Ambition 3. Some popular protocols for data exchange
via the internet are decades old and are no longer
resistant to contemporary attacks. Improved versions of
old internet standards (such as IPv6, or HTTPS) are being
adopted very slowly and as a result the drawbacks of the
old versions (IPv4 and HTTP) will continue to be an issue
for some time.
Businesses and public authorities depend on other
organisations for their data processing, including cloud
providers and their customers, public authorities who
make open data available and certificate providers who
guarantee the integrity of data exchange. The Dutch
government aims to make important (chain)
interdependencies between organisations transparent
but realises that it is not feasible to have a full grasp of
these at all times. The Dutch government is therefore
calling for all organisations to be able to respond
appropriately when the continuity of their services is at
risk. The Digital Trust Center, currently in development,
aims to help parties in this regard by raising awareness
and offering perspectives for action. The center will do
this in consultation with the NCSC and various other
parties, including small and medium businesses. Where
organisations want to use the services of cybersecurity
service providers, it is important that also they deal with
computer networks and sensitive information in a
professional manner and with integrity. Many Dutch
organisation are dependent on a limited number of
foreign digital infrastructure service providers, which
means that the impact of disruption is severe.
Example: Heartbleed
Heartbleed was a vulnerability in the OpenSSL
programming library, which was discovered in 2014.
At the time, the vulnerability had already been
present in this commonly used software for two
years. Many web servers, VPN servers, mail servers
and other applications use OpenSSL to establish
secure connections. Other devices can also use
OpenSSL. Examples include appliances, routers, WiFi
access points and some applications on client systems.
By exploiting Heartbleed, attackers could read the
internal memory of systems remotely. This example
underlines the fact that a vulnerability in open source
software can have major consequences for the
cybersecurity of the business community, public
authorities and citizens.
32 | National Cyber Security Agenda A cyber secure Netherlands
OBJECTIVES
• All relevant parties will be involved in ensuring the
continuity and digital resilience of critical processes
which increases the resilience of the entire chain.
• The Netherlands aims to improve the quality of open
source software and the accelerated adoption of
modern internet protocols and internet standards.
• The Dutch government promotes an innovative
cybersecurity climate in which secure ICT products
and services are developed and adopted.
MEASURES
o In addition to existing obligations for
telecommunications providers under the
Telecommunications Act, the proposal for the
Cybersecurity Act greatly increases the number of
providers of critical services subject to duty of care
requirements and an obligation for notification.
Sectoral supervisory bodies will supervise
cybersecurity in sectors in critical infrastructure, which
was not done up to now, and they will be given the
instruments to do so.
o In addition to the above, these supervisory bodies,
together with the responsible ministries, will develop
a method for identifying dependency relationships of
providers of critical services for their own data-driven
operating processes.
o Research will be conducted into whether additional
(European or international) measures are needed to
mitigate the impact of disruption of the services of a
limited number of foreign providers of digital
infrastructure upon which many Dutch organisations
depend.
o Open source software fulfils a central role in the
exchange of data between organisations. The Ministry
of Economic Affairs and Climate Policy, in close
cooperation with the NCSC, will review how the
communities that develop and maintain open source
software can be supported to improve the quality of
the software.
o The government ensures that suppliers incorporate
modern internet protocols and internet standards in
their products and services, in part through agendasetting in Europe.
o The government, as a launching customer, uses
cybersecurity requirements when procuring ICT
products and services and strongly advices providers
of critical services on this matter.