FC / NETWORK
Registry 01 · Domain
Technology Policy
Seventy-five years of patient work, and a door held open for you.
Standards, accountability, and the legitimacy of governance over emergent systems.
Classification
Research domain
Cross-disciplinary index
Brief / 01
Context record
Technology policy at RAND is organized around the legitimacy problem, what makes governance over emergent technical systems credible, enforceable, and adaptive to systems that evolve faster than the institutions overseeing them.
RAND has worked on cyber, critical infrastructure, and technology governance for more than three decades. Its researchers produced foundational work on zero-day markets, cyber economics, and the policy architecture for autonomous and AI-enabled systems, and maintain continuous engagement with federal regulators, standards bodies, and critical-infrastructure operators.
RAND's Signature Themes in Technology Policy
Cyber economics and risk
How incentives, insurance, and disclosure regimes shape the security posture of firms and critical infrastructure.
Critical-infrastructure security
The policy and technical architecture that makes energy, water, finance, and communications resilient against adversary action.
Standards and accountability
Which institutional forms, regulators, standards bodies, third-party auditors, can credibly govern adaptive systems.
Privacy and surveillance
Consent doctrine, data governance, and the limits of legal frameworks built before the contemporary data environment.
Representative Work
Zero Days, Thousands of Nights
RAND · RR-1751
Markets for Cybercrime Tools and Stolen Data
RAND · RR-610
Content Moderation and the Law
RAND · ongoing
Methodological Emphasis
Mixed-methods policy analysis, structured red-teaming, and economic modeling of security incentives.
Methodological Lineage →Affiliated Researchers