5
NATIONAL CYBERSECURITY
CONTEXT
In the previous section, we explored the global nature of the cybersecurity challenge. We
noted that cybersecurity has been a worry of the international community for many years.
We considered five United Nations cybersecurity Resolutions that warn that failure to fix
the issue may lead to grave impacts on all States. Next, we explore how cyberspace has
graduated from a technical to a strategic domain. The reliance of States on cyberspace
for daily tasks, commerce and national security underlines the domain’s strategic value.
5.1
CRITICAL INFRASTRUCTURE
Cybersecurity requires coordinated cross-sector cooperation because cyberspace both
26
supports and constitutes critical infrastructure (CI). ITU-D Study Group 1 defines CI as
“the key systems, services and functions whose disruption or destruction would have a
debilitating impact on public health and safety, commerce, and national security, or any
combination of these (ITU 2008a).” Whilst what comprises CI varies across States, in
this Guide we regard typical infrastructure sectors as including health, water, transport,
communications, government, energy, food, finance and emergency services sectors.
5.1.1
Critical Information Infrastructure
ITU-D Study Group 1 notes that all the critical infrastructure sectors rely upon physical
infrastructure such as buildings, roads, plants and pipes. Increasingly, the critical sectors
27
also rely on cyberspace and the information and communication technologies (ICTs)
that enable it. The Study Group classifies cyberspace and its supporting ICTs as critical
information infrastructure (CIII). The CII operates and controls the critical sectors and
their physical assets. Consequently, ensuring the reliable functioning of cyberspace is a
28
strategic national objective because the lack of trust and confidence in the use of ICTs
could hinder daily life, commerce and national security. Cybersecurity is a strategic
domain because the complexity and interconnectedness of CII across critical sectors
makes it difficult to predict the outcome of a cyber attack. ITU Study Group 1 sees a
critical information infrastructure protection programmes (CIIP) as about protecting the
virtual aspect of CII. In this Guide, we use the phrase CIIP interchangeably with national
cybersecurity programmes. Figure 4 shows how Study Group 1 visualises the domain.
26
The ITU-D Study Group 1 addresses telecommunication policies and regulatory strategies, which best enable countries to
benefit from the impetus of telecommunications as an engine of economic, social and cultural development.
27
We use the terms cyberspace, cyber environment and critical information infrastructure interchangeably. Recommendation
ITU-T X.1205 contains a detailed definition of terms. Obtain a copy here: http://www.itu.int/rec/T-REC-X.1205-200804-I
28
According to management guru, Peter Drucker, strategic objectives fall into eight classifications including market standing
(share present and new markets); innovation (development of new goods and services) and productivity (efficient use of
resources relative to the output). Reliably functioning critical information infrastructures supports these strategic objectives.
25