51
Internet Engineering Task Force (IETF) Site Security Handbook . The cybersecurity
goals provide an organisation’s security philosophy. Additionally, the goals define
security expectations, identify trade-offs and provide the basis for verifying performance.
Below are the basic goals as per the Handbook.
10.1.1.1 Service offered versus Security
Each service offered to users carries its own security risks. For example, many eGovernment projects are pushing government data online as additional services to
citizens. However, the risk of services such as electronic voting currently outweighs the
benefit. Thus, it might be better to eliminate the service rather than try to secure it.
10.1.1.2 Ease of Use versus Security
Security controls restrict freedom to move about, talk and write and require users to lock
doors; cars and take precious time enter passwords into devices (Parker 1997). The
easiest system to use would allow access to any user and require no passwords.
However, whereas the controls make system use a little less convenient, the constraints
add security. Yet, excessive security may be counterproductive. For example, whereas a
complex 40-character password is secure, it difficult to remember and could instead
reduce security by encouraging users to write it down to aid memory.
10.1.1.3 Cost of Security versus Risk of Loss
IETF (1997) identifies different security costs. These include: monetary i.e. the costs of
purchasing security hardware and software such as firewalls and one-time password
generators; performance i.e. the impact of security functions such as encryption on
service levels; and ease of use i.e. secure systems are typically less convenient to use.
The security risks include loss of privacy, loss of data and loss of service. You should
weigh each cost against each type of loss. If the cost of security substantially outstrips
the impact of loss, you should consider other options such as eliminating the service
altogether rather than try to secure it i.e. avoid the risk.
10.1.2
National Cybersecurity Framework
We recommended that countries adopt a legal strategy to coordinate activities aimed at
enacting and enforcing cybercrime legislation. Likewise, we now call on States to adopt
National Cybersecurity Frameworks. Cybersecurity Frameworks flow from cybersecurity
goals and are the national cybersecurity governance structure. Frameworks define roles
and responsibilities; allocate resources, coordinate and control activities nationally. The
Frameworks define core security principles and standards that apply to a wide range of
stakeholders and thus communicate the security goals. Figure 17 illustrates the process
for generating national cybersecurity frameworks and indicative activities.
51
Obtain a copy of the IETF Site Security Handbook at: http://www.ietf.org/rfc/rfc2196.txt
52