cyber-Insurance|Modeling Cyber-Insurance ]]||Yes||Independent Report ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.2.3 [[Insurance]],&amp;lt;br&amp;gt;,5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Booz Allen Hamilton and the Economist Intelligence Unit ||2012-01-15||[http://www.cyberhub.com/CyberPowerIndex Cyber Power Index ]||No||Industry Report||4. [[Issues]],&amp;lt;br&amp;gt;4.1 [[Metrics]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Bradley, Curtis A. and Goldsmith, Jack L.||2011||[[Overview_of_International_Law_and_Institutions|Overview of International Law and Institutions]]||Yes||Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Brown, Davis ||2006||[[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict|A Proposal for an International Convention To Regulate the Use of Information Systems in Armed Conflict ]]||Yes||Journal Article ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Burstein, Aaron J.||2008||[[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research|Amending the ECPA to Enable a Culture of Cybersecurity Research]]||Yes||Journal Article||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Business Roundtable||2011-10-11||[http://businessroundtable.org/uploads/studies-reports/downloads/2011_10_Mission_Critical_A_Public-Private_Strategy_for_Effective_Cybersecurity.pdf Mission Critical: A Public-Private Strategy for Effective Cybersecurity ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| Business Software Alliance ||2012-02-02||Global Cloud Computing Scorecard a Blueprint for Economic Opportunity||No||Industry Report||3.3.3.3 [[Cloud Computing]]&lt;br /&gt;
|-&lt;br /&gt;
| Business Software Alliance, Center for Democracy &amp;amp; Technology, U.S. Chamber of Commerce, Internet Security Alliance, Tech America ||2011-03-08||[http://www.cdt.org/files/pdfs/20110308_cbyersec_paper.pdf Improving our Nation’s Cybersecurity through the Public-Private Partnership: a White Paper ]||No||Industry Report||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Cabinet Office (United Kingdom) ||2011-11-11||[http://www.cabinetoffice.gov.uk/sites/default/files/resources/uk-cyber-security-strategy-final.pdf The UK Cyber Security Strategy: Protecting and promoting the UK in a digital world ]||No||Non-U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Camp, L. Jean ||2004||[[Economics_of_Information_Security|Economics of Information Security ]]||Yes||Book ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Camp, L. Jean ||2004||[[Pricing_Security|Pricing Security ]]||Yes||Book ||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Center for a New American Security||2012-06-11||[http://www.cnas.org/node/6405 America’s Cyber Future: Security and Prosperity in the Information Age ]||No||Independent Report||1. [[Overview]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Center for Strategic and International Studies ||2008||[[Securing_Cyberspace_for_the_44th_Presidency|Securing Cyberspace for the 44th Presidency ]]||Yes||Independent Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Centre for Secure Information Technologies||2011||[http://www.csit.qub.ac.uk/sites/CSIT/InnovationatCSIT/Reports/Filetoupload,295594,en.pdf World Cybersecurity Technology Research Summit (Belfast 2011) ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| Cetron, Marvin J. and Davies, Owen||2009||[[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity|World War 3.0: Ten Critical Trends for Cybersecurity]]||Yes||Journal Article||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Clark, David and Landau, Susan||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059365.pdf Untangling Attribution]||No||Journal Article||4.8 [[Attribution]],&amp;lt;br&amp;gt;5.6 [[Deterrence]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Clarke, Richard A. ||2010||[[Cyber_War|Cyber War ]]||Yes||Book ||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Clinton, Larry ||Undated ||[[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security|Cyber-Insurance Metrics and Impact on Cyber-Security ]]||Yes||Independent Report ||4.2.3 [[Insurance]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Cloud Security Alliance ||2009-12||[http://www.cloudsecurityalliance.org/csaguide.pdf Security Guidance for Critical Areas of Focus in Cloud Computing V2.1 ]||No||Independent Report||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Cohen, Geoff||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059445.pdf Targeting Third Party Collaboration]||No||Journal Article||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| Computer Economics, Inc. ||2007||[[2007_Malware_Report|2007 Malware Report ]]||Yes||Industry Report ||4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| Computing Research Association ||2003-||[[Four_Grand_Challenges_in_Trustworthy_Computing|Four Grand Challenges in Trustworthy Computing ]]||Yes||Independent Report ||4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.9 [[Identity Management]]&lt;br /&gt;
|-&lt;br /&gt;
| Cornish, Paul||2009||[[Cyber_Security_and_Politically,_Socially_and_Religiously_Motivated_Cyber_Attacks|Cyber Security and Politically, Socially and Religiously Motivated Cyber Attacks]]||Yes||Non-U.S. Government Report||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Cornish, Paul et al.||2009||[[Cyberspace_and_the_National_Security_of_the_United_Kingdom|Cyberspace and the National Security of the United Kingdom - Threats and Responses]]||Yes||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Council on Foreign Relations ||2010-07-15||[http://i.cfr.org/content/publications/attachments/Knake%20-Testimony%20071510.pdf Untangling Attribution: Moving to Accountability in Cyberspace [Testimony]]||No||Independent Report||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;4.8 [[Attribution]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| CSIS Commission on Cybersecurity for the 44th Presidency, Center for Strategic and International Studies ||2011-01||[http://csis.org/files/publication/110128_Lewis_CybersecurityTwoYearsLater_Web.pdf Cybersecurity Two Years Later ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5. [[Approaches]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Cyber Security Forum Initiative ||2011-05-09||[http://www.unveillance.com/wp-content/uploads/2011/05/Project_Cyber_Dawn_Public.pdf Cyber Dawn: Libya ]||No||Industry Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Commerce ||2011-06-14||[http://www.nist.gov/nstic/2012-nstic-governance-recs.pdf Models for a Governance Structure for the National Strategy for Trusted Identities in Cyberspace ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Commerce ||2010||[[Defense_Industrial_Base_Assessment|Defense Industrial Base Assessment ]]||Yes||U.S. Government Report ||3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Commerce, Internet Policy Task Force||2011-06||[http://www.nist.gov/itl/upload/Cybersecurity_Green-Paper_FinalVersion.pdf Cybersecurity, Innovation and the Internet Economy]||No||U.S. Government Report||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2011-07-14||[http://www.defense.gov/news/d20110714cyber.pdf Department of Defense Strategy for Operating in Cyberspace ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2011-11-15||[http://www.defense.gov/home/features/2011/0411_cyberstrategy/docs/NDAA%20Section%20934%20Report_For%20webpage.pdf Department of Defense Cyberspace Policy Report : A Report to Congress Pursuant to the National Defense Authorization Act for Fiscal Year 2011, Section 934 ]||No||U.S. Government Report||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2012-02-16||[http://www.fas.org/sgp/othergov/dod/5200_01v1.pdf DOD Information Security Program: Overview, Classification, and Declassification ]||No||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2012-04-11||[http://www.nsci-va.org/CyberReferenceLib/2011-04-Cyber%20Ops%20Personnel.pdf Cyber Operations Personnel Report (DoD) ]||No||U.S. Government Report||&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||1999||[[An_Assessment_of_International_Legal_Issues_in_Information_Operations|An Assessment of International Legal Issues in Information Operations ]]||Yes||U.S. Government Report ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2005-||[[Strategy_for_Homeland_Defense_and_Civil_Support|Strategy for Homeland Defense and Civil Support ]]||Yes||U.S. Government Report ||3.2.4 [[Terrorists]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2007||[[Mission_Impact_of_Foreign_Influence_on_DoD_Software|Mission Impact of Foreign Influence on DoD Software ]]||Yes||U.S. Government Report ||3.2.4 [[Terrorists]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2011-04||[http://www.nsci-va.org/CyberReferenceLib/2011-04-Cyber%20Ops%20Personnel.pdf Cyber Operations Personnel Report (DOD) ]||No||U.S. Government Report ||&lt;br /&gt;
|-&lt;br /&gt;
| Department of Energy||2012-04||[http://energy.gov/sites/prod/files/OAS-RA-12-04.pdf The Department&#039;s Management of the Smart Grid Investment Grant Program]||No||U.S. Government Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Energy (DOE) Inspector General ||2012-01-01||[http://energy.gov/ig/downloads/departments-management-smart-grid-investment-grant-program-oas-ra-12-04 The Department’s Management of the Smart Grid Investment Grant Program ]||No||U.S. Government Report ||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Energy, Idaho National Laboratory ||2010-05-01||[http://www.fas.org/sgp/eprint/nstb.pdf NSTB Assessments Summary Report: Common Industrial Control System Cyber Security Weaknesses ]||No||U.S. Government Report||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Energy, Office of Electricity Delivery &amp;amp; Energy Reliability ||Undated||[http://energy.gov/oe/technology-development/energy-delivery-systems-cybersecurity Cybersecurity for Energy Delivery Systems Program ]||No||U.S. Government Report ||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2009-09-16||[http://www.cyber.st.dhs.gov/docs/National_Cyber_Leap_Year_Summit_2009_Co-Chairs_Report.pdf National Cyber Leap Year Summit 2009: Co-Chairs&#039; Report]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.8 [[Attribution]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2007-06||[http://www.oig.dhs.gov/assets/Mgmt/OIG_07-48_Jun07.pdf Challenges Remain in Securing the Nation’s Cyber Infrastructure]||No||U.S. Government Report||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2009-11||[http://www.cyber.st.dhs.gov/docs/DHS-Cybersecurity-Roadmap.pdf A Roadmap for Cybersecurity Research]||No||U.S. Government Report||1. [[Overview]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2010-08||[http://www.dhs.gov/xoig/assets/mgmtrpts/OIG_10-111_Aug10.pdf DHS Needs to Improve the Security Posture of Its Cybersecurity Program Systems]||No||U.S. Government Report||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2010-09||[http://www.federalnewsradio.com/pdfs/NCIRP_Interim_Version_September_2010.pdf National Cyber Incident Response Plan]||No||U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2011-11||[http://www.dhs.gov/xlibrary/assets/nppd/blueprint-for-a-secure-cyber-future.pdf Blueprint for a Secure Cyber Future: The Cybersecurity Strategy for the Homeland Security Enterprise]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security ||2003||[[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets|The National Strategy for the Physical Protection of Critical Infrastructures and Key Assets ]]||Yes||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security ||2009||[[A_Roadmap_for_Cybersecurity_Research|A Roadmap for Cybersecurity Research ]]||Yes||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Justice||2011-04||[http://www.justice.gov/oig/reports/FBI/a1122r.pdf The Federal Bureau of Investigation&#039;s Ability to Address the National Security Cyber Intrusion Threat]||No||U.S. Government Report||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Deputy Chief of Staff for Intelligence ||2006||[[Critical_Infrastructure_Threats_and_Terrorism|Critical Infrastructure Threats and Terrorism ]]||Yes||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Dörmann, Knut ||2004||[[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks|Applicability of the Additional Protocols to Computer Network Attacks ]]||Yes||Independent Report ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Douglas Maughan||2010||[[The_Need_for_a_National_Cybersecurity_Research_and_Development_Agenda|The Need for a National Cybersecurity Research and Development Agenda]]||Yes||Article||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Dunlap Charles J, Jr   ||2011||[[Perspectives_for_Cyber_Strategists_on_Law_for_Cyberwar|Perspectives for Cyber Strategists on Law for Cyberwar]]||Yes||Journal Article||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Dunlap, Charles J. Jr. ||2009||[[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century|Towards a Cyberspace Legal Regime in the Twenty-First Century ]]||Yes||Article||4.5 [[Psychology and Politics]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| EastWest Institute ||2011-02-03||[http://vialardi.org/nastrazzuro/pdf/US-Russia.pdf Working Towards Rules for Governing Cyber Conflict: Rendering the Geneva and Hague Conventions in Cyberspace ]||No||Independent Report||3.2.1 [[States]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Energetics Inc. ||2006||[[Roadmap_to_Secure_Control_Systems_in_the_Energy_Sector|Roadmap to Secure Control Systems in the Energy Sector ]]||Yes||Independent Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Energy Sector Control Systems Working Group||2011-09||[http://www.cyber.st.dhs.gov/wp-content/uploads/2011/09/Energy_Roadmap.pdf Roadmap to Achieve Energy Delivery Systems Cybersecurity]||No||U.S. Government Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| ENISA||2010||[[Introduction_to_Country_Reports|Introduction to Country Reports]]||Yes||Non-U.S. Government Report||3.2.1 [[States]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Epstein, Richard A. ||2008||[[Cybersecurity_in_the_Payment_Card_Industry|Cybersecurity in the Payment Card Industry ]]||Yes||Journal Article ||3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| European Network and Information Security Agency ||2010-10-07||[http://www.enisa.europa.eu/media/press-releases/stuxnet-analysis Stuxnet Analysis ]||No||Non-U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| European Network and Information Security Agency (ENISA) ||2011-04-11||[http://www.enisa.europa.eu/act/res/other-areas/inter-x/report/interx-report Resilience of the Internet Interconnection Ecosystem, at: ]||No||Non-U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Federal CIO Council ||2012-01-04||[http://www.gsa.gov/portal/category/102371 Federal Risk and Authorization Management Program (FedRAMP) ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Federal Communications Commission (FCC) ||2010-04-21||[http://hraunfoss.fcc.gov/edocs_public/attachmatch/DOC-305618A1.doc Explore the reliability and resiliency of commercial broadband communications networks ]||No||U.S. Government Report||3.3.3 [[Communications]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Federal Communications Commission (FCC) ||2011-06-03||[ftp://ftp.fcc.gov/pub/Daily_Releases/Daily_Business/2011/db0610/DOC-307454A1.txt FCC&#039;s Plan for Ensuring the Security of Telecommunications Networks ]||No||U.S. Government Report||&lt;br /&gt;
|-&lt;br /&gt;
| Financial Services Sector Coordinating Council for Critical Infrastructure Protection ||2008||[[Research_Agenda_for_the_Banking_and_Finance_Sector|Research Agenda for the Banking and Finance Sector ]]||Yes||Independent Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.1 [[Metrics]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| Fischer, Eric A.&amp;lt;br /&amp;gt;CRS||2012-04-23||[http://www.fas.org/sgp/crs/natsec/R42114.pdf Federal Laws Relating to Cybersecurity: Discussion of Proposed Revisions]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Franklin, Jason, et. al ||2007||[[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants|An Inquiry into the Nature and Causes of the Wealth of Internet Miscreants ]]||Yes||Independent Report ||3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| Gandal, Neil ||2008||[[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security|An Introduction to Key Themes in the Economics of Cyber Security ]]||Yes||Book ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2003-08-27||[http://www.gao.gov/products/GAO-03-760 Efforts to Improve Information sharing Need to Be Strengthened ]||No||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2004-05-28||[http://www.gao.gov/assets/160/157541.pdf Technology Assessment: Cybersecurity for Critical Infrastructure Protection]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2008-07-31||[http://www.gao.gov/assets/280/279084.pdf Cyber Analysis And Warning: DHS Faces Challenges in Establishing a Comprehensive National Capability]||No||U.S. Government Report||5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2009-09-24||[http://www.gao.gov/new.items/d09969.pdf Critical Infrastructure Protection: Current Cyber Sector-Specific Planning Approach Needs Reassessment]||No||U.S. Government Report||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2009-11-17||[http://www.gao.gov/products/GAO-10-230t Continued Efforts Are Needed to Protect Information Systems from Evolving Threats ]||No||U.S. Government Report ||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-03-05||[http://www.gao.gov/products/GAO-10-338 Cybersecurity: Progress Made But Challenges Remain in Defining and Coordinating the Comprehensive National Initiative ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-03-16||[http://www.gao.gov/products/GAO-11-463T Cybersecurity: Continued Attention Is Needed to Protect Federal Information Systems from Evolving Threats ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-03-24||[http://www.gao.gov/products/GAO-10-536t Information Security: Concerted Response Needed to Resolve Persistent Weaknesses, at: ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-04-12||[http://www.gao.gov/products/GAO-10-237 Concerted Effort Needed to Consolidate and Secure Internet Connections at Federal Agencies ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-06-03||[http://www.gao.gov/assets/310/305208.pdf Cybersecurity: Key Challenges Need to Be Addressed to Improve Research and Development]||No||U.S. Government Report||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-06-16||[http://www.gao.gov/products/GAO-10-834t Continued Attention Is Needed to Protect Federal Information Systems from Evolving Threats ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-07-01||[http://www.gao.gov/products/GAO-10-513 Federal Guidance Needed to Address Control Issues With Implementing Cloud Computing ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-07-15||[http://www.gao.gov/products/GAO-10-628 Critical Infrastructure Protection: Key Private and Public Cyber Expectations Need to Be Consistently Addressed ]||No||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-08-02||[http://www.gao.gov/products/GAO-10-606 United States Faces Challenges in Addressing Global Cybersecurity and Governance ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-09-15||[http://www.gao.gov/products/GAO-10-916 Information Security: Progress Made on Harmonizing Policies and Guidance for National Security and Non-National Security Systems ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-09-23||[http://www.gao.gov/products/GAO-10-772 DHS Efforts to Assess and Promote Resiliency Are Evolving but Program Management Could Be Strengthened ]||No||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-10-06||[http://www.gao.gov/products/GAO-11-24 Cyberspace Policy: Executive Branch Is Making Progress Implementing 2009 Policy Review Recommendations, but Sustained Leadership Is Needed ]||No||U.S. Government Report ||5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-11-30||[http://www.gao.gov/products/GAO-11-43 Information Security: Federal Agencies Have Taken Steps to Secure Wireless Networks, but Further Actions Can Mitigate Risk ]||No||U.S. Government Report ||3.3.3 [[Communications]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-01-12||[http://www.gao.gov/products/GAO-11-117 Electricity Grid Modernization: Progress Being Made on Cybersecurity Guidelines, but Key Challenges Remain to be Addressed ]||No||U.S. Government Report ||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-03-16||[http://www.gao.gov/products/GAO-11-463T Cybersecurity: Continued Attention Needed to Protect Our Nation&#039;s Critical Infrastructure and Federal Information Systems ]||No||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-07-08||[http://www.gao.gov/products/GAO-11-149 Information Security: State Has Taken Steps to Implement a Continuous Monitoring Application, but Key Challenges Remain ]||No||U.S. Government Report ||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-07-25||[http://www.gao.gov/products/GAO-11-75 Defense Department Cyber Efforts: DoD Faces Challenges in Its Cyber Activities ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-07-26||[http://www.gao.gov/products/GAO-11-463T Continued Attention Needed to Protect Our Nation’s Critical Infrastructure ]||No||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-07-29||[http://www.gao.gov/products/GAO-11-695R Defense Department Cyber Efforts: Definitions, Focal Point, and Methodology Needed for DoD to Develop Full-Spectrum Cyberspace Budget Estimates ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-10-03||[http://www.gao.gov/products/GAO-12-137 Information Security: Weaknesses Continue Amid New Federal Efforts to Implement Requirements ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-10-05||[http://www.gao.gov/products/GAO-12-130T Information Security: Additional Guidance Needed to Address Cloud Computing Concerns ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-10-17||[http://www.gao.gov/products/GAO-11-634 Federal Chief Information Officers: Opportunities Exist to Improve Role in Information Technology Management ]||No||U.S. Government Report ||5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-11-29||[http://www.gao.gov/products/GAO-12-8 Cybersecurity Human Capital: Initiatives Need Better Planning and Coordination, at: ]||No||U.S. Government Report ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-12-09||[http://www.gao.gov/products/GAO-12-92 Critical Infrastructure Protection: Cybersecurity Guidance Is Available, but More Can Be Done to Promote Its Use ]||No||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2012-01-13||[http://www.gao.gov/assets/590/587681.pdf Defense Contracting: Improved Policies and Tools Could Help Increase Competition on DOD&#039;s National Security Exception Procurements]||No||U.S. Government Report||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2012-02-28||[http://www.csit.qub.ac.uk/media/pdf/Filetoupload,252359,en.pdf Cybersecurity: Challenges to Securing the Modernized Electricity Grid ]||No||Non-U.S. Government Report ||&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2009||[[Critical_Infrastructure_Protection|Critical Infrastructure Protection - Current Cyber Sector-Specific Planning Approach Needs Reassessment]]||Yes||U.S. Government Report||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2009-07||[http://www.gao.gov/new.items/d09546.pdf Information Security: Agencies Continue to Report Progress, but Need to. Mitigate Persistent Weaknesses]||No||U.S. Government Report||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2009-09||[http://www.gao.gov/new.items/d09617.pdf Information Security: Concerted Effort Needed to Improve Federal Performance Measures]||No||U.S. Government Report||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010||[[Information_Security|Information Security - Concerted Effort Needed to Consolidate and Secure Internet Connections at Federal Agencies]]||Yes||U.S. Government Report||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO ||2011-10-05||[http://www.gao.gov/products/GAO-12-130T Information Security: Additional Guidance Needed to Address Cloud Computing Concerns ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Geer, Daniel E. and Conway, Daniel G.||2010||[[Nothing_Ventured,_Nothing_Gained|Nothing Ventured, Nothing Gained]]||Yes||Journal Article||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Gellman, Robert||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059444.pdf Civil Liberties and Privacy Implications of Policies to Prevent Cyberattacks ]||No||Journal Article||4.8 [[Attribution]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2010-07-15||[http://www.gao.gov/products/GAO-10-628 Critical Infrastructure Protection: Key Private and Public Cyber Expectations Need to Be Consistently Addressed ]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2011-01-12||[http://www.gao.gov/products/GAO-11-117 Electricity Grid Modernization: Progress Being Made on Cybersecurity Guidelines, but Key Challenges Remain to be Addressed ]||No||U.S. Government Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2011-03-16||[http://www.gao.gov/products/GAO-11-463T Cybersecurity: Continued Attention Needed to Protect Our Nation&#039;s Critical Infrastructure and Federal Information Systems ]||No||U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2011-07-29||[http://www.gao.gov/products/GAO-11-695R Defense Department Cyber Efforts: Definitions, Focal Point, and Methodology Needed for DOD to Develop Full-Spectrum Cyberspace Budget Estimates ]||No||U.S. Government Report ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2011-11-29||[http://www.gao.gov/products/GAO-12-8 Cybersecurity Human Capital: Initiatives Need Better Planning and Coordination ]||No||U.S. Government Report||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2011-12-09||[http://www.gao.gov/products/GAO-12-92 Critical Infrastructure Protection: Cybersecurity Guidance Is Available, but More Can Be Done to Promote Its Use ]||No||U.S. Government Report ||&lt;br /&gt;
|-&lt;br /&gt;
| General Services Administration (GSA) ||2012-02-07||[http://www.gsa.gov/graphics/staffoffices/FedRAMP_CONOPS.pdf Concept of Operations: FedRAMP ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Grady, Mark F. ||2006||[[The_Law_and_Economics_of_Cybersecurity|The Law and Economics of Cybersecurity ]]||Yes||Book ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Graham David E   ||2010||[[Cyber_Threats_and_the_Law_of_War| Cyber Threats and the Law of War]]||Yes||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Granick, Jennifer Stisa ||2005||[[The_Price_of_Restricting_Vulnerability_Publications|The Price of Restricting Vulnerability Publications ]]||Yes||Journal Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Hollis, Duncan B. ||2007||[[Why_States_Need_an_International_Law_for_Information_Operations|Why States Need an International Law for Information Operations ]]||Yes||Journal Article ||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;4.13.1 [[Government to Government|Government to Government Espionage]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| HP TippingPoint DVLabs ||2010||[[2010_Top_Cyber_Security_Risks_Report|2010 Top Cyber Security Risks Report ]]||Yes||Industry report ||4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| IEEE/EastWest Institute ||2010-05-26||[http://www.ieee-rogucci.org/files/The%20ROGUCCI%20Report.pdf The Reliability of Global Undersea Communications Cable Infrastructure (The Rogucci Report) ]||No||Independent Report||3.3.3 [[Communications]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Institute for Information Infrastructure Protection ||2003||[[Cyber_Security_Research_and_Development_Agenda|Cyber Security Research and Development Agenda ]]||Yes||Independent Report ||4.1 [[Metrics]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Institute for Science and International Security ||2010-12-22||[http://isis-online.org/isis-reports/detail/did-stuxnet-take-out-1000-centrifuges-at-the-natanz-enrichment-plant/ Did Stuxnet Take Out 1,000 Centrifuges at the Natanz Enrichment Plant? Preliminary Assessment ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| International Instrument Users Association (WIB) ||2010-11-10||[http://www.isssource.com/wib/ WIB Security Standard Released ]||No||Industry Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| International Telecommunications Union ||2012-02-10||[http://www.itu.int/ITU-D/cyb/cybersecurity/docs/itu-toolkit-cybercrime-legislation.pdf ITU Toolkit for Cybercrime Legislation ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| James Clapper, Director of National Intelligence ||2011-02-10||[http://www.dni.gov/testimonies/20110210_testimony_clapper.pdf Worldwide Threat Assessment of the U.S. Intelligence Community (Testimony) ]||No||U.S. Government Report||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.2 [[Actors and Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Johnson, Eric M. ||2008||[[Managing_Information_Risk_and_the_Economics_of_Security|Managing Information Risk and the Economics of Security ]]||Yes||Book ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Johnson, Vincent R. ||2005||[[Cybersecurity,_Identity_Theft,_and_the_Limits_of_Tort_Liability|Cybersecurity, Identity Theft, and the Limits of Tort Liability ]]||Yes||Journal Article ||4.9 [[Identity Management]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Joint Workshop of the National Security Threats in Cyberspace and the National Strategy Forum ||2009-09-15||[http://nationalstrategy.com/Portals/0/National%20Security%20Threats%20in%20Cyberspace%20FINAL%2009-15-09.pdf National Security Threats in Cyberspace ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| Joseph S. Nye||2010||[[Cyber_Power|Cyber Power]]||Yes||Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Journal of Strategic Studies ||2011-10-05||[http://www.tandfonline.com/doi/abs/10.1080/01402390.2011.6089393 Cyber War Will Not Take Place ]||No||Journal Article||&lt;br /&gt;
|-&lt;br /&gt;
| Kelly A. Gable||2010||[[Cyber-Apocalypse_Now|Cyber-Apocalypse Now - Securing the Internet Against Cyberterrorism and Using Universal Jurisdiction as a Deterrent]]||Yes||Journal Article||3.2.4 [[Terrorists]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Kerr, Paul K. et al.&amp;lt;br /&amp;gt;CRS||2010-12-09||[http://www.fas.org/sgp/crs/natsec/R41524.pdf The Stuxnet Computer Worm: Harbinger of an Emerging Warfare Capability]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.4 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Kesan, Jay P. and Hayes, Carol M.||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059446.pdf Thinking Through Active Defense in Cyberspace ]||No||Journal Article||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Kobayashi, Bruce H.||2005||[[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods|An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and other Public Security Goods]]||Yes||Journal Article||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Kobayashi, Bruce H. ||2006||[[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods|An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and Other Public Security Goods ]]||Yes||Journal Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Korns, Stephen W. ||2009||[[Cyber_Operations|Cyber Operations ]]||Yes||Journal Article ||4.8 [[Attribution]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Kramer, Franklin D., et. al ||2009||[[Cyberpower_and_National_Security|Cyberpower and National Security ]]||Yes||Book ||1. [[Overview]]&lt;br /&gt;
|-&lt;br /&gt;
| Kundra, Vivek||2010-12-09||[http://www.cio.gov/documents/25-point-implementation-plan-to-reform-federal%20it.pdf 25 Point Implementation Plan to Reform Federal Information Technology Management]||No||U.S. Government Report||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Kundra, Vivek||2011-02-08||[http://www.cio.gov/documents/federal-cloud-computing-strategy.pdf Federal Cloud Computing Strategy]||No||U.S. Government Report||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Lan, Tang et al.||2010||[[Global_Cyber_Deterrence|Global Cyber Deterrence: Views from China, the U.S., Russia, India, and Norway]]||Yes||Independent Report||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Lernard, Thomas M. ||2005||[[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches|An Economic Analysis of Notification Requirements for Data Security Breaches ]]||Yes||Independent Report ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Lernard, Thomas M. ||2006||[[Much_Ado_About_Notification|Much Ado About Notification ]]||Yes||Journal Article ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Lewis, James Andrews||2005||[[Cyber_Security_and_Regulation_in_the_United_States|Aux armes, citoyens: Cyber Security and Regulation in the United States]]||Yes||Journal Article||3.3.1 [[Public Critical Infrastructure,&amp;lt;br&amp;gt;3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;3.3.2.3 [[Transportation]]&lt;br /&gt;
|-&lt;br /&gt;
| Libicki, Martin||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059490.pdf Pulling Punches in Cyberspace]||No||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
|Lin, Herbert||2012||[[Image:Lin-Cyberattack-Capabilities-2009.pdf|Cyber Conflict and National Security]]||No||Article||&lt;br /&gt;
|-&lt;br /&gt;
| Lukasik, Stephen J.||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059438.pdf A Framework for Thinking about Cyber Conflict and Cyber Deterrence with Possible Declatory Policies for these Domain]||No||Journal Article||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Massachusetts Institute of Technology (MIT) ||2011-12-05||[http://web.mit.edu/mitei/research/studies/the-electric-grid-2011.shtml The Future of the Electric Grid ]||No||Independent Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| McAfee ||2011-08-02||[http://www.mcafee.com/us/resources/white-papers/wp-operation-shady-rat.pdf Revealed: Operation Shady RAT: an Investigation Of Targeted Intrusions Into 70+ Global Companies, Governments, and Non-Profit Organizations During the Last 5 Years ]||No||Industry Report||3.2.1 [[States]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.13 [[Espionage]]&lt;br /&gt;
|-&lt;br /&gt;
| McAfee ||2012-02-01||[http://www.mcafee.com/us/resources/reports/rp-sda-cyber-security.pdf?cid=WBB048 Cyber-security: The Vexed Question of Global Rules: An Independent Report on Cyber-Preparedness Around the World ]||No||Industry Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| McAfee and Center for Strategic and International Studies (CSIS) ||2011-04-21||[http://www.mcafee.com/us/resources/reports/rp-critical-infrastructure-protection.pdf In the Dark: Crucial Industries Confront Cyberattacks ]||No||Industry Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt; 4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| McAfee and the Security Defense Agenda||2012-02-12||[http://www.mcafee.com/us/resources/reports/rp-sda-cyber-security.pdf Cyber-security: The Vexed Question of Global Rules: An Independent Report on Cyber-Preparedness Around the World]||No||Industry Report||1. [[Overview]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| McAfee, Inc. ||2010||[[McAfee_Threats_Report|McAfee Threats Report ]]||Yes||Industry Report ||3.2.3 [[Hacktivists]],&amp;lt;br&amp;gt;3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| McDermott, Rose||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059442.pdf Decision Making Under Uncertainty]||No||Journal Article||4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;4.5 [[Psychology and Politics]],&amp;lt;br&amp;gt;4.8 [[Attribution]]&lt;br /&gt;
|-&lt;br /&gt;
| Microsoft||2010-11||[http://cdn.globalfoundationservices.com/documents/InformationSecurityMangSysforMSCloudInfrastructure.pdf Information Security Management System for Microsoft Cloud Infrastructure ]||No||Industry Report||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Mitre Corp (JASON Program Office) ||2010-11||[http://www.fas.org/irp/agency/dod/jason/cyber.pdf Science of Cyber-Security ]||No||Independent Report||1. [[Overview]],&amp;lt;br&amp;gt;4. [[Issues]]&lt;br /&gt;
|-&lt;br /&gt;
