A/68/156
This Directive also calls for participation in the promotion of comprehensive
cybersecurity management within the framework of the relevant principles of the
national cybersecurity strategy.
The Defence Policy Directive, adopted in 2012, also refers to the emergence of
cyberspace as a new field of international relations and identifies as a defence
priority the strengthening of information- and intelligence-gathering systems in
order to support operations such as command and control systems with a view to
reducing the risk of cyberattacks.
In January 2011, the Head of the Chiefs of Defence Staff issued a vision of
military cyberdefence, which provides guidance for the planning, development and
use of the military capacities needed in order to ensure the effective use of
cyberspace during military operations.
4.
Possible measures that could be taken by the international community to
strengthen information security at the global level
Increased dependence on information systems and increased connectivity of
critical infrastructures have made cyberspace security essential to the functioning of
a modern State. For this reason, cybersecurity should be an intrinsic part of national
security planning.
At present, the protection of an international legal framework to meet
cybersecurity threats is lacking. Therefore, without prejudice to States’ sovereignty
in matters related to cybersecurity, there is a need for multilateral cooperation
agreements in this area (analogous or similar to the International Convention for the
Safety of Life at Sea (SOLAS)) whereby States would undertake to harmonize their
legislation with a view to the prosecution of Internet crimes while attempting to
ensure, to the extent possible, that anonymity, the absence of legislation and
economic interests do not make the Internet the ideal breeding ground for crime and
terrorism.
The private sector, and particularly Internet service providers, must be
involved in the effort to combat cybercrime. The cooperation of the private sector is
essential since most Internet services are in the hands of private companies. The
private sector has long dealt with Internet-related threats and its knowledge and
experience in this area could be very valuable.
CERTS play a key role in cybersecurity. The establishment of specialized
teams and the ongoing training of their members are the first steps that
Governments should take in order to ensure cybersecurity. It is also important to
establish law enforcement units that specialize in the investigation of crimes
committed via the Internet.
Because cybersecurity is a global challenge, international cooperation in
improving it is essential and should be strengthened at the policy and operational
levels. There should be constant communication between the CERTS of different
countries in order to facilitate the sharing of information on attacks within a short
response time. Lessons learned and best national and international practices should
also be shared.
8
13-39735