APPENDIX A A COMPREHENSIVE INTER-AMERICAN CYBERSECURITY STRATEGY: A MULTIDIMENSIONAL AND MULTIDISCIPLINARY APPROACH TO CREATING A CULTURE OF CYBERSECURITY INTRODUCTION The Internet and related networks and technologies have become indispensable tools for OAS member states. The Internet has spurred tremendous growth in the global economy and prompted gains in efficiency, productivity, and creativity across the Hemisphere. Individuals, businesses, and governments increasingly use the information networks that comprise the Internet to, inter alia, conduct business; manage personal, industrial, and governmental activities; transmit communications; and perform research. Moreover, at the Third Summit of the Americas, held in Quebec City, Canada, in 2001, our leaders committed to further increasing connectivity in the Americas. Unfortunately, the Internet has also spawned new threats that endanger the entire global community of Internet users. Information that transits the Internet can be misappropriated and manipulated to invade users’ privacy and defraud businesses. The destruction of data that reside on computers linked by the Internet can stymie government functions and disrupt public telecommunications service and other critical infrastructures. Such threats to our citizens, economies, and essential services, such as electricity networks, airports, or water supplies, cannot be addressed by a single government or combated using a solitary discipline or practice. As recognized by the General Assembly in resolution AG/RES. 1939 (XXXIII-O/03), “Development of an Inter-American Strategy to Combat Threats to Cybersecurity,” a comprehensive strategy for protecting information infrastructures that adopts an integral, international, and multidisciplinary approach is needed. The OAS is committed to the development and implementation of such a cybersecurity strategy and, in furtherance of this, held a Conference on Cybersecurity (Buenos Aires, Argentina, July 28-29, 2003) that demonstrated the gravity of cybersecurity threats to the security of critical information systems, critical infrastructures, and economies throughout the world, and underscored that effective action to deal with this issue must involve intersectoral cooperation and coordination among a broad range of governmental and nongovernmental entities.1/ Similarly, at the Special Conference on Security (Mexico City, Mexico, October 28-29, 2003) the member states considered the cybersecurity issue and agreed as follows: "We will develop a culture of cybersecurity in the Americas by taking effective preventive measures to anticipate, address, and respond to cyberattacks, whatever their origin, fighting against cyber threats and cybercrime, criminalizing attacks against cyberspace, protecting critical infrastructure and securing networked systems. We reaffirm our commitment to develop and implement an integral OAS cybersecurity strategy, utilizing the contributions and recommendations developed jointly by member state experts and the REMJA Governmental Experts Group on Cybercrime, CICTE, the Inter-American Telecommunication Commission (CITEL), and other appropriate organs, 1 . Report on the Conference on Cybersecurity, document OEA/Ser.L/X.5, CICTE/CS/doc.2/03.

Select target paragraph3