| Moore, Tyler||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059364.pdf Introducing the Economics of Cybersecurity: Principles and Policy Options]||No||Journal Article||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Moore, Tyler ||2007||[[Examining_the_Impact_of_Website_Take-down_on_Phishing|Examining the Impact of Website Take-down on Phishing ]]||Yes||Independent Report ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Moore, Tyler ||2008||[[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing|The Consequence of Non-Cooperation in the Fight Against Phishing ]]||Yes||Independent Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]]&lt;br /&gt;
|-&lt;br /&gt;
| Moore, Tyler ||2009||[[The_Impact_of_Incentives_on_Notice_and_Take-down|The Impact of Incentives on Notice and Take-down ]]||Yes||Book ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Moore, Tyler, et. al ||2009||[[The_Economics_of_Online_Crime|The Economics of Online Crime ]]||Yes||Journal Article ||3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| Morgan, Patrick M. ||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059436.pdf Applicability of Traditional Deterrence Concepts and Theory to the Cyber Realm ]||No||Journal Article||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]],&amp;lt;br&amp;gt;5.6 [[Deterrence ]]&lt;br /&gt;
|-&lt;br /&gt;
| National Association of Secretaries of State ||2012-01-12||[http://www.nass.org/index.php?option=com_docman&amp;amp;task=doc_download&amp;amp;gid=1257 Developing State Solutions to Business Identity Theft: Assistance, Prevention and Detection Efforts by Secretary of State Offices ]||No||Independent Report||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Cyber Defense Initiative ||2009||[[National_Cyber_Defense_Financial_Services_Workshop_Report|National Cyber Defense Financial Services Workshop Report ]]||Yes||Independent Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Cyber Security Alliance and Microsoft ||2011-05-13||[http://www.staysafeonline.org/sites/default/files/resource_documents/2011%20National%20K-12%20Study%20Final_0.pdf 2011 State of Cyberethics, Cybersafety and Cybersecurity Curriculum in the U.S. Survey ]||No||Industry Report||4.4 [[Usability/Human Factors]]&lt;br /&gt;
|-&lt;br /&gt;
| National Cyber Security Summit Task Force ||2004||[[Information_Security_Governance|Information Security Governance ]]||Yes||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]],&amp;lt;br&amp;gt;5.3 [[government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Infrastructure Advisory Council ||2004||[[Hardening_The_Internet|Hardening The Internet ]]||Yes||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Initiative for Cybersecurity Education||2011-08-11||[http://csrc.nist.gov/nice/documents/nicestratplan/Draft_NICE-Strategic-Plan_Aug2011.pdf National Initiative for Cybersecurity Education Strategic Plan: Building a Digital Nation]||No||U.S. Government Report||1. [[Overview]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Initiative for Cybersecurity Education (NICE) ||2011-11-21||[http://csrc.nist.gov/nice/framework/documents/NICE-Cybersecurity-Workforce-Framework-printable.pdf NICE Cybersecurity Workforce Framework ]||No||U.S. Government Report||4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Institute of Standards and Technology ||2006||[[SP_800-82:_Guide_to_Supervisory_Control_and_Data_Acquisition_(SCADA)_and_Industrial_Control_Systems_Security|SP 800-82: Guide to Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems Security ]]||Yes||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Institute of Standards and Technology (NIST) ||2010-09-02||[http://www.nist.gov/public_affairs/releases/nist-finalizes-initial-set-of-smart-grid-cyber-security-guidelines.cfm NIST Finalizes Initial Set of Smart Grid Cyber Security Guidelines ]||No||U.S. Government Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council ||2009||[http://www.nap.edu/catalog.php?record_id=12651 Technology, Policy, Law, and Ethics Regarding U.S. Acquisition and Use of Cyberattack Capabilities]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council ||2010-09-21||[http://www.nap.edu/catalog.php?record_id=12998 Toward Better Usability, Security, and Privacy of Information Technology: Report of a Workshop ]||No||Independent Report||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;4.10 [[Privacy]]&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council ||2010-10-05||[http://www.nap.edu/catalog.php?record_id=12997#description Proceedings of a Workshop on Deterring Cyberattacks: Informing Strategies and Developing Options for U.S. Policy ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council ||1999||[[Trust_in_Cyberspace|Trust in Cyberspace ]]||Yes||Independent Report ||3.3.3.2 [[Public Data Networks]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council ||2007||[[Toward_a_Safer_and_More_Secure_Cyberspace|Toward a Safer and More Secure Cyberspace ]]||Yes||Independent Report ||1. [[Overview]],&amp;lt;br&amp;gt;4.8 [[Attribution]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council, Committee for Advancing Software-Intensive Systems Producibility ||2010-10-20||[http://www.nap.edu/catalog.php?record_id=12979 Critical Code: Software Producibility for Defense ]||No||Independent Reprot ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| National Science and Technology Council ||2006||[[Federal_Plan_for_Cyber_Security_and_Information_Assurance_Research_and_Development|Federal Plan for Cyber Security and Information Assurance Research and Development ]]||Yes||U.S. Government Report ||4.1 [[Metrics]],&amp;lt;br&amp;gt;4.7 [[Attribution]],&amp;lt;br&amp;gt;4.8 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| National Science Foundation||2011-08-11||[http://www.livescience.com/15423-forefront-cyber-security-research-nsf-bts.html At the Forefront of Cyber Security Research ]||No||U.S. Government Report||5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| National Science Foundation||2012-01-17||[http://www.nsf.gov/awardsearch/showAward.do?AwardNumber=1127185 Information Security Risk Taking ]||No||U.S. Government Report||4.1 [[Metrics]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Security Cyberspace Institute||2012-07-11||[http://www.nsci-va.org/WhitePapers/2011-07-22-Cyber Analogies Whitepaper-K McKee.pdf A Review of Frequently Used Cyber Analogies ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| National Security Initiative ||2010-10-18||[http://www.americansecuritychallenge.com/ American Security Challenge ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| Networking and Information Technology Research and Development ||2009||[[National_Cyber_Leap_Year_Summit_2009,_Co-Chairs%27_Report|National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report ]]||Yes||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| NIST ||2011-09-01||[http://www.nist.gov/customcf/get_pdf.cfm?pub_id=909505 Cloud Computing Reference Architecture ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]]&lt;br /&gt;
|-&lt;br /&gt;
| NIST ||2011-12-01||[http://www.nist.gov/itl/cloud/upload/SP_500_293_volumeII.pdf U.S. Government Cloud Computing Technology Roadmap, Release 1.0 (Draft), Volume II Useful Information for Cloud Adopters ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| NIST ||2012-02-17||[http://www.nist.gov/nstic/2012-nstic-governance-recs.pdf Recommendations for Establishing an Identity Ecosystem Governance Structure for the National Strategy for Trusted Identities in Cyberspace ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Nojeim, Gregory T.||2009||[[Cybersecurity:_Preventing_Terrorist_Attacks_and_Protecting_Privacy_in_Cyberspace|Cybersecurity: Preventing Terrorist Attacks and Protecting Privacy in Cyberspace]]||Yes||U.S. Government Hearing||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| North American Electric Reliability Corp. (NERC) ||2011-01-26||[http://www.wired.com/images_blogs/threatlevel/2011/02/DoE-IG-Report-on-Grid-Security.pdf Federal Energy Regulatory Commission&#039;s Monitoring of Power Grid Cyber Security ]||No||U.S. Government Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| NSTC||2011-12||[http://www.whitehouse.gov/sites/default/files/microsites/ostp/fed_cybersecurity_rd_strategic_plan_2011.pdf Trustworthy Cyberspace: Strategic Plan for the Federal Cybersecurity Research and Development Program]||No||U.S. Government Report||5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Nye, Joseph ||2010||[[Cyber_Power|Cyber Power ]]||Yes||Book ||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;4.13 [[Espionage]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| OECD||2009||[[Cybersecurity_and_Economic_Incentives|Cybersecurity and Economic Incentives]]||Yes||Non-U.S. Government Report||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| OECD||2009||[[The_Market_Consequences_of_Cybersecurity|The Market Consequences of Cybersecurity]]||Yes||Non-U.S. Government Report||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Office of the National Counterintelligence Executive ||2011-11-03||[http://www.ncix.gov/publications/reports/fecie_all/Foreign_Economic_Collection_2011.pdf Foreign Spies Stealing US Economic Secrets in Cyberspace ]||No||U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;4.13 [[Espionage]]&lt;br /&gt;
|-&lt;br /&gt;
| Organisation for Economic Co-operation and Development (OECD) ||2010-11-12||[http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.165.2211&amp;amp;rep=rep1&amp;amp;type=pdf The Role of Internet Service Providers in Botnet Mitigation: an Empirical Analysis Bases on Spam Data ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Organization for Economic Co-operation and Development (OECD) ||2012-01-10||[http://www.oecd-ilibrary.org/docserver/download/fulltext/5k9h2q8v9bln.pdf?expires=1330527950&amp;amp;id=id&amp;amp;accname=guest&amp;amp;checksum=F4470043AC638BE19D5131C3D5CE5EA4 ICT Applications for the Smart Grid: Opportunities and Policy Implications ]||No||Independent Report ||&lt;br /&gt;
|-&lt;br /&gt;
| PCAST||2010-12||[http://www.whitehouse.gov/sites/default/files/microsites/ostp/pcast-nitrd-report-2010.pdf Designing a Digital Future: Federally Funded Research and Development in Networking and Information Technology]||No||U.S. Government Report||4.3 [[Supply Chain Issues]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| PCAST||2011-06||[http://www.whitehouse.gov/sites/default/files/microsites/ostp/pcast-advanced-manufacturing-june2011.pdf Report to the President on Ensuring American Leadership in Advanced Manufacturing]||No||U.S. Government Report||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Perkins, Earl||2009||[[Evolving_Cybersecurity_Issues_in_the_Utility_Industry|Evolving Cybersecurity Issues in the Utility Industry]]||Yes||Independent Report||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.2.4 [[Water, Sewer, etc.]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Pew Research Center’s Internet &amp;amp; American Life Project ||2010-06-11||[http://pewinternet.org/Reports/2010/The-future-of-cloud-computing.aspx The future of cloud computing ]||No||Independent Report||3.3.3.3 [[Cloud Computing]]&lt;br /&gt;
|-&lt;br /&gt;
| Powell, Benjamin ||2005||[[Is_Cybersecurity_a_Public_Good|Is Cybersecurity a Public Good ]]||Yes||Journal Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.5 [[Market Failure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| President&#039;s Commission on Critical Infrastructure Protection ||1997||[[Critical_Foundations|Critical Foundations ]]||Yes||U.S. Government Report ||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.3 [[Communications]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| President&#039;s Information Technology Advisory Council ||2005||[[Cyber_Security:_A_Crisis_of_Prioritization|Cyber Security: A Crisis of Prioritization ]]||Yes||U.S. Government Report ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Project on National Security Reform (PNSR) ||2010-11||[http://www.pnsr.org/data/images/pnsr_the_power_of_people_report.pdf The Power of People: Building an Integrated National Security Professional System for the 21st Century ]||No||U.S. Government Report||4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Quadrennial Defense Review ||2010-07-30||[http://www.usip.org/quadrennial-defense-review-independent-panel-/view-the-report The QDR in Perspective: Meeting AmericaÅfs National Security Needs In the 21st Century (QDR Final Report) ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| RAND||2011-12-21||[http://www.rand.org/content/dam/rand/pubs/occasional_papers/2011/RAND_OP342.pdf A Cyberworm that Knows No Boundaries ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Rattray, Gregory and Healey, Jason||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059437.pdf Categorizing and Understanding Offensive Cyber Capabilities and Their Use ]||No||Journal Article||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Rollins, John and Wilson, Clay||2007||[[Terrorist_Capabilities_for_Cyberattack|Terrorist Capabilities for Cyberattack]]||Yes||U.S. Government Report||3.2.4 [[Terrorists]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Romanosky et al. ||2008||[[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft|Do Data Breach Disclosure Laws Reduce Identity Theft ]]||Yes||Independent Report ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Rosenzweig, Paul||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059443.pdf The Organization of the United States Government and Private Sector for Achieving Cyber Deterrence ]||No||Journal Article||4.3 [[Supply Chain Issues]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Rotenberg et. al. ||2010||[[The_Cyber_War_Threat_Has_Been_Grossly_Exaggerated|The Cyber War Threat Has Been Grossly Exaggerated ]]||Yes||Article||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Rue, Rachel and Pfleeger, Shari Lawrence||2009||[[Making_the_Best_Use_of_Cybersecurity_Economic_Models|Making the Best Use of Cybersecurity Economic Models]]||Yes||Journal Article||4.1 [[Metrics]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| Santos, Joost R., et. al||2007||[[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies|A Framework for Linking Cybersecurity Metrics to the Modeling of Macroeconomic Interdependencies]]||Yes||Journal Article||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;4.1 [[Metrics]]&lt;br /&gt;
|-&lt;br /&gt;
| Schmitt Michael N   ||2002||[[Wired_Warfare| Wired warfare: Computer network attack and jus in bello]]||Yes||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Schmitt Michael N   ||2004||[[Direct_Participation_in_Hostilities|Direct Participation in Hostilities and 21st Century Armed Conflict]]||Yes||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Schmitt, Michael N. ||1999||[[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law|Computer Network Attack and the Use of Force in International Law ]]||Yes||Journal Article ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Schmitt, Michael N. ||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059439.pdf Cyber Operations in International Law: The Use of Force, Collective Security, Self-Defense, and Armed Conflicts]||No||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Schmitt, Michael N., et. al ||2004||[[Computers_and_War|Computers and War ]]||Yes||Independent Report ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Schneidewind, Norman||2010||[[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks|Metrics for Mitigating Cybersecurity Threats to Networks]]||Yes||Journal Article||4.1 [[Metrics]]&lt;br /&gt;
|-&lt;br /&gt;
| Schneier, Bruce ||2003||[[Beyond_Fear|Beyond Fear ]]||Yes||Book ||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;4.5 [[Psychology and Politics]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Schneier, Bruce ||2008||[[Schneier_on_Security|Schneier on Security ]]||Yes||Book ||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Schwartz, Paul ||2007||[[Notification_of_Data_Security_Breaches|Notification of Data Security Breaches ]]||Yes||Journal Article ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Secretary of the Air Force ||2011-07-27||[http://www.e-publishing.af.mil/shared/media/epubs/AFI51-402.pdf Legal Reviews of Weapons and Cyber Capabilities ]||No||U.S. Government Report ||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Shackelford, Scott J.||2010||[[Estonia_Three_Years_Later|Estonia Three Years Later]]||Yes||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Shah, Shashi K.||2004||[[The_Evolving_Landscape_of_Maritime_Cybersecurity|The Evolving Landscape of Maritime Cybersecurity]]||Yes||Journal Article||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.2.3 [[Transportation]]&lt;br /&gt;
|-&lt;br /&gt;
| Sklerov, Matthew J. ||2009||[[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks|Solving the Dilemma of State Responses to Cyberattacks ]]||Yes||Journal Article ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.8 [[Attribution]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Sofaer, Abraham; Clark, David; and Diffie, Whitfield||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059440.pdf Cyber Security and International Cooperation ]||No||Journal Article||5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Software and Information Industry Association (SAII) ||2011-07-26||[http://www.siia.net/index.php?option=com_docman&amp;amp;task=doc_download&amp;amp;gid=3040&amp;amp;Itemid=318 Guide to Cloud Computing for Policy Makers ]||No||Independent Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Stohl, Michael ||2006||[[Cyber_Terrorism|Cyber Terrorism ]]||Yes||Journal Article ||3.2.3 [[Hacktivists]],&amp;lt;br&amp;gt;3.2.4 [[Terrorists]],&amp;lt;br&amp;gt;4.5 [[Psychology and Politics]]&lt;br /&gt;
|-&lt;br /&gt;
| Stuart Madnick et al.||2009||[[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security|Experiences and Challenges with Using CERT Data to Analyze International Cyber Security]]||Yes||Journal Article||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Swire, Peter P. ||2004||[[A_Model_for_When_Disclosure_Helps_Security|A Model for When Disclosure Helps Security ]]||Yes||Journal Article ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Swire, Peter P. ||2006||[[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons|A Theory of Disclosure for Security and Competitive Reasons ]]||Yes||Journal Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Symantec||2011-10-24||[http://www.symantec.com/connect/w32_duqu_precursor_next_stuxnet W32.Duqu: The Precursor to the Next Stuxnet ]||No||Industry Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Symantec Corporation ||2010||[[Symantec_Global_Internet_Security_Threat_Report|Symantec Global Internet Security Threat Report ]]||Yes||Industry Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| Telang, Rahul ||2007||[[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors|Impact of Software Vulnerability Announcements on the Market Value of Software Vendors ]]||Yes||Journal Article ||4.1 [[Metrics]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]]&lt;br /&gt;
|-&lt;br /&gt;
| Theohary, Catherine A. and Rollins, John||2010||[[Cybersecurity:_Current_Legislation,_Executive_Branch_Initiatives,_and_Options_for_Congress|Cybersecurity: Current Legislation, Executive Branch Initiatives, and Options for Congress]]||Yes||U.S. Government Report||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Thom, Maxie    ||2006||[[Information_Warfare_Arms_Control| Information Warfare Arms Control: Risks and Costs]]||Yes||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Thomas, Rob ||2006||[[The_Underground_Economy|The Underground Economy ]]||Yes||Journal Article ||3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| Threat Level Blog (Wired) ||2010-12-27||[http://www.wired.com/threatlevel/2010/12/a-four-day-dive-into-stuxnets-heart/ A Four-Day Dive Into Stuxnet’s Heart ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Todd, Graham H. ||2009||[[Armed_Attack_in_Cyberspace|Armed Attack in Cyberspace ]]||Yes||Journal Article ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.8 [[Attribution]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Trend Micro Incorporated ||2010||[[Trend_Micro_Annual_Report|Trend Micro Annual Report ]]||Yes||Industry Report ||4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Air Force ||2010-07-15||[http://www.e-publishing.af.mil/shared/media/epubs/afdd3-12.pdf Cyberspace Operations: Air Force Doctrine Document 3-12 ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Army War College ||2011-05-09||[http://www.strategicstudiesinstitute.army.mil/pubs/display.cfm?pubid=10670 Cyber Infrastructure Protection ]||No||U.S. Government Report||&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Army War College, Strategy Research Project ||2011-03-24||[http://www.dtic.mil/dtic/tr/fulltext/u2/a552990.pdf China’s Cyber Power and America’s National Security ]||No||U.S. Government Report||3.2.1 [[States]],&amp;lt;br&amp;gt;4.13 [[Espionage]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Department of Energy, Infrastructure Security and Energy Restoration ||2007-01-01||[http://www.oe.netl.doe.gov/docs/prepare/21stepsbooklet.pdf 21 Steps to Improve Cyber Security of SCADA Networks ]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Deputy Secretary of Defense, William J. Lynn (Foreign Affairs) ||2010-009||[http://www.foreignaffairs.com/articles/66552/william-j-lynn-iii/defending-a-new-domain Defending a New Domain ]||No||U.S. Government Report ||&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Appropriations (closed/classified) (Subcommittee on Energy and Power)||2011-03-31||[http://www.dhs.gov/ynews/testimony/testimony_1301595025263.shtm Budget Hearing - National Protection and Programs Directorate, Cybersecurity and Infrastructure Protection Programs  ]||No||U.S. Government Hearing||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2011-02-11||[http://armedservices.house.gov/index.cfm/hearings-display?ContentRecord_id=90d8a16a-23b7-4b9c-a732-cb10ab20e579&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=64562e79-731a-4ac6-aab0-7bd8d1b7e890&amp;amp;MonthDisplay=2&amp;amp;YearDisplay=2011 What Should the Department of Defense’s Role in Cyber Be?]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2011-03-16||[http://armedservices.house.gov/index.cfm/hearings-display?ContentRecord_id=79ce7b4c-f88b-40bf-9540-efdb3a2d26b2&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=64562e79-731a-4ac6-aab0-7bd8d1b7e890&amp;amp;MonthDisplay=3&amp;amp;YearDisplay=2011 2012 Budget Request from U.S. Cyber Command]||No||U.S. Government Hearing||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2011-11-03||[http://armedservices.house.gov/index.cfm/hearings-display?ContentRecord_id=42c170fb-8e0c-453a-81a2-f4ee3fa89283&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=64562e79-731a-4ac6-aab0-7bd8d1b7e890&amp;amp;MonthDisplay=11&amp;amp;YearDisplay=2011 Institutionalizing Irregular Warfare Capabilities]||No||U.S. Government Hearing||4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2012-03-20||[http://armedservices.house.gov/index.cfm/hearings-display?ContentRecord_id=92823c77-38f0-4c20-a3ee-36729e8e19a3&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=64562e79-731a-4ac6-aab0-7bd8d1b7e890&amp;amp;MonthDisplay=3&amp;amp;YearDisplay=2012 Fiscal 2013 Defense Authorization: IT and Cyber Operations]||No||U.S. Government Hearing||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce||2011-05-31||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=8639 Protecting the Electric Grid: the Grid Reliability and Infrastructure Defense Act]||No||U.S. Government Hearing||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Commerce, Manufacturing, and Trade)||2011-06-02||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=8653 Sony and Epsilon: Lessons for Data Security Legislation]||No||U.S. Government Hearing||4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Commerce,Trade and Manufacturing)||2011-06-15||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=8693 Discussion Draft of H.R. ___, a bill to require greater protection for sensitive consumer data and timely notification in case of breach]||No||U.S. Government Hearing||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Communications and Technology)||2012-03-07||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=9342 Cybersecurity:Networks     The Pivotal Role of Communications]||No||U.S. Government Hearing||3.3.3 [[Communications]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Communications and Technology)||2012-03-28||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=9397 Cybersecurity:Threats to Communications Networks and Public-Sector Responses]||No||U.S. Government Hearing||3.3.3 [[Communications]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Oversight and Investigations)||2011-07-26||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=8824 Cybersecurity: Infrastructure An Overview of Risks to Critical]||No||U.S. Government Hearing||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Oversight and Investigations)||2012-02-28||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=9318 Critical Infrastructure Cybersecurity: Assessments of Smart Grid Security]||No||U.S. Government Hearing||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Oversight and Investigations)||2012-03-27||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=9393 IT Supply Chain Security: Review of Government and Industry Efforts]||No||U.S. Government Hearing||4.3 [[Supply Chain Issues]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Financial Services (field hearing in Hoover, AL)||2011-06-29||[http://financialservices.house.gov/Calendar/EventSingle.aspx?EventID=246611 Field Hearing: Hacked Off: Helping Law Enforcement Protect Private Financial Information]||No||U.S. Government Hearing||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Financial Services (Subcommittee on Financial Institutions and Consumer Credit)||2011-09-14||[http://financialservices.house.gov/Calendar/EventSingle.aspx?EventID=258792 Combating Cybercriminals]||No||U.S. Government Hearing||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;5.7 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Foreign Affairs (Subcommittee on Oversight and Investigations)||2011-04-15||[http://foreignaffairs.house.gov/hearing_notice.asp?id=1279 Communist Chinese Cyber-Attacks, Cyber-Espionage and Theft of American Technology]||No||U.S. Government Hearing||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;4.13 [[Espionage]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies and Counterterrorism and Intelligence)||2012-04-19||[http://homeland.house.gov/hearing/subcommittee-hearing-dhs-and-doe-national-labs-finding-efficiencies-and-optimizing-outputs The DHS and DOE National Labs: Finding Efficiencies and Optimizing Outputs in Homeland Security Research and Development]||No||U.S. Government Hearing||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies and Counterterrorism and Intelligence)||2012-04-26||[http://homeland.house.gov/hearing/joint-subcommittee-hearing-iranian-cyber-threat-us-homeland Iranian Cyber Threat to U.S. Homeland]||No||U.S. Government Hearing||3.2.1 [[States]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2011-02-11||[http://homeland.house.gov/hearing/subcommittee-hearing-%E2%80%9Cpreventing-chemical-terrorism-building-foundation-security-our-nation Preventing Chemical Terrorism: Building a Foundation of Security at Our Nation’s Chemical Facilities]||No||U.S. Government Hearing||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2011-03-16||[http://homeland.house.gov/hearing/subcommittee-hearing-examining-cyber-threat-critical-infrastructure-and-american-economy Examining the Cyber Threat to Critical Infrastructure and the American Economy]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2011-04-15||[http://homeland.house.gov/hearing/subcommittee-hearing-%E2%80%9C-dhs-cybersecurity-mission-promoting-innovation-and-securing-critical DHS Cybersecurity Mission: Promoting Innovation and Securing Critical Infrastructure]||No||U.S. Government Hearing||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2011-06-24||[http://homeland.house.gov/hearing/subcommittee-hearing-examining-homeland-security-impact-obamaadministrations-cybersecurity Examining the Homeland Security Impact of the Obama Administration’s Cybersecurity Proposal]||No||U.S. Government Hearing||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2011-12-06||[http://homeland.house.gov/hearing/subcommittee-hearing-hearing-draft-legislative-proposal-cybersecurity Hearing on Draft Legislative Proposal on Cybersecurity]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2012-02-01||[http://homeland.house.gov/markup/subcommittee-markup-hr-3674 Consideration and Markup of H.R. 3674]||No||U.S. Government Hearing||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technology)||2011-10-06||[http://homeland.house.gov/hearing/cloud-computing-what-are-security-implications Cloud Computing: What are the Security Implications?]||No||U.S. Government Hearing||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;4.13 [[Espionage]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection, and Security Technologies)||2011-05-26||[http://homeland.house.gov/hearing/subcommittee-hearing-%E2%80%9Cunlocking-safety-act%E2%80%99s-potential-promote-technology-and-combat Unlocking the SAFETY Act’s Potential to Promote Technology and Combat Terrorism ]||No||U.S. Government Hearing||4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Oversight, Investigations and Management)||2012-04-24||[http://homeland.house.gov/hearing/subcommittee-hearing-america-under-cyber-attack-why-urgent-action-needed America is Under Cyber Attack: Why Urgent Action is Needed]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.2 [[Actors and Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Oversight and Government Reform||2011-07-07||[http://oversight.house.gov/hearing/cybersecurity-assessing-the-nations-ability-to-address-the-growing-cyber-threat/ Cybersecurity: Assessing the Nation’s Ability to Address the Growing Cyber Threat]||No||U.S. Government Hearing||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Oversight and Government Reform (Subcommittee on National Security, Homeland Defense and Foreign Operations)||2011-05-25||[http://oversight.house.gov/hearing/cybersecurity-assessing-the-immediate-threat-to-the-united-states/ Cybersecurity: Assessing the Immediate Threat to the United States]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Science, Space and Technology||2011-07-21||[http://science.house.gov/markup/full-committee-%E2%80%93-markup Markup on H.R. 2096, Cybersecurity Enhancement Act of 2011]||No||U.S. Government Hearing||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Science, Space and Technology (Subcommittee on Research and Science Education)||2011-05-25||[http://science.house.gov/hearing/subcommittee-research-and-science-education-subcommittee-technology-and-innovation-%E2%80%93-joint Protecting Information in the Digital Age: Federal Cybersecurity Research and Development Efforts]||No||U.S. Government Hearing||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Science, Space, and Technology (Subcommittee on Investigations and Oversight)||2012-02-29||[http://science.house.gov/hearing/subcommittee-investigations-and-oversight-hearing-nasa-cybersecurity-examination-agency%E2%80%99s NASA Cybersecurity: An Examination of the Agency’s Information Security]||No||U.S. Government Hearing||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Science, Space, and Technology (Subcommittee on Technology and Innovation)||2011-09-21||[http://science.house.gov/hearing/technology-and-innovation-subcommittee-hearing-cloud-computing The Cloud Computing Outlook]||No||U.S. Government Hearing||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Small Business (Subcommittee on Healthcare and Technology)||2011-12-01||[http://smallbusiness.house.gov/Calendar/EventSingle.aspx?EventID=270278 Cyber Security: Protecting Your Small Business]||No||U.S. Government Hearing||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on the Judiciary||2011-11-16||[http://judiciary.house.gov/hearings/hear_11162011.html Combating Online Piracy (H.R. 3261, Stop the Online Piracy Act)]||No||U.S. Government Hearing||4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on the Judiciary (Subcommittee on Crime, Terrorism and Homeland Security)||2011-11-15||[http://judiciary.house.gov/hearings/hear_11152011.html Cybersecurity: Protecting America’s New Frontier]||No||U.S. Government Hearing||4.10 [[Privacy]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on the Judiciary (Subcommittee on Intellectual Property, Competition and the Internet)||2011-05-25||[http://judiciary.house.gov/hearings/hear_05252011.html Cybersecurity: Problems Innovative Solutions to Challenging]||No||U.S. Government Hearing||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Permenant Select Committee on Intelligence||2011-02-10||[https://intelligence.house.gov/hearing/full-committee-world-wide-threats-hearing World Wide Threats]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Permenant Select Committee on Intelligence||2011-10-04||[https://intelligence.house.gov/hearing/cyber-threats-and-ongoing-efforts-protect-nation Cyber Threats and Ongoing Efforts to Protect the Nation]||No||U.S. Government Hearing||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.13.2 [[Industrial|Industrial Espionage]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Permenant Select Committee on Intelligence||2011-12-01||[https://intelligence.house.gov/markup/mark-hr-xxxx-%E2%80%9Ccyber-intelligence-sharing-and-protection-act-2011%E2%80%9D Markup: Draft Bill: Cyber Intelligence Sharing and Protection Act of 2011]||No||U.S. Government Hearing||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Navy ||2010-06-17||[http://www.doncio.navy.mil/PolicyView.aspx?ID=1804 DON (Department of the Navy) Cybersecurity/Information Assurance Workforce Management, Oversight and Compliance ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Armed Services||2012-03-27||[http://armed-services.senate.gov/e_witnesslist.cfm?id=5283 To receive testimony on U.S. Strategic Command and U.S. Cyber Command in review of the Defense Authorization Request for Fiscal Year 2013 and the Future Years Defense Program.]||No||U.S. Government Hearing||3.2.1 [[States]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2011-05-03||[http://www.armed-services.senate.gov/Transcripts/2011/05%20May/11-31%20-%205-3-11.pdf To receive testimony on the health and status of the defense industrial base and its science and technology-related elements]||No||U.S. Government Hearing||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.3 [[Supply Chain Issues]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2012-03-20||[http://www.armed-services.senate.gov/Transcripts/2012/03%20March/12-14%20-%203-20-12.pdf To receive testimony on cybersecurity research and development in review of the Defense Authorization Request for Fiscal Year 2013 and the Future Years Defense Program]||No||U.S. Government Hearing||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Banking, Housing and Urban Affairs||2011-06-21||[http://banking.senate.gov/public/index.cfm?FuseAction=Hearings.Hearing&amp;amp;Hearing_ID=87487cb2-4710-4c09-a1b0-a9e12cda88f1 Cybersecurity and Data Protection in the Financial Sector]||No||U.S. Government Hearing||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Commerce, Science and Transportation||2011-06-29||[http://commerce.senate.gov/public/index.cfm?p=Hearings&amp;amp;ContentRecord_id=e2c2a2ca-91d6-48a2-b5ea-b5c4104bdb97&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=b06c39af-e033-4cba-9221-de668ca1978a&amp;amp;MonthDisplay=6&amp;amp;YearDisplay=2011 Privacy and Data Security: Protecting Consumers in the Modern World]||No||U.S. Government Hearing||4.9 [[Identity Management]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Energy and Natural Resources||2011-03-15||[ Cybersecurity and Critical Electric Infrastructure (closed)]||No||U.S. Government Hearing||3.3.2.1 [[Electricity, Oil and Natural Gas]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Energy and Natural Resources||2011-05-05||[http://www.energy.senate.gov/public/index.cfm/hearings-and-business-meetings?ID=929c1441-da25-c99d-3e27-af20c29e3b4b Cybersecurity of the Bulk-Power System and Electric Infrastructure]||No||U.S. Government Hearing||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Homeland Security and Governmental Affairs||2011-02-17||[http://www.hsgac.senate.gov/hearings/the-homeland-security-departments-budget-submission-for-fiscal-year-2012 Homeland Security Department’s Budget Submission for Fiscal Year 2012]||No||U.S. Government Hearing||&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Homeland Security and Governmental Affairs||2011-03-10||[http://www.hsgac.senate.gov/hearings/information-sharing-in-the-era-of-wikileaks-balancing-security-and-collaboration Information Sharing in the Era of WikiLeaks: Balancing Security and Collaboration]||No||U.S. Government Hearing||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Homeland Security and Governmental Affairs||2011-05-23||[http://www.hsgac.senate.gov/hearings/protecting-cyberspace-assessing-the-white-house-proposal Protecting Cyberspace: Assessing the White House Proposal]||No||U.S. Government Hearing||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Homeland Security and Governmental Affairs||2012-02-16||[http://www.hsgac.senate.gov/hearings/securing-americas-future-the-cybersecurity-act-of-2012 Securing America’s Future: The Cybersecurity Act of 2012]||No||U.S. Government Hearing||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Judiciary||2011-03-30||[http://www.judiciary.senate.gov/hearings/hearing.cfm?id=e655f9e2809e5476862f735da1697f72 Oversight of the Federal Bureau of Investigation]||No||U.S. Government Hearing||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Judiciary||2011-09-07||[http://www.judiciary.senate.gov/hearings/hearing.cfm?id=3d9031b47812de2592c3baeba629084b Cybercrime: Updating the Computer Fraud and Abuse Act to Protect Cyberspace and Combat Emerging Threats]||No||U.S. Government Hearing||3.11 [[Cybercrime]],&amp;lt;br&amp;gt;4.13.2 [[Industrial|Industrial Espionage]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Judiciary||2012-03-13||[http://www.judiciary.senate.gov/hearings/hearing.cfm?id=8b30fa475a5089d793576cd947089793 The Freedom of Information Act: Safeguarding Critical Infrastructure Information and the Public’s Right to Know]||No||U.S. Government Hearing||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Judiciary (Subcommittee on Crime and Terrorism)||2011-04-12||[http://www.judiciary.senate.gov/hearings/hearing.cfm?id=e655f9e2809e5476862f735da16a9959 Cyber Security: Responding to the Threat of Cyber Crime and Terrorism]||No||U.S. Government Hearing||4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Judiciary (Subcommittee on Crime and Terrorism)||2011-06-21||[http://www.judiciary.senate.gov/hearings/hearing.cfm?id=e655f9e2809e5476862f735da16e1bbe Cybersecurity: Evaluating the Administration’s Proposals]||No||U.S. Government Hearing||1. [[Overview]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Small Business and Entrepreneurship||2011-07-25||[http://www.sbc.senate.gov/public/index.cfm?p=Hearings&amp;amp;ContentRecord_id=6b4d51de-dd67-434b-869f-a717b315e6c2&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=43eb5e02-e987-4077-b9a7-1e5a9cf28964&amp;amp;MonthDisplay=7&amp;amp;YearDisplay=2011 Role of Small Business in Strengthening Cybersecurity Efforts in the United States]||No||U.S. Government Hearing||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.7 [[public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| United States Secret Service ||2004||[[Insider_Threat_Study|Insider Threat Study ]]||Yes||U.S. Government Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]]&lt;br /&gt;
