ANNEX TO RESOLUTION PCC.I/RES.49 (IV-04) CITEL: The Identification and Adoption of Technical Standards for a Secure Internet Architecture An effective cybersecurity strategy must recognize that the security of the network of information systems that comprise the Internet requires a partnership between government and industry. Both the telecommunications and information technology industries and the governments of OAS Member States are seeking cost-effective comprehensive cybersecurity solutions. Security capabilities in computer products are crucial to the overall network security. However, as more technologies are produced and integrated into existing networks, their compatibility and interoperability–or the lack thereof–will determine their effectiveness. Security must be developed in a manner that promotes the interweaving of acceptable security capabilities with the overall network architecture. To achieve such integrated, technology-based cybersecurity solutions, network security should be designed around international standards developed in an open process. The development of standards for Internet security architecture will require a multi-step process to ensure that adequate agreement, planning, and acceptance is achieved among the various governmental and private entities that must play a role in the promulgation of such standards. Drawing upon the work of such standards development organizations as the Standardization Sector of the International Telecommunication Union (ITU-T), CITEL is identifying and evaluating technical standards to recommend their applicability to the Americas region, bearing in mind that the development of networks in some of the OAS Member States has suffered some delays, which implies that for those countries, the achievement of a certain degree of quality for their networks will be important to fully realize adequately secure information exchange systems. To expedite its work, CITEL and the ITU-T organized a joint workshop on Cybersecurity in March 2004. CITEL is also establishing liaisons with other standards bodies and industry fora to obtain the participation and feedback of those parties. The identification of cyber security standards will be a multi-stepped process. Once CITEL's evaluation of existing technical standards is completed, it will recommend the adoption of standards of particular importance to the region. It will also, on a timely and ongoing basis, identify obstacles to implementation of those security standards in the networks of the region, and possible appropriate action that may be considered by Member States. The development of technical standards is not a “one-size-fits-all” endeavor. CITEL will evaluate regional approaches to network security, deployment strategies, information exchange, and outreach to the public and the private sector. As part of this effort CITEL will identify resources for best practices for network communication and technology-based infrastructure protection. This process will require that CITEL review the objectives, scopes, expertise, technical frameworks and guidelines associated with available resources in order to determine their applicability within the Americas region to determine which ones are most appropriate. CITEL will continue to work with Member States to assist them for the most appropriate and effective implementation. CITEL’s contribution to the cyber security strategy will take a prospective approach and seek to foster information sharing among Member States to promote secure networks. It will identify and evaluate technical issues relating to standards required for security of future communications networks across the region, as well as existing ones. This task will draw primarily on the work of ITU-T. Through CITEL, other existing standards-setting bodies will also be considered, as

Select target paragraph3