Cybersecurity guide for developing countries The dynamic dimension of security represents a crucial challenge not only for the providers of security tools and software publishers, but also for system administrators and security administrators, who rarely have the time needed to incorporate all of the patches and updates that are available. As computer managers, security administrators and system administrators possess full access to the organization’s IT resources, not only is it necessary to apply strict surveillance and control procedures for their activity (proportionate to the risks to which they potentially expose the systems under their control), but these staff must also display irreproachable personal integrity. I.2.5.2 Outsourcing and dependence Service providers who offer anti-virus and anti-spam filters effectively take over a part of the security management for their customers. This trend is starting to change the distribution of roles and responsibilities in security matters. Security will increasingly be shifted onto the service provider or technical provider. This shift does not, of course, resolve the problem of security, it merely transfers it to the service provider, who becomes responsible not only for the availability and performance of the service, but also for the management and maintenance of a certain level of security. Publishers of anti-virus software typically offer an automatic update service. The addition of this new dimension of service makes software rental increasingly attractive, as the responsibility for maintenance is transferred to the publisher for a lengthy period. It also fuels a broader trend towards outsourcing of applications and a concomitant business model. The question of outsourcing or delegating all or part of the security mission is not a purely technical one. It is of a strategic and legal nature, and raises the fundamental issue of dependence on suppliers. A security outsourcing strategy may include the definition of policy, its implementation, access management, firewall administration, remote maintenance of systems and networks, third-party application maintenance, back-up management, and so on. The choice of a contractor must be accompanied by a quality-control process, and may take into account such things as the contractor’s experience, in-house expertise, technologies used, response time, support service, contractual arrangements (e.g. guaranteed results), or sharing of the legal responsibilities. I.2.5.3 Preventive and remedial action6 Security prevention is, by definition, proactive. It involves the human, legal, organizational, economic (ratio between implementation cost/level of security/services offered) and technological dimensions. Until now, IT environment security has concerned itself largely with the technical dimension. This way of understanding information systems security, primarily from a technical point of view, neglecting the human dimension, is a real problem in controlling the technology risk associated with criminal acts. This is because criminality is primarily a human issue, and not a technical one. A purely technical response is therefore inappropriate for controlling what is essentially a human risk. The approach to addressing IT criminality is typically one of reaction and prosecution. It thus comes after the event, i.e. following the occurrence of an incident which by definition has highlighted a gap in the protective measures. It is necessary not only to prevent and deter cyberattacks by developing investigative/criminal mechanisms, but also to identify in the security policy those measures that are 6 This section is adapted from the book Sécurité informatique et réseaux by S. Ghernaouti-Hélie, Dunod 2006. 14 Cybersecurity

Select target paragraph3