|-&lt;br /&gt;
| University of Southern California (USC) Information Sciences Institute, University of California Berkeley (UCB), McAfee Research ||2011-01-13||[http://www.isi.edu/deter/news/news.php?story=20 Design of the DETER Security Testbed ]||No||Independent Report||5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| van Eeten, Michael and Bauer, Johannes M.||2009||[[Emerging_Threats_to_Internet_Security|Emerging Threats to Internet Security: Incentives, Externalities and Policy Implications]]||Yes||Journal Article||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| van Eeten, Michel J. G. ||2008||[[Economics_of_Malware|Economics of Malware ]]||Yes||Non-U.S. Government Report ||4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| Varian, Hal ||2000||[[Managing_Online_Security_Risks|Managing Online Security Risks ]]||Yes||Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| Varian, Hal ||2004||[[System_Reliability_and_Free_Riding|System Reliability and Free Riding ]]||Yes||Book ||4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| Vatis, Michael A.||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059441.pdf The Council of Europe Convention on Cybercrime]||No||Journal Article||4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Verizon ||2010||[[2010_Data_Breach_Investigations_Report|2010 Data Breach Investigations Report ]]||Yes||Industry Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Watts, Sean ||2010||[[Combatant_Status_and_Computer_Network_Attack|Combatant Status and Computer Network Attack ]]||Yes||Journal Article ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| White House||2009||[http://www.whitehouse.gov/assets/documents/Cyberspace_Policy_Review_final.pdf Cyberspace Policy Review: Assuring a Trusted and Resilient Information and Communications Infrastructure]||No||U.S. Government Report||1. [[Overview]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| White House||2011-04||[http://www.whitehouse.gov/sites/default/files/rss_viewer/NSTICstrategy_041511.pdf National Strategy for Trusted Identities in Cyberspace: Enhancing Online Choice, Efficiency, Security, and Privacy]||No||U.S. Government Report||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]]&lt;br /&gt;
|-&lt;br /&gt;
| White House||2011-05||[http://www.whitehouse.gov/sites/default/files/rss_viewer/international_strategy_for_cyberspace.pdf International Strategy for Cyberspace: Prosperity, Security, and Openness in a Networked World]||No||U.S. Government Report||1. [[Overview]]&lt;br /&gt;
|-&lt;br /&gt;
| White House||2012-01||[http://www.whitehouse.gov/sites/default/files/national_strategy_for_global_supply_chain_security.pdf National Strategy for Global Supply Chain Security]||No||U.S. Government Report||4.3 [[Supply Chain Issues]]&lt;br /&gt;
|-&lt;br /&gt;
| White House||2012-02||[http://www.whitehouse.gov/sites/default/files/privacy-final.pdf Consumer Data Privacy in a Networked World: A Framework for Protecting Privacy and Promoting Innovation in the Global Digital Economy]||No||U.S. Government Report||4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2010-12-16||[http://www.whitehouse.gov/sites/default/files/microsites/ostp/pcast-nitrd-report-2010.pdf Designing A Digital Future: Federally Funded Research And Development In Networking And Information Technology ]||No||U.S. Government Report||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2011-02-13||[http://www.cio.gov/documents/Federal-Cloud-Computing-Strategy.pdf Federal Cloud Computing Strategy ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2011-04-15||[http://www.whitehouse.gov/the-press-office/2011/04/15/administration-releases-strategy-protect-online-consumers-and-support-in Administration Releases Strategy to Protect Online Consumers and Support Innovation and Fact Sheet on National Strategy for Trusted Identities in Cyberspace ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2011-04-15||[http://www.whitehouse.gov/sites/default/files/rss_viewer/NSTICstrategy_041511.pdf National Strategy for Trusted Identities in Cyberspace ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2003||[[The_National_Strategy_to_Secure_Cyberspace|The National Strategy to Secure Cyberspace ]]||Yes||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2009||[[Cyberspace_Policy_Review|Cyberspace Policy Review ]]||Yes||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2010||[[The_Comprehensive_National_Cybersecurity_Initiative|The Comprehensive National Cybersecurity Initiative ]]||Yes||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House (Office of Science &amp;amp; Technology Policy) ||2010-12-06||[http://www.whitehouse.gov/blog/2010/12/06/partnership-cybersecurity-innovation Partnership for Cybersecurity Innovation ]||No||U.S. Government Report||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/Office of Management and Budget (OMB) ||2011-12-08||[http://www.cio.gov/fedrampmemo.pdf Security Authorization of Information Systems in Cloud Computing Environments (FedRAMP) ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2009-05-29||[http://www.whitehouse.gov/assets/documents/Cyberspace_Policy_Review_final.pdf Cyberspace Policy Review: Assuring a Trusted and Resilient Communications Infrastructure ]||No||U.S. Government Report ||4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2010-03-02||[http://www.whitehouse.gov/cybersecurity/comprehensive-national-cybersecurity-initiative Comprehensive National Cybersecurity Initiative (CNCI) ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2010-06-25||[http://www.dhs.gov/xlibrary/assets/ns_tic.pdf The National Strategy for Trusted Identities in Cyberspace: Creating Options for Enhanced Online Security and Privacy ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2010-07-06||[http://www.whitehouse.gov/sites/default/files/omb/assets/memoranda_2010/m10-28.pdf Clarifying Cybersecurity Responsibilities ]||No||U.S. Government Report ||5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2010-12-09||[http://www.cio.gov/documents/25-Point-Implementation-Plan-to-Reform-Federal%20IT.pdf 25 Point Implementation Plan to Reform Federal Information Technology Management ]||No||U.S. Government Report ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-02-13||[http://www.cio.gov/documents/Federal-Cloud-Computing-Strategy.pdf Federal Cloud Computing Strategy ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-05-12||[http://www.whitehouse.gov/the-press-office/2011/05/12/fact-sheet-cybersecurity-legislative-proposal Cybersecurity Legislative Proposal (Fact Sheet) ]||No||U.S. Government Report ||4. [[Issues]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-05-16||[http://www.whitehouse.gov/sites/default/files/rss_viewer/international_strategy_for_cyberspace.pdf International Strategy for Cyberspace ]||No||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-09-14||[http://www.whitehouse.gov/sites/default/files/omb/memoranda/2011/m11-33.pdf FY 2012 Reporting Instructions for the Federal Information Security Management Act and Agency Privacy Managementa ]||No||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-10-07||[http://www.whitehouse.gov/the-press-office/2011/10/07/executive-order-structural-reforms-improve-security-classified-networks- Structural Reforms to Improve the Security of Classified Networks and the Responsible Sharing and Safeguarding of Classified Information ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-12-06||[http://www.whitehouse.gov/sites/default/files/microsites/ostp/fed_cybersecurity_rd_strategic_plan_2011.pdf Trustworthy Cyberspace: Strategic Plan for the Federal Cybersecurity Research and Development Program ]||No||U.S. Government Report ||5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Wilshusen, Gregory C. and Powner, David A.||2009||[[Continued_Efforts_are_Needed_to_Protect_Information_Systems_from_Evolving_Threats|Continued Efforts Are Needed to Protect Information Systems from Evolving Threats]]||Yes||U.S. Government Hearing||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Wilson, Clay||2007-03-20||[http://www.fas.org/sgp/crs/natsec/RL31787.pdf Information Operations, Electronic Warfare, and Cyberwar: Capabilities and Related Policy Issues]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Zittrain, Jonathan L. ||2008||[[The_Future_of_the_Internet_and_How_To_Stop_It|The Future of the Internet and How To Stop It ]]||Yes||Book ||4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Centre for Secure Information Technologies||2012||[http://www.csit.qub.ac.uk/sites/CSIT/InnovationatCSIT/Reports/Filetoupload,295595,en.pdf 2nd World Cyber security Technology Research Summit (Belfast 2012)]||No||Independent Report||&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Template:Filtered_Table&amp;diff=6848</id>
		<title>Template:Filtered Table</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Template:Filtered_Table&amp;diff=6848"/>
		<updated>2013-01-25T20:58:32Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;dt_types&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|U.S. Government Report&lt;br /&gt;
|-&lt;br /&gt;
|U.S. Government Hearing&lt;br /&gt;
|-&lt;br /&gt;
|Non-U.S. Government Report&lt;br /&gt;
|-&lt;br /&gt;
|Independent Report&lt;br /&gt;
|-&lt;br /&gt;
|Industry Report&lt;br /&gt;
|-&lt;br /&gt;
|Book&lt;br /&gt;
|-&lt;br /&gt;
|Journal Article&lt;br /&gt;
|-&lt;br /&gt;
|Article&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;dt_categories&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|1. Overview&lt;br /&gt;
|-&lt;br /&gt;
|3. Threats and Actors&lt;br /&gt;
|-&lt;br /&gt;
|3.1 The Threat and Skeptics&lt;br /&gt;
|-&lt;br /&gt;
|3.2 Actors and Incentives&lt;br /&gt;
|-&lt;br /&gt;
|3.2.1 States&lt;br /&gt;
|-&lt;br /&gt;
|3.2.2 Groups&lt;br /&gt;
|-&lt;br /&gt;
|3.2.3 Hacktivists&lt;br /&gt;
|-&lt;br /&gt;
|3.2.4 Terrorists&lt;br /&gt;
|-&lt;br /&gt;
|3.2.5 Criminals and Criminal Organizations&lt;br /&gt;
|-&lt;br /&gt;
|3.3 Security Targets&lt;br /&gt;
|-&lt;br /&gt;
|3.3.1 Public Critical Infrastructure&lt;br /&gt;
|-&lt;br /&gt;
|3.3.1.1 Government Networks (.gov)&lt;br /&gt;
|-&lt;br /&gt;
|3.3.1.2 Military Networks (.mil)&lt;br /&gt;
|-&lt;br /&gt;
|3.3.2 Private Critical Infrastructure&lt;br /&gt;
|-&lt;br /&gt;
|3.3.2.1 Electricity, Oil and Natural Gas&lt;br /&gt;
|-&lt;br /&gt;
|3.3.2.2 Financial Institutions and Networks&lt;br /&gt;
|-&lt;br /&gt;
|3.3.2.3 Transportation&lt;br /&gt;
|-&lt;br /&gt;
|3.3.2.4 Water, Sewer, etc.&lt;br /&gt;
|-&lt;br /&gt;
|3.3.3 Communications&lt;br /&gt;
|-&lt;br /&gt;
|3.3.3.1 Telephone&lt;br /&gt;
|-&lt;br /&gt;
|3.3.3.2 Public Data Networks&lt;br /&gt;
|-&lt;br /&gt;
|3.3.3.3 Cloud Computing&lt;br /&gt;
|-&lt;br /&gt;
|4. Issues&lt;br /&gt;
|-&lt;br /&gt;
|4.1 Metrics&lt;br /&gt;
|-&lt;br /&gt;
|4.2 Economics of Cybersecurity&lt;br /&gt;
|-&lt;br /&gt;
|4.2.1 Risk Management and Investment&lt;br /&gt;
|-&lt;br /&gt;
|4.2.2 Incentives&lt;br /&gt;
|-&lt;br /&gt;
|4.2.3 Insurance&lt;br /&gt;
|-&lt;br /&gt;
|4.2.4 Behavioral Economics&lt;br /&gt;
|-&lt;br /&gt;
|4.2.5 Market Failure&lt;br /&gt;
|-&lt;br /&gt;
|4.3 Supply Chain Issues&lt;br /&gt;
|-&lt;br /&gt;
|4.4 Usability/Human Factors&lt;br /&gt;
|-&lt;br /&gt;
|4.5 Psychology and Politics&lt;br /&gt;
|-&lt;br /&gt;
|4.6 Information Sharing/Disclosure&lt;br /&gt;
|-&lt;br /&gt;
|4.7 Public-Private Cooperation&lt;br /&gt;
|-&lt;br /&gt;
|4.8 Attribution&lt;br /&gt;
|-&lt;br /&gt;
|4.9 Identity Management&lt;br /&gt;
|-&lt;br /&gt;
|4.10 Privacy&lt;br /&gt;
|-&lt;br /&gt;
|4.11 Cybercrime&lt;br /&gt;
|-&lt;br /&gt;
|4.12 Cyberwar&lt;br /&gt;
|-&lt;br /&gt;
|4.13 Espionage&lt;br /&gt;
|-&lt;br /&gt;
|4.13.1 Government to Government&lt;br /&gt;
|-&lt;br /&gt;
|4.13.2 Industrial&lt;br /&gt;
|-&lt;br /&gt;
|4.13.3 Media Perceptions&lt;br /&gt;
|-&lt;br /&gt;
|5. Approaches&lt;br /&gt;
|-&lt;br /&gt;
|5.1 Regulation/Liability&lt;br /&gt;
|-&lt;br /&gt;
|5.2 Private Efforts/Organizations&lt;br /&gt;
|-&lt;br /&gt;
|5.3 Government Organizations&lt;br /&gt;
|-&lt;br /&gt;
|5.4 International Cooperation&lt;br /&gt;
|-&lt;br /&gt;
|5.5 International Law (including Laws of War)&lt;br /&gt;
|-&lt;br /&gt;
|5.6 Deterrence&lt;br /&gt;
|-&lt;br /&gt;
|5.7 Technology&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable datatable&amp;quot; data-type-filter=&amp;quot;{{{1}}}&amp;quot; data-category-filter=&amp;quot;{{{2}}}&amp;quot; data-search-filter=&amp;quot;{{{3}}}&amp;quot; border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;1&amp;quot; cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;border: 1px solid LightGrey;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background-color:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Author/Agency&#039;&#039;&#039;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background-color:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Date&#039;&#039;&#039;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background-color:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Title&#039;&#039;&#039;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Wiki Entry&#039;&#039;&#039;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Type&#039;&#039;&#039;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Category&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| Aloise, Gene et al.||2008||[[Nuclear_Security|Nuclear Security]]||Yes||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]]&lt;br /&gt;
|-&lt;br /&gt;
| Anderson, Ross ||2001||[[Why_Information_Security_is_Hard|Why Information Security is Hard ]]||Yes||Independent Report ||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Anderson, Ross ||2006||[[The_Economics_of_Information_Security|The Economics of Information Security ]]||Yes||Journal Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Anderson, Ross J. ||2008||[[Security_Engineering|Security Engineering ]]||Yes||Book ||3.2 [[Security Targets]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Anderson, Ross, et. al ||2008||[[Security_Economics_and_the_Internal_Market|Security Economics and the Internal Market ]]||Yes||Article||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Arora et al. ||2006||[[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure|Does Information Security Attack Frequency Increase With Vulnerability Disclosure ]]||Yes||Journal Article ||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]]&lt;br /&gt;
|-&lt;br /&gt;
| Aviram, Amitai ||2004||[[Overcoming_Impediments_to_Information_Sharing|Overcoming Impediments to Information Sharing ]]||Yes||Journal Article ||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Barkham, Jason ||2001||[[Information_Warfare_and_International_Law_on_the_Use_of_Force|Information Warfare and International Law on the Use of Force ]]||Yes||Journal Article ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Bauer, Johannes M. and van Eeten, Michel J. G.||2009||[[Cybersecurity|Cybersecurity: Stakeholder Incentives, Externalities, and Policy Options]]||Yes||Journal Article||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Beard, Jack M. ||2009||[[Law_and_War_in_the_Virtual_Era|Law and War in the Virtual Era ]]||Yes||Journal Article ||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Bellovin, Steven M.||2009||[[The_Government_and_Cybersecurity|The Government and Cybersecurity]]||Yes||Journal Article||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;4.7[[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Besunder, Allison A.||2009||[[Best_Practices_for_Data_Protection_and_Privacy|Best Practices for Data Protection and Privacy]]||Yes||Book||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Boebert, W. Earl||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059366.pdf A Survey of Challenges in Attribution]||No||Journal Article||4.8 [[Attribution]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Bohme, Rainer ||2005||[[Cyber-Insurance_Revisited|Cyber-Insurance Revisited ]]||Yes||Independent Report ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.2.3 [[Insurance]],&amp;lt;br&amp;gt;,4.2.5 [[Market Failure]]&lt;br /&gt;
|-&lt;br /&gt;
| Bohme, Rainer ||2006||[[Models_and_Measures_for_Correlation_in_Cyber-Insurance|Models and Measures for Correlation in Cyber-Insurance ]]||Yes||Independent Report ||4.2.3 [[Insurance]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Bohme, Rainer ||2010||[[Modeling_Cyber-Insurance|Modeling Cyber-Insurance ]]||Yes||Independent Report ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.2.3 [[Insurance]],&amp;lt;br&amp;gt;,5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Booz Allen Hamilton and the Economist Intelligence Unit ||2012-01-15||[http://www.cyberhub.com/CyberPowerIndex Cyber Power Index ]||No||Industry Report||4. [[Issues]],&amp;lt;br&amp;gt;4.1 [[Metrics]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Bradley, Curtis A. and Goldsmith, Jack L.||2011||[[Overview_of_International_Law_and_Institutions|Overview of International Law and Institutions]]||Yes||Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Brown, Davis ||2006||[[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict|A Proposal for an International Convention To Regulate the Use of Information Systems in Armed Conflict ]]||Yes||Journal Article ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Burstein, Aaron J.||2008||[[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research|Amending the ECPA to Enable a Culture of Cybersecurity Research]]||Yes||Journal Article||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Business Roundtable||2011-10-11||[http://businessroundtable.org/uploads/studies-reports/downloads/2011_10_Mission_Critical_A_Public-Private_Strategy_for_Effective_Cybersecurity.pdf Mission Critical: A Public-Private Strategy for Effective Cybersecurity ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| Business Software Alliance ||2012-02-02||Global Cloud Computing Scorecard a Blueprint for Economic Opportunity||No||Industry Report||3.3.3.3 [[Cloud Computing]]&lt;br /&gt;
|-&lt;br /&gt;
| Business Software Alliance, Center for Democracy &amp;amp; Technology, U.S. Chamber of Commerce, Internet Security Alliance, Tech America ||2011-03-08||[http://www.cdt.org/files/pdfs/20110308_cbyersec_paper.pdf Improving our Nation’s Cybersecurity through the Public-Private Partnership: a White Paper ]||No||Industry Report||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Cabinet Office (United Kingdom) ||2011-11-11||[http://www.cabinetoffice.gov.uk/sites/default/files/resources/uk-cyber-security-strategy-final.pdf The UK Cyber Security Strategy: Protecting and promoting the UK in a digital world ]||No||Non-U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Camp, L. Jean ||2004||[[Economics_of_Information_Security|Economics of Information Security ]]||Yes||Book ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Camp, L. Jean ||2004||[[Pricing_Security|Pricing Security ]]||Yes||Book ||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Center for a New American Security||2012-06-11||[http://www.cnas.org/node/6405 America’s Cyber Future: Security and Prosperity in the Information Age ]||No||Independent Report||1. [[Overview]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Center for Strategic and International Studies ||2008||[[Securing_Cyberspace_for_the_44th_Presidency|Securing Cyberspace for the 44th Presidency ]]||Yes||Independent Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Centre for Secure Information Technologies||2011||[http://www.csit.qub.ac.uk/sites/CSIT/InnovationatCSIT/Reports/Filetoupload,295594,en.pdf World Cybersecurity Technology Research Summit (Belfast 2011) ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| Cetron, Marvin J. and Davies, Owen||2009||[[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity|World War 3.0: Ten Critical Trends for Cybersecurity]]||Yes||Journal Article||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Clark, David and Landau, Susan||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059365.pdf Untangling Attribution]||No||Journal Article||4.8 [[Attribution]],&amp;lt;br&amp;gt;5.6 [[Deterrence]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Clarke, Richard A. ||2010||[[Cyber_War|Cyber War ]]||Yes||Book ||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Clinton, Larry ||Undated ||[[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security|Cyber-Insurance Metrics and Impact on Cyber-Security ]]||Yes||Independent Report ||4.2.3 [[Insurance]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Cloud Security Alliance ||2009-12||[http://www.cloudsecurityalliance.org/csaguide.pdf Security Guidance for Critical Areas of Focus in Cloud Computing V2.1 ]||No||Independent Report||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Cohen, Geoff||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059445.pdf Targeting Third Party Collaboration]||No||Journal Article||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| Computer Economics, Inc. ||2007||[[2007_Malware_Report|2007 Malware Report ]]||Yes||Industry Report ||4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| Computing Research Association ||2003-||[[Four_Grand_Challenges_in_Trustworthy_Computing|Four Grand Challenges in Trustworthy Computing ]]||Yes||Independent Report ||4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.9 [[Identity Management]]&lt;br /&gt;
|-&lt;br /&gt;
| Cornish, Paul||2009||[[Cyber_Security_and_Politically,_Socially_and_Religiously_Motivated_Cyber_Attacks|Cyber Security and Politically, Socially and Religiously Motivated Cyber Attacks]]||Yes||Non-U.S. Government Report||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Cornish, Paul et al.||2009||[[Cyberspace_and_the_National_Security_of_the_United_Kingdom|Cyberspace and the National Security of the United Kingdom - Threats and Responses]]||Yes||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Council on Foreign Relations ||2010-07-15||[http://i.cfr.org/content/publications/attachments/Knake%20-Testimony%20071510.pdf Untangling Attribution: Moving to Accountability in Cyberspace [Testimony]]||No||Independent Report||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;4.8 [[Attribution]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| CSIS Commission on Cybersecurity for the 44th Presidency, Center for Strategic and International Studies ||2011-01||[http://csis.org/files/publication/110128_Lewis_CybersecurityTwoYearsLater_Web.pdf Cybersecurity Two Years Later ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5. [[Approaches]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Cyber Security Forum Initiative ||2011-05-09||[http://www.unveillance.com/wp-content/uploads/2011/05/Project_Cyber_Dawn_Public.pdf Cyber Dawn: Libya ]||No||Industry Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Commerce ||2011-06-14||[http://www.nist.gov/nstic/2012-nstic-governance-recs.pdf Models for a Governance Structure for the National Strategy for Trusted Identities in Cyberspace ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Commerce ||2010||[[Defense_Industrial_Base_Assessment|Defense Industrial Base Assessment ]]||Yes||U.S. Government Report ||3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Commerce, Internet Policy Task Force||2011-06||[http://www.nist.gov/itl/upload/Cybersecurity_Green-Paper_FinalVersion.pdf Cybersecurity, Innovation and the Internet Economy]||No||U.S. Government Report||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2011-07-14||[http://www.defense.gov/news/d20110714cyber.pdf Department of Defense Strategy for Operating in Cyberspace ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2011-11-15||[http://www.defense.gov/home/features/2011/0411_cyberstrategy/docs/NDAA%20Section%20934%20Report_For%20webpage.pdf Department of Defense Cyberspace Policy Report : A Report to Congress Pursuant to the National Defense Authorization Act for Fiscal Year 2011, Section 934 ]||No||U.S. Government Report||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2012-02-16||[http://www.fas.org/sgp/othergov/dod/5200_01v1.pdf DOD Information Security Program: Overview, Classification, and Declassification ]||No||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2012-04-11||[http://www.nsci-va.org/CyberReferenceLib/2011-04-Cyber%20Ops%20Personnel.pdf Cyber Operations Personnel Report (DoD) ]||No||U.S. Government Report||&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||1999||[[An_Assessment_of_International_Legal_Issues_in_Information_Operations|An Assessment of International Legal Issues in Information Operations ]]||Yes||U.S. Government Report ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2005-||[[Strategy_for_Homeland_Defense_and_Civil_Support|Strategy for Homeland Defense and Civil Support ]]||Yes||U.S. Government Report ||3.2.4 [[Terrorists]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2007||[[Mission_Impact_of_Foreign_Influence_on_DoD_Software|Mission Impact of Foreign Influence on DoD Software ]]||Yes||U.S. Government Report ||3.2.4 [[Terrorists]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2011-04||[http://www.nsci-va.org/CyberReferenceLib/2011-04-Cyber%20Ops%20Personnel.pdf Cyber Operations Personnel Report (DOD) ]||No||U.S. Government Report ||&lt;br /&gt;
|-&lt;br /&gt;
| Department of Energy||2012-04||[http://energy.gov/sites/prod/files/OAS-RA-12-04.pdf The Department&#039;s Management of the Smart Grid Investment Grant Program]||No||U.S. Government Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Energy (DOE) Inspector General ||2012-01-01||[http://energy.gov/ig/downloads/departments-management-smart-grid-investment-grant-program-oas-ra-12-04 The Department’s Management of the Smart Grid Investment Grant Program ]||No||U.S. Government Report ||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Energy, Idaho National Laboratory ||2010-05-01||[http://www.fas.org/sgp/eprint/nstb.pdf NSTB Assessments Summary Report: Common Industrial Control System Cyber Security Weaknesses ]||No||U.S. Government Report||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Energy, Office of Electricity Delivery &amp;amp; Energy Reliability ||Undated||[http://energy.gov/oe/technology-development/energy-delivery-systems-cybersecurity Cybersecurity for Energy Delivery Systems Program ]||No||U.S. Government Report ||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2009-09-16||[http://www.cyber.st.dhs.gov/docs/National_Cyber_Leap_Year_Summit_2009_Co-Chairs_Report.pdf National Cyber Leap Year Summit 2009: Co-Chairs&#039; Report]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.8 [[Attribution]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2007-06||[http://www.oig.dhs.gov/assets/Mgmt/OIG_07-48_Jun07.pdf Challenges Remain in Securing the Nation’s Cyber Infrastructure]||No||U.S. Government Report||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2009-11||[http://www.cyber.st.dhs.gov/docs/DHS-Cybersecurity-Roadmap.pdf A Roadmap for Cybersecurity Research]||No||U.S. Government Report||1. [[Overview]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2010-08||[http://www.dhs.gov/xoig/assets/mgmtrpts/OIG_10-111_Aug10.pdf DHS Needs to Improve the Security Posture of Its Cybersecurity Program Systems]||No||U.S. Government Report||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2010-09||[http://www.federalnewsradio.com/pdfs/NCIRP_Interim_Version_September_2010.pdf National Cyber Incident Response Plan]||No||U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2011-11||[http://www.dhs.gov/xlibrary/assets/nppd/blueprint-for-a-secure-cyber-future.pdf Blueprint for a Secure Cyber Future: The Cybersecurity Strategy for the Homeland Security Enterprise]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security ||2003||[[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets|The National Strategy for the Physical Protection of Critical Infrastructures and Key Assets ]]||Yes||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security ||2009||[[A_Roadmap_for_Cybersecurity_Research|A Roadmap for Cybersecurity Research ]]||Yes||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Justice||2011-04||[http://www.justice.gov/oig/reports/FBI/a1122r.pdf The Federal Bureau of Investigation&#039;s Ability to Address the National Security Cyber Intrusion Threat]||No||U.S. Government Report||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Deputy Chief of Staff for Intelligence ||2006||[[Critical_Infrastructure_Threats_and_Terrorism|Critical Infrastructure Threats and Terrorism ]]||Yes||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Dörmann, Knut ||2004||[[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks|Applicability of the Additional Protocols to Computer Network Attacks ]]||Yes||Independent Report ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Douglas Maughan||2010||[[The_Need_for_a_National_Cybersecurity_Research_and_Development_Agenda|The Need for a National Cybersecurity Research and Development Agenda]]||Yes||Article||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Dunlap Charles J, Jr   ||2011||[[Perspectives_for_Cyber_Strategists_on_Law_for_Cyberwar|Perspectives for Cyber Strategists on Law for Cyberwar]]||Yes||Journal Article||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Dunlap, Charles J. Jr. ||2009||[[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century|Towards a Cyberspace Legal Regime in the Twenty-First Century ]]||Yes||Article||4.5 [[Psychology and Politics]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| EastWest Institute ||2011-02-03||[http://vialardi.org/nastrazzuro/pdf/US-Russia.pdf Working Towards Rules for Governing Cyber Conflict: Rendering the Geneva and Hague Conventions in Cyberspace ]||No||Independent Report||3.2.1 [[States]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Energetics Inc. ||2006||[[Roadmap_to_Secure_Control_Systems_in_the_Energy_Sector|Roadmap to Secure Control Systems in the Energy Sector ]]||Yes||Independent Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Energy Sector Control Systems Working Group||2011-09||[http://www.cyber.st.dhs.gov/wp-content/uploads/2011/09/Energy_Roadmap.pdf Roadmap to Achieve Energy Delivery Systems Cybersecurity]||No||U.S. Government Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| ENISA||2010||[[Introduction_to_Country_Reports|Introduction to Country Reports]]||Yes||Non-U.S. Government Report||3.2.1 [[States]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Epstein, Richard A. ||2008||[[Cybersecurity_in_the_Payment_Card_Industry|Cybersecurity in the Payment Card Industry ]]||Yes||Journal Article ||3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| European Network and Information Security Agency ||2010-10-07||[http://www.enisa.europa.eu/media/press-releases/stuxnet-analysis Stuxnet Analysis ]||No||Non-U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| European Network and Information Security Agency (ENISA) ||2011-04-11||[http://www.enisa.europa.eu/act/res/other-areas/inter-x/report/interx-report Resilience of the Internet Interconnection Ecosystem, at: ]||No||Non-U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Federal CIO Council ||2012-01-04||[http://www.gsa.gov/portal/category/102371 Federal Risk and Authorization Management Program (FedRAMP) ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Federal Communications Commission (FCC) ||2010-04-21||[http://hraunfoss.fcc.gov/edocs_public/attachmatch/DOC-305618A1.doc Explore the reliability and resiliency of commercial broadband communications networks ]||No||U.S. Government Report||3.3.3 [[Communications]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Federal Communications Commission (FCC) ||2011-06-03||[ftp://ftp.fcc.gov/pub/Daily_Releases/Daily_Business/2011/db0610/DOC-307454A1.txt FCC&#039;s Plan for Ensuring the Security of Telecommunications Networks ]||No||U.S. Government Report||&lt;br /&gt;
|-&lt;br /&gt;
