Cybersecurity guide for developing countries
within an IT culture, perhaps in the form of the computer user’s licence recommended by the CIGREF
(Club Informatique des Grandes Entreprises Françaises), an association of major French corporations
for IT issues7.
The internet should be made into a commons open to all, so that all cybercitizens can potentially
benefit from the infrastructures and services at their disposal, without taking excessive security risks.
A code of security ethics needs to be developed, accepted and respected by all players in cyberspace.
I.2.9
The legal dimension
I.2.9.1
Critical success factor
Some bodies of national law and international conventions legally bind organizations to put into place
security measures. As a result, the managers of the organization, and, by virtue of the delegation of
authority, their security administrators, have an obligation with respect to security measures (but not
an obligation in terms of results). A legal entity that is guilty of a security lapse leading to an
infraction may have a responsibility of a criminal, civil or administrative nature. Whether or not such
responsibility is established will of course have no bearing on the criminal responsibility of the
individuals who are guilty of the infraction.
Appropriate legislation on data processing makes it possible to strengthen the economic partners’
confidence in the national infrastructure, contributing to the economic development of the country.
Thus, by helping to create a favourable context for data exchange based on compliance with the law,
they act as a factor for the adoption of information and communication-based services by the general
public. Legislation and security may be viewed as two levers of the national economy. Cybersecurity
conceived in terms of confidence and quality lays the foundations for the development of a sound
service economy.
I.2.9.2
Strengthening legislation and enforcement
At the present time, cybercrime is not well controlled, as becomes clear if one examines the annual
statistics produced by the Computer Security Institute (CSI)8 or the Computer Emergency and
Response Team (CERT)9. Thus, it may be seen how security measures put in place by organizations
tend to provide protection for a given environment, in a particular context, but are helpless to prevent
criminal activity via the internet. The reasons for this state of affairs have to do, in particular, with the
following:
–
the nature of cybercrime (automation, intelligent malware, remote activation);
–
the ease and impunity with which hackers can usurp legitimate user identities, thereby
thwarting the ability of the legal system to identify the authors of a criminal act;
–
the need to resolve competence issues before conducting an investigation;
–
lack of human and material resources within the services responsible for anti-cybercrime
work;
–
the transnational nature of cybercrime, which necessitates frequent calls for international
assistance and judiciary cooperation, imposing time delays that are at odds with the speed of
the attackers and the demand for immediate resumption of operation of IT systems that have
been attacked;
7 www.cigref.fr
8 www.gocsi.com
9 www.cert.org
Cybersecurity
17