The creation of the hemispheric network of CSIRTs will require a series of progressive steps that will depend upon the active participation of the member states: • Identification of Existing CSIRT Organizations – A survey of CSIRTs must be conducted within the Hemisphere to identify gaps in the coverage of CSIRTs that currently exist in the Hemisphere and to prevent redundant efforts. • Establishment of a Service Model – National CSIRTs should be so designated by their respective governments and certified and accredited in accordance with international norms in the computer security community. They should also establish a minimum set of standards for cooperation and information-sharing among CSIRTs, as enumerated in CICTE/REGVAC/doc.2/04. • Addressing Trust Issues – Since much of the information that CSIRTs need to exchange is proprietary or otherwise sensitive, trust must be developed among the participants as an essential element of the hemispheric network. To build such trusted relationships, CSIRTs should be created to possess the attributes and capabilities identified in CICTE/REGVAC/doc.2/04, which include a secure infrastructure for managing sensitive information; the ability to communicate securely with stakeholders; and procedures to guard against inappropriate disclosure of information. Member states will always maintain the right to decide on the type of information that will be exchanged through their designated CSIRTs. • Building Public Awareness – National CSIRTs should ensure the public knows how to report a cyber incident and to whom. • Extending the Network – Member states will consider, when appropriate, extending the capability of the hemispheric network, with a view to assisting states that so request in the development of specific plans, obtaining funding, and developing capacity-building projects. • Maintaining the Network – The Group of Government Cybersecurity Practitioners would meet periodically as necessary and as convened by CICTE, within available resources. CITEL: The Identification and Adoption of Technical Standards for a Secure Internet Architecture The IV Meeting of Permanent Consultative Committee I: Telecommunication Standardization, held in Quito, Ecuador, from March 16 to 19, 2004, adopted the attached resolution, CCP.I/RES.49 (IV-04), 5/ "Cybersecurity," after conducting a joint workshop with the International Telecommunication Union (ITU) that addressed key issues of cybersecurity as related to CITEL. The said resolution, which encompasses the contribution of CITEL to the Comprehensive Inter-American Cybersecurity Strategy, provides guidance for the future work to be developed by CITEL in that area. 5 . Appendix II.

Select target paragraph3