evsjv‡`k †M‡RU, AwZwi³, gvP© 11, 2014
9709
Action 3: Critical Information Infrastructure Protection
This Action focuses on defining a process for tracking and fixing vulnerabilities;
improving attack attribution and prevention capabilities.
Vulnerabilities are weaknesses that allow a threat or attack to break a system’s
confidentiality, integrity and availability defenses. Most of cyber attacks result
from poor technical designs or the exploitation of known but unfixed
vulnerabilities. The impact of the exploitation of vulnerability depends on the
value and criticality of information. Critical information infrastructures inevitably
store valuable information.
The National Cybersecurity Strategy identifies the following major actions and
initiatives to reduce threats and related vulnerabilities in Bangladesh:
• Create a process for national vulnerability assessments to help understand the
potential consequences of threats and vulnerabilities;
• Designate important systems as critical information infrastructure and enforce
an accreditation regime around them. For example, no system will connect to
critical infrastructure without a penetration test and other assurance activities;
• Enhance law enforcement capabilities in the investigation, prevention and
prosecution of cybercrimes;
• Require the use of evaluated software products;
• Prioritize national cybersecurity research and development activities;
• Assess and secure emerging systems; and
• Participate in international efforts to improve the security of Internet protocols
and routing technologies.
Priority 3: Organisational Structures
This Priority Area requires the building of organizational structures and strategies
to help prevent, detect and respond to attacks against critical infrastructure. The
National Cybersecurity Strategy identifies the actions below as essential for
creating appropriate national and regional organizational structures and policies
on cybercrime: