Cybersecurity guide for developing countries Identification and authentication procedures are implemented in order to help achieve the following: – data confidentiality and integrity (access to resources is restricted to identified authorized users, and resources are protected against change by all except those who are so authorized); – non-repudiation and imputability (actions can be traced to an identified and authenticated entity), traceability of messages and transactions (transmissions can be traced to an identified and authenticated entity), proof of destination (the message can be proven to be addressed to an identified and authenticated entity). I.2.10.5 Non-repudiation In some circumstances, it is necessary to verify that an event or transaction has taken place. Nonrepudiation is associated with the concepts of accountability, imputability, traceability and, in some cases, auditability. Establishing responsibility presupposes the existence of mechanisms for authenticating individuals and attributing their actions. The possibility of recording information to make it possible to trace the performance of an action becomes important when there is a need to reconstitute the sequence of events, particularly when performing computer investigations to find a system address used to send data, for example. The information needed to conduct subsequent analysis, for system auditing purposes, needs to be saved (information logging). This is called system auditability. I.2.10.6 Physical security The spaces within which workstations, servers, IT areas and services (air-conditioning, electrical supply panels, etc.) are located need to be physically protected against unauthorized access and accidents (fire, water damage, etc.). Physical security is the most fundamental and ubiquitous type of IT system control. I.2.10.7 Security solutions In view of the daily reality of security-related problems for most infrastructures, the proliferation of proposed solutions, and a flourishing security market, a number of questions are in order: – Are the proposed security solutions adapted to requirements? – – Are they correctly installed and managed? Can they be used in, or adapted to, a dynamically evolving environment? – Can they moderate the inordinate concentration of power in the position of system administrator? – How can they be used to address security problems which have their origins in negligence, human error, design flaws, installation problems or mismanagement of technology and security solutions? – etc. Cybersecurity 23

Select target paragraph3