Cybersecurity guide for developing countries The quality of IT security depends primarily on the identification and evaluation of the value of the information assets, operational deployment of appropriate security measures based on a well-conceived security policy, and effective management. I.2.4.4 Deploy the solutions Various types of measures need to be instituted to make the IT and telecommunication infrastructure more secure. These include: – build awareness; educate and train all stakeholders for cybersecurity; – create units that can function as the national early-warning and crisis-response centre, pool the resources necessary to do so effectively and share them across several countries, for a region; – institute surveillance and checks (analogous to road checks); – build expertise in a cyberpolice team that can contribute to a cooperative international effort for the investigation and prosecution of computer-related crime; – develop technological solutions for identity management, access control, the use of secure hardware and software platforms, back-up infrastructures, encryption protocols and operational management. I.2.5 The management perspective I.2.5.1 Dynamic management5 Approaching security through a dynamic and continuous management process positions the organization to deal with the dynamic nature of the risk and the evolving needs, by continuously adapting and improving its solutions. The quality of the security management will determine the level of security provided. The cybersecurity policy should be defined at the level of top management. There are as many security strategies, policies, measures, procedures and solutions as there are organizations with security needs that need to be met at any particular time. For an example of the dynamic context within which security management must operate, consider the process of detecting and patching security vulnerabilities. This is done by means of periodic issues of security patches. Information newsletters, more or less customized, make it possible to stay informed about vulnerabilities that have been detected and how to patch them up. If a minimum level of security is to be maintained, the security administrator or system administrator will have to install the security patches as they are issued. However, knowledge of dangerous system vulnerabilities is useful not just to the security administrator, but also to hackers, who may attempt to exploit them before the patches have been applied. It is therefore imperative to allocate sufficient resources to implement a dynamic management that continuously updates the security solutions and thus maintains a consistent level of security. Published alerts and patches allow the administrator to control the update process (by choosing whether to install those patches or not); it is also possible to do so in automatic mode, effectively delegating the responsibility for regular and systematic patch installation to the software publisher. This raises the question of responsibility. For example, what are the legal consequences of a software update that has been declined, when problems arise from the exploitation of an uncorrected vulnerability? Since numerous attacks do just that, the question of who decides, and the responsibility of the system administrator, is a very pertinent one. 5 The following two sections are adapted from an article entitled “Sécurité informatique, la piège de la dépendance”, A. Dufour, G. Ghernaouti-Hélie, Revue Information et Système, 2006. Cybersecurity 13

Select target paragraph3