| Financial Services Sector Coordinating Council for Critical Infrastructure Protection ||2008||[[Research_Agenda_for_the_Banking_and_Finance_Sector|Research Agenda for the Banking and Finance Sector ]]||Yes||Independent Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.1 [[Metrics]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| Fischer, Eric A.&amp;lt;br /&amp;gt;CRS||2012-04-23||[http://www.fas.org/sgp/crs/natsec/R42114.pdf Federal Laws Relating to Cybersecurity: Discussion of Proposed Revisions]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Franklin, Jason, et. al ||2007||[[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants|An Inquiry into the Nature and Causes of the Wealth of Internet Miscreants ]]||Yes||Independent Report ||3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| Gandal, Neil ||2008||[[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security|An Introduction to Key Themes in the Economics of Cyber Security ]]||Yes||Book ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2003-08-27||[http://www.gao.gov/products/GAO-03-760 Efforts to Improve Information sharing Need to Be Strengthened ]||No||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2004-05-28||[http://www.gao.gov/assets/160/157541.pdf Technology Assessment: Cybersecurity for Critical Infrastructure Protection]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2008-07-31||[http://www.gao.gov/assets/280/279084.pdf Cyber Analysis And Warning: DHS Faces Challenges in Establishing a Comprehensive National Capability]||No||U.S. Government Report||5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2009-09-24||[http://www.gao.gov/new.items/d09969.pdf Critical Infrastructure Protection: Current Cyber Sector-Specific Planning Approach Needs Reassessment]||No||U.S. Government Report||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2009-11-17||[http://www.gao.gov/products/GAO-10-230t Continued Efforts Are Needed to Protect Information Systems from Evolving Threats ]||No||U.S. Government Report ||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-03-05||[http://www.gao.gov/products/GAO-10-338 Cybersecurity: Progress Made But Challenges Remain in Defining and Coordinating the Comprehensive National Initiative ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-03-16||[http://www.gao.gov/products/GAO-11-463T Cybersecurity: Continued Attention Is Needed to Protect Federal Information Systems from Evolving Threats ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-03-24||[http://www.gao.gov/products/GAO-10-536t Information Security: Concerted Response Needed to Resolve Persistent Weaknesses, at: ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-04-12||[http://www.gao.gov/products/GAO-10-237 Concerted Effort Needed to Consolidate and Secure Internet Connections at Federal Agencies ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-06-03||[http://www.gao.gov/assets/310/305208.pdf Cybersecurity: Key Challenges Need to Be Addressed to Improve Research and Development]||No||U.S. Government Report||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-06-16||[http://www.gao.gov/products/GAO-10-834t Continued Attention Is Needed to Protect Federal Information Systems from Evolving Threats ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-07-01||[http://www.gao.gov/products/GAO-10-513 Federal Guidance Needed to Address Control Issues With Implementing Cloud Computing ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-07-15||[http://www.gao.gov/products/GAO-10-628 Critical Infrastructure Protection: Key Private and Public Cyber Expectations Need to Be Consistently Addressed ]||No||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-08-02||[http://www.gao.gov/products/GAO-10-606 United States Faces Challenges in Addressing Global Cybersecurity and Governance ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-09-15||[http://www.gao.gov/products/GAO-10-916 Information Security: Progress Made on Harmonizing Policies and Guidance for National Security and Non-National Security Systems ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-09-23||[http://www.gao.gov/products/GAO-10-772 DHS Efforts to Assess and Promote Resiliency Are Evolving but Program Management Could Be Strengthened ]||No||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-10-06||[http://www.gao.gov/products/GAO-11-24 Cyberspace Policy: Executive Branch Is Making Progress Implementing 2009 Policy Review Recommendations, but Sustained Leadership Is Needed ]||No||U.S. Government Report ||5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-11-30||[http://www.gao.gov/products/GAO-11-43 Information Security: Federal Agencies Have Taken Steps to Secure Wireless Networks, but Further Actions Can Mitigate Risk ]||No||U.S. Government Report ||3.3.3 [[Communications]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-01-12||[http://www.gao.gov/products/GAO-11-117 Electricity Grid Modernization: Progress Being Made on Cybersecurity Guidelines, but Key Challenges Remain to be Addressed ]||No||U.S. Government Report ||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-03-16||[http://www.gao.gov/products/GAO-11-463T Cybersecurity: Continued Attention Needed to Protect Our Nation&#039;s Critical Infrastructure and Federal Information Systems ]||No||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-07-08||[http://www.gao.gov/products/GAO-11-149 Information Security: State Has Taken Steps to Implement a Continuous Monitoring Application, but Key Challenges Remain ]||No||U.S. Government Report ||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-07-25||[http://www.gao.gov/products/GAO-11-75 Defense Department Cyber Efforts: DoD Faces Challenges in Its Cyber Activities ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-07-26||[http://www.gao.gov/products/GAO-11-463T Continued Attention Needed to Protect Our Nation’s Critical Infrastructure ]||No||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-07-29||[http://www.gao.gov/products/GAO-11-695R Defense Department Cyber Efforts: Definitions, Focal Point, and Methodology Needed for DoD to Develop Full-Spectrum Cyberspace Budget Estimates ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-10-03||[http://www.gao.gov/products/GAO-12-137 Information Security: Weaknesses Continue Amid New Federal Efforts to Implement Requirements ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-10-05||[http://www.gao.gov/products/GAO-12-130T Information Security: Additional Guidance Needed to Address Cloud Computing Concerns ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-10-17||[http://www.gao.gov/products/GAO-11-634 Federal Chief Information Officers: Opportunities Exist to Improve Role in Information Technology Management ]||No||U.S. Government Report ||5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-11-29||[http://www.gao.gov/products/GAO-12-8 Cybersecurity Human Capital: Initiatives Need Better Planning and Coordination, at: ]||No||U.S. Government Report ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-12-09||[http://www.gao.gov/products/GAO-12-92 Critical Infrastructure Protection: Cybersecurity Guidance Is Available, but More Can Be Done to Promote Its Use ]||No||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2012-01-13||[http://www.gao.gov/assets/590/587681.pdf Defense Contracting: Improved Policies and Tools Could Help Increase Competition on DOD&#039;s National Security Exception Procurements]||No||U.S. Government Report||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2012-02-28||[http://www.csit.qub.ac.uk/media/pdf/Filetoupload,252359,en.pdf Cybersecurity: Challenges to Securing the Modernized Electricity Grid ]||No||Non-U.S. Government Report ||&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2009||[[Critical_Infrastructure_Protection|Critical Infrastructure Protection - Current Cyber Sector-Specific Planning Approach Needs Reassessment]]||Yes||U.S. Government Report||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2009-07||[http://www.gao.gov/new.items/d09546.pdf Information Security: Agencies Continue to Report Progress, but Need to. Mitigate Persistent Weaknesses]||No||U.S. Government Report||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2009-09||[http://www.gao.gov/new.items/d09617.pdf Information Security: Concerted Effort Needed to Improve Federal Performance Measures]||No||U.S. Government Report||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010||[[Information_Security|Information Security - Concerted Effort Needed to Consolidate and Secure Internet Connections at Federal Agencies]]||Yes||U.S. Government Report||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO ||2011-10-05||[http://www.gao.gov/products/GAO-12-130T Information Security: Additional Guidance Needed to Address Cloud Computing Concerns ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Geer, Daniel E. and Conway, Daniel G.||2010||[[Nothing_Ventured,_Nothing_Gained|Nothing Ventured, Nothing Gained]]||Yes||Journal Article||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Gellman, Robert||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059444.pdf Civil Liberties and Privacy Implications of Policies to Prevent Cyberattacks ]||No||Journal Article||4.8 [[Attribution]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2010-07-15||[http://www.gao.gov/products/GAO-10-628 Critical Infrastructure Protection: Key Private and Public Cyber Expectations Need to Be Consistently Addressed ]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2011-01-12||[http://www.gao.gov/products/GAO-11-117 Electricity Grid Modernization: Progress Being Made on Cybersecurity Guidelines, but Key Challenges Remain to be Addressed ]||No||U.S. Government Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2011-03-16||[http://www.gao.gov/products/GAO-11-463T Cybersecurity: Continued Attention Needed to Protect Our Nation&#039;s Critical Infrastructure and Federal Information Systems ]||No||U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2011-07-29||[http://www.gao.gov/products/GAO-11-695R Defense Department Cyber Efforts: Definitions, Focal Point, and Methodology Needed for DOD to Develop Full-Spectrum Cyberspace Budget Estimates ]||No||U.S. Government Report ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2011-11-29||[http://www.gao.gov/products/GAO-12-8 Cybersecurity Human Capital: Initiatives Need Better Planning and Coordination ]||No||U.S. Government Report||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2011-12-09||[http://www.gao.gov/products/GAO-12-92 Critical Infrastructure Protection: Cybersecurity Guidance Is Available, but More Can Be Done to Promote Its Use ]||No||U.S. Government Report ||&lt;br /&gt;
|-&lt;br /&gt;
| General Services Administration (GSA) ||2012-02-07||[http://www.gsa.gov/graphics/staffoffices/FedRAMP_CONOPS.pdf Concept of Operations: FedRAMP ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Grady, Mark F. ||2006||[[The_Law_and_Economics_of_Cybersecurity|The Law and Economics of Cybersecurity ]]||Yes||Book ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Graham David E   ||2010||[[Cyber_Threats_and_the_Law_of_War| Cyber Threats and the Law of War]]||Yes||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Granick, Jennifer Stisa ||2005||[[The_Price_of_Restricting_Vulnerability_Publications|The Price of Restricting Vulnerability Publications ]]||Yes||Journal Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Hollis, Duncan B. ||2007||[[Why_States_Need_an_International_Law_for_Information_Operations|Why States Need an International Law for Information Operations ]]||Yes||Journal Article ||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;4.13.1 [[Government to Government|Government to Government Espionage]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| HP TippingPoint DVLabs ||2010||[[2010_Top_Cyber_Security_Risks_Report|2010 Top Cyber Security Risks Report ]]||Yes||Industry report ||4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| IEEE/EastWest Institute ||2010-05-26||[http://www.ieee-rogucci.org/files/The%20ROGUCCI%20Report.pdf The Reliability of Global Undersea Communications Cable Infrastructure (The Rogucci Report) ]||No||Independent Report||3.3.3 [[Communications]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Institute for Information Infrastructure Protection ||2003||[[Cyber_Security_Research_and_Development_Agenda|Cyber Security Research and Development Agenda ]]||Yes||Independent Report ||4.1 [[Metrics]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Institute for Science and International Security ||2010-12-22||[http://isis-online.org/isis-reports/detail/did-stuxnet-take-out-1000-centrifuges-at-the-natanz-enrichment-plant/ Did Stuxnet Take Out 1,000 Centrifuges at the Natanz Enrichment Plant? Preliminary Assessment ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| International Instrument Users Association (WIB) ||2010-11-10||[http://www.isssource.com/wib/ WIB Security Standard Released ]||No||Industry Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| International Telecommunications Union ||2012-02-10||[http://www.itu.int/ITU-D/cyb/cybersecurity/docs/itu-toolkit-cybercrime-legislation.pdf ITU Toolkit for Cybercrime Legislation ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| James Clapper, Director of National Intelligence ||2011-02-10||[http://www.dni.gov/testimonies/20110210_testimony_clapper.pdf Worldwide Threat Assessment of the U.S. Intelligence Community (Testimony) ]||No||U.S. Government Report||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.2 [[Actors and Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Johnson, Eric M. ||2008||[[Managing_Information_Risk_and_the_Economics_of_Security|Managing Information Risk and the Economics of Security ]]||Yes||Book ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Johnson, Vincent R. ||2005||[[Cybersecurity,_Identity_Theft,_and_the_Limits_of_Tort_Liability|Cybersecurity, Identity Theft, and the Limits of Tort Liability ]]||Yes||Journal Article ||4.9 [[Identity Management]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Joint Workshop of the National Security Threats in Cyberspace and the National Strategy Forum ||2009-09-15||[http://nationalstrategy.com/Portals/0/National%20Security%20Threats%20in%20Cyberspace%20FINAL%2009-15-09.pdf National Security Threats in Cyberspace ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| Joseph S. Nye||2010||[[Cyber_Power|Cyber Power]]||Yes||Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Journal of Strategic Studies ||2011-10-05||[http://www.tandfonline.com/doi/abs/10.1080/01402390.2011.6089393 Cyber War Will Not Take Place ]||No||Journal Article||&lt;br /&gt;
|-&lt;br /&gt;
| Kelly A. Gable||2010||[[Cyber-Apocalypse_Now|Cyber-Apocalypse Now - Securing the Internet Against Cyberterrorism and Using Universal Jurisdiction as a Deterrent]]||Yes||Journal Article||3.2.4 [[Terrorists]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Kerr, Paul K. et al.&amp;lt;br /&amp;gt;CRS||2010-12-09||[http://www.fas.org/sgp/crs/natsec/R41524.pdf The Stuxnet Computer Worm: Harbinger of an Emerging Warfare Capability]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.4 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Kesan, Jay P. and Hayes, Carol M.||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059446.pdf Thinking Through Active Defense in Cyberspace ]||No||Journal Article||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Kobayashi, Bruce H.||2005||[[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods|An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and other Public Security Goods]]||Yes||Journal Article||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Kobayashi, Bruce H. ||2006||[[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods|An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and Other Public Security Goods ]]||Yes||Journal Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Korns, Stephen W. ||2009||[[Cyber_Operations|Cyber Operations ]]||Yes||Journal Article ||4.8 [[Attribution]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Kramer, Franklin D., et. al ||2009||[[Cyberpower_and_National_Security|Cyberpower and National Security ]]||Yes||Book ||1. [[Overview]]&lt;br /&gt;
|-&lt;br /&gt;
| Kundra, Vivek||2010-12-09||[http://www.cio.gov/documents/25-point-implementation-plan-to-reform-federal%20it.pdf 25 Point Implementation Plan to Reform Federal Information Technology Management]||No||U.S. Government Report||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Kundra, Vivek||2011-02-08||[http://www.cio.gov/documents/federal-cloud-computing-strategy.pdf Federal Cloud Computing Strategy]||No||U.S. Government Report||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Lan, Tang et al.||2010||[[Global_Cyber_Deterrence|Global Cyber Deterrence: Views from China, the U.S., Russia, India, and Norway]]||Yes||Independent Report||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Lernard, Thomas M. ||2005||[[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches|An Economic Analysis of Notification Requirements for Data Security Breaches ]]||Yes||Independent Report ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Lernard, Thomas M. ||2006||[[Much_Ado_About_Notification|Much Ado About Notification ]]||Yes||Journal Article ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Lewis, James Andrews||2005||[[Cyber_Security_and_Regulation_in_the_United_States|Aux armes, citoyens: Cyber Security and Regulation in the United States]]||Yes||Journal Article||3.3.1 [[Public Critical Infrastructure,&amp;lt;br&amp;gt;3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;3.3.2.3 [[Transportation]]&lt;br /&gt;
|-&lt;br /&gt;
| Libicki, Martin||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059490.pdf Pulling Punches in Cyberspace]||No||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
|Lin, Herbert||2012||[[Image:NRC-Cyberattack-Capabilities-2009.pdf|Cyber Conflict and National Security]]||No||Article||&lt;br /&gt;
|-&lt;br /&gt;
| Lukasik, Stephen J.||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059438.pdf A Framework for Thinking about Cyber Conflict and Cyber Deterrence with Possible Declatory Policies for these Domain]||No||Journal Article||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Massachusetts Institute of Technology (MIT) ||2011-12-05||[http://web.mit.edu/mitei/research/studies/the-electric-grid-2011.shtml The Future of the Electric Grid ]||No||Independent Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| McAfee ||2011-08-02||[http://www.mcafee.com/us/resources/white-papers/wp-operation-shady-rat.pdf Revealed: Operation Shady RAT: an Investigation Of Targeted Intrusions Into 70+ Global Companies, Governments, and Non-Profit Organizations During the Last 5 Years ]||No||Industry Report||3.2.1 [[States]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.13 [[Espionage]]&lt;br /&gt;
|-&lt;br /&gt;
| McAfee ||2012-02-01||[http://www.mcafee.com/us/resources/reports/rp-sda-cyber-security.pdf?cid=WBB048 Cyber-security: The Vexed Question of Global Rules: An Independent Report on Cyber-Preparedness Around the World ]||No||Industry Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| McAfee and Center for Strategic and International Studies (CSIS) ||2011-04-21||[http://www.mcafee.com/us/resources/reports/rp-critical-infrastructure-protection.pdf In the Dark: Crucial Industries Confront Cyberattacks ]||No||Industry Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt; 4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| McAfee and the Security Defense Agenda||2012-02-12||[http://www.mcafee.com/us/resources/reports/rp-sda-cyber-security.pdf Cyber-security: The Vexed Question of Global Rules: An Independent Report on Cyber-Preparedness Around the World]||No||Industry Report||1. [[Overview]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| McAfee, Inc. ||2010||[[McAfee_Threats_Report|McAfee Threats Report ]]||Yes||Industry Report ||3.2.3 [[Hacktivists]],&amp;lt;br&amp;gt;3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| McDermott, Rose||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059442.pdf Decision Making Under Uncertainty]||No||Journal Article||4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;4.5 [[Psychology and Politics]],&amp;lt;br&amp;gt;4.8 [[Attribution]]&lt;br /&gt;
|-&lt;br /&gt;
| Microsoft||2010-11||[http://cdn.globalfoundationservices.com/documents/InformationSecurityMangSysforMSCloudInfrastructure.pdf Information Security Management System for Microsoft Cloud Infrastructure ]||No||Industry Report||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Mitre Corp (JASON Program Office) ||2010-11||[http://www.fas.org/irp/agency/dod/jason/cyber.pdf Science of Cyber-Security ]||No||Independent Report||1. [[Overview]],&amp;lt;br&amp;gt;4. [[Issues]]&lt;br /&gt;
|-&lt;br /&gt;
| Moore, Tyler||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059364.pdf Introducing the Economics of Cybersecurity: Principles and Policy Options]||No||Journal Article||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Moore, Tyler ||2007||[[Examining_the_Impact_of_Website_Take-down_on_Phishing|Examining the Impact of Website Take-down on Phishing ]]||Yes||Independent Report ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Moore, Tyler ||2008||[[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing|The Consequence of Non-Cooperation in the Fight Against Phishing ]]||Yes||Independent Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]]&lt;br /&gt;
|-&lt;br /&gt;
| Moore, Tyler ||2009||[[The_Impact_of_Incentives_on_Notice_and_Take-down|The Impact of Incentives on Notice and Take-down ]]||Yes||Book ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Moore, Tyler, et. al ||2009||[[The_Economics_of_Online_Crime|The Economics of Online Crime ]]||Yes||Journal Article ||3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| Morgan, Patrick M. ||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059436.pdf Applicability of Traditional Deterrence Concepts and Theory to the Cyber Realm ]||No||Journal Article||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]],&amp;lt;br&amp;gt;5.6 [[Deterrence ]]&lt;br /&gt;
|-&lt;br /&gt;
| National Association of Secretaries of State ||2012-01-12||[http://www.nass.org/index.php?option=com_docman&amp;amp;task=doc_download&amp;amp;gid=1257 Developing State Solutions to Business Identity Theft: Assistance, Prevention and Detection Efforts by Secretary of State Offices ]||No||Independent Report||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Cyber Defense Initiative ||2009||[[National_Cyber_Defense_Financial_Services_Workshop_Report|National Cyber Defense Financial Services Workshop Report ]]||Yes||Independent Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Cyber Security Alliance and Microsoft ||2011-05-13||[http://www.staysafeonline.org/sites/default/files/resource_documents/2011%20National%20K-12%20Study%20Final_0.pdf 2011 State of Cyberethics, Cybersafety and Cybersecurity Curriculum in the U.S. Survey ]||No||Industry Report||4.4 [[Usability/Human Factors]]&lt;br /&gt;
|-&lt;br /&gt;
| National Cyber Security Summit Task Force ||2004||[[Information_Security_Governance|Information Security Governance ]]||Yes||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]],&amp;lt;br&amp;gt;5.3 [[government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Infrastructure Advisory Council ||2004||[[Hardening_The_Internet|Hardening The Internet ]]||Yes||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Initiative for Cybersecurity Education||2011-08-11||[http://csrc.nist.gov/nice/documents/nicestratplan/Draft_NICE-Strategic-Plan_Aug2011.pdf National Initiative for Cybersecurity Education Strategic Plan: Building a Digital Nation]||No||U.S. Government Report||1. [[Overview]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Initiative for Cybersecurity Education (NICE) ||2011-11-21||[http://csrc.nist.gov/nice/framework/documents/NICE-Cybersecurity-Workforce-Framework-printable.pdf NICE Cybersecurity Workforce Framework ]||No||U.S. Government Report||4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Institute of Standards and Technology ||2006||[[SP_800-82:_Guide_to_Supervisory_Control_and_Data_Acquisition_(SCADA)_and_Industrial_Control_Systems_Security|SP 800-82: Guide to Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems Security ]]||Yes||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Institute of Standards and Technology (NIST) ||2010-09-02||[http://www.nist.gov/public_affairs/releases/nist-finalizes-initial-set-of-smart-grid-cyber-security-guidelines.cfm NIST Finalizes Initial Set of Smart Grid Cyber Security Guidelines ]||No||U.S. Government Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council ||2009||[http://www.nap.edu/catalog.php?record_id=12651 Technology, Policy, Law, and Ethics Regarding U.S. Acquisition and Use of Cyberattack Capabilities]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council ||2010-09-21||[http://www.nap.edu/catalog.php?record_id=12998 Toward Better Usability, Security, and Privacy of Information Technology: Report of a Workshop ]||No||Independent Report||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;4.10 [[Privacy]]&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council ||2010-10-05||[http://www.nap.edu/catalog.php?record_id=12997#description Proceedings of a Workshop on Deterring Cyberattacks: Informing Strategies and Developing Options for U.S. Policy ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council ||1999||[[Trust_in_Cyberspace|Trust in Cyberspace ]]||Yes||Independent Report ||3.3.3.2 [[Public Data Networks]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council ||2007||[[Toward_a_Safer_and_More_Secure_Cyberspace|Toward a Safer and More Secure Cyberspace ]]||Yes||Independent Report ||1. [[Overview]],&amp;lt;br&amp;gt;4.8 [[Attribution]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council, Committee for Advancing Software-Intensive Systems Producibility ||2010-10-20||[http://www.nap.edu/catalog.php?record_id=12979 Critical Code: Software Producibility for Defense ]||No||Independent Reprot ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| National Science and Technology Council ||2006||[[Federal_Plan_for_Cyber_Security_and_Information_Assurance_Research_and_Development|Federal Plan for Cyber Security and Information Assurance Research and Development ]]||Yes||U.S. Government Report ||4.1 [[Metrics]],&amp;lt;br&amp;gt;4.7 [[Attribution]],&amp;lt;br&amp;gt;4.8 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| National Science Foundation||2011-08-11||[http://www.livescience.com/15423-forefront-cyber-security-research-nsf-bts.html At the Forefront of Cyber Security Research ]||No||U.S. Government Report||5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| National Science Foundation||2012-01-17||[http://www.nsf.gov/awardsearch/showAward.do?AwardNumber=1127185 Information Security Risk Taking ]||No||U.S. Government Report||4.1 [[Metrics]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Security Cyberspace Institute||2012-07-11||[http://www.nsci-va.org/WhitePapers/2011-07-22-Cyber Analogies Whitepaper-K McKee.pdf A Review of Frequently Used Cyber Analogies ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| National Security Initiative ||2010-10-18||[http://www.americansecuritychallenge.com/ American Security Challenge ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| Networking and Information Technology Research and Development ||2009||[[National_Cyber_Leap_Year_Summit_2009,_Co-Chairs%27_Report|National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report ]]||Yes||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| NIST ||2011-09-01||[http://www.nist.gov/customcf/get_pdf.cfm?pub_id=909505 Cloud Computing Reference Architecture ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]]&lt;br /&gt;
|-&lt;br /&gt;
| NIST ||2011-12-01||[http://www.nist.gov/itl/cloud/upload/SP_500_293_volumeII.pdf U.S. Government Cloud Computing Technology Roadmap, Release 1.0 (Draft), Volume II Useful Information for Cloud Adopters ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| NIST ||2012-02-17||[http://www.nist.gov/nstic/2012-nstic-governance-recs.pdf Recommendations for Establishing an Identity Ecosystem Governance Structure for the National Strategy for Trusted Identities in Cyberspace ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Nojeim, Gregory T.||2009||[[Cybersecurity:_Preventing_Terrorist_Attacks_and_Protecting_Privacy_in_Cyberspace|Cybersecurity: Preventing Terrorist Attacks and Protecting Privacy in Cyberspace]]||Yes||U.S. Government Hearing||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| North American Electric Reliability Corp. (NERC) ||2011-01-26||[http://www.wired.com/images_blogs/threatlevel/2011/02/DoE-IG-Report-on-Grid-Security.pdf Federal Energy Regulatory Commission&#039;s Monitoring of Power Grid Cyber Security ]||No||U.S. Government Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| NSTC||2011-12||[http://www.whitehouse.gov/sites/default/files/microsites/ostp/fed_cybersecurity_rd_strategic_plan_2011.pdf Trustworthy Cyberspace: Strategic Plan for the Federal Cybersecurity Research and Development Program]||No||U.S. Government Report||5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Nye, Joseph ||2010||[[Cyber_Power|Cyber Power ]]||Yes||Book ||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;4.13 [[Espionage]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| OECD||2009||[[Cybersecurity_and_Economic_Incentives|Cybersecurity and Economic Incentives]]||Yes||Non-U.S. Government Report||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| OECD||2009||[[The_Market_Consequences_of_Cybersecurity|The Market Consequences of Cybersecurity]]||Yes||Non-U.S. Government Report||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Office of the National Counterintelligence Executive ||2011-11-03||[http://www.ncix.gov/publications/reports/fecie_all/Foreign_Economic_Collection_2011.pdf Foreign Spies Stealing US Economic Secrets in Cyberspace ]||No||U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;4.13 [[Espionage]]&lt;br /&gt;
|-&lt;br /&gt;
| Organisation for Economic Co-operation and Development (OECD) ||2010-11-12||[http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.165.2211&amp;amp;rep=rep1&amp;amp;type=pdf The Role of Internet Service Providers in Botnet Mitigation: an Empirical Analysis Bases on Spam Data ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Organization for Economic Co-operation and Development (OECD) ||2012-01-10||[http://www.oecd-ilibrary.org/docserver/download/fulltext/5k9h2q8v9bln.pdf?expires=1330527950&amp;amp;id=id&amp;amp;accname=guest&amp;amp;checksum=F4470043AC638BE19D5131C3D5CE5EA4 ICT Applications for the Smart Grid: Opportunities and Policy Implications ]||No||Independent Report ||&lt;br /&gt;
|-&lt;br /&gt;
| PCAST||2010-12||[http://www.whitehouse.gov/sites/default/files/microsites/ostp/pcast-nitrd-report-2010.pdf Designing a Digital Future: Federally Funded Research and Development in Networking and Information Technology]||No||U.S. Government Report||4.3 [[Supply Chain Issues]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| PCAST||2011-06||[http://www.whitehouse.gov/sites/default/files/microsites/ostp/pcast-advanced-manufacturing-june2011.pdf Report to the President on Ensuring American Leadership in Advanced Manufacturing]||No||U.S. Government Report||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Perkins, Earl||2009||[[Evolving_Cybersecurity_Issues_in_the_Utility_Industry|Evolving Cybersecurity Issues in the Utility Industry]]||Yes||Independent Report||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.2.4 [[Water, Sewer, etc.]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Pew Research Center’s Internet &amp;amp; American Life Project ||2010-06-11||[http://pewinternet.org/Reports/2010/The-future-of-cloud-computing.aspx The future of cloud computing ]||No||Independent Report||3.3.3.3 [[Cloud Computing]]&lt;br /&gt;
|-&lt;br /&gt;
| Powell, Benjamin ||2005||[[Is_Cybersecurity_a_Public_Good|Is Cybersecurity a Public Good ]]||Yes||Journal Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.5 [[Market Failure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| President&#039;s Commission on Critical Infrastructure Protection ||1997||[[Critical_Foundations|Critical Foundations ]]||Yes||U.S. Government Report ||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.3 [[Communications]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| President&#039;s Information Technology Advisory Council ||2005||[[Cyber_Security:_A_Crisis_of_Prioritization|Cyber Security: A Crisis of Prioritization ]]||Yes||U.S. Government Report ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Project on National Security Reform (PNSR) ||2010-11||[http://www.pnsr.org/data/images/pnsr_the_power_of_people_report.pdf The Power of People: Building an Integrated National Security Professional System for the 21st Century ]||No||U.S. Government Report||4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Quadrennial Defense Review ||2010-07-30||[http://www.usip.org/quadrennial-defense-review-independent-panel-/view-the-report The QDR in Perspective: Meeting AmericaÅfs National Security Needs In the 21st Century (QDR Final Report) ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| RAND||2011-12-21||[http://www.rand.org/content/dam/rand/pubs/occasional_papers/2011/RAND_OP342.pdf A Cyberworm that Knows No Boundaries ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Rattray, Gregory and Healey, Jason||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059437.pdf Categorizing and Understanding Offensive Cyber Capabilities and Their Use ]||No||Journal Article||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Rollins, John and Wilson, Clay||2007||[[Terrorist_Capabilities_for_Cyberattack|Terrorist Capabilities for Cyberattack]]||Yes||U.S. Government Report||3.2.4 [[Terrorists]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Romanosky et al. ||2008||[[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft|Do Data Breach Disclosure Laws Reduce Identity Theft ]]||Yes||Independent Report ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Rosenzweig, Paul||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059443.pdf The Organization of the United States Government and Private Sector for Achieving Cyber Deterrence ]||No||Journal Article||4.3 [[Supply Chain Issues]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Rotenberg et. al. ||2010||[[The_Cyber_War_Threat_Has_Been_Grossly_Exaggerated|The Cyber War Threat Has Been Grossly Exaggerated ]]||Yes||Article||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Rue, Rachel and Pfleeger, Shari Lawrence||2009||[[Making_the_Best_Use_of_Cybersecurity_Economic_Models|Making the Best Use of Cybersecurity Economic Models]]||Yes||Journal Article||4.1 [[Metrics]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| Santos, Joost R., et. al||2007||[[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies|A Framework for Linking Cybersecurity Metrics to the Modeling of Macroeconomic Interdependencies]]||Yes||Journal Article||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;4.1 [[Metrics]]&lt;br /&gt;
|-&lt;br /&gt;
| Schmitt Michael N   ||2002||[[Wired_Warfare| Wired warfare: Computer network attack and jus in bello]]||Yes||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Schmitt Michael N   ||2004||[[Direct_Participation_in_Hostilities|Direct Participation in Hostilities and 21st Century Armed Conflict]]||Yes||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Schmitt, Michael N. ||1999||[[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law|Computer Network Attack and the Use of Force in International Law ]]||Yes||Journal Article ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Schmitt, Michael N. ||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059439.pdf Cyber Operations in International Law: The Use of Force, Collective Security, Self-Defense, and Armed Conflicts]||No||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Schmitt, Michael N., et. al ||2004||[[Computers_and_War|Computers and War ]]||Yes||Independent Report ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Schneidewind, Norman||2010||[[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks|Metrics for Mitigating Cybersecurity Threats to Networks]]||Yes||Journal Article||4.1 [[Metrics]]&lt;br /&gt;
|-&lt;br /&gt;
| Schneier, Bruce ||2003||[[Beyond_Fear|Beyond Fear ]]||Yes||Book ||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;4.5 [[Psychology and Politics]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Schneier, Bruce ||2008||[[Schneier_on_Security|Schneier on Security ]]||Yes||Book ||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Schwartz, Paul ||2007||[[Notification_of_Data_Security_Breaches|Notification of Data Security Breaches ]]||Yes||Journal Article ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Secretary of the Air Force ||2011-07-27||[http://www.e-publishing.af.mil/shared/media/epubs/AFI51-402.pdf Legal Reviews of Weapons and Cyber Capabilities ]||No||U.S. Government Report ||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Shackelford, Scott J.||2010||[[Estonia_Three_Years_Later|Estonia Three Years Later]]||Yes||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Shah, Shashi K.||2004||[[The_Evolving_Landscape_of_Maritime_Cybersecurity|The Evolving Landscape of Maritime Cybersecurity]]||Yes||Journal Article||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.2.3 [[Transportation]]&lt;br /&gt;
|-&lt;br /&gt;
