Cybersecurity guide for developing countries
They represent, at best, a tentative attempt to deal with the dynamic reality facing them: fluid
technology, shifting targets, evolving hacker skills, and mutating threats and risks. There can thus be
no guarantee that a particular approach to security will provide lasting protection, nor, as a corollary,
that the return on the investment it represents can be assured.
Security strategy is often limited to setting up mechanisms to reduce the risks to which the
organization’s information assets are exposed, usually by means of a purely technological approach. A
better strategy would be one that takes into account all the dimensions of the problem and addresses
the security needs of individuals, in particular as regards the protection of privacy and basic rights.
Cybersecurity should cover everyone, extending protection to data of a personal nature.
Security solutions are already available. In many cases they are purely technological in nature,
addressing a particular problem in a specific context. But, like all technology, they are fallible and can
be circumvented. In most cases they merely displace the security problem and shift responsibility to
another part of the system they are supposed to protect. Furthermore, they are themselves in need of
protection and secure management. They can never provide absolute or final protection, due to the
evolutionary nature of the security context, itself a result of the dynamic environment (evolving needs,
risks, technologies, hacker skills, etc.). There is thus a problem because existing solutions are shortlived at best. Another problem is that the proliferation of heterogeneous solutions may harm the
overall coherence of the security strategy. Clearly, technology alone will not suffice; it must be
integrated in a management approach.
Overall coherence of the security strategy is complicated by the wide range of different entities and
individuals involved (engineers, developers, auditors, systems engineers, legal experts, investigators,
clients, suppliers, users, etc.) and by the broad array of interests, visions, environments, and languages.
A unified, systemic grasp of security risks and measures is needed, and a recognition of the respective
responsibilities of all involved, if it is hoped to achieve the level of security that is required to
confidently conduct activities using information and communication technologies, and contribute to
building confidence in the digital economy.
I.2.4
Lessons to be drawn
I.2.4.1
Take charge of security
At the start of the 21st century, most major organizations – and many smaller ones – have generally
accepted the importance of facing up to the challenges of IT security. Security strategy is no longer
conceived as merely a hotchpotch of security tools. Instead, it is widely – and correctly – viewed as an
ongoing process.
The goal of security governance is to ensure that the most suitable security measures are used at each
place and time. This concept is based on the following simple questions:
–
Who does what, how and when?
–
Who are the players who develop the rules, define and validate them, implement them and
exercise control over them?
I.2.4.2
Identify and manage the risks
The security strategy for digital infrastructures must be guided by an analysis of the risks associated
with information processing, telecommunication and cyberspace, as part of the risk management
process. The IT security risks (also referred to as computer risks, information risks or technology
risks) need to be identified along with all the other risks facing the organization (strategic, social,
environmental, etc.).
10
Cybersecurity