Cybersecurity guide for developing countries
Figure I.7 – OECD principles for information security (July 2002)
Awareness
Responsibility
Response
Ethics
Democracy
Risk assessment
Security design and
implementation
Security management
Reassessment
I.2.10
All participants are responsible for the security of information
systems and networks
All involved have a share in the security of systems and
information networks
Participants should act in a timely and cooperative manner to
prevent, detect and respond to security incidents
Participants should respect the legitimate interests of others
The security of information systems and networks should be
compatible with essential values of a democratic society
Participants should conduct risk assessments
Participants should incorporate security as an essential
element of information systems and networks
Participants should adopt a comprehensive approach to
security management
Participants should review and reassess the security of
information systems and networks, and make appropriate
modifications to security policies, practices, measures and
procedures
Cybersecurity basics
Security solutions must contribute to satisfying basic security criteria such as availability, integrity and
confidentiality (the AIC criteria). Other criteria that are often cited in this context are authentication
(which makes it possible to verify the identity of an entity), non-repudiation and imputability (which
make it possible to verify that actions or events have taken place) (see Figure I.8).
I.2.10.1
Availability
To ensure the availability of services, systems and data, the components of the infrastructure systems
must be appropriately sized and possess the necessary redundancy; in addition, operational
management of resources and services must be provided.
Availability is measured over the period of time during which the service provided is operational. The
potential volume of work that can be handled during the period of availability of the service
determines the capacity of the resource (a server or network, for example). The availability of a
resource is closely linked to its accessibility.
I.2.10.2
Integrity
Preserving the integrity of data, processing or services means protecting them against accidental and
intentional modification, tampering and destruction. This is needed to ensure they remain correct and
reliable.
To prevent tampering, a way is needed of certifying that they have not been modified during storage or
transfer.
Cybersecurity
21