Cybersecurity guide for developing countries Figure I.7 – OECD principles for information security (July 2002) Awareness Responsibility Response Ethics Democracy Risk assessment Security design and implementation Security management Reassessment I.2.10 All participants are responsible for the security of information systems and networks All involved have a share in the security of systems and information networks Participants should act in a timely and cooperative manner to prevent, detect and respond to security incidents Participants should respect the legitimate interests of others The security of information systems and networks should be compatible with essential values of a democratic society Participants should conduct risk assessments Participants should incorporate security as an essential element of information systems and networks Participants should adopt a comprehensive approach to security management Participants should review and reassess the security of information systems and networks, and make appropriate modifications to security policies, practices, measures and procedures Cybersecurity basics Security solutions must contribute to satisfying basic security criteria such as availability, integrity and confidentiality (the AIC criteria). Other criteria that are often cited in this context are authentication (which makes it possible to verify the identity of an entity), non-repudiation and imputability (which make it possible to verify that actions or events have taken place) (see Figure I.8). I.2.10.1 Availability To ensure the availability of services, systems and data, the components of the infrastructure systems must be appropriately sized and possess the necessary redundancy; in addition, operational management of resources and services must be provided. Availability is measured over the period of time during which the service provided is operational. The potential volume of work that can be handled during the period of availability of the service determines the capacity of the resource (a server or network, for example). The availability of a resource is closely linked to its accessibility. I.2.10.2 Integrity Preserving the integrity of data, processing or services means protecting them against accidental and intentional modification, tampering and destruction. This is needed to ensure they remain correct and reliable. To prevent tampering, a way is needed of certifying that they have not been modified during storage or transfer. Cybersecurity 21

Select target paragraph3