An effective cybersecurity strategy must recognize that the security of the network of
information systems that comprise the Internet requires a partnership between government and industry.
Both the telecommunications and information technology industries and the governments of OAS
member states are seeking cost-effective comprehensive cybersecurity solutions. Security capabilities in
computer products are crucial to the overall network security. However, as more technologies are
produced and integrated into existing networks, their compatibility and interoperability--or the lack
thereof--will determine their effectiveness. Security must be developed in a manner that promotes the
integration of acceptable security capabilities into the overall network architecture. To achieve such
integrated, technology-based cybersecurity solutions, network security should be designed around
international standards developed in an open process.
The development of standards for Internet security architecture will require a multi-step process
to ensure that adequate agreement, planning, and acceptance are achieved among the various
governmental and private entities that must play a role in the promulgation of such standards. Drawing
upon the work of such standards development organizations as the Standardization Sector of the
International Telecommunication Union (ITU-T), CITEL is identifying and evaluating technical
standards to recommend their applicability to the Americas region, bearing in mind that the
development of networks in some of the OAS member states has suffered some delays, which implies
that for those countries, the achievement of a certain degree of quality for their networks will be
important to fully realize adequately secure information exchange systems. CITEL is also establishing
liaisons with other standards bodies and industry forums to obtain the participation and feedback of
those parties.
The identification of cybersecurity standards will also be a multi-step process. Once CITEL's
evaluation of existing technical standards is completed, it will recommend the adoption of standards of
particular importance to the region. It will also, on a timely and ongoing basis, identify obstacles to the
implementation of those security standards in the networks of the region, and possible appropriate
action that may be considered by member states.
The development of technical standards is not a “one-size-fits-all” endeavor. CITEL will
evaluate regional approaches to network security, deployment strategies, information exchange, and
outreach to the public and the private sector. As part of this effort, CITEL will identify resources for
best practices for network communication and technology-based infrastructure protection. This process
will require that CITEL review the objectives, scope, expertise, technical frameworks, and guidelines
associated with available resources, in order to determine their applicability within the Americas region
to determine which ones are most appropriate. CITEL will continue to work with member states to
assist them in the most appropriate and effective implementation.
CITEL’s contribution to the Comprehensive Inter-American Cybersecurity Strategy will take a
prospective approach and seek to foster information-sharing among member states to promote secure
networks. It will identify and evaluate technical issues relating to standards required for the security of
future communications networks across the region, as well as existing ones. This task will draw
primarily on the work of ITU-T. Through CITEL, other existing standards-setting bodies will also be
considered, as appropriate. Ultimately, CITEL will highlight security standards of particular importance
and recommend that member states endorse those standards. It is also important to highlight the crucial
role of CITEL in promoting capacity-building and training programs so as to advance the process of
spreading technical and practical information related to cybersecurity issues.