Cybersecurity guide for developing countries While it is impossible to eliminate risk entirely, and difficult to anticipate all the emerging threats, it is important to reduce the vulnerability of environments and resources that are to be protected, as it certainly lies at the origin of many of the security problems. The security policy should specify, among other things, the resources, structure, procedures, and plans for defence and mitigation to ensure that operational, technological and information risks can be controlled. ISO 17799 proposes a code of practice for security management. It can be considered as a reference for defining a security policy; as a checklist for analysing risk; as a security audit tool, whether for purposes of certification or not; or as a communication hub for security. The standard can be interpreted, and implemented, in various ways. Its value resides in the fact that it addresses the organizational, human, legal and technological aspects of security at each of the different stages of design, implementation and maintenance of security. The 2005 version of the standard (ISO/IEC 17799:2005)4 emphasizes risk evaluation and analysis, management of assets and resources, and incident management. This is indicative of the importance that is attached to the management dimension of security. Figure I.6 – To manage security, first define a security policy The components of a security policy What to protect? From whom? Against what are we protecting ourselves? Why? Organization of security Assign responsibilities to the competent individuals with the necessary authority and resources What are the real risks? Can they be tolerated? Identify security targets for each domain and component of the information system Define the threats and identify vulnerabilities What is the organization’s current security position? What is the desired level of security? Define security measures Define security practices What are the real constraints? What are the available resources? How should they be deployed? The effectiveness of a security policy should not be measured by the size of its budget; rather, it depends on the risk-management policy, and on the quality of the risk analysis (Figure I.6). Among the factors that determine the risk are the area of activity of an organization, its size, its image, system sensitivity, the system environment and associated threats, and the degree to which the organization depends on its information system. 4 The table of contents of the standard is given in Annex B to this guide. 12 Cybersecurity

Select target paragraph3