Government Cybersecurity Policies
Many OAS Member States began their cybersecurity efforts by establishing
CSIRTs. In fact, most countries, save some Caribbean states, now have
national-level incident response capabilities. These CSIRTs represent the
full spectrum of development. Some provide varied incident response and
prevention services, while others are still facing difficulties protecting their
networks. Problems facing the latter group are complicated by difficulties
securing human and financial resources, precluding improved operations. Even
the Caribbean states that have not yet established a national CSIRT have
acknowledged the important role cybersecurity plays in economic and social
development. Some maintain cyberforensic labs or will shortly launch CSIRTs.
Still, significant barriers remain, including those particular to small island states.
Even where operating a CSIRT may not make sense, Caribbean countries
are taking other practical measures to mitigate cybersecurity risks, including
raising awareness and strengthening police cybercrime units, although most
governments agree that more needs to be done.9
Incident response only represents one area of cybersecurity in which Latin
American and Caribbean states have made significant progress. Many are
following the recent trend set by countries like Canada, Estonia, Germany,
Japan, the United Kingdom, and the United States, and beginning to draft
comprehensive national cybersecurity policies and strategies. With the support
of the OAS, Colombia became the first Latin American country to adopt a
comprehensive national cybersecurity and cyberdefense strategy. Countries
like Chile, Peru, Mexico, Trinidad and Tobago, Uruguay, and others are
endeavoring to do the same. Emulating those adopted by North American and
European governments, Latin American and Caribbean strategies identify key
stakeholders, delineate roles and responsibilities, establish coordination and
information-sharing mechanisms, and prepare strategic action plans for national
cybersecurity efforts.
Recent acknowledgment of vulnerabilities in critical infrastructures has spurred
several OAS Member States to adopt initiatives seeking to strengthen their
ICS security. Argentina, for instance, will host the “2013 Meridian Conference”
on critical infrastructure protection, the first Latin American country to do so.10
Panama’s development of a national strategy also stressed the importance of
protecting important ICS, especially those whose compromise would negatively
affect businesses on a global scale. Mexico similarly acknowledged the acute
risks that threats to ICS pose and supported specialized training for many
of its incident response technicians. These three countries are just a few of
those working to secure the increasingly important yet still vulnerable ICS in
the region. Many others are studying technical- or policy-based measures for
securing their most important infrastructures.
9
10
Agreements have been reached during the August 2012 Cybersecurity and Cybercrime
Workshop for the Caribbean and during the 2013 OAS Permanent Council Meeting of the
Committee on Hemispheric Security on “Special Security Concerns of Small Island States of
the Caribbean.”
https://www.meridian2012.org/pages/the-conference
PAGE 19 | Latin American and Caribbean Cybersecurity Trends and Government Responses