| Sklerov, Matthew J. ||2009||[[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks|Solving the Dilemma of State Responses to Cyberattacks ]]||Yes||Journal Article ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.8 [[Attribution]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Sofaer, Abraham; Clark, David; and Diffie, Whitfield||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059440.pdf Cyber Security and International Cooperation ]||No||Journal Article||5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Software and Information Industry Association (SAII) ||2011-07-26||[http://www.siia.net/index.php?option=com_docman&amp;amp;task=doc_download&amp;amp;gid=3040&amp;amp;Itemid=318 Guide to Cloud Computing for Policy Makers ]||No||Independent Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Stohl, Michael ||2006||[[Cyber_Terrorism|Cyber Terrorism ]]||Yes||Journal Article ||3.2.3 [[Hacktivists]],&amp;lt;br&amp;gt;3.2.4 [[Terrorists]],&amp;lt;br&amp;gt;4.5 [[Psychology and Politics]]&lt;br /&gt;
|-&lt;br /&gt;
| Stuart Madnick et al.||2009||[[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security|Experiences and Challenges with Using CERT Data to Analyze International Cyber Security]]||Yes||Journal Article||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Swire, Peter P. ||2004||[[A_Model_for_When_Disclosure_Helps_Security|A Model for When Disclosure Helps Security ]]||Yes||Journal Article ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Swire, Peter P. ||2006||[[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons|A Theory of Disclosure for Security and Competitive Reasons ]]||Yes||Journal Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Symantec||2011-10-24||[http://www.symantec.com/connect/w32_duqu_precursor_next_stuxnet W32.Duqu: The Precursor to the Next Stuxnet ]||No||Industry Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Symantec Corporation ||2010||[[Symantec_Global_Internet_Security_Threat_Report|Symantec Global Internet Security Threat Report ]]||Yes||Industry Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| Telang, Rahul ||2007||[[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors|Impact of Software Vulnerability Announcements on the Market Value of Software Vendors ]]||Yes||Journal Article ||4.1 [[Metrics]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]]&lt;br /&gt;
|-&lt;br /&gt;
| Theohary, Catherine A. and Rollins, John||2010||[[Cybersecurity:_Current_Legislation,_Executive_Branch_Initiatives,_and_Options_for_Congress|Cybersecurity: Current Legislation, Executive Branch Initiatives, and Options for Congress]]||Yes||U.S. Government Report||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Thom, Maxie    ||2006||[[Information_Warfare_Arms_Control| Information Warfare Arms Control: Risks and Costs]]||Yes||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Thomas, Rob ||2006||[[The_Underground_Economy|The Underground Economy ]]||Yes||Journal Article ||3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| Threat Level Blog (Wired) ||2010-12-27||[http://www.wired.com/threatlevel/2010/12/a-four-day-dive-into-stuxnets-heart/ A Four-Day Dive Into Stuxnet’s Heart ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Todd, Graham H. ||2009||[[Armed_Attack_in_Cyberspace|Armed Attack in Cyberspace ]]||Yes||Journal Article ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.8 [[Attribution]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Trend Micro Incorporated ||2010||[[Trend_Micro_Annual_Report|Trend Micro Annual Report ]]||Yes||Industry Report ||4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Air Force ||2010-07-15||[http://www.e-publishing.af.mil/shared/media/epubs/afdd3-12.pdf Cyberspace Operations: Air Force Doctrine Document 3-12 ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Army War College ||2011-05-09||[http://www.strategicstudiesinstitute.army.mil/pubs/display.cfm?pubid=10670 Cyber Infrastructure Protection ]||No||U.S. Government Report||&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Army War College, Strategy Research Project ||2011-03-24||[http://www.dtic.mil/dtic/tr/fulltext/u2/a552990.pdf China’s Cyber Power and America’s National Security ]||No||U.S. Government Report||3.2.1 [[States]],&amp;lt;br&amp;gt;4.13 [[Espionage]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Department of Energy, Infrastructure Security and Energy Restoration ||2007-01-01||[http://www.oe.netl.doe.gov/docs/prepare/21stepsbooklet.pdf 21 Steps to Improve Cyber Security of SCADA Networks ]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Deputy Secretary of Defense, William J. Lynn (Foreign Affairs) ||2010-009||[http://www.foreignaffairs.com/articles/66552/william-j-lynn-iii/defending-a-new-domain Defending a New Domain ]||No||U.S. Government Report ||&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Appropriations (closed/classified) (Subcommittee on Energy and Power)||2011-03-31||[http://www.dhs.gov/ynews/testimony/testimony_1301595025263.shtm Budget Hearing - National Protection and Programs Directorate, Cybersecurity and Infrastructure Protection Programs  ]||No||U.S. Government Hearing||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2011-02-11||[http://armedservices.house.gov/index.cfm/hearings-display?ContentRecord_id=90d8a16a-23b7-4b9c-a732-cb10ab20e579&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=64562e79-731a-4ac6-aab0-7bd8d1b7e890&amp;amp;MonthDisplay=2&amp;amp;YearDisplay=2011 What Should the Department of Defense’s Role in Cyber Be?]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2011-03-16||[http://armedservices.house.gov/index.cfm/hearings-display?ContentRecord_id=79ce7b4c-f88b-40bf-9540-efdb3a2d26b2&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=64562e79-731a-4ac6-aab0-7bd8d1b7e890&amp;amp;MonthDisplay=3&amp;amp;YearDisplay=2011 2012 Budget Request from U.S. Cyber Command]||No||U.S. Government Hearing||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2011-11-03||[http://armedservices.house.gov/index.cfm/hearings-display?ContentRecord_id=42c170fb-8e0c-453a-81a2-f4ee3fa89283&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=64562e79-731a-4ac6-aab0-7bd8d1b7e890&amp;amp;MonthDisplay=11&amp;amp;YearDisplay=2011 Institutionalizing Irregular Warfare Capabilities]||No||U.S. Government Hearing||4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2012-03-20||[http://armedservices.house.gov/index.cfm/hearings-display?ContentRecord_id=92823c77-38f0-4c20-a3ee-36729e8e19a3&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=64562e79-731a-4ac6-aab0-7bd8d1b7e890&amp;amp;MonthDisplay=3&amp;amp;YearDisplay=2012 Fiscal 2013 Defense Authorization: IT and Cyber Operations]||No||U.S. Government Hearing||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce||2011-05-31||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=8639 Protecting the Electric Grid: the Grid Reliability and Infrastructure Defense Act]||No||U.S. Government Hearing||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Commerce, Manufacturing, and Trade)||2011-06-02||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=8653 Sony and Epsilon: Lessons for Data Security Legislation]||No||U.S. Government Hearing||4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Commerce,Trade and Manufacturing)||2011-06-15||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=8693 Discussion Draft of H.R. ___, a bill to require greater protection for sensitive consumer data and timely notification in case of breach]||No||U.S. Government Hearing||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Communications and Technology)||2012-03-07||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=9342 Cybersecurity:Networks     The Pivotal Role of Communications]||No||U.S. Government Hearing||3.3.3 [[Communications]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Communications and Technology)||2012-03-28||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=9397 Cybersecurity:Threats to Communications Networks and Public-Sector Responses]||No||U.S. Government Hearing||3.3.3 [[Communications]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Oversight and Investigations)||2011-07-26||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=8824 Cybersecurity: Infrastructure An Overview of Risks to Critical]||No||U.S. Government Hearing||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Oversight and Investigations)||2012-02-28||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=9318 Critical Infrastructure Cybersecurity: Assessments of Smart Grid Security]||No||U.S. Government Hearing||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Oversight and Investigations)||2012-03-27||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=9393 IT Supply Chain Security: Review of Government and Industry Efforts]||No||U.S. Government Hearing||4.3 [[Supply Chain Issues]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Financial Services (field hearing in Hoover, AL)||2011-06-29||[http://financialservices.house.gov/Calendar/EventSingle.aspx?EventID=246611 Field Hearing: Hacked Off: Helping Law Enforcement Protect Private Financial Information]||No||U.S. Government Hearing||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Financial Services (Subcommittee on Financial Institutions and Consumer Credit)||2011-09-14||[http://financialservices.house.gov/Calendar/EventSingle.aspx?EventID=258792 Combating Cybercriminals]||No||U.S. Government Hearing||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;5.7 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Foreign Affairs (Subcommittee on Oversight and Investigations)||2011-04-15||[http://foreignaffairs.house.gov/hearing_notice.asp?id=1279 Communist Chinese Cyber-Attacks, Cyber-Espionage and Theft of American Technology]||No||U.S. Government Hearing||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;4.13 [[Espionage]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies and Counterterrorism and Intelligence)||2012-04-19||[http://homeland.house.gov/hearing/subcommittee-hearing-dhs-and-doe-national-labs-finding-efficiencies-and-optimizing-outputs The DHS and DOE National Labs: Finding Efficiencies and Optimizing Outputs in Homeland Security Research and Development]||No||U.S. Government Hearing||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies and Counterterrorism and Intelligence)||2012-04-26||[http://homeland.house.gov/hearing/joint-subcommittee-hearing-iranian-cyber-threat-us-homeland Iranian Cyber Threat to U.S. Homeland]||No||U.S. Government Hearing||3.2.1 [[States]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2011-02-11||[http://homeland.house.gov/hearing/subcommittee-hearing-%E2%80%9Cpreventing-chemical-terrorism-building-foundation-security-our-nation Preventing Chemical Terrorism: Building a Foundation of Security at Our Nation’s Chemical Facilities]||No||U.S. Government Hearing||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2011-03-16||[http://homeland.house.gov/hearing/subcommittee-hearing-examining-cyber-threat-critical-infrastructure-and-american-economy Examining the Cyber Threat to Critical Infrastructure and the American Economy]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2011-04-15||[http://homeland.house.gov/hearing/subcommittee-hearing-%E2%80%9C-dhs-cybersecurity-mission-promoting-innovation-and-securing-critical DHS Cybersecurity Mission: Promoting Innovation and Securing Critical Infrastructure]||No||U.S. Government Hearing||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2011-06-24||[http://homeland.house.gov/hearing/subcommittee-hearing-examining-homeland-security-impact-obamaadministrations-cybersecurity Examining the Homeland Security Impact of the Obama Administration’s Cybersecurity Proposal]||No||U.S. Government Hearing||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2011-12-06||[http://homeland.house.gov/hearing/subcommittee-hearing-hearing-draft-legislative-proposal-cybersecurity Hearing on Draft Legislative Proposal on Cybersecurity]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2012-02-01||[http://homeland.house.gov/markup/subcommittee-markup-hr-3674 Consideration and Markup of H.R. 3674]||No||U.S. Government Hearing||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technology)||2011-10-06||[http://homeland.house.gov/hearing/cloud-computing-what-are-security-implications Cloud Computing: What are the Security Implications?]||No||U.S. Government Hearing||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;4.13 [[Espionage]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection, and Security Technologies)||2011-05-26||[http://homeland.house.gov/hearing/subcommittee-hearing-%E2%80%9Cunlocking-safety-act%E2%80%99s-potential-promote-technology-and-combat Unlocking the SAFETY Act’s Potential to Promote Technology and Combat Terrorism ]||No||U.S. Government Hearing||4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Oversight, Investigations and Management)||2012-04-24||[http://homeland.house.gov/hearing/subcommittee-hearing-america-under-cyber-attack-why-urgent-action-needed America is Under Cyber Attack: Why Urgent Action is Needed]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.2 [[Actors and Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Oversight and Government Reform||2011-07-07||[http://oversight.house.gov/hearing/cybersecurity-assessing-the-nations-ability-to-address-the-growing-cyber-threat/ Cybersecurity: Assessing the Nation’s Ability to Address the Growing Cyber Threat]||No||U.S. Government Hearing||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Oversight and Government Reform (Subcommittee on National Security, Homeland Defense and Foreign Operations)||2011-05-25||[http://oversight.house.gov/hearing/cybersecurity-assessing-the-immediate-threat-to-the-united-states/ Cybersecurity: Assessing the Immediate Threat to the United States]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Science, Space and Technology||2011-07-21||[http://science.house.gov/markup/full-committee-%E2%80%93-markup Markup on H.R. 2096, Cybersecurity Enhancement Act of 2011]||No||U.S. Government Hearing||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Science, Space and Technology (Subcommittee on Research and Science Education)||2011-05-25||[http://science.house.gov/hearing/subcommittee-research-and-science-education-subcommittee-technology-and-innovation-%E2%80%93-joint Protecting Information in the Digital Age: Federal Cybersecurity Research and Development Efforts]||No||U.S. Government Hearing||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Science, Space, and Technology (Subcommittee on Investigations and Oversight)||2012-02-29||[http://science.house.gov/hearing/subcommittee-investigations-and-oversight-hearing-nasa-cybersecurity-examination-agency%E2%80%99s NASA Cybersecurity: An Examination of the Agency’s Information Security]||No||U.S. Government Hearing||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Science, Space, and Technology (Subcommittee on Technology and Innovation)||2011-09-21||[http://science.house.gov/hearing/technology-and-innovation-subcommittee-hearing-cloud-computing The Cloud Computing Outlook]||No||U.S. Government Hearing||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Small Business (Subcommittee on Healthcare and Technology)||2011-12-01||[http://smallbusiness.house.gov/Calendar/EventSingle.aspx?EventID=270278 Cyber Security: Protecting Your Small Business]||No||U.S. Government Hearing||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on the Judiciary||2011-11-16||[http://judiciary.house.gov/hearings/hear_11162011.html Combating Online Piracy (H.R. 3261, Stop the Online Piracy Act)]||No||U.S. Government Hearing||4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on the Judiciary (Subcommittee on Crime, Terrorism and Homeland Security)||2011-11-15||[http://judiciary.house.gov/hearings/hear_11152011.html Cybersecurity: Protecting America’s New Frontier]||No||U.S. Government Hearing||4.10 [[Privacy]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on the Judiciary (Subcommittee on Intellectual Property, Competition and the Internet)||2011-05-25||[http://judiciary.house.gov/hearings/hear_05252011.html Cybersecurity: Problems Innovative Solutions to Challenging]||No||U.S. Government Hearing||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Permenant Select Committee on Intelligence||2011-02-10||[https://intelligence.house.gov/hearing/full-committee-world-wide-threats-hearing World Wide Threats]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Permenant Select Committee on Intelligence||2011-10-04||[https://intelligence.house.gov/hearing/cyber-threats-and-ongoing-efforts-protect-nation Cyber Threats and Ongoing Efforts to Protect the Nation]||No||U.S. Government Hearing||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.13.2 [[Industrial|Industrial Espionage]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Permenant Select Committee on Intelligence||2011-12-01||[https://intelligence.house.gov/markup/mark-hr-xxxx-%E2%80%9Ccyber-intelligence-sharing-and-protection-act-2011%E2%80%9D Markup: Draft Bill: Cyber Intelligence Sharing and Protection Act of 2011]||No||U.S. Government Hearing||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Navy ||2010-06-17||[http://www.doncio.navy.mil/PolicyView.aspx?ID=1804 DON (Department of the Navy) Cybersecurity/Information Assurance Workforce Management, Oversight and Compliance ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Armed Services||2012-03-27||[http://armed-services.senate.gov/e_witnesslist.cfm?id=5283 To receive testimony on U.S. Strategic Command and U.S. Cyber Command in review of the Defense Authorization Request for Fiscal Year 2013 and the Future Years Defense Program.]||No||U.S. Government Hearing||3.2.1 [[States]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2011-05-03||[http://www.armed-services.senate.gov/Transcripts/2011/05%20May/11-31%20-%205-3-11.pdf To receive testimony on the health and status of the defense industrial base and its science and technology-related elements]||No||U.S. Government Hearing||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.3 [[Supply Chain Issues]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2012-03-20||[http://www.armed-services.senate.gov/Transcripts/2012/03%20March/12-14%20-%203-20-12.pdf To receive testimony on cybersecurity research and development in review of the Defense Authorization Request for Fiscal Year 2013 and the Future Years Defense Program]||No||U.S. Government Hearing||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Banking, Housing and Urban Affairs||2011-06-21||[http://banking.senate.gov/public/index.cfm?FuseAction=Hearings.Hearing&amp;amp;Hearing_ID=87487cb2-4710-4c09-a1b0-a9e12cda88f1 Cybersecurity and Data Protection in the Financial Sector]||No||U.S. Government Hearing||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Commerce, Science and Transportation||2011-06-29||[http://commerce.senate.gov/public/index.cfm?p=Hearings&amp;amp;ContentRecord_id=e2c2a2ca-91d6-48a2-b5ea-b5c4104bdb97&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=b06c39af-e033-4cba-9221-de668ca1978a&amp;amp;MonthDisplay=6&amp;amp;YearDisplay=2011 Privacy and Data Security: Protecting Consumers in the Modern World]||No||U.S. Government Hearing||4.9 [[Identity Management]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Energy and Natural Resources||2011-03-15||[ Cybersecurity and Critical Electric Infrastructure (closed)]||No||U.S. Government Hearing||3.3.2.1 [[Electricity, Oil and Natural Gas]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Energy and Natural Resources||2011-05-05||[http://www.energy.senate.gov/public/index.cfm/hearings-and-business-meetings?ID=929c1441-da25-c99d-3e27-af20c29e3b4b Cybersecurity of the Bulk-Power System and Electric Infrastructure]||No||U.S. Government Hearing||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Homeland Security and Governmental Affairs||2011-02-17||[http://www.hsgac.senate.gov/hearings/the-homeland-security-departments-budget-submission-for-fiscal-year-2012 Homeland Security Department’s Budget Submission for Fiscal Year 2012]||No||U.S. Government Hearing||&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Homeland Security and Governmental Affairs||2011-03-10||[http://www.hsgac.senate.gov/hearings/information-sharing-in-the-era-of-wikileaks-balancing-security-and-collaboration Information Sharing in the Era of WikiLeaks: Balancing Security and Collaboration]||No||U.S. Government Hearing||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Homeland Security and Governmental Affairs||2011-05-23||[http://www.hsgac.senate.gov/hearings/protecting-cyberspace-assessing-the-white-house-proposal Protecting Cyberspace: Assessing the White House Proposal]||No||U.S. Government Hearing||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Homeland Security and Governmental Affairs||2012-02-16||[http://www.hsgac.senate.gov/hearings/securing-americas-future-the-cybersecurity-act-of-2012 Securing America’s Future: The Cybersecurity Act of 2012]||No||U.S. Government Hearing||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Judiciary||2011-03-30||[http://www.judiciary.senate.gov/hearings/hearing.cfm?id=e655f9e2809e5476862f735da1697f72 Oversight of the Federal Bureau of Investigation]||No||U.S. Government Hearing||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Judiciary||2011-09-07||[http://www.judiciary.senate.gov/hearings/hearing.cfm?id=3d9031b47812de2592c3baeba629084b Cybercrime: Updating the Computer Fraud and Abuse Act to Protect Cyberspace and Combat Emerging Threats]||No||U.S. Government Hearing||3.11 [[Cybercrime]],&amp;lt;br&amp;gt;4.13.2 [[Industrial|Industrial Espionage]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Judiciary||2012-03-13||[http://www.judiciary.senate.gov/hearings/hearing.cfm?id=8b30fa475a5089d793576cd947089793 The Freedom of Information Act: Safeguarding Critical Infrastructure Information and the Public’s Right to Know]||No||U.S. Government Hearing||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Judiciary (Subcommittee on Crime and Terrorism)||2011-04-12||[http://www.judiciary.senate.gov/hearings/hearing.cfm?id=e655f9e2809e5476862f735da16a9959 Cyber Security: Responding to the Threat of Cyber Crime and Terrorism]||No||U.S. Government Hearing||4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Judiciary (Subcommittee on Crime and Terrorism)||2011-06-21||[http://www.judiciary.senate.gov/hearings/hearing.cfm?id=e655f9e2809e5476862f735da16e1bbe Cybersecurity: Evaluating the Administration’s Proposals]||No||U.S. Government Hearing||1. [[Overview]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Small Business and Entrepreneurship||2011-07-25||[http://www.sbc.senate.gov/public/index.cfm?p=Hearings&amp;amp;ContentRecord_id=6b4d51de-dd67-434b-869f-a717b315e6c2&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=43eb5e02-e987-4077-b9a7-1e5a9cf28964&amp;amp;MonthDisplay=7&amp;amp;YearDisplay=2011 Role of Small Business in Strengthening Cybersecurity Efforts in the United States]||No||U.S. Government Hearing||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.7 [[public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| United States Secret Service ||2004||[[Insider_Threat_Study|Insider Threat Study ]]||Yes||U.S. Government Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]]&lt;br /&gt;
|-&lt;br /&gt;
| University of Southern California (USC) Information Sciences Institute, University of California Berkeley (UCB), McAfee Research ||2011-01-13||[http://www.isi.edu/deter/news/news.php?story=20 Design of the DETER Security Testbed ]||No||Independent Report||5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| van Eeten, Michael and Bauer, Johannes M.||2009||[[Emerging_Threats_to_Internet_Security|Emerging Threats to Internet Security: Incentives, Externalities and Policy Implications]]||Yes||Journal Article||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| van Eeten, Michel J. G. ||2008||[[Economics_of_Malware|Economics of Malware ]]||Yes||Non-U.S. Government Report ||4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| Varian, Hal ||2000||[[Managing_Online_Security_Risks|Managing Online Security Risks ]]||Yes||Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| Varian, Hal ||2004||[[System_Reliability_and_Free_Riding|System Reliability and Free Riding ]]||Yes||Book ||4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| Vatis, Michael A.||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059441.pdf The Council of Europe Convention on Cybercrime]||No||Journal Article||4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Verizon ||2010||[[2010_Data_Breach_Investigations_Report|2010 Data Breach Investigations Report ]]||Yes||Industry Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Watts, Sean ||2010||[[Combatant_Status_and_Computer_Network_Attack|Combatant Status and Computer Network Attack ]]||Yes||Journal Article ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| White House||2009||[http://www.whitehouse.gov/assets/documents/Cyberspace_Policy_Review_final.pdf Cyberspace Policy Review: Assuring a Trusted and Resilient Information and Communications Infrastructure]||No||U.S. Government Report||1. [[Overview]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| White House||2011-04||[http://www.whitehouse.gov/sites/default/files/rss_viewer/NSTICstrategy_041511.pdf National Strategy for Trusted Identities in Cyberspace: Enhancing Online Choice, Efficiency, Security, and Privacy]||No||U.S. Government Report||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]]&lt;br /&gt;
|-&lt;br /&gt;
| White House||2011-05||[http://www.whitehouse.gov/sites/default/files/rss_viewer/international_strategy_for_cyberspace.pdf International Strategy for Cyberspace: Prosperity, Security, and Openness in a Networked World]||No||U.S. Government Report||1. [[Overview]]&lt;br /&gt;
|-&lt;br /&gt;
| White House||2012-01||[http://www.whitehouse.gov/sites/default/files/national_strategy_for_global_supply_chain_security.pdf National Strategy for Global Supply Chain Security]||No||U.S. Government Report||4.3 [[Supply Chain Issues]]&lt;br /&gt;
|-&lt;br /&gt;
| White House||2012-02||[http://www.whitehouse.gov/sites/default/files/privacy-final.pdf Consumer Data Privacy in a Networked World: A Framework for Protecting Privacy and Promoting Innovation in the Global Digital Economy]||No||U.S. Government Report||4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2010-12-16||[http://www.whitehouse.gov/sites/default/files/microsites/ostp/pcast-nitrd-report-2010.pdf Designing A Digital Future: Federally Funded Research And Development In Networking And Information Technology ]||No||U.S. Government Report||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2011-02-13||[http://www.cio.gov/documents/Federal-Cloud-Computing-Strategy.pdf Federal Cloud Computing Strategy ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2011-04-15||[http://www.whitehouse.gov/the-press-office/2011/04/15/administration-releases-strategy-protect-online-consumers-and-support-in Administration Releases Strategy to Protect Online Consumers and Support Innovation and Fact Sheet on National Strategy for Trusted Identities in Cyberspace ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2011-04-15||[http://www.whitehouse.gov/sites/default/files/rss_viewer/NSTICstrategy_041511.pdf National Strategy for Trusted Identities in Cyberspace ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2003||[[The_National_Strategy_to_Secure_Cyberspace|The National Strategy to Secure Cyberspace ]]||Yes||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2009||[[Cyberspace_Policy_Review|Cyberspace Policy Review ]]||Yes||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2010||[[The_Comprehensive_National_Cybersecurity_Initiative|The Comprehensive National Cybersecurity Initiative ]]||Yes||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House (Office of Science &amp;amp; Technology Policy) ||2010-12-06||[http://www.whitehouse.gov/blog/2010/12/06/partnership-cybersecurity-innovation Partnership for Cybersecurity Innovation ]||No||U.S. Government Report||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/Office of Management and Budget (OMB) ||2011-12-08||[http://www.cio.gov/fedrampmemo.pdf Security Authorization of Information Systems in Cloud Computing Environments (FedRAMP) ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2009-05-29||[http://www.whitehouse.gov/assets/documents/Cyberspace_Policy_Review_final.pdf Cyberspace Policy Review: Assuring a Trusted and Resilient Communications Infrastructure ]||No||U.S. Government Report ||4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2010-03-02||[http://www.whitehouse.gov/cybersecurity/comprehensive-national-cybersecurity-initiative Comprehensive National Cybersecurity Initiative (CNCI) ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2010-06-25||[http://www.dhs.gov/xlibrary/assets/ns_tic.pdf The National Strategy for Trusted Identities in Cyberspace: Creating Options for Enhanced Online Security and Privacy ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2010-07-06||[http://www.whitehouse.gov/sites/default/files/omb/assets/memoranda_2010/m10-28.pdf Clarifying Cybersecurity Responsibilities ]||No||U.S. Government Report ||5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2010-12-09||[http://www.cio.gov/documents/25-Point-Implementation-Plan-to-Reform-Federal%20IT.pdf 25 Point Implementation Plan to Reform Federal Information Technology Management ]||No||U.S. Government Report ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-02-13||[http://www.cio.gov/documents/Federal-Cloud-Computing-Strategy.pdf Federal Cloud Computing Strategy ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-05-12||[http://www.whitehouse.gov/the-press-office/2011/05/12/fact-sheet-cybersecurity-legislative-proposal Cybersecurity Legislative Proposal (Fact Sheet) ]||No||U.S. Government Report ||4. [[Issues]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-05-16||[http://www.whitehouse.gov/sites/default/files/rss_viewer/international_strategy_for_cyberspace.pdf International Strategy for Cyberspace ]||No||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-09-14||[http://www.whitehouse.gov/sites/default/files/omb/memoranda/2011/m11-33.pdf FY 2012 Reporting Instructions for the Federal Information Security Management Act and Agency Privacy Managementa ]||No||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-10-07||[http://www.whitehouse.gov/the-press-office/2011/10/07/executive-order-structural-reforms-improve-security-classified-networks- Structural Reforms to Improve the Security of Classified Networks and the Responsible Sharing and Safeguarding of Classified Information ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-12-06||[http://www.whitehouse.gov/sites/default/files/microsites/ostp/fed_cybersecurity_rd_strategic_plan_2011.pdf Trustworthy Cyberspace: Strategic Plan for the Federal Cybersecurity Research and Development Program ]||No||U.S. Government Report ||5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Wilshusen, Gregory C. and Powner, David A.||2009||[[Continued_Efforts_are_Needed_to_Protect_Information_Systems_from_Evolving_Threats|Continued Efforts Are Needed to Protect Information Systems from Evolving Threats]]||Yes||U.S. Government Hearing||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Wilson, Clay||2007-03-20||[http://www.fas.org/sgp/crs/natsec/RL31787.pdf Information Operations, Electronic Warfare, and Cyberwar: Capabilities and Related Policy Issues]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Zittrain, Jonathan L. ||2008||[[The_Future_of_the_Internet_and_How_To_Stop_It|The Future of the Internet and How To Stop It ]]||Yes||Book ||4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Centre for Secure Information Technologies||2012||[http://www.csit.qub.ac.uk/sites/CSIT/InnovationatCSIT/Reports/Filetoupload,295595,en.pdf 2nd World Cyber security Technology Research Summit (Belfast 2012)]||No||Independent Report||&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=File:NRC-Cyberattack_Capabilities-2009.pdf&amp;diff=6847</id>
		<title>File:NRC-Cyberattack Capabilities-2009.pdf</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=File:NRC-Cyberattack_Capabilities-2009.pdf&amp;diff=6847"/>
		<updated>2013-01-25T20:56:06Z</updated>

		<summary type="html">&lt;p&gt;David: Made available with permission from Herbert Lin.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Made available with permission from Herbert Lin.&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=File:Lin-Cyber_Conflict_and_National_Security_2012.pdf&amp;diff=6846</id>
		<title>File:Lin-Cyber Conflict and National Security 2012.pdf</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=File:Lin-Cyber_Conflict_and_National_Security_2012.pdf&amp;diff=6846"/>
		<updated>2013-01-25T20:55:36Z</updated>

		<summary type="html">&lt;p&gt;David: Made available with permission from Herbert Lin.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Made available with permission from Herbert Lin.&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Template:Filtered_Table&amp;diff=6845</id>
		<title>Template:Filtered Table</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Template:Filtered_Table&amp;diff=6845"/>
		<updated>2013-01-24T19:49:27Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;dt_types&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|U.S. Government Report&lt;br /&gt;
|-&lt;br /&gt;
|U.S. Government Hearing&lt;br /&gt;
|-&lt;br /&gt;
|Non-U.S. Government Report&lt;br /&gt;
|-&lt;br /&gt;
|Independent Report&lt;br /&gt;
|-&lt;br /&gt;
|Industry Report&lt;br /&gt;
|-&lt;br /&gt;
|Book&lt;br /&gt;
|-&lt;br /&gt;
|Journal Article&lt;br /&gt;
|-&lt;br /&gt;
|Article&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;dt_categories&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|1. Overview&lt;br /&gt;
|-&lt;br /&gt;
|3. Threats and Actors&lt;br /&gt;
|-&lt;br /&gt;
|3.1 The Threat and Skeptics&lt;br /&gt;
|-&lt;br /&gt;
|3.2 Actors and Incentives&lt;br /&gt;
|-&lt;br /&gt;
|3.2.1 States&lt;br /&gt;
|-&lt;br /&gt;
|3.2.2 Groups&lt;br /&gt;
|-&lt;br /&gt;
|3.2.3 Hacktivists&lt;br /&gt;
|-&lt;br /&gt;
|3.2.4 Terrorists&lt;br /&gt;
|-&lt;br /&gt;
|3.2.5 Criminals and Criminal Organizations&lt;br /&gt;
|-&lt;br /&gt;
|3.3 Security Targets&lt;br /&gt;
|-&lt;br /&gt;
|3.3.1 Public Critical Infrastructure&lt;br /&gt;
|-&lt;br /&gt;
|3.3.1.1 Government Networks (.gov)&lt;br /&gt;
|-&lt;br /&gt;
|3.3.1.2 Military Networks (.mil)&lt;br /&gt;
|-&lt;br /&gt;
|3.3.2 Private Critical Infrastructure&lt;br /&gt;
|-&lt;br /&gt;
|3.3.2.1 Electricity, Oil and Natural Gas&lt;br /&gt;
|-&lt;br /&gt;
|3.3.2.2 Financial Institutions and Networks&lt;br /&gt;
|-&lt;br /&gt;
|3.3.2.3 Transportation&lt;br /&gt;
|-&lt;br /&gt;
|3.3.2.4 Water, Sewer, etc.&lt;br /&gt;
|-&lt;br /&gt;
|3.3.3 Communications&lt;br /&gt;
|-&lt;br /&gt;
|3.3.3.1 Telephone&lt;br /&gt;
|-&lt;br /&gt;
|3.3.3.2 Public Data Networks&lt;br /&gt;
|-&lt;br /&gt;
|3.3.3.3 Cloud Computing&lt;br /&gt;
|-&lt;br /&gt;
|4. Issues&lt;br /&gt;
|-&lt;br /&gt;
|4.1 Metrics&lt;br /&gt;
|-&lt;br /&gt;
|4.2 Economics of Cybersecurity&lt;br /&gt;
|-&lt;br /&gt;
|4.2.1 Risk Management and Investment&lt;br /&gt;
|-&lt;br /&gt;
|4.2.2 Incentives&lt;br /&gt;
|-&lt;br /&gt;
|4.2.3 Insurance&lt;br /&gt;
|-&lt;br /&gt;
|4.2.4 Behavioral Economics&lt;br /&gt;
|-&lt;br /&gt;
|4.2.5 Market Failure&lt;br /&gt;
|-&lt;br /&gt;
|4.3 Supply Chain Issues&lt;br /&gt;
|-&lt;br /&gt;
|4.4 Usability/Human Factors&lt;br /&gt;
|-&lt;br /&gt;
|4.5 Psychology and Politics&lt;br /&gt;
|-&lt;br /&gt;
|4.6 Information Sharing/Disclosure&lt;br /&gt;
|-&lt;br /&gt;
|4.7 Public-Private Cooperation&lt;br /&gt;
|-&lt;br /&gt;
|4.8 Attribution&lt;br /&gt;
|-&lt;br /&gt;
|4.9 Identity Management&lt;br /&gt;
|-&lt;br /&gt;
|4.10 Privacy&lt;br /&gt;
|-&lt;br /&gt;
|4.11 Cybercrime&lt;br /&gt;
|-&lt;br /&gt;
|4.12 Cyberwar&lt;br /&gt;
|-&lt;br /&gt;
|4.13 Espionage&lt;br /&gt;
|-&lt;br /&gt;
|4.13.1 Government to Government&lt;br /&gt;
|-&lt;br /&gt;
|4.13.2 Industrial&lt;br /&gt;
|-&lt;br /&gt;
|4.13.3 Media Perceptions&lt;br /&gt;
|-&lt;br /&gt;
|5. Approaches&lt;br /&gt;
|-&lt;br /&gt;
|5.1 Regulation/Liability&lt;br /&gt;
|-&lt;br /&gt;
|5.2 Private Efforts/Organizations&lt;br /&gt;
|-&lt;br /&gt;
|5.3 Government Organizations&lt;br /&gt;
|-&lt;br /&gt;
|5.4 International Cooperation&lt;br /&gt;
|-&lt;br /&gt;
|5.5 International Law (including Laws of War)&lt;br /&gt;
|-&lt;br /&gt;
|5.6 Deterrence&lt;br /&gt;
|-&lt;br /&gt;
