Cybersecurity guide for developing countries
Page
Section III.2 – Security tools................................................................................................ 60
III.2.1 Data encryption .................................................................................................. 60
III.2.1.1 Symmetric encryption ............................................................................. 60
III.2.1.2 Asymmetric or public-key encryption .................................................... 61
III.2.1.3 Encryption keys....................................................................................... 61
III.2.1.4 Key management system......................................................................... 62
III.2.1.5 Digital certificates ................................................................................... 62
III.2.1.6 Trusted third party ................................................................................... 63
III.2.1.7 Drawbacks and limitations of public key infrastructures ........................ 64
III.2.1.8 Signature and authentication ................................................................... 64
III.2.1.9 Data integrity........................................................................................... 65
III.2.1.10 Non-repudiation ...................................................................................... 65
III.2.1.11 Limitations of encryption-based security solutions ................................ 65
III.2.2 Secure IP protocol .............................................................................................. 66
III.2.2.1 IPv6 protocol ........................................................................................... 66
III.2.2.2 IPSec protocol ......................................................................................... 67
III.2.2.3 Virtual private networks.......................................................................... 67
III.2.3 Security of applications ...................................................................................... 67
III.2.4 Secure sockets layer (SSL) and secure HTTP (S-HTTP) protocols .................. 68
III.2.5 E-mail and name server security ........................................................................ 68
III.2.6 Intrusion detection .............................................................................................. 70
III.2.7 Environment partitioning ................................................................................... 70
III.2.8 Access control .................................................................................................... 72
III.2.8.1 General principles ................................................................................... 72
III.2.8.2
Contributions and limitations of biometry ............................................. 73
III.2.9 Protection and management of communication infrastructures ......................... 74
III.2.9.1
Protection ............................................................................................... 74
III.2.9.2 Management ............................................................................................ 75
PART IV – A comprehensive approach ............................................................................. 77
Section IV.1 – Various aspects of the law regulating new technologies .......................... 79
IV.1.1 Personal data protection and e-commerce.......................................................... 79
IV.1.1.1 E-commerce: what’s illegal “offline” is also illegal “online” ................. 79
IV.1.1.2 The duty to protect .................................................................................. 79
IV.1.1.3 Respect for fundamental rights ............................................................... 80
IV.1.1.4 The economic value of legislation .......................................................... 81
xii
Table of contents