Cybersecurity guide for developing countries Page Section III.2 – Security tools................................................................................................ 60 III.2.1 Data encryption .................................................................................................. 60 III.2.1.1 Symmetric encryption ............................................................................. 60 III.2.1.2 Asymmetric or public-key encryption .................................................... 61 III.2.1.3 Encryption keys....................................................................................... 61 III.2.1.4 Key management system......................................................................... 62 III.2.1.5 Digital certificates ................................................................................... 62 III.2.1.6 Trusted third party ................................................................................... 63 III.2.1.7 Drawbacks and limitations of public key infrastructures ........................ 64 III.2.1.8 Signature and authentication ................................................................... 64 III.2.1.9 Data integrity........................................................................................... 65 III.2.1.10 Non-repudiation ...................................................................................... 65 III.2.1.11 Limitations of encryption-based security solutions ................................ 65 III.2.2 Secure IP protocol .............................................................................................. 66 III.2.2.1 IPv6 protocol ........................................................................................... 66 III.2.2.2 IPSec protocol ......................................................................................... 67 III.2.2.3 Virtual private networks.......................................................................... 67 III.2.3 Security of applications ...................................................................................... 67 III.2.4 Secure sockets layer (SSL) and secure HTTP (S-HTTP) protocols .................. 68 III.2.5 E-mail and name server security ........................................................................ 68 III.2.6 Intrusion detection .............................................................................................. 70 III.2.7 Environment partitioning ................................................................................... 70 III.2.8 Access control .................................................................................................... 72 III.2.8.1 General principles ................................................................................... 72 III.2.8.2 Contributions and limitations of biometry ............................................. 73 III.2.9 Protection and management of communication infrastructures ......................... 74 III.2.9.1 Protection ............................................................................................... 74 III.2.9.2 Management ............................................................................................ 75 PART IV – A comprehensive approach ............................................................................. 77 Section IV.1 – Various aspects of the law regulating new technologies .......................... 79 IV.1.1 Personal data protection and e-commerce.......................................................... 79 IV.1.1.1 E-commerce: what’s illegal “offline” is also illegal “online” ................. 79 IV.1.1.2 The duty to protect .................................................................................. 79 IV.1.1.3 Respect for fundamental rights ............................................................... 80 IV.1.1.4 The economic value of legislation .......................................................... 81 xii Table of contents

Select target paragraph3