|5.7 Technology&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable datatable&amp;quot; data-type-filter=&amp;quot;{{{1}}}&amp;quot; data-category-filter=&amp;quot;{{{2}}}&amp;quot; data-search-filter=&amp;quot;{{{3}}}&amp;quot; border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;1&amp;quot; cellspacing=&amp;quot;0&amp;quot; style=&amp;quot;border: 1px solid LightGrey;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background-color:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Author/Agency&#039;&#039;&#039;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background-color:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Date&#039;&#039;&#039;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background-color:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Title&#039;&#039;&#039;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Wiki Entry&#039;&#039;&#039;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Type&#039;&#039;&#039;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#f0f0f0;&amp;quot;|&#039;&#039;&#039;Category&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| Aloise, Gene et al.||2008||[[Nuclear_Security|Nuclear Security]]||Yes||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]]&lt;br /&gt;
|-&lt;br /&gt;
| Anderson, Ross ||2001||[[Why_Information_Security_is_Hard|Why Information Security is Hard ]]||Yes||Independent Report ||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Anderson, Ross ||2006||[[The_Economics_of_Information_Security|The Economics of Information Security ]]||Yes||Journal Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Anderson, Ross J. ||2008||[[Security_Engineering|Security Engineering ]]||Yes||Book ||3.2 [[Security Targets]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Anderson, Ross, et. al ||2008||[[Security_Economics_and_the_Internal_Market|Security Economics and the Internal Market ]]||Yes||Article||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Arora et al. ||2006||[[Does_Information_Security_Attack_Frequency_Increase_With_Vulnerability_Disclosure|Does Information Security Attack Frequency Increase With Vulnerability Disclosure ]]||Yes||Journal Article ||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]]&lt;br /&gt;
|-&lt;br /&gt;
| Aviram, Amitai ||2004||[[Overcoming_Impediments_to_Information_Sharing|Overcoming Impediments to Information Sharing ]]||Yes||Journal Article ||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Barkham, Jason ||2001||[[Information_Warfare_and_International_Law_on_the_Use_of_Force|Information Warfare and International Law on the Use of Force ]]||Yes||Journal Article ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Bauer, Johannes M. and van Eeten, Michel J. G.||2009||[[Cybersecurity|Cybersecurity: Stakeholder Incentives, Externalities, and Policy Options]]||Yes||Journal Article||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Beard, Jack M. ||2009||[[Law_and_War_in_the_Virtual_Era|Law and War in the Virtual Era ]]||Yes||Journal Article ||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Bellovin, Steven M.||2009||[[The_Government_and_Cybersecurity|The Government and Cybersecurity]]||Yes||Journal Article||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;4.7[[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Besunder, Allison A.||2009||[[Best_Practices_for_Data_Protection_and_Privacy|Best Practices for Data Protection and Privacy]]||Yes||Book||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Boebert, W. Earl||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059366.pdf A Survey of Challenges in Attribution]||No||Journal Article||4.8 [[Attribution]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Bohme, Rainer ||2005||[[Cyber-Insurance_Revisited|Cyber-Insurance Revisited ]]||Yes||Independent Report ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.2.3 [[Insurance]],&amp;lt;br&amp;gt;,4.2.5 [[Market Failure]]&lt;br /&gt;
|-&lt;br /&gt;
| Bohme, Rainer ||2006||[[Models_and_Measures_for_Correlation_in_Cyber-Insurance|Models and Measures for Correlation in Cyber-Insurance ]]||Yes||Independent Report ||4.2.3 [[Insurance]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Bohme, Rainer ||2010||[[Modeling_Cyber-Insurance|Modeling Cyber-Insurance ]]||Yes||Independent Report ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.2.3 [[Insurance]],&amp;lt;br&amp;gt;,5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Booz Allen Hamilton and the Economist Intelligence Unit ||2012-01-15||[http://www.cyberhub.com/CyberPowerIndex Cyber Power Index ]||No||Industry Report||4. [[Issues]],&amp;lt;br&amp;gt;4.1 [[Metrics]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Bradley, Curtis A. and Goldsmith, Jack L.||2011||[[Overview_of_International_Law_and_Institutions|Overview of International Law and Institutions]]||Yes||Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Brown, Davis ||2006||[[A_Proposal_for_an_International_Convention_To_Regulate_the_Use_of_Information_Systems_in_Armed_Conflict|A Proposal for an International Convention To Regulate the Use of Information Systems in Armed Conflict ]]||Yes||Journal Article ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Burstein, Aaron J.||2008||[[Amending_The_ECPA_To_Enable_a_Culture_of_Cybersecurity_Research|Amending the ECPA to Enable a Culture of Cybersecurity Research]]||Yes||Journal Article||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Business Roundtable||2011-10-11||[http://businessroundtable.org/uploads/studies-reports/downloads/2011_10_Mission_Critical_A_Public-Private_Strategy_for_Effective_Cybersecurity.pdf Mission Critical: A Public-Private Strategy for Effective Cybersecurity ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| Business Software Alliance ||2012-02-02||Global Cloud Computing Scorecard a Blueprint for Economic Opportunity||No||Industry Report||3.3.3.3 [[Cloud Computing]]&lt;br /&gt;
|-&lt;br /&gt;
| Business Software Alliance, Center for Democracy &amp;amp; Technology, U.S. Chamber of Commerce, Internet Security Alliance, Tech America ||2011-03-08||[http://www.cdt.org/files/pdfs/20110308_cbyersec_paper.pdf Improving our Nation’s Cybersecurity through the Public-Private Partnership: a White Paper ]||No||Industry Report||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Cabinet Office (United Kingdom) ||2011-11-11||[http://www.cabinetoffice.gov.uk/sites/default/files/resources/uk-cyber-security-strategy-final.pdf The UK Cyber Security Strategy: Protecting and promoting the UK in a digital world ]||No||Non-U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Camp, L. Jean ||2004||[[Economics_of_Information_Security|Economics of Information Security ]]||Yes||Book ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Camp, L. Jean ||2004||[[Pricing_Security|Pricing Security ]]||Yes||Book ||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Center for a New American Security||2012-06-11||[http://www.cnas.org/node/6405 America’s Cyber Future: Security and Prosperity in the Information Age ]||No||Independent Report||1. [[Overview]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Center for Strategic and International Studies ||2008||[[Securing_Cyberspace_for_the_44th_Presidency|Securing Cyberspace for the 44th Presidency ]]||Yes||Independent Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Centre for Secure Information Technologies||2011||[http://www.csit.qub.ac.uk/sites/CSIT/InnovationatCSIT/Reports/Filetoupload,295594,en.pdf World Cybersecurity Technology Research Summit (Belfast 2011) ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| Cetron, Marvin J. and Davies, Owen||2009||[[World_War_3.0:_Ten_Critical_Trends_for_Cybersecurity|World War 3.0: Ten Critical Trends for Cybersecurity]]||Yes||Journal Article||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Clark, David and Landau, Susan||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059365.pdf Untangling Attribution]||No||Journal Article||4.8 [[Attribution]],&amp;lt;br&amp;gt;5.6 [[Deterrence]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Clarke, Richard A. ||2010||[[Cyber_War|Cyber War ]]||Yes||Book ||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Clinton, Larry ||Undated ||[[Cyber-Insurance_Metrics_and_Impact_on_Cyber-Security|Cyber-Insurance Metrics and Impact on Cyber-Security ]]||Yes||Independent Report ||4.2.3 [[Insurance]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Cloud Security Alliance ||2009-12||[http://www.cloudsecurityalliance.org/csaguide.pdf Security Guidance for Critical Areas of Focus in Cloud Computing V2.1 ]||No||Independent Report||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Cohen, Geoff||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059445.pdf Targeting Third Party Collaboration]||No||Journal Article||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| Computer Economics, Inc. ||2007||[[2007_Malware_Report|2007 Malware Report ]]||Yes||Industry Report ||4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| Computing Research Association ||2003-||[[Four_Grand_Challenges_in_Trustworthy_Computing|Four Grand Challenges in Trustworthy Computing ]]||Yes||Independent Report ||4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.9 [[Identity Management]]&lt;br /&gt;
|-&lt;br /&gt;
| Cornish, Paul||2009||[[Cyber_Security_and_Politically,_Socially_and_Religiously_Motivated_Cyber_Attacks|Cyber Security and Politically, Socially and Religiously Motivated Cyber Attacks]]||Yes||Non-U.S. Government Report||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Cornish, Paul et al.||2009||[[Cyberspace_and_the_National_Security_of_the_United_Kingdom|Cyberspace and the National Security of the United Kingdom - Threats and Responses]]||Yes||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Council on Foreign Relations ||2010-07-15||[http://i.cfr.org/content/publications/attachments/Knake%20-Testimony%20071510.pdf Untangling Attribution: Moving to Accountability in Cyberspace [Testimony]]||No||Independent Report||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;4.8 [[Attribution]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| CSIS Commission on Cybersecurity for the 44th Presidency, Center for Strategic and International Studies ||2011-01||[http://csis.org/files/publication/110128_Lewis_CybersecurityTwoYearsLater_Web.pdf Cybersecurity Two Years Later ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5. [[Approaches]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Cyber Security Forum Initiative ||2011-05-09||[http://www.unveillance.com/wp-content/uploads/2011/05/Project_Cyber_Dawn_Public.pdf Cyber Dawn: Libya ]||No||Industry Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Commerce ||2011-06-14||[http://www.nist.gov/nstic/2012-nstic-governance-recs.pdf Models for a Governance Structure for the National Strategy for Trusted Identities in Cyberspace ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Commerce ||2010||[[Defense_Industrial_Base_Assessment|Defense Industrial Base Assessment ]]||Yes||U.S. Government Report ||3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Commerce, Internet Policy Task Force||2011-06||[http://www.nist.gov/itl/upload/Cybersecurity_Green-Paper_FinalVersion.pdf Cybersecurity, Innovation and the Internet Economy]||No||U.S. Government Report||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2011-07-14||[http://www.defense.gov/news/d20110714cyber.pdf Department of Defense Strategy for Operating in Cyberspace ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2011-11-15||[http://www.defense.gov/home/features/2011/0411_cyberstrategy/docs/NDAA%20Section%20934%20Report_For%20webpage.pdf Department of Defense Cyberspace Policy Report : A Report to Congress Pursuant to the National Defense Authorization Act for Fiscal Year 2011, Section 934 ]||No||U.S. Government Report||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2012-02-16||[http://www.fas.org/sgp/othergov/dod/5200_01v1.pdf DOD Information Security Program: Overview, Classification, and Declassification ]||No||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2012-04-11||[http://www.nsci-va.org/CyberReferenceLib/2011-04-Cyber%20Ops%20Personnel.pdf Cyber Operations Personnel Report (DoD) ]||No||U.S. Government Report||&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||1999||[[An_Assessment_of_International_Legal_Issues_in_Information_Operations|An Assessment of International Legal Issues in Information Operations ]]||Yes||U.S. Government Report ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2005-||[[Strategy_for_Homeland_Defense_and_Civil_Support|Strategy for Homeland Defense and Civil Support ]]||Yes||U.S. Government Report ||3.2.4 [[Terrorists]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2007||[[Mission_Impact_of_Foreign_Influence_on_DoD_Software|Mission Impact of Foreign Influence on DoD Software ]]||Yes||U.S. Government Report ||3.2.4 [[Terrorists]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Defense ||2011-04||[http://www.nsci-va.org/CyberReferenceLib/2011-04-Cyber%20Ops%20Personnel.pdf Cyber Operations Personnel Report (DOD) ]||No||U.S. Government Report ||&lt;br /&gt;
|-&lt;br /&gt;
| Department of Energy||2012-04||[http://energy.gov/sites/prod/files/OAS-RA-12-04.pdf The Department&#039;s Management of the Smart Grid Investment Grant Program]||No||U.S. Government Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Energy (DOE) Inspector General ||2012-01-01||[http://energy.gov/ig/downloads/departments-management-smart-grid-investment-grant-program-oas-ra-12-04 The Department’s Management of the Smart Grid Investment Grant Program ]||No||U.S. Government Report ||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Energy, Idaho National Laboratory ||2010-05-01||[http://www.fas.org/sgp/eprint/nstb.pdf NSTB Assessments Summary Report: Common Industrial Control System Cyber Security Weaknesses ]||No||U.S. Government Report||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Energy, Office of Electricity Delivery &amp;amp; Energy Reliability ||Undated||[http://energy.gov/oe/technology-development/energy-delivery-systems-cybersecurity Cybersecurity for Energy Delivery Systems Program ]||No||U.S. Government Report ||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2009-09-16||[http://www.cyber.st.dhs.gov/docs/National_Cyber_Leap_Year_Summit_2009_Co-Chairs_Report.pdf National Cyber Leap Year Summit 2009: Co-Chairs&#039; Report]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.8 [[Attribution]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2007-06||[http://www.oig.dhs.gov/assets/Mgmt/OIG_07-48_Jun07.pdf Challenges Remain in Securing the Nation’s Cyber Infrastructure]||No||U.S. Government Report||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2009-11||[http://www.cyber.st.dhs.gov/docs/DHS-Cybersecurity-Roadmap.pdf A Roadmap for Cybersecurity Research]||No||U.S. Government Report||1. [[Overview]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2010-08||[http://www.dhs.gov/xoig/assets/mgmtrpts/OIG_10-111_Aug10.pdf DHS Needs to Improve the Security Posture of Its Cybersecurity Program Systems]||No||U.S. Government Report||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2010-09||[http://www.federalnewsradio.com/pdfs/NCIRP_Interim_Version_September_2010.pdf National Cyber Incident Response Plan]||No||U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security||2011-11||[http://www.dhs.gov/xlibrary/assets/nppd/blueprint-for-a-secure-cyber-future.pdf Blueprint for a Secure Cyber Future: The Cybersecurity Strategy for the Homeland Security Enterprise]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security ||2003||[[The_National_Strategy_for_the_Physical_Protection_of_Critical_Infrastructures_and_Key_Assets|The National Strategy for the Physical Protection of Critical Infrastructures and Key Assets ]]||Yes||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Homeland Security ||2009||[[A_Roadmap_for_Cybersecurity_Research|A Roadmap for Cybersecurity Research ]]||Yes||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Department of Justice||2011-04||[http://www.justice.gov/oig/reports/FBI/a1122r.pdf The Federal Bureau of Investigation&#039;s Ability to Address the National Security Cyber Intrusion Threat]||No||U.S. Government Report||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Deputy Chief of Staff for Intelligence ||2006||[[Critical_Infrastructure_Threats_and_Terrorism|Critical Infrastructure Threats and Terrorism ]]||Yes||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Dörmann, Knut ||2004||[[Applicability_of_the_Additional_Protocols_to_Computer_Network_Attacks|Applicability of the Additional Protocols to Computer Network Attacks ]]||Yes||Independent Report ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Douglas Maughan||2010||[[The_Need_for_a_National_Cybersecurity_Research_and_Development_Agenda|The Need for a National Cybersecurity Research and Development Agenda]]||Yes||Article||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Dunlap Charles J, Jr   ||2011||[[Perspectives_for_Cyber_Strategists_on_Law_for_Cyberwar|Perspectives for Cyber Strategists on Law for Cyberwar]]||Yes||Journal Article||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Dunlap, Charles J. Jr. ||2009||[[Towards_a_Cyberspace_Legal_Regime_in_the_Twenty-First_Century|Towards a Cyberspace Legal Regime in the Twenty-First Century ]]||Yes||Article||4.5 [[Psychology and Politics]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| EastWest Institute ||2011-02-03||[http://vialardi.org/nastrazzuro/pdf/US-Russia.pdf Working Towards Rules for Governing Cyber Conflict: Rendering the Geneva and Hague Conventions in Cyberspace ]||No||Independent Report||3.2.1 [[States]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Energetics Inc. ||2006||[[Roadmap_to_Secure_Control_Systems_in_the_Energy_Sector|Roadmap to Secure Control Systems in the Energy Sector ]]||Yes||Independent Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Energy Sector Control Systems Working Group||2011-09||[http://www.cyber.st.dhs.gov/wp-content/uploads/2011/09/Energy_Roadmap.pdf Roadmap to Achieve Energy Delivery Systems Cybersecurity]||No||U.S. Government Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| ENISA||2010||[[Introduction_to_Country_Reports|Introduction to Country Reports]]||Yes||Non-U.S. Government Report||3.2.1 [[States]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Epstein, Richard A. ||2008||[[Cybersecurity_in_the_Payment_Card_Industry|Cybersecurity in the Payment Card Industry ]]||Yes||Journal Article ||3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| European Network and Information Security Agency ||2010-10-07||[http://www.enisa.europa.eu/media/press-releases/stuxnet-analysis Stuxnet Analysis ]||No||Non-U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| European Network and Information Security Agency (ENISA) ||2011-04-11||[http://www.enisa.europa.eu/act/res/other-areas/inter-x/report/interx-report Resilience of the Internet Interconnection Ecosystem, at: ]||No||Non-U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Federal CIO Council ||2012-01-04||[http://www.gsa.gov/portal/category/102371 Federal Risk and Authorization Management Program (FedRAMP) ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Federal Communications Commission (FCC) ||2010-04-21||[http://hraunfoss.fcc.gov/edocs_public/attachmatch/DOC-305618A1.doc Explore the reliability and resiliency of commercial broadband communications networks ]||No||U.S. Government Report||3.3.3 [[Communications]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Federal Communications Commission (FCC) ||2011-06-03||[ftp://ftp.fcc.gov/pub/Daily_Releases/Daily_Business/2011/db0610/DOC-307454A1.txt FCC&#039;s Plan for Ensuring the Security of Telecommunications Networks ]||No||U.S. Government Report||&lt;br /&gt;
|-&lt;br /&gt;
| Financial Services Sector Coordinating Council for Critical Infrastructure Protection ||2008||[[Research_Agenda_for_the_Banking_and_Finance_Sector|Research Agenda for the Banking and Finance Sector ]]||Yes||Independent Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.1 [[Metrics]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| Fischer, Eric A.&amp;lt;br /&amp;gt;CRS||2012-04-23||[http://www.fas.org/sgp/crs/natsec/R42114.pdf Federal Laws Relating to Cybersecurity: Discussion of Proposed Revisions]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Franklin, Jason, et. al ||2007||[[An_Inquiry_into_the_Nature_and_Causes_of_the_Wealth_of_Internet_Miscreants|An Inquiry into the Nature and Causes of the Wealth of Internet Miscreants ]]||Yes||Independent Report ||3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| Gandal, Neil ||2008||[[An_Introduction_to_Key_Themes_in_the_Economics_of_Cyber_Security|An Introduction to Key Themes in the Economics of Cyber Security ]]||Yes||Book ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2003-08-27||[http://www.gao.gov/products/GAO-03-760 Efforts to Improve Information sharing Need to Be Strengthened ]||No||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2004-05-28||[http://www.gao.gov/assets/160/157541.pdf Technology Assessment: Cybersecurity for Critical Infrastructure Protection]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2008-07-31||[http://www.gao.gov/assets/280/279084.pdf Cyber Analysis And Warning: DHS Faces Challenges in Establishing a Comprehensive National Capability]||No||U.S. Government Report||5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2009-09-24||[http://www.gao.gov/new.items/d09969.pdf Critical Infrastructure Protection: Current Cyber Sector-Specific Planning Approach Needs Reassessment]||No||U.S. Government Report||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2009-11-17||[http://www.gao.gov/products/GAO-10-230t Continued Efforts Are Needed to Protect Information Systems from Evolving Threats ]||No||U.S. Government Report ||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-03-05||[http://www.gao.gov/products/GAO-10-338 Cybersecurity: Progress Made But Challenges Remain in Defining and Coordinating the Comprehensive National Initiative ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-03-16||[http://www.gao.gov/products/GAO-11-463T Cybersecurity: Continued Attention Is Needed to Protect Federal Information Systems from Evolving Threats ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-03-24||[http://www.gao.gov/products/GAO-10-536t Information Security: Concerted Response Needed to Resolve Persistent Weaknesses, at: ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-04-12||[http://www.gao.gov/products/GAO-10-237 Concerted Effort Needed to Consolidate and Secure Internet Connections at Federal Agencies ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-06-03||[http://www.gao.gov/assets/310/305208.pdf Cybersecurity: Key Challenges Need to Be Addressed to Improve Research and Development]||No||U.S. Government Report||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-06-16||[http://www.gao.gov/products/GAO-10-834t Continued Attention Is Needed to Protect Federal Information Systems from Evolving Threats ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-07-01||[http://www.gao.gov/products/GAO-10-513 Federal Guidance Needed to Address Control Issues With Implementing Cloud Computing ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-07-15||[http://www.gao.gov/products/GAO-10-628 Critical Infrastructure Protection: Key Private and Public Cyber Expectations Need to Be Consistently Addressed ]||No||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-08-02||[http://www.gao.gov/products/GAO-10-606 United States Faces Challenges in Addressing Global Cybersecurity and Governance ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-09-15||[http://www.gao.gov/products/GAO-10-916 Information Security: Progress Made on Harmonizing Policies and Guidance for National Security and Non-National Security Systems ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-09-23||[http://www.gao.gov/products/GAO-10-772 DHS Efforts to Assess and Promote Resiliency Are Evolving but Program Management Could Be Strengthened ]||No||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-10-06||[http://www.gao.gov/products/GAO-11-24 Cyberspace Policy: Executive Branch Is Making Progress Implementing 2009 Policy Review Recommendations, but Sustained Leadership Is Needed ]||No||U.S. Government Report ||5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010-11-30||[http://www.gao.gov/products/GAO-11-43 Information Security: Federal Agencies Have Taken Steps to Secure Wireless Networks, but Further Actions Can Mitigate Risk ]||No||U.S. Government Report ||3.3.3 [[Communications]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-01-12||[http://www.gao.gov/products/GAO-11-117 Electricity Grid Modernization: Progress Being Made on Cybersecurity Guidelines, but Key Challenges Remain to be Addressed ]||No||U.S. Government Report ||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-03-16||[http://www.gao.gov/products/GAO-11-463T Cybersecurity: Continued Attention Needed to Protect Our Nation&#039;s Critical Infrastructure and Federal Information Systems ]||No||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-07-08||[http://www.gao.gov/products/GAO-11-149 Information Security: State Has Taken Steps to Implement a Continuous Monitoring Application, but Key Challenges Remain ]||No||U.S. Government Report ||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-07-25||[http://www.gao.gov/products/GAO-11-75 Defense Department Cyber Efforts: DoD Faces Challenges in Its Cyber Activities ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-07-26||[http://www.gao.gov/products/GAO-11-463T Continued Attention Needed to Protect Our Nation’s Critical Infrastructure ]||No||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-07-29||[http://www.gao.gov/products/GAO-11-695R Defense Department Cyber Efforts: Definitions, Focal Point, and Methodology Needed for DoD to Develop Full-Spectrum Cyberspace Budget Estimates ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-10-03||[http://www.gao.gov/products/GAO-12-137 Information Security: Weaknesses Continue Amid New Federal Efforts to Implement Requirements ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-10-05||[http://www.gao.gov/products/GAO-12-130T Information Security: Additional Guidance Needed to Address Cloud Computing Concerns ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-10-17||[http://www.gao.gov/products/GAO-11-634 Federal Chief Information Officers: Opportunities Exist to Improve Role in Information Technology Management ]||No||U.S. Government Report ||5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-11-29||[http://www.gao.gov/products/GAO-12-8 Cybersecurity Human Capital: Initiatives Need Better Planning and Coordination, at: ]||No||U.S. Government Report ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2011-12-09||[http://www.gao.gov/products/GAO-12-92 Critical Infrastructure Protection: Cybersecurity Guidance Is Available, but More Can Be Done to Promote Its Use ]||No||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2012-01-13||[http://www.gao.gov/assets/590/587681.pdf Defense Contracting: Improved Policies and Tools Could Help Increase Competition on DOD&#039;s National Security Exception Procurements]||No||U.S. Government Report||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2012-02-28||[http://www.csit.qub.ac.uk/media/pdf/Filetoupload,252359,en.pdf Cybersecurity: Challenges to Securing the Modernized Electricity Grid ]||No||Non-U.S. Government Report ||&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2009||[[Critical_Infrastructure_Protection|Critical Infrastructure Protection - Current Cyber Sector-Specific Planning Approach Needs Reassessment]]||Yes||U.S. Government Report||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2009-07||[http://www.gao.gov/new.items/d09546.pdf Information Security: Agencies Continue to Report Progress, but Need to. Mitigate Persistent Weaknesses]||No||U.S. Government Report||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2009-09||[http://www.gao.gov/new.items/d09617.pdf Information Security: Concerted Effort Needed to Improve Federal Performance Measures]||No||U.S. Government Report||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO||2010||[[Information_Security|Information Security - Concerted Effort Needed to Consolidate and Secure Internet Connections at Federal Agencies]]||Yes||U.S. Government Report||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| GAO ||2011-10-05||[http://www.gao.gov/products/GAO-12-130T Information Security: Additional Guidance Needed to Address Cloud Computing Concerns ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Geer, Daniel E. and Conway, Daniel G.||2010||[[Nothing_Ventured,_Nothing_Gained|Nothing Ventured, Nothing Gained]]||Yes||Journal Article||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Gellman, Robert||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059444.pdf Civil Liberties and Privacy Implications of Policies to Prevent Cyberattacks ]||No||Journal Article||4.8 [[Attribution]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2010-07-15||[http://www.gao.gov/products/GAO-10-628 Critical Infrastructure Protection: Key Private and Public Cyber Expectations Need to Be Consistently Addressed ]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2011-01-12||[http://www.gao.gov/products/GAO-11-117 Electricity Grid Modernization: Progress Being Made on Cybersecurity Guidelines, but Key Challenges Remain to be Addressed ]||No||U.S. Government Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2011-03-16||[http://www.gao.gov/products/GAO-11-463T Cybersecurity: Continued Attention Needed to Protect Our Nation&#039;s Critical Infrastructure and Federal Information Systems ]||No||U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2011-07-29||[http://www.gao.gov/products/GAO-11-695R Defense Department Cyber Efforts: Definitions, Focal Point, and Methodology Needed for DOD to Develop Full-Spectrum Cyberspace Budget Estimates ]||No||U.S. Government Report ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2011-11-29||[http://www.gao.gov/products/GAO-12-8 Cybersecurity Human Capital: Initiatives Need Better Planning and Coordination ]||No||U.S. Government Report||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| General Accountability Office (GAO) ||2011-12-09||[http://www.gao.gov/products/GAO-12-92 Critical Infrastructure Protection: Cybersecurity Guidance Is Available, but More Can Be Done to Promote Its Use ]||No||U.S. Government Report ||&lt;br /&gt;
|-&lt;br /&gt;
| General Services Administration (GSA) ||2012-02-07||[http://www.gsa.gov/graphics/staffoffices/FedRAMP_CONOPS.pdf Concept of Operations: FedRAMP ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Grady, Mark F. ||2006||[[The_Law_and_Economics_of_Cybersecurity|The Law and Economics of Cybersecurity ]]||Yes||Book ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Graham David E   ||2010||[[Cyber_Threats_and_the_Law_of_War| Cyber Threats and the Law of War]]||Yes||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Granick, Jennifer Stisa ||2005||[[The_Price_of_Restricting_Vulnerability_Publications|The Price of Restricting Vulnerability Publications ]]||Yes||Journal Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Hollis, Duncan B. ||2007||[[Why_States_Need_an_International_Law_for_Information_Operations|Why States Need an International Law for Information Operations ]]||Yes||Journal Article ||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;4.13.1 [[Government to Government|Government to Government Espionage]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| HP TippingPoint DVLabs ||2010||[[2010_Top_Cyber_Security_Risks_Report|2010 Top Cyber Security Risks Report ]]||Yes||Industry report ||4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| IEEE/EastWest Institute ||2010-05-26||[http://www.ieee-rogucci.org/files/The%20ROGUCCI%20Report.pdf The Reliability of Global Undersea Communications Cable Infrastructure (The Rogucci Report) ]||No||Independent Report||3.3.3 [[Communications]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Institute for Information Infrastructure Protection ||2003||[[Cyber_Security_Research_and_Development_Agenda|Cyber Security Research and Development Agenda ]]||Yes||Independent Report ||4.1 [[Metrics]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Institute for Science and International Security ||2010-12-22||[http://isis-online.org/isis-reports/detail/did-stuxnet-take-out-1000-centrifuges-at-the-natanz-enrichment-plant/ Did Stuxnet Take Out 1,000 Centrifuges at the Natanz Enrichment Plant? Preliminary Assessment ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| International Instrument Users Association (WIB) ||2010-11-10||[http://www.isssource.com/wib/ WIB Security Standard Released ]||No||Industry Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| International Telecommunications Union ||2012-02-10||[http://www.itu.int/ITU-D/cyb/cybersecurity/docs/itu-toolkit-cybercrime-legislation.pdf ITU Toolkit for Cybercrime Legislation ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| James Clapper, Director of National Intelligence ||2011-02-10||[http://www.dni.gov/testimonies/20110210_testimony_clapper.pdf Worldwide Threat Assessment of the U.S. Intelligence Community (Testimony) ]||No||U.S. Government Report||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.2 [[Actors and Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Johnson, Eric M. ||2008||[[Managing_Information_Risk_and_the_Economics_of_Security|Managing Information Risk and the Economics of Security ]]||Yes||Book ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Johnson, Vincent R. ||2005||[[Cybersecurity,_Identity_Theft,_and_the_Limits_of_Tort_Liability|Cybersecurity, Identity Theft, and the Limits of Tort Liability ]]||Yes||Journal Article ||4.9 [[Identity Management]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Joint Workshop of the National Security Threats in Cyberspace and the National Strategy Forum ||2009-09-15||[http://nationalstrategy.com/Portals/0/National%20Security%20Threats%20in%20Cyberspace%20FINAL%2009-15-09.pdf National Security Threats in Cyberspace ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| Joseph S. Nye||2010||[[Cyber_Power|Cyber Power]]||Yes||Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Journal of Strategic Studies ||2011-10-05||[http://www.tandfonline.com/doi/abs/10.1080/01402390.2011.6089393 Cyber War Will Not Take Place ]||No||Journal Article||&lt;br /&gt;
|-&lt;br /&gt;
| Kelly A. Gable||2010||[[Cyber-Apocalypse_Now|Cyber-Apocalypse Now - Securing the Internet Against Cyberterrorism and Using Universal Jurisdiction as a Deterrent]]||Yes||Journal Article||3.2.4 [[Terrorists]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Kerr, Paul K. et al.&amp;lt;br /&amp;gt;CRS||2010-12-09||[http://www.fas.org/sgp/crs/natsec/R41524.pdf The Stuxnet Computer Worm: Harbinger of an Emerging Warfare Capability]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.4 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Kesan, Jay P. and Hayes, Carol M.||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059446.pdf Thinking Through Active Defense in Cyberspace ]||No||Journal Article||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Kobayashi, Bruce H.||2005||[[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_other_Public_Security_Goods|An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and other Public Security Goods]]||Yes||Journal Article||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Kobayashi, Bruce H. ||2006||[[An_Economic_Analysis_of_the_Private_and_Social_Costs_of_the_Provision_of_Cybersecurity_and_Other_Public_Security_Goods|An Economic Analysis of the Private and Social Costs of the Provision of Cybersecurity and Other Public Security Goods ]]||Yes||Journal Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Korns, Stephen W. ||2009||[[Cyber_Operations|Cyber Operations ]]||Yes||Journal Article ||4.8 [[Attribution]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Kramer, Franklin D., et. al ||2009||[[Cyberpower_and_National_Security|Cyberpower and National Security ]]||Yes||Book ||1. [[Overview]]&lt;br /&gt;
|-&lt;br /&gt;
| Kundra, Vivek||2010-12-09||[http://www.cio.gov/documents/25-point-implementation-plan-to-reform-federal%20it.pdf 25 Point Implementation Plan to Reform Federal Information Technology Management]||No||U.S. Government Report||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Kundra, Vivek||2011-02-08||[http://www.cio.gov/documents/federal-cloud-computing-strategy.pdf Federal Cloud Computing Strategy]||No||U.S. Government Report||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Lan, Tang et al.||2010||[[Global_Cyber_Deterrence|Global Cyber Deterrence: Views from China, the U.S., Russia, India, and Norway]]||Yes||Independent Report||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Lernard, Thomas M. ||2005||[[An_Economic_Analysis_of_Notification_Requirements_for_Data_Security_Breaches|An Economic Analysis of Notification Requirements for Data Security Breaches ]]||Yes||Independent Report ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Lernard, Thomas M. ||2006||[[Much_Ado_About_Notification|Much Ado About Notification ]]||Yes||Journal Article ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Lewis, James Andrews||2005||[[Cyber_Security_and_Regulation_in_the_United_States|Aux armes, citoyens: Cyber Security and Regulation in the United States]]||Yes||Journal Article||3.3.1 [[Public Critical Infrastructure,&amp;lt;br&amp;gt;3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;3.3.2.3 [[Transportation]]&lt;br /&gt;
|-&lt;br /&gt;
| Libicki, Martin||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059490.pdf Pulling Punches in Cyberspace]||No||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Lukasik, Stephen J.||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059438.pdf A Framework for Thinking about Cyber Conflict and Cyber Deterrence with Possible Declatory Policies for these Domain]||No||Journal Article||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Massachusetts Institute of Technology (MIT) ||2011-12-05||[http://web.mit.edu/mitei/research/studies/the-electric-grid-2011.shtml The Future of the Electric Grid ]||No||Independent Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| McAfee ||2011-08-02||[http://www.mcafee.com/us/resources/white-papers/wp-operation-shady-rat.pdf Revealed: Operation Shady RAT: an Investigation Of Targeted Intrusions Into 70+ Global Companies, Governments, and Non-Profit Organizations During the Last 5 Years ]||No||Industry Report||3.2.1 [[States]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.13 [[Espionage]]&lt;br /&gt;
|-&lt;br /&gt;
| McAfee ||2012-02-01||[http://www.mcafee.com/us/resources/reports/rp-sda-cyber-security.pdf?cid=WBB048 Cyber-security: The Vexed Question of Global Rules: An Independent Report on Cyber-Preparedness Around the World ]||No||Industry Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| McAfee and Center for Strategic and International Studies (CSIS) ||2011-04-21||[http://www.mcafee.com/us/resources/reports/rp-critical-infrastructure-protection.pdf In the Dark: Crucial Industries Confront Cyberattacks ]||No||Industry Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt; 4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| McAfee and the Security Defense Agenda||2012-02-12||[http://www.mcafee.com/us/resources/reports/rp-sda-cyber-security.pdf Cyber-security: The Vexed Question of Global Rules: An Independent Report on Cyber-Preparedness Around the World]||No||Industry Report||1. [[Overview]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| McAfee, Inc. ||2010||[[McAfee_Threats_Report|McAfee Threats Report ]]||Yes||Industry Report ||3.2.3 [[Hacktivists]],&amp;lt;br&amp;gt;3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| McDermott, Rose||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059442.pdf Decision Making Under Uncertainty]||No||Journal Article||4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;4.5 [[Psychology and Politics]],&amp;lt;br&amp;gt;4.8 [[Attribution]]&lt;br /&gt;
|-&lt;br /&gt;
| Microsoft||2010-11||[http://cdn.globalfoundationservices.com/documents/InformationSecurityMangSysforMSCloudInfrastructure.pdf Information Security Management System for Microsoft Cloud Infrastructure ]||No||Industry Report||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Mitre Corp (JASON Program Office) ||2010-11||[http://www.fas.org/irp/agency/dod/jason/cyber.pdf Science of Cyber-Security ]||No||Independent Report||1. [[Overview]],&amp;lt;br&amp;gt;4. [[Issues]]&lt;br /&gt;
|-&lt;br /&gt;
| Moore, Tyler||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059364.pdf Introducing the Economics of Cybersecurity: Principles and Policy Options]||No||Journal Article||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Moore, Tyler ||2007||[[Examining_the_Impact_of_Website_Take-down_on_Phishing|Examining the Impact of Website Take-down on Phishing ]]||Yes||Independent Report ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Moore, Tyler ||2008||[[The_Consequence_of_Non-Cooperation_in_the_Fight_Against_Phishing|The Consequence of Non-Cooperation in the Fight Against Phishing ]]||Yes||Independent Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]]&lt;br /&gt;
|-&lt;br /&gt;
| Moore, Tyler ||2009||[[The_Impact_of_Incentives_on_Notice_and_Take-down|The Impact of Incentives on Notice and Take-down ]]||Yes||Book ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Moore, Tyler, et. al ||2009||[[The_Economics_of_Online_Crime|The Economics of Online Crime ]]||Yes||Journal Article ||3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| Morgan, Patrick M. ||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059436.pdf Applicability of Traditional Deterrence Concepts and Theory to the Cyber Realm ]||No||Journal Article||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]],&amp;lt;br&amp;gt;5.6 [[Deterrence ]]&lt;br /&gt;
|-&lt;br /&gt;
| National Association of Secretaries of State ||2012-01-12||[http://www.nass.org/index.php?option=com_docman&amp;amp;task=doc_download&amp;amp;gid=1257 Developing State Solutions to Business Identity Theft: Assistance, Prevention and Detection Efforts by Secretary of State Offices ]||No||Independent Report||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Cyber Defense Initiative ||2009||[[National_Cyber_Defense_Financial_Services_Workshop_Report|National Cyber Defense Financial Services Workshop Report ]]||Yes||Independent Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Cyber Security Alliance and Microsoft ||2011-05-13||[http://www.staysafeonline.org/sites/default/files/resource_documents/2011%20National%20K-12%20Study%20Final_0.pdf 2011 State of Cyberethics, Cybersafety and Cybersecurity Curriculum in the U.S. Survey ]||No||Industry Report||4.4 [[Usability/Human Factors]]&lt;br /&gt;
|-&lt;br /&gt;
| National Cyber Security Summit Task Force ||2004||[[Information_Security_Governance|Information Security Governance ]]||Yes||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]],&amp;lt;br&amp;gt;5.3 [[government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Infrastructure Advisory Council ||2004||[[Hardening_The_Internet|Hardening The Internet ]]||Yes||U.S. Government Report ||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Initiative for Cybersecurity Education||2011-08-11||[http://csrc.nist.gov/nice/documents/nicestratplan/Draft_NICE-Strategic-Plan_Aug2011.pdf National Initiative for Cybersecurity Education Strategic Plan: Building a Digital Nation]||No||U.S. Government Report||1. [[Overview]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Initiative for Cybersecurity Education (NICE) ||2011-11-21||[http://csrc.nist.gov/nice/framework/documents/NICE-Cybersecurity-Workforce-Framework-printable.pdf NICE Cybersecurity Workforce Framework ]||No||U.S. Government Report||4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Institute of Standards and Technology ||2006||[[SP_800-82:_Guide_to_Supervisory_Control_and_Data_Acquisition_(SCADA)_and_Industrial_Control_Systems_Security|SP 800-82: Guide to Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems Security ]]||Yes||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Institute of Standards and Technology (NIST) ||2010-09-02||[http://www.nist.gov/public_affairs/releases/nist-finalizes-initial-set-of-smart-grid-cyber-security-guidelines.cfm NIST Finalizes Initial Set of Smart Grid Cyber Security Guidelines ]||No||U.S. Government Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council ||2009||[http://www.nap.edu/catalog.php?record_id=12651 Technology, Policy, Law, and Ethics Regarding U.S. Acquisition and Use of Cyberattack Capabilities]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council ||2010-09-21||[http://www.nap.edu/catalog.php?record_id=12998 Toward Better Usability, Security, and Privacy of Information Technology: Report of a Workshop ]||No||Independent Report||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;4.10 [[Privacy]]&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council ||2010-10-05||[http://www.nap.edu/catalog.php?record_id=12997#description Proceedings of a Workshop on Deterring Cyberattacks: Informing Strategies and Developing Options for U.S. Policy ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council ||1999||[[Trust_in_Cyberspace|Trust in Cyberspace ]]||Yes||Independent Report ||3.3.3.2 [[Public Data Networks]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council ||2007||[[Toward_a_Safer_and_More_Secure_Cyberspace|Toward a Safer and More Secure Cyberspace ]]||Yes||Independent Report ||1. [[Overview]],&amp;lt;br&amp;gt;4.8 [[Attribution]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| National Research Council, Committee for Advancing Software-Intensive Systems Producibility ||2010-10-20||[http://www.nap.edu/catalog.php?record_id=12979 Critical Code: Software Producibility for Defense ]||No||Independent Reprot ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| National Science and Technology Council ||2006||[[Federal_Plan_for_Cyber_Security_and_Information_Assurance_Research_and_Development|Federal Plan for Cyber Security and Information Assurance Research and Development ]]||Yes||U.S. Government Report ||4.1 [[Metrics]],&amp;lt;br&amp;gt;4.7 [[Attribution]],&amp;lt;br&amp;gt;4.8 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| National Science Foundation||2011-08-11||[http://www.livescience.com/15423-forefront-cyber-security-research-nsf-bts.html At the Forefront of Cyber Security Research ]||No||U.S. Government Report||5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| National Science Foundation||2012-01-17||[http://www.nsf.gov/awardsearch/showAward.do?AwardNumber=1127185 Information Security Risk Taking ]||No||U.S. Government Report||4.1 [[Metrics]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| National Security Cyberspace Institute||2012-07-11||[http://www.nsci-va.org/WhitePapers/2011-07-22-Cyber Analogies Whitepaper-K McKee.pdf A Review of Frequently Used Cyber Analogies ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| National Security Initiative ||2010-10-18||[http://www.americansecuritychallenge.com/ American Security Challenge ]||No||Independent Report||&lt;br /&gt;
|-&lt;br /&gt;
| Networking and Information Technology Research and Development ||2009||[[National_Cyber_Leap_Year_Summit_2009,_Co-Chairs%27_Report|National Cyber Leap Year Summit 2009, Co-Chairs&#039; Report ]]||Yes||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| NIST ||2011-09-01||[http://www.nist.gov/customcf/get_pdf.cfm?pub_id=909505 Cloud Computing Reference Architecture ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]]&lt;br /&gt;
|-&lt;br /&gt;
| NIST ||2011-12-01||[http://www.nist.gov/itl/cloud/upload/SP_500_293_volumeII.pdf U.S. Government Cloud Computing Technology Roadmap, Release 1.0 (Draft), Volume II Useful Information for Cloud Adopters ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| NIST ||2012-02-17||[http://www.nist.gov/nstic/2012-nstic-governance-recs.pdf Recommendations for Establishing an Identity Ecosystem Governance Structure for the National Strategy for Trusted Identities in Cyberspace ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Nojeim, Gregory T.||2009||[[Cybersecurity:_Preventing_Terrorist_Attacks_and_Protecting_Privacy_in_Cyberspace|Cybersecurity: Preventing Terrorist Attacks and Protecting Privacy in Cyberspace]]||Yes||U.S. Government Hearing||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| North American Electric Reliability Corp. (NERC) ||2011-01-26||[http://www.wired.com/images_blogs/threatlevel/2011/02/DoE-IG-Report-on-Grid-Security.pdf Federal Energy Regulatory Commission&#039;s Monitoring of Power Grid Cyber Security ]||No||U.S. Government Report||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| NSTC||2011-12||[http://www.whitehouse.gov/sites/default/files/microsites/ostp/fed_cybersecurity_rd_strategic_plan_2011.pdf Trustworthy Cyberspace: Strategic Plan for the Federal Cybersecurity Research and Development Program]||No||U.S. Government Report||5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Nye, Joseph ||2010||[[Cyber_Power|Cyber Power ]]||Yes||Book ||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;4.13 [[Espionage]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| OECD||2009||[[Cybersecurity_and_Economic_Incentives|Cybersecurity and Economic Incentives]]||Yes||Non-U.S. Government Report||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| OECD||2009||[[The_Market_Consequences_of_Cybersecurity|The Market Consequences of Cybersecurity]]||Yes||Non-U.S. Government Report||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Office of the National Counterintelligence Executive ||2011-11-03||[http://www.ncix.gov/publications/reports/fecie_all/Foreign_Economic_Collection_2011.pdf Foreign Spies Stealing US Economic Secrets in Cyberspace ]||No||U.S. Government Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;4.13 [[Espionage]]&lt;br /&gt;
|-&lt;br /&gt;
| Organisation for Economic Co-operation and Development (OECD) ||2010-11-12||[http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.165.2211&amp;amp;rep=rep1&amp;amp;type=pdf The Role of Internet Service Providers in Botnet Mitigation: an Empirical Analysis Bases on Spam Data ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Organization for Economic Co-operation and Development (OECD) ||2012-01-10||[http://www.oecd-ilibrary.org/docserver/download/fulltext/5k9h2q8v9bln.pdf?expires=1330527950&amp;amp;id=id&amp;amp;accname=guest&amp;amp;checksum=F4470043AC638BE19D5131C3D5CE5EA4 ICT Applications for the Smart Grid: Opportunities and Policy Implications ]||No||Independent Report ||&lt;br /&gt;
|-&lt;br /&gt;
| PCAST||2010-12||[http://www.whitehouse.gov/sites/default/files/microsites/ostp/pcast-nitrd-report-2010.pdf Designing a Digital Future: Federally Funded Research and Development in Networking and Information Technology]||No||U.S. Government Report||4.3 [[Supply Chain Issues]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| PCAST||2011-06||[http://www.whitehouse.gov/sites/default/files/microsites/ostp/pcast-advanced-manufacturing-june2011.pdf Report to the President on Ensuring American Leadership in Advanced Manufacturing]||No||U.S. Government Report||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Perkins, Earl||2009||[[Evolving_Cybersecurity_Issues_in_the_Utility_Industry|Evolving Cybersecurity Issues in the Utility Industry]]||Yes||Independent Report||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.2.4 [[Water, Sewer, etc.]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Pew Research Center’s Internet &amp;amp; American Life Project ||2010-06-11||[http://pewinternet.org/Reports/2010/The-future-of-cloud-computing.aspx The future of cloud computing ]||No||Independent Report||3.3.3.3 [[Cloud Computing]]&lt;br /&gt;
|-&lt;br /&gt;
| Powell, Benjamin ||2005||[[Is_Cybersecurity_a_Public_Good|Is Cybersecurity a Public Good ]]||Yes||Journal Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.5 [[Market Failure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| President&#039;s Commission on Critical Infrastructure Protection ||1997||[[Critical_Foundations|Critical Foundations ]]||Yes||U.S. Government Report ||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.3 [[Communications]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| President&#039;s Information Technology Advisory Council ||2005||[[Cyber_Security:_A_Crisis_of_Prioritization|Cyber Security: A Crisis of Prioritization ]]||Yes||U.S. Government Report ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Project on National Security Reform (PNSR) ||2010-11||[http://www.pnsr.org/data/images/pnsr_the_power_of_people_report.pdf The Power of People: Building an Integrated National Security Professional System for the 21st Century ]||No||U.S. Government Report||4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Quadrennial Defense Review ||2010-07-30||[http://www.usip.org/quadrennial-defense-review-independent-panel-/view-the-report The QDR in Perspective: Meeting AmericaÅfs National Security Needs In the 21st Century (QDR Final Report) ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| RAND||2011-12-21||[http://www.rand.org/content/dam/rand/pubs/occasional_papers/2011/RAND_OP342.pdf A Cyberworm that Knows No Boundaries ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Rattray, Gregory and Healey, Jason||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059437.pdf Categorizing and Understanding Offensive Cyber Capabilities and Their Use ]||No||Journal Article||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Rollins, John and Wilson, Clay||2007||[[Terrorist_Capabilities_for_Cyberattack|Terrorist Capabilities for Cyberattack]]||Yes||U.S. Government Report||3.2.4 [[Terrorists]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| Romanosky et al. ||2008||[[Do_Data_Breach_Disclosure_Laws_Reduce_Identity_Theft|Do Data Breach Disclosure Laws Reduce Identity Theft ]]||Yes||Independent Report ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Rosenzweig, Paul||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059443.pdf The Organization of the United States Government and Private Sector for Achieving Cyber Deterrence ]||No||Journal Article||4.3 [[Supply Chain Issues]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Rotenberg et. al. ||2010||[[The_Cyber_War_Threat_Has_Been_Grossly_Exaggerated|The Cyber War Threat Has Been Grossly Exaggerated ]]||Yes||Article||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Rue, Rachel and Pfleeger, Shari Lawrence||2009||[[Making_the_Best_Use_of_Cybersecurity_Economic_Models|Making the Best Use of Cybersecurity Economic Models]]||Yes||Journal Article||4.1 [[Metrics]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| Santos, Joost R., et. al||2007||[[A_Framework_for_Linking_Cybersecurity_Metrics_to_the_Modeling_of_Macroeconomic_Interdependencies|A Framework for Linking Cybersecurity Metrics to the Modeling of Macroeconomic Interdependencies]]||Yes||Journal Article||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;4.1 [[Metrics]]&lt;br /&gt;
|-&lt;br /&gt;
| Schmitt Michael N   ||2002||[[Wired_Warfare| Wired warfare: Computer network attack and jus in bello]]||Yes||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Schmitt Michael N   ||2004||[[Direct_Participation_in_Hostilities|Direct Participation in Hostilities and 21st Century Armed Conflict]]||Yes||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Schmitt, Michael N. ||1999||[[Computer_Network_Attack_and_the_Use_of_Force_in_International_Law|Computer Network Attack and the Use of Force in International Law ]]||Yes||Journal Article ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Schmitt, Michael N. ||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059439.pdf Cyber Operations in International Law: The Use of Force, Collective Security, Self-Defense, and Armed Conflicts]||No||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Schmitt, Michael N., et. al ||2004||[[Computers_and_War|Computers and War ]]||Yes||Independent Report ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Schneidewind, Norman||2010||[[Metrics_for_Mitigating_Cybersecurity_Threats_to_Networks|Metrics for Mitigating Cybersecurity Threats to Networks]]||Yes||Journal Article||4.1 [[Metrics]]&lt;br /&gt;
|-&lt;br /&gt;
| Schneier, Bruce ||2003||[[Beyond_Fear|Beyond Fear ]]||Yes||Book ||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;4.5 [[Psychology and Politics]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Schneier, Bruce ||2008||[[Schneier_on_Security|Schneier on Security ]]||Yes||Book ||3.2 [[Actors and Incentives]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Schwartz, Paul ||2007||[[Notification_of_Data_Security_Breaches|Notification of Data Security Breaches ]]||Yes||Journal Article ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Secretary of the Air Force ||2011-07-27||[http://www.e-publishing.af.mil/shared/media/epubs/AFI51-402.pdf Legal Reviews of Weapons and Cyber Capabilities ]||No||U.S. Government Report ||4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Shackelford, Scott J.||2010||[[Estonia_Three_Years_Later|Estonia Three Years Later]]||Yes||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Shah, Shashi K.||2004||[[The_Evolving_Landscape_of_Maritime_Cybersecurity|The Evolving Landscape of Maritime Cybersecurity]]||Yes||Journal Article||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.2.3 [[Transportation]]&lt;br /&gt;
|-&lt;br /&gt;
| Sklerov, Matthew J. ||2009||[[Solving_the_Dilemma_of_State_Responses_to_Cyberattacks|Solving the Dilemma of State Responses to Cyberattacks ]]||Yes||Journal Article ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.8 [[Attribution]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Sofaer, Abraham; Clark, David; and Diffie, Whitfield||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059440.pdf Cyber Security and International Cooperation ]||No||Journal Article||5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Software and Information Industry Association (SAII) ||2011-07-26||[http://www.siia.net/index.php?option=com_docman&amp;amp;task=doc_download&amp;amp;gid=3040&amp;amp;Itemid=318 Guide to Cloud Computing for Policy Makers ]||No||Independent Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Stohl, Michael ||2006||[[Cyber_Terrorism|Cyber Terrorism ]]||Yes||Journal Article ||3.2.3 [[Hacktivists]],&amp;lt;br&amp;gt;3.2.4 [[Terrorists]],&amp;lt;br&amp;gt;4.5 [[Psychology and Politics]]&lt;br /&gt;
|-&lt;br /&gt;
| Stuart Madnick et al.||2009||[[Experiences_and_Challenges_with_Using_CERT_Data_to_Analyze_International_Cyber_Security|Experiences and Challenges with Using CERT Data to Analyze International Cyber Security]]||Yes||Journal Article||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| Swire, Peter P. ||2004||[[A_Model_for_When_Disclosure_Helps_Security|A Model for When Disclosure Helps Security ]]||Yes||Journal Article ||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Swire, Peter P. ||2006||[[A_Theory_of_Disclosure_for_Security_and_Competitive_Reasons|A Theory of Disclosure for Security and Competitive Reasons ]]||Yes||Journal Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Symantec||2011-10-24||[http://www.symantec.com/connect/w32_duqu_precursor_next_stuxnet W32.Duqu: The Precursor to the Next Stuxnet ]||No||Industry Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Symantec Corporation ||2010||[[Symantec_Global_Internet_Security_Threat_Report|Symantec Global Internet Security Threat Report ]]||Yes||Industry Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| Telang, Rahul ||2007||[[Impact_of_Software_Vulnerability_Announcements_on_the_Market_Value_of_Software_Vendors|Impact of Software Vulnerability Announcements on the Market Value of Software Vendors ]]||Yes||Journal Article ||4.1 [[Metrics]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]]&lt;br /&gt;
|-&lt;br /&gt;
| Theohary, Catherine A. and Rollins, John||2010||[[Cybersecurity:_Current_Legislation,_Executive_Branch_Initiatives,_and_Options_for_Congress|Cybersecurity: Current Legislation, Executive Branch Initiatives, and Options for Congress]]||Yes||U.S. Government Report||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Thom, Maxie    ||2006||[[Information_Warfare_Arms_Control| Information Warfare Arms Control: Risks and Costs]]||Yes||Journal Article||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| Thomas, Rob ||2006||[[The_Underground_Economy|The Underground Economy ]]||Yes||Journal Article ||3.2.5 [[Criminals and Criminal Organizations]],&amp;lt;br&amp;gt;3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| Threat Level Blog (Wired) ||2010-12-27||[http://www.wired.com/threatlevel/2010/12/a-four-day-dive-into-stuxnets-heart/ A Four-Day Dive Into Stuxnet’s Heart ]||No||Independent Report||3. [[Threats and Actors]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Todd, Graham H. ||2009||[[Armed_Attack_in_Cyberspace|Armed Attack in Cyberspace ]]||Yes||Journal Article ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.8 [[Attribution]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| Trend Micro Incorporated ||2010||[[Trend_Micro_Annual_Report|Trend Micro Annual Report ]]||Yes||Industry Report ||4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Air Force ||2010-07-15||[http://www.e-publishing.af.mil/shared/media/epubs/afdd3-12.pdf Cyberspace Operations: Air Force Doctrine Document 3-12 ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Army War College ||2011-05-09||[http://www.strategicstudiesinstitute.army.mil/pubs/display.cfm?pubid=10670 Cyber Infrastructure Protection ]||No||U.S. Government Report||&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Army War College, Strategy Research Project ||2011-03-24||[http://www.dtic.mil/dtic/tr/fulltext/u2/a552990.pdf China’s Cyber Power and America’s National Security ]||No||U.S. Government Report||3.2.1 [[States]],&amp;lt;br&amp;gt;4.13 [[Espionage]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Department of Energy, Infrastructure Security and Energy Restoration ||2007-01-01||[http://www.oe.netl.doe.gov/docs/prepare/21stepsbooklet.pdf 21 Steps to Improve Cyber Security of SCADA Networks ]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Deputy Secretary of Defense, William J. Lynn (Foreign Affairs) ||2010-009||[http://www.foreignaffairs.com/articles/66552/william-j-lynn-iii/defending-a-new-domain Defending a New Domain ]||No||U.S. Government Report ||&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Appropriations (closed/classified) (Subcommittee on Energy and Power)||2011-03-31||[http://www.dhs.gov/ynews/testimony/testimony_1301595025263.shtm Budget Hearing - National Protection and Programs Directorate, Cybersecurity and Infrastructure Protection Programs  ]||No||U.S. Government Hearing||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2011-02-11||[http://armedservices.house.gov/index.cfm/hearings-display?ContentRecord_id=90d8a16a-23b7-4b9c-a732-cb10ab20e579&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=64562e79-731a-4ac6-aab0-7bd8d1b7e890&amp;amp;MonthDisplay=2&amp;amp;YearDisplay=2011 What Should the Department of Defense’s Role in Cyber Be?]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2011-03-16||[http://armedservices.house.gov/index.cfm/hearings-display?ContentRecord_id=79ce7b4c-f88b-40bf-9540-efdb3a2d26b2&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=64562e79-731a-4ac6-aab0-7bd8d1b7e890&amp;amp;MonthDisplay=3&amp;amp;YearDisplay=2011 2012 Budget Request from U.S. Cyber Command]||No||U.S. Government Hearing||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2011-11-03||[http://armedservices.house.gov/index.cfm/hearings-display?ContentRecord_id=42c170fb-8e0c-453a-81a2-f4ee3fa89283&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=64562e79-731a-4ac6-aab0-7bd8d1b7e890&amp;amp;MonthDisplay=11&amp;amp;YearDisplay=2011 Institutionalizing Irregular Warfare Capabilities]||No||U.S. Government Hearing||4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2012-03-20||[http://armedservices.house.gov/index.cfm/hearings-display?ContentRecord_id=92823c77-38f0-4c20-a3ee-36729e8e19a3&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=64562e79-731a-4ac6-aab0-7bd8d1b7e890&amp;amp;MonthDisplay=3&amp;amp;YearDisplay=2012 Fiscal 2013 Defense Authorization: IT and Cyber Operations]||No||U.S. Government Hearing||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce||2011-05-31||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=8639 Protecting the Electric Grid: the Grid Reliability and Infrastructure Defense Act]||No||U.S. Government Hearing||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Commerce, Manufacturing, and Trade)||2011-06-02||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=8653 Sony and Epsilon: Lessons for Data Security Legislation]||No||U.S. Government Hearing||4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Commerce,Trade and Manufacturing)||2011-06-15||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=8693 Discussion Draft of H.R. ___, a bill to require greater protection for sensitive consumer data and timely notification in case of breach]||No||U.S. Government Hearing||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Communications and Technology)||2012-03-07||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=9342 Cybersecurity:Networks     The Pivotal Role of Communications]||No||U.S. Government Hearing||3.3.3 [[Communications]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Communications and Technology)||2012-03-28||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=9397 Cybersecurity:Threats to Communications Networks and Public-Sector Responses]||No||U.S. Government Hearing||3.3.3 [[Communications]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Oversight and Investigations)||2011-07-26||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=8824 Cybersecurity: Infrastructure An Overview of Risks to Critical]||No||U.S. Government Hearing||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Oversight and Investigations)||2012-02-28||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=9318 Critical Infrastructure Cybersecurity: Assessments of Smart Grid Security]||No||U.S. Government Hearing||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Energy and Commerce (Subcommittee on Oversight and Investigations)||2012-03-27||[http://energycommerce.house.gov/hearings/hearingdetail.aspx?NewsID=9393 IT Supply Chain Security: Review of Government and Industry Efforts]||No||U.S. Government Hearing||4.3 [[Supply Chain Issues]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Financial Services (field hearing in Hoover, AL)||2011-06-29||[http://financialservices.house.gov/Calendar/EventSingle.aspx?EventID=246611 Field Hearing: Hacked Off: Helping Law Enforcement Protect Private Financial Information]||No||U.S. Government Hearing||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Financial Services (Subcommittee on Financial Institutions and Consumer Credit)||2011-09-14||[http://financialservices.house.gov/Calendar/EventSingle.aspx?EventID=258792 Combating Cybercriminals]||No||U.S. Government Hearing||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;5.7 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Foreign Affairs (Subcommittee on Oversight and Investigations)||2011-04-15||[http://foreignaffairs.house.gov/hearing_notice.asp?id=1279 Communist Chinese Cyber-Attacks, Cyber-Espionage and Theft of American Technology]||No||U.S. Government Hearing||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;4.13 [[Espionage]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies and Counterterrorism and Intelligence)||2012-04-19||[http://homeland.house.gov/hearing/subcommittee-hearing-dhs-and-doe-national-labs-finding-efficiencies-and-optimizing-outputs The DHS and DOE National Labs: Finding Efficiencies and Optimizing Outputs in Homeland Security Research and Development]||No||U.S. Government Hearing||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies and Counterterrorism and Intelligence)||2012-04-26||[http://homeland.house.gov/hearing/joint-subcommittee-hearing-iranian-cyber-threat-us-homeland Iranian Cyber Threat to U.S. Homeland]||No||U.S. Government Hearing||3.2.1 [[States]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2011-02-11||[http://homeland.house.gov/hearing/subcommittee-hearing-%E2%80%9Cpreventing-chemical-terrorism-building-foundation-security-our-nation Preventing Chemical Terrorism: Building a Foundation of Security at Our Nation’s Chemical Facilities]||No||U.S. Government Hearing||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2011-03-16||[http://homeland.house.gov/hearing/subcommittee-hearing-examining-cyber-threat-critical-infrastructure-and-american-economy Examining the Cyber Threat to Critical Infrastructure and the American Economy]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2011-04-15||[http://homeland.house.gov/hearing/subcommittee-hearing-%E2%80%9C-dhs-cybersecurity-mission-promoting-innovation-and-securing-critical DHS Cybersecurity Mission: Promoting Innovation and Securing Critical Infrastructure]||No||U.S. Government Hearing||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2011-06-24||[http://homeland.house.gov/hearing/subcommittee-hearing-examining-homeland-security-impact-obamaadministrations-cybersecurity Examining the Homeland Security Impact of the Obama Administration’s Cybersecurity Proposal]||No||U.S. Government Hearing||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2011-12-06||[http://homeland.house.gov/hearing/subcommittee-hearing-hearing-draft-legislative-proposal-cybersecurity Hearing on Draft Legislative Proposal on Cybersecurity]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technologies)||2012-02-01||[http://homeland.house.gov/markup/subcommittee-markup-hr-3674 Consideration and Markup of H.R. 3674]||No||U.S. Government Hearing||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection and Security Technology)||2011-10-06||[http://homeland.house.gov/hearing/cloud-computing-what-are-security-implications Cloud Computing: What are the Security Implications?]||No||U.S. Government Hearing||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;4.13 [[Espionage]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Cybersecurity, Infrastructure Protection, and Security Technologies)||2011-05-26||[http://homeland.house.gov/hearing/subcommittee-hearing-%E2%80%9Cunlocking-safety-act%E2%80%99s-potential-promote-technology-and-combat Unlocking the SAFETY Act’s Potential to Promote Technology and Combat Terrorism ]||No||U.S. Government Hearing||4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Homeland Security (Subcommittee on Oversight, Investigations and Management)||2012-04-24||[http://homeland.house.gov/hearing/subcommittee-hearing-america-under-cyber-attack-why-urgent-action-needed America is Under Cyber Attack: Why Urgent Action is Needed]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.2 [[Actors and Incentives]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Oversight and Government Reform||2011-07-07||[http://oversight.house.gov/hearing/cybersecurity-assessing-the-nations-ability-to-address-the-growing-cyber-threat/ Cybersecurity: Assessing the Nation’s Ability to Address the Growing Cyber Threat]||No||U.S. Government Hearing||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Oversight and Government Reform (Subcommittee on National Security, Homeland Defense and Foreign Operations)||2011-05-25||[http://oversight.house.gov/hearing/cybersecurity-assessing-the-immediate-threat-to-the-united-states/ Cybersecurity: Assessing the Immediate Threat to the United States]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Science, Space and Technology||2011-07-21||[http://science.house.gov/markup/full-committee-%E2%80%93-markup Markup on H.R. 2096, Cybersecurity Enhancement Act of 2011]||No||U.S. Government Hearing||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Science, Space and Technology (Subcommittee on Research and Science Education)||2011-05-25||[http://science.house.gov/hearing/subcommittee-research-and-science-education-subcommittee-technology-and-innovation-%E2%80%93-joint Protecting Information in the Digital Age: Federal Cybersecurity Research and Development Efforts]||No||U.S. Government Hearing||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Science, Space, and Technology (Subcommittee on Investigations and Oversight)||2012-02-29||[http://science.house.gov/hearing/subcommittee-investigations-and-oversight-hearing-nasa-cybersecurity-examination-agency%E2%80%99s NASA Cybersecurity: An Examination of the Agency’s Information Security]||No||U.S. Government Hearing||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Science, Space, and Technology (Subcommittee on Technology and Innovation)||2011-09-21||[http://science.house.gov/hearing/technology-and-innovation-subcommittee-hearing-cloud-computing The Cloud Computing Outlook]||No||U.S. Government Hearing||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on Small Business (Subcommittee on Healthcare and Technology)||2011-12-01||[http://smallbusiness.house.gov/Calendar/EventSingle.aspx?EventID=270278 Cyber Security: Protecting Your Small Business]||No||U.S. Government Hearing||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on the Judiciary||2011-11-16||[http://judiciary.house.gov/hearings/hear_11162011.html Combating Online Piracy (H.R. 3261, Stop the Online Piracy Act)]||No||U.S. Government Hearing||4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on the Judiciary (Subcommittee on Crime, Terrorism and Homeland Security)||2011-11-15||[http://judiciary.house.gov/hearings/hear_11152011.html Cybersecurity: Protecting America’s New Frontier]||No||U.S. Government Hearing||4.10 [[Privacy]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Committee on the Judiciary (Subcommittee on Intellectual Property, Competition and the Internet)||2011-05-25||[http://judiciary.house.gov/hearings/hear_05252011.html Cybersecurity: Problems Innovative Solutions to Challenging]||No||U.S. Government Hearing||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Permenant Select Committee on Intelligence||2011-02-10||[https://intelligence.house.gov/hearing/full-committee-world-wide-threats-hearing World Wide Threats]||No||U.S. Government Hearing||3.1 [[The Threat and Skeptics]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Permenant Select Committee on Intelligence||2011-10-04||[https://intelligence.house.gov/hearing/cyber-threats-and-ongoing-efforts-protect-nation Cyber Threats and Ongoing Efforts to Protect the Nation]||No||U.S. Government Hearing||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.13.2 [[Industrial|Industrial Espionage]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. House Permenant Select Committee on Intelligence||2011-12-01||[https://intelligence.house.gov/markup/mark-hr-xxxx-%E2%80%9Ccyber-intelligence-sharing-and-protection-act-2011%E2%80%9D Markup: Draft Bill: Cyber Intelligence Sharing and Protection Act of 2011]||No||U.S. Government Hearing||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Navy ||2010-06-17||[http://www.doncio.navy.mil/PolicyView.aspx?ID=1804 DON (Department of the Navy) Cybersecurity/Information Assurance Workforce Management, Oversight and Compliance ]||No||U.S. Government Report ||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Armed Services||2012-03-27||[http://armed-services.senate.gov/e_witnesslist.cfm?id=5283 To receive testimony on U.S. Strategic Command and U.S. Cyber Command in review of the Defense Authorization Request for Fiscal Year 2013 and the Future Years Defense Program.]