Cybersecurity guide for developing countries
Figure I.3 – The levels of cybersecurity: individuals, organizations and countries
• Attacks against a person’s dignity
• Semantic attacks
• Manipulation of public opinion
• Advocacy of crimes against
humanity
• Destruction of information
• Incitement to racial hatred
• Info-war
• Crimes against children
• Breach of professional trust
• Libel
• Boycott
• Attacks on privacy
• Identity theft
INDIVIDUAL
ACCIDENT
STATE
• Distribution of illicit content
ERRORS
• Financial fraud
ORGANIZATION
ZATION-
• Damage to integrity
• Saturation attack
MALICIOUS ATTACKS
• Blackmail
• Impaired availability
• Cyberterrorism
• Sabotage
• Breach of confidentiality
• Embezzlement, theft
• Fraud
• Etc.
If activities based on information processing are to grow and thus help to narrow the digital divide,
this will require:
–
reliable and secure information infrastructures (with guaranteed accessibility, availability,
dependability and continuity of services);
–
policies to create trust;
–
an appropriate legal framework;
–
judiciary and police authorities conversant with new technologies and able to cooperate with
their counterparts in other countries;
–
information risk and security management tools;
–
security implementation tools that will foster confidence in the applications and services
provided (e-business, e-finance, e-health, e-government, e-voting, etc.) and in the procedures
set up to protect human rights, in particular regarding privacy.
The goal of cybersecurity is to help protect the organization’s assets and resources in organizational,
human, financial, technical and information terms, allowing it to pursue its mission.
The ultimate objective is to ensure that no lasting harm is done to the organization. This consists of
reducing the likelihood that a threat materializes; limiting the resulting damage or malfunction; and
ensuring that, following a security incident, normal operations can be restored within an acceptable
time-frame and at an acceptable cost.
The cybersecurity process involves the whole of society, in that every individual is concerned by its
implementation. It can be made more relevant by developing a cyber code of conduct and
promulgating a genuine security policy that stipulates the standards that cybersecurity users, entities,
partners and providers will be expected to meet.
8
Cybersecurity