Security Without Accountability: The LAG Framework for Web 3.0 Governance
Abstract
Decentralized and autonomous systems associated with Web 3.0 challenge long-standing assumptions about security governance, responsibility, and control. Although advances in cryptography, consensus mechanisms, and automation have strengthened technical protections, they have also fragmented accountability across software agents, organizations, and ecosystems, producing security failures in environments where responsibility for prevention, response, and remediation is unclear or contested. This paper demonstrates that many such failures stem not from inadequate technical safeguards but from governance gaps created by sociotechnical complexity. Drawing on sociotechnical systems theory, it introduces the LAG (Layers-Accountability-Governance) framework, which distinguishes among information technology security, information security, and enterprise-level governance, and clarifies the misalignment between ex ante preventive mechanisms and ex post response and recovery processes. Through analysis of decentralized architectures, autonomous agents, and machine identities, and case studies of the DAO, Poly Network, and oracle-related failures, the paper shows how technically correct system behavior can nonetheless produce governance failure and discusses implications for the design and governance of secure systems in complex digital ecosystems where traditional organizational boundaries no longer apply.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.