Cybersecurity guide for developing countries
needed to respond to attacks and prosecute the attackers. For this, back-up and continuity plans must
be designed and put into place, incorporating the constraints related to the investigation and
prosecution of cybercrime within the different work processes and objectives, with specific
time-scales.
I.2.6
The political dimension
I.2.6.1
Responsibility of the State
The State possesses considerable responsibility for making digital security a reality. This is
particularly true for the definition of an appropriate legal framework, one that is unified and practical.
The State should not merely promote and encourage research and development in security but also
promote a security culture and demand compliance with minimum security standards (security should
be built into products and services), while strengthening law enforcement in respect of cybercrime.
This raises the question of the underlying financial model and public-private partnership for national
and international action plans.
At the strategic level it is necessary to ensure prevention, reporting, information sharing and alert
management. It is also necessary to raise awareness of best practices in risk management and security.
Another important requirement is for coordination and harmonization of legal systems. Assistance to
promote law enforcement and security, the elaboration of proposed cooperative ventures
(formal/informal, multilateral/bilateral, active/passive, national/international) must also be defined.
At the same time, it is essential to provide education, information and training in information
processing and communication technologies, not merely security and deterrent measures. Building
awareness of security issues should not be limited to the promotion of a particular security culture and
cyber code of conduct. The security culture must be underpinned, upstream, by an IT culture.
The different players must be given the means to learn to manage the technological, operational and
information risks that threaten them in connection with the use of new technologies. In this context,
the State must also encourage reporting of instances of cybercrime and ensure that there is trust
between the various players of the economic world and the legal and law-enforcement authorities.
Those authorities, but also the civil-defence authorities, emergency services, armed forces and security
forces, have a tactical and operational role to play as well, in the struggle against cybercrime, in order
to protect, prosecute and repair. Surveillance, detection and information centres for IT and criminal
risks must be made operational in order to provide prevention, necessary for the control of those risks.
It is up to each State to define a development policy for the information society reflecting its own
particular values, and to provide the resources necessary to make it a reality. This includes the means
for protection and the struggle against cybercrime.
To contain cybercrime in a global, centralized and coordinated manner, a response is needed at the
political, economic, legal and technological level, a single response that can be adopted by all of the
players in the digital chain as fellow partners in security.
I.2.6.2
State sovereignty
The desire for simplicity and effectiveness in security is at odds with the complexity of needs and
environments, and makes the outsourcing of services and system and information security to
specialized providers more attractive. This tendency creates a high, or total, degree of dependence.
Cybersecurity
15