The creation of the hemispheric network of CSIRTs will require a series of progressive steps
that will depend upon the active participation of the member states:
•
Identification of Existing CSIRT Organizations – A survey of CSIRTs must be
conducted within the Hemisphere to identify gaps in the coverage of CSIRTs that
currently exist in the Hemisphere and to prevent redundant efforts.
•
Establishment of a Service Model – National CSIRTs should be so designated by
their respective governments and certified and accredited in accordance with
international norms in the computer security community. They should also establish
a minimum set of standards for cooperation and information-sharing among CSIRTs,
as enumerated in CICTE/REGVAC/doc.2/04.
•
Addressing Trust Issues – Since much of the information that CSIRTs need to
exchange is proprietary or otherwise sensitive, trust must be developed among the
participants as an essential element of the hemispheric network. To build such
trusted relationships, CSIRTs should be created to possess the attributes and
capabilities identified in CICTE/REGVAC/doc.2/04, which include a secure
infrastructure for managing sensitive information; the ability to communicate
securely with stakeholders; and procedures to guard against inappropriate disclosure
of information. Member states will always maintain the right to decide on the type of
information that will be exchanged through their designated CSIRTs.
•
Building Public Awareness – National CSIRTs should ensure the public knows how
to report a cyber incident and to whom.
•
Extending the Network – Member states will consider, when appropriate, extending
the capability of the hemispheric network, with a view to assisting states that so
request in the development of specific plans, obtaining funding, and developing
capacity-building projects.
•
Maintaining the Network – The Group of Government Cybersecurity Practitioners
would meet periodically as necessary and as convened by CICTE, within available
resources.
CITEL: The Identification and Adoption of Technical Standards for a Secure Internet
Architecture
The IV Meeting of Permanent Consultative Committee I: Telecommunication
Standardization, held in Quito, Ecuador, from March 16 to 19, 2004, adopted the attached resolution,
CCP.I/RES.49 (IV-04), 5/ "Cybersecurity," after conducting a joint workshop with the International
Telecommunication Union (ITU) that addressed key issues of cybersecurity as related to CITEL. The
said resolution, which encompasses the contribution of CITEL to the Comprehensive Inter-American
Cybersecurity Strategy, provides guidance for the future work to be developed by CITEL in that area.
5
.
Appendix II.