2 GLOBAL CONTEXT OF CYBERSECURITY 2.1 CYBERSECURITY AND INFORMATION SECURITY It is a good bet that you are reading this Guide because you have responsibility for, or an interest in, cybersecurity. We are sure, therefore, that you know the terms cybersecurity and information security. Perhaps, even at expert level. For the benefit of all readers, we contrast the terms. We deem it an important exercise because the views formed about the two terms might either lead to a false sense of security or panic about cyber risks. 1 Both concepts aim to attain and maintain the security properties of confidentiality , 2 3 integrity and availability (ITU 2008d). However, the global reach of the Internet gives cybersecurity a unique character. First, whilst information security started when most systems were standalone and rarely traversed jurisdictions, cybersecurity works on global threats under legal uncertainty. Thus, laws created for information security are 4 woefully inadequate in the Internet era. Second, cybersecurity has to contend with an 5 6 Internet architecture that makes it virtually impossible to attribute an attack to an actor (Sinks 2008). Third, due to its origins in the military and diplomatic services, information 7 security typically focuses on confidentiality. Whilst WikiLeaks underlined the import of 8 9 confidentiality, cybersecurity focuses more on integrity and availability . Thus, cybersecurity is information security with jurisdictional uncertainty and attribution issues. 2.2 THE AGE OF CYBER ATTACKS As we see later, a cyber attack occurs if a threat successfully breaches security controls. Evidence shows that cyber attacks are growing in sophistication, frequency and gravity. Our ever-growing reliance upon cyberspace places all Governments, businesses, other organisations and individual users at the risk of computer-enabled fraud, sabotage and vandalism. Accordingly, cyber threat actors routinely access, steal and corrupt sensitive 10 corporate and government information. The ITU notes that even prominent tech-savvy companies are not immune anymore. Reported victims of cyber attacks include Google, RSA, Sony, Lockheed Martin, PBS, Epsilon and Citibank. This list of victims includes security companies, defense contractors and some of the brightest lights in technology. We expect the list to be longer as many organisations do not report cyber attacks due to legal and reputational risk concerns. Worse still, a worrying number of organisations lack the capacity to detect attacks. Awareness of an attack is not an issue if the perpetrators 1 Confidentiality focuses on providing assurance that access to information is restricted to authorised parties only The integrity principle deals with the prevention of unauthorised modification of information. Integrity also covers trust in the accuracy, completeness and thus reliability of information. 3 Availability aims to provide assurance that assets will be accessible to authorised users in a timely manner if required. 4 The UK Computer Misuse Act 1990 is a prime example. The law came into force well before the widespread use of the Internet and in particular the World Wide Web. The UK updated its cybercrime law under Police and Justice Act 2006. 5 IPv6, the upgrade from IPv4 will significantly reduce the anonymity of online transactions 6 Find the ITU Security Manual here: http://www.itu.int/dms_pub/itu-t/opb/hdb/T-HDB-SEC.04-2009-PDF-E.pdf 7 WikiLeaks enabled one of the largest unauthorised computerised disclosures of classified government information. 8 Integrity is a focus due to low trust in the accuracy, completeness and hence reliability of information. 9 Availability is critical in cyberspace due to concerns that information, systems and assets may not be available to authorised users in a timely manner if required. 10 Obtain the ITU “Making the Online World Safer” document here: http://www.itu.int/net/itunews/issues/2011/05/38.aspx 2 13

Select target paragraph3