PORTALE DELLA DIDATTICA

PORTALE DELLA DIDATTICA

PORTALE DELLA DIDATTICA

Elenco notifiche



Cybersecurity laws and regulations

01GZBWQ, 01GZBWR, 01GZBYG

A.A. 2027/28

Course Language

Inglese

Degree programme(s)

Master of science-level of the Bologna process in Cybersecurity Engineering - Torino
Master of science-level of the Bologna process in Ingegneria Informatica (Computer Engineering) - Torino

Course structure
Teaching Hours
Lecturers
Teacher Status SSD h.Les h.Ex h.Lab h.Tut Years teaching
Co-lectures
Espandi

Context
SSD CFU Activities Area context
IUS/01 6 C - Affini o integrative Attività formative affini o integrative
2026/27
The main aim of this course is to provide a general overview of the legal issues relating to cybersecurity and data security. Given the global dimension of data flows and their economic and strategic value, the legal framework will be considered at different levels, namely international, EU and national. The first part of the course focuses on data regulation as the legal protection provided to personal and non-personal data is at the root of cybersecurity laws that aim to safeguard these intangible assets. Moreover, some key data protection regulations, such as the GDPR, already include specific data security and cybersecurity requirements. In line with the transnational dimension of cybersecurity, attention will also be paid to international conventions and frameworks (Convention 108 and 108+ of the Council of Europe, OECD Guidelines). Specific environments, such as IoT and cloud computing, will be considered when dealing with data and cybersecurity issues. Finally, the recent development of AI regulation in Europe and the risk-based approach adopted by legislators will be discussed concerning the requirements that increase the level of data and system security. The second part of the course aims to provide case studies and practical examples in the field of information security. Special attention will be given to the Cybercrime Convention, GDPR-Data Breach, NIS2, Cybersecurity Act, and EU bodies (ENISA, CERT, etc.). The Cybercrime Convention, also known as the Council of Europe Convention on Cybercrime, was signed on November 23, 2001. It is the first international convention to address Internet and computer crime by harmonizing national laws, improving investigative techniques, and increasing cooperation among nations. The General Data Protection Regulation (GDPR), the Network and Information Systems Directive (NIS2), and the Cybersecurity Act are essential pieces of legislation aimed at protecting personal data and ensuring the security of information systems. Together, these pieces of legislation play a crucial role in promoting and protecting the security of personal data information in the digital age. Each of the individual pieces of EU legislation mentioned above will be addressed by highlighting the most relevant aspects and focusing on the practical effects in the cybersecurity world. Through case studies, the student will gain detailed knowledge of the real issues that need to be addressed to manage cybersecurity risks.
The main aim of this course is to provide a general overview of the legal issues relating to cybersecurity and data security. Given the global dimension of data flows and their economic and strategic value, the legal framework will be considered at different levels, namely international, EU and national. The first part of the course focuses on data regulation as the legal protection provided to personal and non-personal data is at the root of cybersecurity laws that aim to safeguard these intangible assets. Moreover, some key data protection regulations, such as the GDPR, already include specific data security and cybersecurity requirements. In line with the transnational dimension of cybersecurity, attention will also be paid to international conventions and frameworks (Convention 108 and 108+ of the Council of Europe, OECD Guidelines). Specific environments, such as IoT and cloud computing, will be considered when dealing with data and cybersecurity issues. Finally, the recent development of AI regulation in Europe and the risk-based approach adopted by legislators will be discussed concerning the requirements that increase data and system security. Particular emphasis will be placed on the EU Artificial Intelligence Act (Regulation (EU) 2024/1689), the first comprehensive legal framework on AI worldwide. The course will examine its risk-based structure (prohibited practices, high-risk AI systems and transparency obligations), the rules for general-purpose AI models and the requirements most relevant from a security perspective, namely risk management, data governance and the accuracy, robustness and cybersecurity of high-risk AI systems, including resilience against AI-specific attacks such as data poisoning, model poisoning and adversarial examples. The interplay between the AI Act, the GDPR and EU cybersecurity legislation will also be