Cybersecurity guide for developing countries IT risks are operational risks, which need to be mastered. At the heart of risk management is an analysis of security needs, which makes it possible to define a security strategy and security policy. A number of questions need to be asked at this stage: – – – – – – – Who will be in charge of the risk analysis and risk management? What is the best way to conduct the analysis? What tools and methods are available? How reliable are they? How much emphasis will there be on results? What are the costs? Would it be better to outsource this function ? Etc. Risk may be defined as a danger that can be anticipated to some extent. It is quantified by the likelihood of damage and the resulting harm. Risk expresses the probability of an asset or value being lost due to a vulnerability connected with some hazard or danger. In deciding on the desired level of protection and the types of security measures to put in place, it is necessary to balance the magnitude of the risk (in financial terms) against what it would cost to reduce it (see Figure I.5). As a minimum, the assets to be protected must be identified, along with the rationale for protecting them, depending on actual constraints and the available organizational, financial, human and technical resources. The measures taken must be effective, and must reflect a balance between performance and cost-effectiveness. For an organization, mastering IT risks means elaborating a strategy, defining a security policy and deciding on its tactical and operational implementation. Figure II.4 Différents compromis la maîtrise des risques : un choix politique Figure I.5 – Trade-offs in controlling risk: a policypour decision Risks Risques IT and Infrastructure telecommunication Informatique infrastructure & Télécommunication maîtrise du risque Reduce risks to an Réduire les risques acceptable level à un niveau acceptable Maîtrise des Risk control risques Cost Coûtofdurisk Risquecost versus ofVersus controlling Coût de risk Besoin de protection Protection Versus versus Besoin de production production Politique sécurité Security de policy Minimiser les pertes Minimize losses Permettre un usage efficace des Make sure technology can betechnologies used effectively I.2.4.3 Define a security policy The security policy translates what is understood about the risks and their impact into security measures for implementation. It facilitates both prevention and remedial action in response to security problems, and helps to reduce the risks and their impact. Cybersecurity 11

Select target paragraph3