3. Security cluster The public policy issues in the security cluster aim to ensure functional and reliable use of the Internet. The security cluster highlights cybersecurity as its main umbrella issue, and includes other more specific Internet policy issues. 3.1 Cybersecurity There is no agreed definition of what cybersecurity is. The broad understanding is that it includes issues related to technical security of networks, national security and security for the general public. It is an umbrella concept covering several areas: cybercrime, critical information infrastructure protection (CIIP), and cyberconflicts. Most online threats come about as a result of software and hardware vulnerabilities exploited by organised and expanding global cybercrime communities. The international community still lacks a systematic and decisive approach to combating these global cybercrime groups. Status of governance mechanisms for cybersecurity At national level, a growing volume of legislation and jurisprudence deals with cybersecurity, with a focus on combating cybercrime and, increasingly, protecting the critical information infrastructure from sabotage and attacks as a result of conflicts and terrorist attacks. At regional levels, more and more organisations are realising the importance of cybersecurity and are working on strategies, recommendations, and conventions, such as the Council of Europe Convention on Cybercrime, the Asia-Pacific Economic Cooperation (APEC) Strategy on Secure Online Space, the EU Cybersecurity Strategy, the OSCE Decision on ConfidenceBuilding measures, and the African Cybersecurity Convention. At the international level, the UN General Assembly has passed several resolutions on a yearly basis on ‘developments in the field of information and telecommunications in the context of international security’. The ITU has produced a large number of security standards and recommendations. A security on provision was included in the 2012 International Telecommunication Regulations (ITRs). One of the main G8 developments in cybersecurity was establishing 24/7 communication between the cybersecurity centres of member states. The Forum of Incident Response and Security Teams (FIRST) is an international technical network which coordinates the activities of national and regional Computer Emergency Response Teams (CERTs). For the network security, a key existing mechanism is the Security and Stability Advisory Committee (SSAC) under ICANN. A series of Conferences on Cyberspace has been held in London (2011), Budapest (2012) and Seoul (2013). 17

Select target paragraph3