addressed. The second part of the course aims to provide case studies and practical examples in information security. Special attention will be given to the Cybercrime Convention, GDPR-Data Breach, NIS2, Cybersecurity Act, AI Act, ISO/IEC 27001, and EU bodies (ENISA, CERT, etc.). The Cybercrime Convention, also known as the Council of Europe Convention on Cybercrime, was signed on November 23, 2001. It is the first international convention to address Internet and computer crime by harmonizing national laws, improving investigative techniques, and increasing cooperation among nations. The General Data Protection Regulation (GDPR), the Network and Information Systems Directive (NIS2), and the Cybersecurity Act are essential pieces of legislation aimed at protecting personal data and ensuring the security of information systems. Together, these pieces of legislation play a crucial role in promoting and protecting the security of personal data information in the digital age. The course will also examine the relationship between this legislation and ISO/IEC 27001, the international standard for information security management systems (ISMS). Its importance will be discussed as a tool for translating legal obligations, such as the security measures required by the GDPR and the cybersecurity risk-management measures required by NIS2, into a structured, auditable and certifiable management system, while also considering the value and limits of certification as evidence of compliance. A key focus will be the concept of risk assessment (risk identification, analysis and evaluation, and selection of treatment measures), the cornerstone of both ISO/IEC 27001 and the risk-based approach of the GDPR, NIS2 and the AI Act. Each of the individual pieces of EU legislation mentioned above will be addressed by highlighting the most relevant aspects and focusing on the practical effects in the cybersecurity world. Through case studies, the student will gain detailed knowledge of the fundamental issues that need to be addressed to manage cybersecurity risks.
Students will acquire knowledge of the legal requirements and safeguards characterizing the field of cybersecurity. They will have knowledge of the legal principles and language, which will give them the ability to facilitate their interaction in the corporate and public sector environment, as well as in a multidisciplinary context.
Knowledge and understanding. By the end of the course the student will be able to: - describe the international, European and national sources that regulate data and cybersecurity (Convention 108 and 108+, OECD Guidelines, GDPR, Regulation (EU) 2018/1807, Budapest Convention, NIS2, Cybersecurity Act, AI Act); - explain the security, accountability and notification obligations imposed by the GDPR and the cybersecurity risk-management measures required by NIS2; - illustrate the risk-based approach shared by the GDPR, NIS2 and the AI Act, and the role of ISO/IEC 27001 and of risk assessment in demonstrating compliance; - identify the offences and the investigative and cooperation mechanisms established by the Budapest Convention; - describe the tasks of the EU bodies and networks involved in cybersecurity (ENISA, CSIRTs/CERTs, supervisory authorities, EDPB). Applying knowledge and understanding. By the end of the course the student will be able to: - determine the legal regime applicable to a given processing operation or ICT service, distinguishing personal from non-personal data and identifying the roles and the responsibilities involved; - classify an AI system under the risk categories of the AI Act and select the security requirements applicable to it; - analyse a data breach scenario and decide whether, to whom and within which deadlines notification is required under the GDPR and NIS2; - carry out a basic information security risk assessment and connect the resulting measures to the legal obligations and to the controls of ISO/IEC 27001; - argue a legal solution to a cybersecurity case, compare it with alternative solutions and justify it with the relevant sources.
No previous legal knowledge is required: the basic legal concepts and the methodology needed to read and apply European and national legal sources are introduced in the first classes. Students are expected to be familiar with the technical notions acquired in the previous courses of the programme, in particular the architecture of information systems and networks, the main categories of cyber-attacks and the basic security measures (access control, encryption, logging, backup), since the legal analysis is applied to these scenarios. A good knowledge of English is required, as classes, materials and the exam are entirely in English.
Part I - Data and Privacy - The international framework: Council of Europe and OECD - The GDPR and legal compliance - Sector-specific applications and Regulation 2018/1807 on non-personal data - AI regulation and risk-based approach Part II – Cybersecurity and Cybercrime - Cybercrime Convention (Budapest, November 23 2001) - Data Breach and GDPR: 3 leading cases - Nis Directive 2 and Cybersecurity Act - The role of EU bodies (ENISA, CERT) and the most important case studies
