Executive Summary In 2014, African Union (AU) members adopted the African Union Convention on Cyber Security and Personal Data Protection (“the Convention”).1 To facilitate implementation of the Convention, the African Union Commission (AUC) asked the Internet Society (ISOC) to jointly develop Internet Infrastructure Security Guidelines for Africa (“the Guidelines”). The Guidelines were created with contributions from regional and global Internet infrastructure security experts, government and CERT representatives, and network and ccTLD DNS operators. The Guidelines emphasize the importance of the multistakeholder model and a collaborative security approach in protecting Internet infrastructure. The Guidelines put forward four essential principles of Internet infrastructure security: Awareness, Responsibility, Cooperation, and adherence to Fundamental Rights and Internet Properties. The Guidelines recommend the most critical actions for various stakeholders to take on Internet infrastructure security. These critical actions are tailored to the African cyber security environment’s unique features: a shortage of skilled human resources; limited resources (including financial) for governments and organizations to allocate for cyber security; limited levels of awareness of cyber security issues among stakeholders; and a general lack of awareness of the risks involved in the use of information and communication technologies (ICTs). Given the broad nature of Internet infrastructure security, a single document is not sufficient, and further work will be needed to complement the Guidelines with specific recommendations addressing particular issues. This set of recommendations is a first, yet significant, step in producing a visible and positive change in the African Internet infrastructure security landscape. Regional (African Union) Level • Form an Africa-wide Cyber Security Collaboration and Coordination Committee (ACS3C) • The committee would be a multistakeholder group that would advise policymakers of the AUC on regional strategies and capacity building, and facilitate information sharing across the region. • Engage in Capacity Building and Knowledge Sharing on a pan-African Level • The AUC should develop capacity building programs, as advised by the ACS3C, in all areas of Internet infrastructure security. National Level • Identify and Protect Critical Internet Infrastructure • National governments should take a services-based approach to identifying critical Internet infrastructure for protection. • Facilitate Information Exchange through a National Multistakeholder Structure • National governments should develop multistakeholder structures to advise on cyber security strategy and policy, and to facilitate information sharing. • Establish and Strengthen National Level Computer Security Incident Response Teams (CSIRTs) • National governments working with other stakeholders should establish or support existing national CSIRTs to coordinate security incident response and pre-response. 1 4 See the Convention at http://www.au.int/en/sites/default/files/treaties/29560-treaty-0048_-_african_union_convention_on_cyber_ security_and_personal_data_protection_e.pdf Internet Infrastructure Security Guidelines for Africa internetsociety.org

Select target paragraph3