Define classes of security:
A: Tested by 3rd party sec authority to standard xyz, perhaps sub levels. $$$
B: Tested by 3rd party sec authority $$
C: Tested internally $
D: Not tested assumed secure
E: Not secure (yes we should have this)
If you make software or a product you have to choose a sec class.
Then classes regarding deployment
1: Full outbound access to the internet
2: Partial outbound access to internet
3: No outbound access to internet
If you install or deploy you have to notify client of deployment class.
So if a network installer deploys, or a customer demands Z1 they deserved to get fined for participation in a Bot Net.
Build legislation around a non financially restrictive model.
I am here by the will of the people and I won't leave until I get my raincoat back. - a slogan of the anarchists in Richard Kadrey's "Metrophage"