Government Cybersecurity Policies Many OAS Member States began their cybersecurity efforts by establishing CSIRTs. In fact, most countries, save some Caribbean states, now have national-level incident response capabilities. These CSIRTs represent the full spectrum of development. Some provide varied incident response and prevention services, while others are still facing difficulties protecting their networks. Problems facing the latter group are complicated by difficulties securing human and financial resources, precluding improved operations. Even the Caribbean states that have not yet established a national CSIRT have acknowledged the important role cybersecurity plays in economic and social development. Some maintain cyberforensic labs or will shortly launch CSIRTs. Still, significant barriers remain, including those particular to small island states. Even where operating a CSIRT may not make sense, Caribbean countries are taking other practical measures to mitigate cybersecurity risks, including raising awareness and strengthening police cybercrime units, although most governments agree that more needs to be done.9 Incident response only represents one area of cybersecurity in which Latin American and Caribbean states have made significant progress. Many are following the recent trend set by countries like Canada, Estonia, Germany, Japan, the United Kingdom, and the United States, and beginning to draft comprehensive national cybersecurity policies and strategies. With the support of the OAS, Colombia became the first Latin American country to adopt a comprehensive national cybersecurity and cyberdefense strategy. Countries like Chile, Peru, Mexico, Trinidad and Tobago, Uruguay, and others are endeavoring to do the same. Emulating those adopted by North American and European governments, Latin American and Caribbean strategies identify key stakeholders, delineate roles and responsibilities, establish coordination and information-sharing mechanisms, and prepare strategic action plans for national cybersecurity efforts. Recent acknowledgment of vulnerabilities in critical infrastructures has spurred several OAS Member States to adopt initiatives seeking to strengthen their ICS security. Argentina, for instance, will host the “2013 Meridian Conference” on critical infrastructure protection, the first Latin American country to do so.10 Panama’s development of a national strategy also stressed the importance of protecting important ICS, especially those whose compromise would negatively affect businesses on a global scale. Mexico similarly acknowledged the acute risks that threats to ICS pose and supported specialized training for many of its incident response technicians. These three countries are just a few of those working to secure the increasingly important yet still vulnerable ICS in the region. Many others are studying technical- or policy-based measures for securing their most important infrastructures. 9 10 Agreements have been reached during the August 2012 Cybersecurity and Cybercrime Workshop for the Caribbean and during the 2013 OAS Permanent Council Meeting of the Committee on Hemispheric Security on “Special Security Concerns of Small Island States of the Caribbean.” https://www.meridian2012.org/pages/the-conference PAGE 19 | Latin American and Caribbean Cybersecurity Trends and Government Responses

Select target paragraph3