Cybersecurity guide for developing countries
The dynamic dimension of security represents a crucial challenge not only for the providers of security
tools and software publishers, but also for system administrators and security administrators, who
rarely have the time needed to incorporate all of the patches and updates that are available.
As computer managers, security administrators and system administrators possess full access to the
organization’s IT resources, not only is it necessary to apply strict surveillance and control procedures
for their activity (proportionate to the risks to which they potentially expose the systems under their
control), but these staff must also display irreproachable personal integrity.
I.2.5.2
Outsourcing and dependence
Service providers who offer anti-virus and anti-spam filters effectively take over a part of the security
management for their customers. This trend is starting to change the distribution of roles and responsibilities in security matters. Security will increasingly be shifted onto the service provider or technical
provider. This shift does not, of course, resolve the problem of security, it merely transfers it to the
service provider, who becomes responsible not only for the availability and performance of the
service, but also for the management and maintenance of a certain level of security.
Publishers of anti-virus software typically offer an automatic update service. The addition of this new
dimension of service makes software rental increasingly attractive, as the responsibility for
maintenance is transferred to the publisher for a lengthy period. It also fuels a broader trend towards
outsourcing of applications and a concomitant business model.
The question of outsourcing or delegating all or part of the security mission is not a purely technical
one. It is of a strategic and legal nature, and raises the fundamental issue of dependence on suppliers.
A security outsourcing strategy may include the definition of policy, its implementation, access
management, firewall administration, remote maintenance of systems and networks, third-party
application maintenance, back-up management, and so on. The choice of a contractor must be
accompanied by a quality-control process, and may take into account such things as the contractor’s
experience, in-house expertise, technologies used, response time, support service, contractual
arrangements (e.g. guaranteed results), or sharing of the legal responsibilities.
I.2.5.3
Preventive and remedial action6
Security prevention is, by definition, proactive. It involves the human, legal, organizational, economic
(ratio between implementation cost/level of security/services offered) and technological dimensions.
Until now, IT environment security has concerned itself largely with the technical dimension. This
way of understanding information systems security, primarily from a technical point of view,
neglecting the human dimension, is a real problem in controlling the technology risk associated with
criminal acts. This is because criminality is primarily a human issue, and not a technical one. A purely
technical response is therefore inappropriate for controlling what is essentially a human risk.
The approach to addressing IT criminality is typically one of reaction and prosecution. It thus comes
after the event, i.e. following the occurrence of an incident which by definition has highlighted a gap
in the protective measures. It is necessary not only to prevent and deter cyberattacks by developing
investigative/criminal mechanisms, but also to identify in the security policy those measures that are
6 This section is adapted from the book Sécurité informatique et réseaux by S. Ghernaouti-Hélie, Dunod 2006.
14
Cybersecurity