Part I - Data and Privacy (24 hours) - The international framework: Council of Europe and OECD (4 h) - The GDPR and legal compliance (10 h) - Sector-specific applications and Regulation 2018/1807 on non-personal data (4 h) - AI regulation and risk-based approach: the EU AI Act (Regulation (EU) 2024/1689) (6 h) Part II – Cybersecurity and Cybercrime (32 hours) - Cybercrime Convention (Budapest, November 23 2001) (6 h) - Data Breach and GDPR: 3 leading cases (6 h) - Nis Directive 2 and Cybersecurity Act (8 h) - AI Act and cybersecurity: requirements for high-risk AI systems and AI-specific threats (4 h) - ISO/IEC 27001 and risk assessment: the relationship between legal requirements and information security management systems (6 h) - The role of EU bodies (ENISA, CERT) and the most important case studies (2 h) The remaining 4 hours are devoted to tutoring and review activities (see Course structure). Total: 60 hours, 6 CFU.
The course is divided into lectures, and students' contributions and group activities will be encouraged.
The course is divided into lectures, and students' contributions and group activities will be encouraged. The 60 hours of the course are organised as follows: 30 hours of lectures, 18 hours of classroom exercises, 8 hours of laboratory and 4 hours of tutoring. Lectures present the legal framework, the relevant case law and the decisions of the supervisory authorities; the slides are made available on the course portal. Classroom exercises are devoted to the guided analysis of real cases (decisions of data protection authorities, data breaches, cyber-attacks, AI applications). Students receive a short document in advance and are asked to answer guided questions and to take a position on the case, which is then discussed with the teacher. In the laboratory hours students work in small groups on a case study: each group reconstructs the facts, identifies the applicable legal framework and prepares a short written analysis, for instance the classification of an AI system under the AI Act, the notification duties following a personal data breach, or the security measures required by NIS2 and ISO/IEC 27001. Each group then presents its conclusions in class and the different solutions are compared and discussed. The tutoring hours support the learning process: clarification of legal concepts and methodology, guidance during the group work, feedback on the analyses produced by the groups and review sessions on the topics that students find most difficult. These activities are not assessed. Students' contributions, that is questions, comments, the presentation of the group work and participation in class discussion, are encouraged throughout the course. They do not contribute to the final mark: their purpose is to develop the ability to apply the legal framework to concrete situations, which is what the written exam assesses.
- Hoofnagle, Chris Jay, Bart van der Sloot, e Frederik Zuiderveen Borgesius. «The European Union general data protection regulation: what it is and what it means». Information & Communications Technology Law 28, fasc. 1 (2 gennaio 2019): 65–98. https://doi.org/10.1080/13600834.2019.1573501 (open access) - Mantelero Alessandro, Giuseppe Vaciago, Maria Samantha Esposito, e Nicole Monte. «The common EU approach to personal data and cybersecurity regulation». 2020, 28(4) International Journal of Law and Information Technology 297–328 https://doi.org/10.1093/ijlit/eaaa021 (open access) - Papakonstantinou Vagelis, «Cybersecurity as praxis and as a state: The EU law path towards acknowledgement of a new right to cybersecurity? », Computer Law & Security Review, Volume 44, April 2022, 105653 https://www.sciencedirect.com/science/article/pii/S0267364922000012
- Hoofnagle, Chris Jay, Bart van der Sloot, e Frederik Zuiderveen Borgesius. «The European Union general data protection regulation: what it is and what it means». Information & Communications Technology Law 28, fasc. 1 (2 gennaio 2019): 65–98. https://doi.org/10.1080/13600834.2019.1573501 (open access) - Mantelero Alessandro, Giuseppe Vaciago, Maria Samantha Esposito, e Nicole Monte. «The common EU approach to personal data and cybersecurity regulation». 2020, 28(4) International Journal of Law and Information Technology 297–328 https://doi.org/10.1093/ijlit/eaaa021 (open access) - Papakonstantinou Vagelis, «Cybersecurity as praxis and as a state: The EU law path towards acknowledgement of a new right to cybersecurity? », Computer Law & Security Review, Volume 44, April 2022, 105653 https://www.sciencedirect.com/science/article/pii/S0267364922000012 - Nolte Henrik, Miriam Rateike, e Michèle Finck. «Robustness and Cybersecurity in the EU Artificial Intelligence Act». 2025, Proceedings of the 2025 ACM Conference on Fairness, Accountability, and Transparency (FAccT '25) https://doi.org/10.1145/3715275.3732020 (open access) - ENISA, «NIS2 Technical Implementation Guidance», version 1.0, June 2025, in particular Section 2 (Risk management policy) and the mapping of requirements to ISO/IEC 27001:2022 https://www.enisa.europa.eu/publications/nis2-technical-implementation-guidance - Slides, case files and additional materials distributed by the teacher on the course portal. For each class an “exam” version of the slides is also made available, which marks the perimeter of the topics that may be asked in the written test.
