2
GLOBAL CONTEXT OF
CYBERSECURITY
2.1
CYBERSECURITY AND INFORMATION
SECURITY
It is a good bet that you are reading this Guide because you have responsibility for, or an
interest in, cybersecurity. We are sure, therefore, that you know the terms cybersecurity
and information security. Perhaps, even at expert level. For the benefit of all readers, we
contrast the terms. We deem it an important exercise because the views formed about
the two terms might either lead to a false sense of security or panic about cyber risks.
1
Both concepts aim to attain and maintain the security properties of confidentiality ,
2
3
integrity and availability (ITU 2008d). However, the global reach of the Internet gives
cybersecurity a unique character. First, whilst information security started when most
systems were standalone and rarely traversed jurisdictions, cybersecurity works on
global threats under legal uncertainty. Thus, laws created for information security are
4
woefully inadequate in the Internet era. Second, cybersecurity has to contend with an
5
6
Internet architecture that makes it virtually impossible to attribute an attack to an actor
(Sinks 2008). Third, due to its origins in the military and diplomatic services, information
7
security typically focuses on confidentiality. Whilst WikiLeaks underlined the import of
8
9
confidentiality, cybersecurity focuses more on integrity and availability . Thus,
cybersecurity is information security with jurisdictional uncertainty and attribution issues.
2.2
THE AGE OF CYBER ATTACKS
As we see later, a cyber attack occurs if a threat successfully breaches security controls.
Evidence shows that cyber attacks are growing in sophistication, frequency and gravity.
Our ever-growing reliance upon cyberspace places all Governments, businesses, other
organisations and individual users at the risk of computer-enabled fraud, sabotage and
vandalism. Accordingly, cyber threat actors routinely access, steal and corrupt sensitive
10
corporate and government information. The ITU notes that even prominent tech-savvy
companies are not immune anymore. Reported victims of cyber attacks include Google,
RSA, Sony, Lockheed Martin, PBS, Epsilon and Citibank. This list of victims includes
security companies, defense contractors and some of the brightest lights in technology.
We expect the list to be longer as many organisations do not report cyber attacks due to
legal and reputational risk concerns. Worse still, a worrying number of organisations lack
the capacity to detect attacks. Awareness of an attack is not an issue if the perpetrators
1
Confidentiality focuses on providing assurance that access to information is restricted to authorised parties only
The integrity principle deals with the prevention of unauthorised modification of information. Integrity also covers trust in the
accuracy, completeness and thus reliability of information.
3
Availability aims to provide assurance that assets will be accessible to authorised users in a timely manner if required.
4
The UK Computer Misuse Act 1990 is a prime example. The law came into force well before the widespread use of the
Internet and in particular the World Wide Web. The UK updated its cybercrime law under Police and Justice Act 2006.
5
IPv6, the upgrade from IPv4 will significantly reduce the anonymity of online transactions
6
Find the ITU Security Manual here: http://www.itu.int/dms_pub/itu-t/opb/hdb/T-HDB-SEC.04-2009-PDF-E.pdf
7
WikiLeaks enabled one of the largest unauthorised computerised disclosures of classified government information.
8
Integrity is a focus due to low trust in the accuracy, completeness and hence reliability of information.
9
Availability is critical in cyberspace due to concerns that information, systems and assets may not be available to authorised
users in a timely manner if required.
10
Obtain the ITU “Making the Online World Safer” document here: http://www.itu.int/net/itunews/issues/2011/05/38.aspx
2
13