Author
Listed:
- Trayce Hockstad
- Mizanur Rahman
- Steven Jones
- Mashrur Chowdhury
Abstract
Although the need for regulatory and enforcement measures is dire, there is no all‐encompassing federal law or regulatory framework that governs cybersecurity or data privacy in the US transportation industry. The objective of this paper is to analyze the gaps that exist in US cybersecurity regulatory schematic as applied to transportation law and policy. As opposed to a theoretical approach, this study relies on a systematic gap analysis methodology to canvas a broad topic and distill specific insights that can be used as a foundation for establishing legislative and policy goals. Specifically, this paper attempts to answer: (i) what federal and/or state agencies are responsible for governing cybersecurity practices in the United States, including risk assessment, preventative measures, detection of breaches, and remedial enforcement; and (ii) how do industry experts assess the greatest risks/threats to ensuring cybersecurity in the transportation sector? The scope of selected legislative analysis is purposefully all‐encompassing of the transportation industry to highlight the scant nature of existing US law on the subject. Several states have enacted their own cybersecurity legislation, creating an unsynchronized approach nationwide that implicates jurisdictional issues, preemption problems, and inconsistent compliance requirements for national stakeholders. This paper next considers states' perspectives of transportation cybersecurity as assessed through a national survey of US state transportation agencies. Specific areas of concern identified as being important to the transportation industry but largely overlooked in the legislative spectrum include issues related to third‐party vendor liability, identifying cybersecurity tools, and supply chain risk management. Legislation covering workforce, ransomware, and cybersecurity‐related privacy issues saw more success, but low passage rates were still reflected with respect to the number of bills proposed. On the other hand, funding, insurance, and penalization issues appeared to be frequently prioritized. This paper presents the results of a gap analysis research approach identifying discrepancies between “what is” and “what should be” in transportation cybersecurity legislation.
Suggested Citation
Trayce Hockstad & Mizanur Rahman & Steven Jones & Mashrur Chowdhury, 2025.
"A regulatory gap analysis in transportation cybersecurity and data privacy,"
Transportation Journal, John Wiley & Sons, vol. 64(1), January.
Handle:
RePEc:wly:transj:v:64:y:2025:i:1:n:e12036
DOI: 10.1002/tjo3.12036
Download full text from publisher
Corrections
All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:wly:transj:v:64:y:2025:i:1:n:e12036. See general information about how to correct material in RePEc.
If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.
We have no bibliographic references for this item. You can help adding them by using this form .
If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.
For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: Wiley Content Delivery (email available below). General contact details of provider: .
Please note that corrections may take a couple of weeks to filter through
the various RePEc services.