Cybersecurity guide for developing countries within an IT culture, perhaps in the form of the computer user’s licence recommended by the CIGREF (Club Informatique des Grandes Entreprises Françaises), an association of major French corporations for IT issues7. The internet should be made into a commons open to all, so that all cybercitizens can potentially benefit from the infrastructures and services at their disposal, without taking excessive security risks. A code of security ethics needs to be developed, accepted and respected by all players in cyberspace. I.2.9 The legal dimension I.2.9.1 Critical success factor Some bodies of national law and international conventions legally bind organizations to put into place security measures. As a result, the managers of the organization, and, by virtue of the delegation of authority, their security administrators, have an obligation with respect to security measures (but not an obligation in terms of results). A legal entity that is guilty of a security lapse leading to an infraction may have a responsibility of a criminal, civil or administrative nature. Whether or not such responsibility is established will of course have no bearing on the criminal responsibility of the individuals who are guilty of the infraction. Appropriate legislation on data processing makes it possible to strengthen the economic partners’ confidence in the national infrastructure, contributing to the economic development of the country. Thus, by helping to create a favourable context for data exchange based on compliance with the law, they act as a factor for the adoption of information and communication-based services by the general public. Legislation and security may be viewed as two levers of the national economy. Cybersecurity conceived in terms of confidence and quality lays the foundations for the development of a sound service economy. I.2.9.2 Strengthening legislation and enforcement At the present time, cybercrime is not well controlled, as becomes clear if one examines the annual statistics produced by the Computer Security Institute (CSI)8 or the Computer Emergency and Response Team (CERT)9. Thus, it may be seen how security measures put in place by organizations tend to provide protection for a given environment, in a particular context, but are helpless to prevent criminal activity via the internet. The reasons for this state of affairs have to do, in particular, with the following: – the nature of cybercrime (automation, intelligent malware, remote activation); – the ease and impunity with which hackers can usurp legitimate user identities, thereby thwarting the ability of the legal system to identify the authors of a criminal act; – the need to resolve competence issues before conducting an investigation; – lack of human and material resources within the services responsible for anti-cybercrime work; – the transnational nature of cybercrime, which necessitates frequent calls for international assistance and judiciary cooperation, imposing time delays that are at odds with the speed of the attackers and the demand for immediate resumption of operation of IT systems that have been attacked; 7 www.cigref.fr 8 www.gocsi.com 9 www.cert.org Cybersecurity 17

Select target paragraph3