Dispense; Libro di testo;
Lecture notes; Text book;
Modalita di esame: Prova scritta (in aula); Prova scritta in aula tramite PC con l'utilizzo della piattaforma di ateneo;
Exam: Written test; Computer-based written test in class using POLITO platform;
... Assessment and grading criteria for the ONSITE exam. The final exam aims to evaluate the student's understanding of the topics discussed during the course and how much students apply the acquired notions to various cases. The exam is written and is 45 minutes in duration. It is divided into two sections, one focused on case analysis and one on the general legal framework (open-question).
Gli studenti e le studentesse con disabilita o con Disturbi Specifici di Apprendimento (DSA), oltre alla segnalazione tramite procedura informatizzata, sono invitati a comunicare anche direttamente al/la docente titolare dell'insegnamento, con un preavviso non inferiore ad una settimana dall'avvio della sessione d'esame, gli strumenti compensativi concordati con l'Unita Special Needs, al fine di permettere al/la docente la declinazione piu idonea in riferimento alla specifica tipologia di esame.
Exam: Written test; Computer-based written test in class using POLITO platform;
Objectives of the exam The exam verifies that the student is able to: (i) recognise the legal sources applicable to a data or cybersecurity scenario and describe the obligations they impose; (ii) apply those obligations to a concrete case, in particular by classifying an AI system under the AI Act, by determining the notification duties following a data breach and by identifying the security and risk-management measures required by the GDPR, NIS2 and ISO/IEC 27001; (iii) justify the proposed solution with the relevant provisions, using appropriate legal terminology. Structure of the exam The exam consists of a single written test of 90 minutes, divided into two sections: - Section A: 4 multiple-choice questions (5 point each), which assess the knowledge of the legal framework, of the definitions and of the obligations examined during the course. Only one answer is correct and no points are deducted for wrong or missing answers. - Section B: 1 open questions (up to 11 points each), at least one of which is based on a short practical case of the type discussed during the exercises and the group work. The questions cover the whole programme and are distributed in proportion to the hours devoted to each part (approximately 45% Part I and 55% Part II). Grading criteria Section A is graded on the correctness of the answers. Each open question of Section B is graded on the identification of the applicable legal framework (up to 2 points), the correct application to the case and the completeness of the answer (up to 2 points), and the clarity of the reasoning and the use of proper legal terminology (up to 2 points). The final mark is the sum of the points obtained in the two sections (maximum 30). The exam is passed with a mark of at least 18/30. Honours (lode) are awarded to students who reach the maximum score and whose answers to the open questions show a particularly accurate and well-argued analysis. Rules The test is closed book: books, notes, slides, legal texts and electronic devices may not be used. Where an answer requires the exact wording of a provision, the relevant text is reproduced in the exam paper. No intermediate tests are scheduled. The teacher may ask the student for a short oral clarification where the written answers are illegible or their evaluation is doubtful. Students with disabilities or with specific learning disorders (SLD) are invited to contact the teacher and the Special Needs Unit at least one week before the exam date, in order to agree on the appropriate arrangements. Sustainable development goals Peace, justice and strong institutions (SDG 16); Industry, innovation and infrastructure (SDG 9).
In addition to the message sent by the online system, students with disabilities or Specific Learning Disorders (SLD) are invited to directly inform the professor in charge of the course about the special arrangements for the exam that have been agreed with the Special Needs Unit. The professor has to be informed at least one week before the beginning of the examination session in order to provide students with the most suitable arrangements for each specific type of exam.
Esporta Word