10 PRIORITY 2 – TECHNICAL AND PROCEDURAL MEASURES All stakeholders have an interest in increasing the resiliency and reliability of critical information infrastructure. In keeping with the second GCA pillar, this priority focuses on the development of measures for addressing vulnerabilities in hardware and software products. The measures are critical because whereas threats and threat actors change, security vulnerabilities exist throughout the life of a system or protocol unless addressed. Therefore, global security standards offer the best defence against shared vulnerabilities. 10.1 PROCEDURAL MEASURES Simply put, procedural measures are processes that help preserve the security around physical and information assets. Whilst this is a technical and procedural priority, we present the Procedural Measures first because they provide the operational context for technical measures. Security goals or context informs the selection of Procedural and Technical Measures. Without clear security goals, organisations typically fail to make effective use of security tools as it unclear what to check for and the restrictions to impose (IETF 1997). We align this priority with the strategic goals related to the Technical and Procedural Measures Pillar of the GCA as follows: GCA PILLAR: TECHNICAL AND PROCEDURAL MEASURES Corresponding GCA Goal – Procedural Measures Goal 3 Goal 5 Development of a strategy for the establishment of globally accepted minimum security criteria and accreditation schemes for hardware and software applications and systems. Development of global strategies for the creation and endorsement of a generic and universal digital identity system and the necessary organisational structures to ensure the recognition of digital credentials across geographical boundaries. Figure 16 – Procedural Measures and related GCA goals 10.1.1 Cybersecurity Goals We feel that cybersecurity goals should precede the adoption of technical and procedural measures. We hold this opinion because cybersecurity goals define the overall risk 50 tolerance . Without defining the goals, relevant stakeholders can never know when a system is sufficiently secure. We adopt the cybersecurity goals we use here from the 50 Defined simply, risk tolerance means the degree of exposure to security risk acceptable to policy makers/business owners. 51

Select target paragraph3