||No||U.S. Government Hearing||3.2.1 [[States]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2011-05-03||[http://www.armed-services.senate.gov/Transcripts/2011/05%20May/11-31%20-%205-3-11.pdf To receive testimony on the health and status of the defense industrial base and its science and technology-related elements]||No||U.S. Government Hearing||3.3.1.2 [[Military Networks (.mil)]],&amp;lt;br&amp;gt;4.3 [[Supply Chain Issues]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Armed Services (Subcommittee on Emerging Threats and Capabilities)||2012-03-20||[http://www.armed-services.senate.gov/Transcripts/2012/03%20March/12-14%20-%203-20-12.pdf To receive testimony on cybersecurity research and development in review of the Defense Authorization Request for Fiscal Year 2013 and the Future Years Defense Program]||No||U.S. Government Hearing||4.2.1 [[Risk Management and Investment]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Banking, Housing and Urban Affairs||2011-06-21||[http://banking.senate.gov/public/index.cfm?FuseAction=Hearings.Hearing&amp;amp;Hearing_ID=87487cb2-4710-4c09-a1b0-a9e12cda88f1 Cybersecurity and Data Protection in the Financial Sector]||No||U.S. Government Hearing||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Commerce, Science and Transportation||2011-06-29||[http://commerce.senate.gov/public/index.cfm?p=Hearings&amp;amp;ContentRecord_id=e2c2a2ca-91d6-48a2-b5ea-b5c4104bdb97&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=b06c39af-e033-4cba-9221-de668ca1978a&amp;amp;MonthDisplay=6&amp;amp;YearDisplay=2011 Privacy and Data Security: Protecting Consumers in the Modern World]||No||U.S. Government Hearing||4.9 [[Identity Management]],&amp;lt;br&amp;gt;4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Energy and Natural Resources||2011-03-15||[ Cybersecurity and Critical Electric Infrastructure (closed)]||No||U.S. Government Hearing||3.3.2.1 [[Electricity, Oil and Natural Gas]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Energy and Natural Resources||2011-05-05||[http://www.energy.senate.gov/public/index.cfm/hearings-and-business-meetings?ID=929c1441-da25-c99d-3e27-af20c29e3b4b Cybersecurity of the Bulk-Power System and Electric Infrastructure]||No||U.S. Government Hearing||3.3.2.1 [[Electricity, Oil and Natural Gas]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Homeland Security and Governmental Affairs||2011-02-17||[http://www.hsgac.senate.gov/hearings/the-homeland-security-departments-budget-submission-for-fiscal-year-2012 Homeland Security Department’s Budget Submission for Fiscal Year 2012]||No||U.S. Government Hearing||&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Homeland Security and Governmental Affairs||2011-03-10||[http://www.hsgac.senate.gov/hearings/information-sharing-in-the-era-of-wikileaks-balancing-security-and-collaboration Information Sharing in the Era of WikiLeaks: Balancing Security and Collaboration]||No||U.S. Government Hearing||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Homeland Security and Governmental Affairs||2011-05-23||[http://www.hsgac.senate.gov/hearings/protecting-cyberspace-assessing-the-white-house-proposal Protecting Cyberspace: Assessing the White House Proposal]||No||U.S. Government Hearing||3.3 [[Security Targets]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Homeland Security and Governmental Affairs||2012-02-16||[http://www.hsgac.senate.gov/hearings/securing-americas-future-the-cybersecurity-act-of-2012 Securing America’s Future: The Cybersecurity Act of 2012]||No||U.S. Government Hearing||3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Judiciary||2011-03-30||[http://www.judiciary.senate.gov/hearings/hearing.cfm?id=e655f9e2809e5476862f735da1697f72 Oversight of the Federal Bureau of Investigation]||No||U.S. Government Hearing||3. [[Threats and Actors]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Judiciary||2011-09-07||[http://www.judiciary.senate.gov/hearings/hearing.cfm?id=3d9031b47812de2592c3baeba629084b Cybercrime: Updating the Computer Fraud and Abuse Act to Protect Cyberspace and Combat Emerging Threats]||No||U.S. Government Hearing||3.11 [[Cybercrime]],&amp;lt;br&amp;gt;4.13.2 [[Industrial|Industrial Espionage]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Judiciary||2012-03-13||[http://www.judiciary.senate.gov/hearings/hearing.cfm?id=8b30fa475a5089d793576cd947089793 The Freedom of Information Act: Safeguarding Critical Infrastructure Information and the Public’s Right to Know]||No||U.S. Government Hearing||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Judiciary (Subcommittee on Crime and Terrorism)||2011-04-12||[http://www.judiciary.senate.gov/hearings/hearing.cfm?id=e655f9e2809e5476862f735da16a9959 Cyber Security: Responding to the Threat of Cyber Crime and Terrorism]||No||U.S. Government Hearing||4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Judiciary (Subcommittee on Crime and Terrorism)||2011-06-21||[http://www.judiciary.senate.gov/hearings/hearing.cfm?id=e655f9e2809e5476862f735da16e1bbe Cybersecurity: Evaluating the Administration’s Proposals]||No||U.S. Government Hearing||1. [[Overview]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| U.S. Senate Committee on Small Business and Entrepreneurship||2011-07-25||[http://www.sbc.senate.gov/public/index.cfm?p=Hearings&amp;amp;ContentRecord_id=6b4d51de-dd67-434b-869f-a717b315e6c2&amp;amp;ContentType_id=14f995b9-dfa5-407a-9d35-56cc7152a7ed&amp;amp;Group_id=43eb5e02-e987-4077-b9a7-1e5a9cf28964&amp;amp;MonthDisplay=7&amp;amp;YearDisplay=2011 Role of Small Business in Strengthening Cybersecurity Efforts in the United States]||No||U.S. Government Hearing||4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.7 [[public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| United States Secret Service ||2004||[[Insider_Threat_Study|Insider Threat Study ]]||Yes||U.S. Government Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.2.2 [[Incentives]],&amp;lt;br&amp;gt;4.4 [[Usability/Human Factors]]&lt;br /&gt;
|-&lt;br /&gt;
| University of Southern California (USC) Information Sciences Institute, University of California Berkeley (UCB), McAfee Research ||2011-01-13||[http://www.isi.edu/deter/news/news.php?story=20 Design of the DETER Security Testbed ]||No||Independent Report||5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| van Eeten, Michael and Bauer, Johannes M.||2009||[[Emerging_Threats_to_Internet_Security|Emerging Threats to Internet Security: Incentives, Externalities and Policy Implications]]||Yes||Journal Article||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]]&lt;br /&gt;
|-&lt;br /&gt;
| van Eeten, Michel J. G. ||2008||[[Economics_of_Malware|Economics of Malware ]]||Yes||Non-U.S. Government Report ||4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| Varian, Hal ||2000||[[Managing_Online_Security_Risks|Managing Online Security Risks ]]||Yes||Article ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;4.2.1 [[Risk Management and Investment]]&lt;br /&gt;
|-&lt;br /&gt;
| Varian, Hal ||2004||[[System_Reliability_and_Free_Riding|System Reliability and Free Riding ]]||Yes||Book ||4.2 [[Economics of Cybersecurity]]&lt;br /&gt;
|-&lt;br /&gt;
| Vatis, Michael A.||2010||[http://sites.nationalacademies.org/xpedio/groups/cstbsite/documents/webpage/cstb_059441.pdf The Council of Europe Convention on Cybercrime]||No||Journal Article||4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]],&amp;lt;br&amp;gt;5.6 [[Deterrence]]&lt;br /&gt;
|-&lt;br /&gt;
| Verizon ||2010||[[2010_Data_Breach_Investigations_Report|2010 Data Breach Investigations Report ]]||Yes||Industry Report ||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.11 [[Cybercrime]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Watts, Sean ||2010||[[Combatant_Status_and_Computer_Network_Attack|Combatant Status and Computer Network Attack ]]||Yes||Journal Article ||3.2.1 [[States]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]],&amp;lt;br&amp;gt;5.5 [[International Law (including Laws of War)]]&lt;br /&gt;
|-&lt;br /&gt;
| White House||2009||[http://www.whitehouse.gov/assets/documents/Cyberspace_Policy_Review_final.pdf Cyberspace Policy Review: Assuring a Trusted and Resilient Information and Communications Infrastructure]||No||U.S. Government Report||1. [[Overview]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| White House||2011-04||[http://www.whitehouse.gov/sites/default/files/rss_viewer/NSTICstrategy_041511.pdf National Strategy for Trusted Identities in Cyberspace: Enhancing Online Choice, Efficiency, Security, and Privacy]||No||U.S. Government Report||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]]&lt;br /&gt;
|-&lt;br /&gt;
| White House||2011-05||[http://www.whitehouse.gov/sites/default/files/rss_viewer/international_strategy_for_cyberspace.pdf International Strategy for Cyberspace: Prosperity, Security, and Openness in a Networked World]||No||U.S. Government Report||1. [[Overview]]&lt;br /&gt;
|-&lt;br /&gt;
| White House||2012-01||[http://www.whitehouse.gov/sites/default/files/national_strategy_for_global_supply_chain_security.pdf National Strategy for Global Supply Chain Security]||No||U.S. Government Report||4.3 [[Supply Chain Issues]]&lt;br /&gt;
|-&lt;br /&gt;
| White House||2012-02||[http://www.whitehouse.gov/sites/default/files/privacy-final.pdf Consumer Data Privacy in a Networked World: A Framework for Protecting Privacy and Promoting Innovation in the Global Digital Economy]||No||U.S. Government Report||4.10 [[Privacy]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2010-12-16||[http://www.whitehouse.gov/sites/default/files/microsites/ostp/pcast-nitrd-report-2010.pdf Designing A Digital Future: Federally Funded Research And Development In Networking And Information Technology ]||No||U.S. Government Report||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2011-02-13||[http://www.cio.gov/documents/Federal-Cloud-Computing-Strategy.pdf Federal Cloud Computing Strategy ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2011-04-15||[http://www.whitehouse.gov/the-press-office/2011/04/15/administration-releases-strategy-protect-online-consumers-and-support-in Administration Releases Strategy to Protect Online Consumers and Support Innovation and Fact Sheet on National Strategy for Trusted Identities in Cyberspace ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2011-04-15||[http://www.whitehouse.gov/sites/default/files/rss_viewer/NSTICstrategy_041511.pdf National Strategy for Trusted Identities in Cyberspace ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2003||[[The_National_Strategy_to_Secure_Cyberspace|The National Strategy to Secure Cyberspace ]]||Yes||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2009||[[Cyberspace_Policy_Review|Cyberspace Policy Review ]]||Yes||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.2 [[Private Efforts/Organizations]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House ||2010||[[The_Comprehensive_National_Cybersecurity_Initiative|The Comprehensive National Cybersecurity Initiative ]]||Yes||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;3.3.2 [[Private Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House (Office of Science &amp;amp; Technology Policy) ||2010-12-06||[http://www.whitehouse.gov/blog/2010/12/06/partnership-cybersecurity-innovation Partnership for Cybersecurity Innovation ]||No||U.S. Government Report||3.3.2.2 [[Financial Institutions and Networks]],&amp;lt;br&amp;gt;4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/Office of Management and Budget (OMB) ||2011-12-08||[http://www.cio.gov/fedrampmemo.pdf Security Authorization of Information Systems in Cloud Computing Environments (FedRAMP) ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2009-05-29||[http://www.whitehouse.gov/assets/documents/Cyberspace_Policy_Review_final.pdf Cyberspace Policy Review: Assuring a Trusted and Resilient Communications Infrastructure ]||No||U.S. Government Report ||4. [[Issues]],&amp;lt;br&amp;gt;5. [[Approaches]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2010-03-02||[http://www.whitehouse.gov/cybersecurity/comprehensive-national-cybersecurity-initiative Comprehensive National Cybersecurity Initiative (CNCI) ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2010-06-25||[http://www.dhs.gov/xlibrary/assets/ns_tic.pdf The National Strategy for Trusted Identities in Cyberspace: Creating Options for Enhanced Online Security and Privacy ]||No||U.S. Government Report ||4.7 [[Public-Private Cooperation]],&amp;lt;br&amp;gt;4.9 [[Identity Management]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2010-07-06||[http://www.whitehouse.gov/sites/default/files/omb/assets/memoranda_2010/m10-28.pdf Clarifying Cybersecurity Responsibilities ]||No||U.S. Government Report ||5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2010-12-09||[http://www.cio.gov/documents/25-Point-Implementation-Plan-to-Reform-Federal%20IT.pdf 25 Point Implementation Plan to Reform Federal Information Technology Management ]||No||U.S. Government Report ||4.2 [[Economics of Cybersecurity]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-02-13||[http://www.cio.gov/documents/Federal-Cloud-Computing-Strategy.pdf Federal Cloud Computing Strategy ]||No||U.S. Government Report ||3.3.3.3 [[Cloud Computing]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-05-12||[http://www.whitehouse.gov/the-press-office/2011/05/12/fact-sheet-cybersecurity-legislative-proposal Cybersecurity Legislative Proposal (Fact Sheet) ]||No||U.S. Government Report ||4. [[Issues]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-05-16||[http://www.whitehouse.gov/sites/default/files/rss_viewer/international_strategy_for_cyberspace.pdf International Strategy for Cyberspace ]||No||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.4 [[International Cooperation]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-09-14||[http://www.whitehouse.gov/sites/default/files/omb/memoranda/2011/m11-33.pdf FY 2012 Reporting Instructions for the Federal Information Security Management Act and Agency Privacy Managementa ]||No||U.S. Government Report ||4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-10-07||[http://www.whitehouse.gov/the-press-office/2011/10/07/executive-order-structural-reforms-improve-security-classified-networks- Structural Reforms to Improve the Security of Classified Networks and the Responsible Sharing and Safeguarding of Classified Information ]||No||U.S. Government Report ||3.3.1 [[Public Critical Infrastructure]],&amp;lt;br&amp;gt;4.6 [[Information Sharing/Disclosure]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| White House/OMB||2011-12-06||[http://www.whitehouse.gov/sites/default/files/microsites/ostp/fed_cybersecurity_rd_strategic_plan_2011.pdf Trustworthy Cyberspace: Strategic Plan for the Federal Cybersecurity Research and Development Program ]||No||U.S. Government Report ||5.3 [[Government Organizations]],&amp;lt;br&amp;gt;5.7 [[Technology]]&lt;br /&gt;
|-&lt;br /&gt;
| Wilshusen, Gregory C. and Powner, David A.||2009||[[Continued_Efforts_are_Needed_to_Protect_Information_Systems_from_Evolving_Threats|Continued Efforts Are Needed to Protect Information Systems from Evolving Threats]]||Yes||U.S. Government Hearing||3.3.1.1 [[Government Networks (.gov)]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]],&amp;lt;br&amp;gt;5.3 [[Government Organizations]]&lt;br /&gt;
|-&lt;br /&gt;
| Wilson, Clay||2007-03-20||[http://www.fas.org/sgp/crs/natsec/RL31787.pdf Information Operations, Electronic Warfare, and Cyberwar: Capabilities and Related Policy Issues]||No||U.S. Government Report||3.3 [[Security Targets]],&amp;lt;br&amp;gt;4.12 [[Cyberwar]]&lt;br /&gt;
|-&lt;br /&gt;
| Zittrain, Jonathan L. ||2008||[[The_Future_of_the_Internet_and_How_To_Stop_It|The Future of the Internet and How To Stop It ]]||Yes||Book ||4.4 [[Usability/Human Factors]],&amp;lt;br&amp;gt;5.1 [[Regulation/Liability]]&lt;br /&gt;
|-&lt;br /&gt;
| Centre for Secure Information Technologies||2012||[http://www.csit.qub.ac.uk/sites/CSIT/InnovationatCSIT/Reports/Filetoupload,295595,en.pdf 2nd World Cyber security Technology Research Summit (Belfast 2012)]||No||Independent Report||&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Submitting_Feedback&amp;diff=6761</id>
		<title>Submitting Feedback</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Submitting_Feedback&amp;diff=6761"/>
		<updated>2012-08-07T21:33:09Z</updated>

		<summary type="html">&lt;p&gt;David: /* Formatting */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The wiki is currently closed to external editors as we finalize the content and underlying structure of the Literature Review. However, the materials featured in this wiki are just a starting point for our inquiry and we look forward to building upon them with more recent publications. The wiki&#039;s approach to [[Cybersecurity Overview|defining Cybersecurity]] remains open and inclusive, therefore we would welcome suggestions from various related fields.&lt;br /&gt;
&lt;br /&gt;
If you have suggestions for inclusion in the wiki we request that you send them to [mailto:cybersecurity-feedback@cyber.law.harvard.edu cybersecurity-feedback@cyber.law.harvard.edu], following the format outline below.&lt;br /&gt;
&lt;br /&gt;
==Information to Include==&lt;br /&gt;
Each suggestion must include the following information:&lt;br /&gt;
&lt;br /&gt;
* Full citation, including at a minimum:&lt;br /&gt;
** Full title&lt;br /&gt;
** Author (or publishing Agency)&lt;br /&gt;
** Year&lt;br /&gt;
* Link to document (or to where a document can be purchased in case access is restricted)&lt;br /&gt;
&lt;br /&gt;
==Formatting==&lt;br /&gt;
All entries on the wiki follow a certain format. It would be helpful if your submission will include the following sections:&lt;br /&gt;
&lt;br /&gt;
* Full title of reference&lt;br /&gt;
* Full citation&lt;br /&gt;
* Categorization&lt;br /&gt;
** Please consult the [[Table of Contents]] for a list of existing categories.&lt;br /&gt;
** Please limit yourself to three categories per entry.&lt;br /&gt;
* Type&lt;br /&gt;
** Please consult the [[Table of Contents]] for a list of existing document types.&lt;br /&gt;
* Keywords&lt;br /&gt;
** If available, pull a list of keywords from your a publication (e.g. &amp;quot;cybersecurity, public goods, and security goods&amp;quot; are potential keywords from [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=708562 this article]).&lt;br /&gt;
* Synopsis&lt;br /&gt;
** The purpose of the synopsis is to provide a concise overview of the main arguments presented in the article, and highlight its relevance to the understanding of cybersecurity issues.&lt;br /&gt;
** If available, please attach an abstract.&lt;br /&gt;
&lt;br /&gt;
==Additional Notes==&lt;br /&gt;
This section refers to any further context that you could provide for the submission such as book reviews, conference reports, key articles referenced in footnotes, or a table of contents.&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Submitting_Feedback&amp;diff=6760</id>
		<title>Submitting Feedback</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Submitting_Feedback&amp;diff=6760"/>
		<updated>2012-08-07T21:20:09Z</updated>

		<summary type="html">&lt;p&gt;David: /* Formatting */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The wiki is currently closed to external editors as we finalize the content and underlying structure of the Literature Review. However, the materials featured in this wiki are just a starting point for our inquiry and we look forward to building upon them with more recent publications. The wiki&#039;s approach to [[Cybersecurity Overview|defining Cybersecurity]] remains open and inclusive, therefore we would welcome suggestions from various related fields.&lt;br /&gt;
&lt;br /&gt;
If you have suggestions for inclusion in the wiki we request that you send them to [mailto:cybersecurity-feedback@cyber.law.harvard.edu cybersecurity-feedback@cyber.law.harvard.edu], following the format outline below.&lt;br /&gt;
&lt;br /&gt;
==Information to Include==&lt;br /&gt;
Each suggestion must include the following information:&lt;br /&gt;
&lt;br /&gt;
* Full citation, including at a minimum:&lt;br /&gt;
** Full title&lt;br /&gt;
** Author (or publishing Agency)&lt;br /&gt;
** Year&lt;br /&gt;
* Link to document (or to where a document can be purchased in case access is restricted)&lt;br /&gt;
&lt;br /&gt;
==Formatting==&lt;br /&gt;
All entries on the wiki follow a certain format. It would be helpful if your submission will include the following sections:&lt;br /&gt;
&lt;br /&gt;
* Full title of reference&lt;br /&gt;
* Full citation&lt;br /&gt;
* Categorization&lt;br /&gt;
** Please consult the [[Table of Contents]] for a list of existing categories.&lt;br /&gt;
** Please limit yourself to three categories per entry.&lt;br /&gt;
* Type&lt;br /&gt;
** Please consult the [[Table of Contents]] for a list of existing document types.&lt;br /&gt;
* Keywords&lt;br /&gt;
** If available, pull a list of keywords from your a publication (e.g. &amp;quot;cybersecurity, public goods, and security goods&amp;quot; are potential keywords from [http://papers.ssrn.com/sol3/papers.cfm?abstract_id=708562 this article]).&lt;br /&gt;
* Synopsis&lt;br /&gt;
** the purpose of the synopsis is to provide a concise overview of the main arguments presented in the article, and highlight its relevance to the understanding of cybersecurity issues.&lt;br /&gt;
** If available, please attach an abstract.&lt;br /&gt;
&lt;br /&gt;
==Additional Notes==&lt;br /&gt;
This section refers to any further context that you could provide for the submission such as book reviews, conference reports, key articles referenced in footnotes, or a table of contents.&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cyber.harvard.edu/cybersecurity/?title=Main_Page&amp;diff=6364</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://cyber.harvard.edu/cybersecurity/?title=Main_Page&amp;diff=6364"/>
		<updated>2012-06-05T18:18:24Z</updated>

		<summary type="html">&lt;p&gt;David: /* About the Project */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{TOCright}}&lt;br /&gt;
&lt;br /&gt;
==Start at the [[Table of Contents]]==&lt;br /&gt;
&lt;br /&gt;
To get started immediately, visit the &#039;&#039;&#039;[[Table of Contents]]&#039;&#039;&#039; and click on a topic of interest.&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
This Cybersecurity wiki provides a set of evolving resources on cybersecurity, broadly defined, and includes an &#039;&#039;&#039;[[Table of Contents | annotated list]]&#039;&#039;&#039; of relevant articles and literature, which can be searched in a number of ways. Please see below.&lt;br /&gt;
&lt;br /&gt;
This wiki is intended as a tool/resource for researchers, technologists, students, policy-makers and others who are interested in cybersecurity issues more broadly. For more information about this first phase of the project, please see [http://cyber.law.harvard.edu/cybersecurity/Main_Page#About_the_Project About the Project].&lt;br /&gt;
&lt;br /&gt;
==Cybersecurity Overview==&lt;br /&gt;
&lt;br /&gt;
The term “Cybersecurity” encompasses a range of issues from [[Cybercrime]] to [[Cyberwar]]. These in turn embrace a diverse set of activities and interests.&lt;br /&gt;
&lt;br /&gt;
Cybercrime, for example, can refer to a lone [[Keyword_Index_and_Glossary_of_Core_Ideas#Hacker | hacker]] breaking into a single computer or to an [[Keyword_Index_and_Glossary_of_Core_Ideas#Organized_Crime | organized network of computer criminals]] collecting thousands or millions of [[Keyword_Index_and_Glossary_of_Core_Ideas#Credit_Card_Fraud | credit card numbers]] and/or [[Keyword_Index_and_Glossary_of_Core_Ideas#Identity_Fraud.2FTheft | personal information records]] from multiple poorly protected corporate sources. Responses to cybercrime range from offering [[Incentives | incentives]] to individuals, manufacturers and/or corporations to protect against [[Keyword_Index_and_Glossary_of_Core_Ideas#Malware | malware]] and [[Keyword_Index_and_Glossary_of_Core_Ideas#Botnet | botnet attacks]] to decisions about [[Insurance | insurance]] and [[Risk_Management_and_Investment | risk management]].&lt;br /&gt;
&lt;br /&gt;
[[Cyberwar| Cyberwarfare]] includes covert [[Espionage | espionage]] attacks against secure systems to collect sensitive [[Keyword_Index_and_Glossary_of_Core_Ideas#National_Security | national security]] information, distributed attacks against the [[Private_Critical_Infrastructure | civilian infrastructure]] to cause widespread failures of [[Electricity, Oil and Natural Gas | energy]] and/or [[Communications | communication systems]] or targeted attacks against [[Government_Networks_(.gov) | military targets]] with the intent to render offensive and defensive systems inoperable or to take control of systems with the ability to deliver [[Keyword_Index_and_Glossary_of_Core_Ideas#Kinetic_Attack | kinetic attacks]]. These attacks all create complicated questions of [[Attribution | attribution]] and [[International Law (including Laws of War) | law]], as the normal [[Keyword_Index_and_Glossary_of_Core_Ideas#Laws_of_War | laws of war]] are of questionable value when applied to threats delivered domestically from a anonymous source in a distant location. In addition, [[Deterrence| deterrence]], offensive actions and defensive response often become blurred in the cyber realm, requiring a fresh look at what policies such as “no first strike” mean in cyberspace.&lt;br /&gt;
&lt;br /&gt;
Solutions to these problems will involve addressing questions of [[Economics_of_Cybersecurity | economics]], incentives, [[Regulation/Liability |law,  legislation]], politics, [[Public-Private_Cooperation | government-private cooperation]] and [[International_Cooperation |international diplomacy]]. Government, industry, the military and the public must all play a role in deciding [[Keyword_Index_and_Glossary_of_Core_Ideas#Cyber_Security_as_a_Public_Good | how much cybersecurity is needed]] and who will pay for it. These stakeholders must also address the tradeoffs between [[Privacy | privacy]] and security that often arise in addressing cyber threats. Finally, there needs to be a way to [[Metrics | measure the threat]] and the protections put in place so that the players can make intelligent choices in allocating scare resources.&lt;br /&gt;
&lt;br /&gt;
==Key Resources - How to Use this Wiki==&lt;br /&gt;
&lt;br /&gt;
===Navigating Through the  [[Table of Contents]]===&lt;br /&gt;
Because this bibliography encompasses such a wide range of cybersecurity issues, the most direct way to get started is to look through the detailed &#039;&#039;&#039;[[Table of Contents]]&#039;&#039;&#039; and select &#039;&#039;&#039;Specific Issues or Themes&#039;&#039;&#039; of interest.  For example, [[Cybercrime | Cybercrime]] or [[Financial Institutions and Networks |Financial Institutions and Networks]].  At the top of each topic page within the Table of Contents is a &amp;quot;bread crumb&amp;quot; trail showing the path through the Table of Contents to that page.  This trail not only shows you how the current page topic fits into the overall structure of the bibliography, each level in this trail is individually selectable allowing you to move up one or more levels to broaden your search.  For example, if you are looking at the &#039;&#039;[[Table of Contents | TOC-&amp;gt;]][[Issues | Issues-&amp;gt;]][[Economics of Cybersecurity | Economics of Cybersecurity-&amp;gt;]][[Incentives]]&#039;&#039; page, you can click on the [[Issues | Issues-&amp;gt;]] link to see references addressing all the cybersecurity Issues topics.&lt;br /&gt;
&lt;br /&gt;
At the bottom of each topic page is a list of subcategories leading deeper into the Table of Contents from the current topic.  This allows you to drill down to pages with greater specificity.  For example, if the current page is &#039;&#039;[[Table of Contents | TOC-&amp;gt;]][[Issues | Issues-&amp;gt;]][[Economics of Cybersecurity | Economics of Cybersecurity-&amp;gt;]]&#039;&#039; (shown in the bread crumb trail at the top of the page), the bottom of the page will offer links to the five subcategories of the &#039;&#039;&#039;Economics of Cybersecurity&#039;&#039;&#039; including:&lt;br /&gt;
&lt;br /&gt;
*&#039;&#039;[[Economics of Cybersecurity | Economics of Cybersecurity-&amp;gt;]][[Risk Management and Investment]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Economics of Cybersecurity | Economics of Cybersecurity-&amp;gt;]][[Incentives]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Economics of Cybersecurity | Economics of Cybersecurity-&amp;gt;]][[Insurance]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Economics of Cybersecurity | Economics of Cybersecurity-&amp;gt;]][[Behavioral Economics]]&#039;&#039;&lt;br /&gt;
*&#039;&#039;[[Economics of Cybersecurity | Economics of Cybersecurity-&amp;gt;]][[Market Failure]]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===Choose a [[Broad Topics | Broad Topic Area]] to Explore===&lt;br /&gt;
If you are interested in beginning with a broad topic area, however, you might choose to start your search from one of the &#039;&#039;&#039;[[Broad Topics]]&#039;&#039;&#039;.  This allows you to search within the broad categories of &#039;&#039;&#039;[[Overview]]&#039;&#039;&#039;, &#039;&#039;&#039;[[Resource by Type]]&#039;&#039;&#039;, &#039;&#039;&#039;[[Threats_and_Actors | Threats and Actors]]&#039;&#039;&#039;, &#039;&#039;&#039;[[Issues | Issues]]&#039;&#039;&#039;, and &#039;&#039;&#039;[[Approaches | Approaches]]&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
===Select an [[Overview | Overview Document]]===&lt;br /&gt;
Alternately, you can access one of the &#039;&#039;&#039;[[Overview]]&#039;&#039;&#039; readings or one of the selected readings that we&#039;ve summarized by&lt;br /&gt;
&#039;&#039;&#039;[[Resource by Type | Resource Type]]&#039;&#039;&#039;, which includes &#039;&#039;&#039;[[Government Reports and Documents]]&#039;&#039;&#039;, &#039;&#039;&#039;[[Independent Reports]]&#039;&#039;&#039;, &#039;&#039;&#039;[[Industry Reports]]&#039;&#039;&#039;  and &#039;&#039;&#039;[[Books]]&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
===Access the [[Keyword Index and Glossary of Core Ideas | Keyword Index]]===&lt;br /&gt;
For a more targeted review by &#039;&#039;&#039;Key Word&#039;&#039;&#039;, please review our &#039;&#039;&#039;[[Keyword Index and Glossary of Core Ideas]]&#039;&#039;&#039;, which will enable you to search definitions and references related to specific terms, from [[Keyword_Index_and_Glossary_of_Core_Ideas#Air-Gapped_Network| Air-Gapped Network]] to [[Keyword_Index_and_Glossary_of_Core_Ideas#Zero-Day_Exploit | Zero-Day Exploit]].&lt;br /&gt;
&lt;br /&gt;
===See a [[Cybersecurity Annotated Bibliography| List of All Articles]]===&lt;br /&gt;
An alphabetized &#039;&#039;&#039;List of All Articles&#039;&#039;&#039; in the bibliography is available in the &#039;&#039;&#039;[[Cybersecurity Annotated Bibliography]]&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
===Export References in Standard BibTex Format===&lt;br /&gt;
References may also be accessed and exported in a standard bibliographic format ([http://www.bibtex.org/ BibTeX]) here: &#039;&#039;&#039;[http://cyber.law.harvard.edu/cybersecurity/Special:Bibliography Bibliography]&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
==Ongoing Work==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;A Note on Methodology&#039;&#039;&#039;: The materials featured in this wiki are just a starting point for our inquiry; the collected articles are dated through 2011. They were selected as foundational documents on the recommendation of select researchers, and we look forward to building upon them with more recent publications. During the next phase of the project, experts, policy-makers, academics, and others will be asked to review and evaluate the current collection and make recommendations for additional resources to include.  We have also included a list of suggested materials for review and possible inclusion in the next phase of the project. &lt;br /&gt;
&lt;br /&gt;
Additional articles for consideration are listed here: [[Suggested References to Add to Wiki]]&lt;br /&gt;
&lt;br /&gt;
==About the Project==&lt;br /&gt;
&lt;br /&gt;
The development of this wiki is supported by the [http://minerva.dtic.mil/ Minerva Initiative].  &lt;br /&gt;
&lt;br /&gt;
The resources have been assembled by a team at the [http://cyber.law.harvard.edu/ Berkman Center for Internet &amp;amp; Society], under the guidance of [http://cyber.law.harvard.edu/people/jgoldsmith Jack Goldsmith]. Please see [http://www.lawfareblog.com/ Jack&#039;s blog] for up-to-date coverage of national security and cybersecurity news, issues, and analysis.  &lt;br /&gt;
&lt;br /&gt;
Contributors include: [http://cyber.law.harvard.edu/people/dabrams David Abrams], Jacob Albert, [http://cyber.law.harvard.edu/people/ugasser Urs Gasser], Shane Matthews, Caroline Nolan, David O&#039;Brien, and Felix Treguer.&lt;br /&gt;
&lt;br /&gt;
If you have feedback, comments, or suggested additional readings/resources, please contact: [mailto:cybersecurity-feedback@cyber.law.harvard.edu cybersecurity-feedback@cyber.law.harvard.edu]. &lt;br /&gt;
&lt;br /&gt;
Please note that the wiki is currently closed to external editors as we finalize the content and underlying structure of the Literature Review. During Spring-Summer of 2012, we will provide additional opportunities for users to weigh in, contribute to, and comment on the wiki content. We will also update the initial collection of articles with more recent writings, and based on feedback and recommendations from external reviewers and others.&lt;br /&gt;
&lt;br /&gt;
==Templates and Wiki Tools==&lt;br /&gt;
&lt;br /&gt;
[[Adding a Reference | How to Add a New Reference to this Wiki]]&lt;br /&gt;
&lt;br /&gt;
[[TemplateForSources | Template for Sources]]&lt;br /&gt;
&lt;br /&gt;
[[Guidelines for adding Bibliography entries]]&lt;br /&gt;
&lt;br /&gt;
[[List of Keyword links to copy into reference pages | Keyword Links]]&lt;br /&gt;
&lt;br /&gt;
Wiki [http://meta.wikimedia.org/wiki/Help:Contents User&#039;s Guide]&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
</feed>