Cybersecurity guide for developing countries
Identification and authentication procedures are implemented in order to help achieve the following:
–
data confidentiality and integrity (access to resources is restricted to identified authorized
users, and resources are protected against change by all except those who are so authorized);
–
non-repudiation and imputability (actions can be traced to an identified and authenticated
entity), traceability of messages and transactions (transmissions can be traced to an identified
and authenticated entity), proof of destination (the message can be proven to be addressed to
an identified and authenticated entity).
I.2.10.5
Non-repudiation
In some circumstances, it is necessary to verify that an event or transaction has taken place. Nonrepudiation is associated with the concepts of accountability, imputability, traceability and, in some
cases, auditability.
Establishing responsibility presupposes the existence of mechanisms for authenticating individuals and
attributing their actions. The possibility of recording information to make it possible to trace the
performance of an action becomes important when there is a need to reconstitute the sequence of
events, particularly when performing computer investigations to find a system address used to send
data, for example. The information needed to conduct subsequent analysis, for system auditing
purposes, needs to be saved (information logging). This is called system auditability.
I.2.10.6
Physical security
The spaces within which workstations, servers, IT areas and services (air-conditioning, electrical
supply panels, etc.) are located need to be physically protected against unauthorized access and
accidents (fire, water damage, etc.). Physical security is the most fundamental and ubiquitous type of
IT system control.
I.2.10.7
Security solutions
In view of the daily reality of security-related problems for most infrastructures, the proliferation of
proposed solutions, and a flourishing security market, a number of questions are in order:
–
Are the proposed security solutions adapted to requirements?
–
–
Are they correctly installed and managed?
Can they be used in, or adapted to, a dynamically evolving environment?
–
Can they moderate the inordinate concentration of power in the position of system administrator?
–
How can they be used to address security problems which have their origins in negligence,
human error, design flaws, installation problems or mismanagement of technology and
security solutions?
–
etc.
Cybersecurity
23