Cybersecurity guide for developing countries They represent, at best, a tentative attempt to deal with the dynamic reality facing them: fluid technology, shifting targets, evolving hacker skills, and mutating threats and risks. There can thus be no guarantee that a particular approach to security will provide lasting protection, nor, as a corollary, that the return on the investment it represents can be assured. Security strategy is often limited to setting up mechanisms to reduce the risks to which the organization’s information assets are exposed, usually by means of a purely technological approach. A better strategy would be one that takes into account all the dimensions of the problem and addresses the security needs of individuals, in particular as regards the protection of privacy and basic rights. Cybersecurity should cover everyone, extending protection to data of a personal nature. Security solutions are already available. In many cases they are purely technological in nature, addressing a particular problem in a specific context. But, like all technology, they are fallible and can be circumvented. In most cases they merely displace the security problem and shift responsibility to another part of the system they are supposed to protect. Furthermore, they are themselves in need of protection and secure management. They can never provide absolute or final protection, due to the evolutionary nature of the security context, itself a result of the dynamic environment (evolving needs, risks, technologies, hacker skills, etc.). There is thus a problem because existing solutions are shortlived at best. Another problem is that the proliferation of heterogeneous solutions may harm the overall coherence of the security strategy. Clearly, technology alone will not suffice; it must be integrated in a management approach. Overall coherence of the security strategy is complicated by the wide range of different entities and individuals involved (engineers, developers, auditors, systems engineers, legal experts, investigators, clients, suppliers, users, etc.) and by the broad array of interests, visions, environments, and languages. A unified, systemic grasp of security risks and measures is needed, and a recognition of the respective responsibilities of all involved, if it is hoped to achieve the level of security that is required to confidently conduct activities using information and communication technologies, and contribute to building confidence in the digital economy. I.2.4 Lessons to be drawn I.2.4.1 Take charge of security At the start of the 21st century, most major organizations – and many smaller ones – have generally accepted the importance of facing up to the challenges of IT security. Security strategy is no longer conceived as merely a hotchpotch of security tools. Instead, it is widely – and correctly – viewed as an ongoing process. The goal of security governance is to ensure that the most suitable security measures are used at each place and time. This concept is based on the following simple questions: – Who does what, how and when? – Who are the players who develop the rules, define and validate them, implement them and exercise control over them? I.2.4.2 Identify and manage the risks The security strategy for digital infrastructures must be guided by an analysis of the risks associated with information processing, telecommunication and cyberspace, as part of the risk management process. The IT security risks (also referred to as computer risks, information risks or technology risks) need to be identified along with all the other risks facing the organization (strategic, social, environmental, etc.). 10 Cybersecurity

Select target paragraph3