51 Internet Engineering Task Force (IETF) Site Security Handbook . The cybersecurity goals provide an organisation’s security philosophy. Additionally, the goals define security expectations, identify trade-offs and provide the basis for verifying performance. Below are the basic goals as per the Handbook. 10.1.1.1 Service offered versus Security Each service offered to users carries its own security risks. For example, many eGovernment projects are pushing government data online as additional services to citizens. However, the risk of services such as electronic voting currently outweighs the benefit. Thus, it might be better to eliminate the service rather than try to secure it. 10.1.1.2 Ease of Use versus Security Security controls restrict freedom to move about, talk and write and require users to lock doors; cars and take precious time enter passwords into devices (Parker 1997). The easiest system to use would allow access to any user and require no passwords. However, whereas the controls make system use a little less convenient, the constraints add security. Yet, excessive security may be counterproductive. For example, whereas a complex 40-character password is secure, it difficult to remember and could instead reduce security by encouraging users to write it down to aid memory. 10.1.1.3 Cost of Security versus Risk of Loss IETF (1997) identifies different security costs. These include: monetary i.e. the costs of purchasing security hardware and software such as firewalls and one-time password generators; performance i.e. the impact of security functions such as encryption on service levels; and ease of use i.e. secure systems are typically less convenient to use. The security risks include loss of privacy, loss of data and loss of service. You should weigh each cost against each type of loss. If the cost of security substantially outstrips the impact of loss, you should consider other options such as eliminating the service altogether rather than try to secure it i.e. avoid the risk. 10.1.2 National Cybersecurity Framework We recommended that countries adopt a legal strategy to coordinate activities aimed at enacting and enforcing cybercrime legislation. Likewise, we now call on States to adopt National Cybersecurity Frameworks. Cybersecurity Frameworks flow from cybersecurity goals and are the national cybersecurity governance structure. Frameworks define roles and responsibilities; allocate resources, coordinate and control activities nationally. The Frameworks define core security principles and standards that apply to a wide range of stakeholders and thus communicate the security goals. Figure 17 illustrates the process for generating national cybersecurity frameworks and indicative activities. 51 Obtain a copy of the IETF Site Security Handbook at: http://www.ietf.org/rfc/rfc2196.txt 52

Select target paragraph3