1. Introduction The importance of the Internet and ICTs as effective tools for achieving socio-economic development in developing countries is widely recognized by governments, financial institutions, and development partners. The Internet and ICTs form vital infrastructure for development. They are a new source of growth, and drivers for innovation and social well-being. As the Internet economy grows, stakeholders and the rest of the economy become increasingly reliant on digital infrastructure to perform their essential functions. The role of the Internet in supporting the economy, delivering information and education, and in enabling creativity is well understood and acknowledged. The Internet economy is a dynamic environment where technologies, applications, uses and markets constantly evolve, often in an unpredictable manner. While the Internet benefits economic growth and innovation, attacks against Internet infrastructure represent a major risk to economic growth and innovation. The joint AUC-Symantec report Cyber Crime & Cyber Security Trends in Africa, published in November 2016, reveals that 24 million malware incidents targeting Africa were observed in 2016.2 A 2017 report from McAfee finds that, in the fourth quarter of 2016 alone, nearly 12% of their African mobile customers reported malware infections.3 Vulnerabilities, or exploitable weaknesses, pose a threat to devices, networks and systems, along with those who rely on them. These vulnerabilities are exploited by attackers to attack an increasingly diverse range of industries, organizations and targets.4 In light of the threat to socio-economic development posed by attacks on Internet infrastructure, it is the responsibility of all stakeholders, including governments and Internet service providers, to agree upon solutions to ensure the Internet in every country remains safe, secure and resilient. A key aspect of choosing security solutions is to preserve the open nature of the Internet and reinforce trust. Since the Internet is essential for the economy and for all stakeholders, the consequences of security failures can directly impact society as a whole. Therefore, there has to be a commitment by all stakeholders to secure cyber operations. The nature of these threats continues to include activities such as theft (of identity, personal data, and secrets of all kinds), infringement of intellectual property rights, denial of service attacks, defacement, and other sources of disruption. However, large-scale distributed denial of service (DDoS) attacks, misuse or breaches of personal data, and the disruption of critical infrastructure should be of the most concern to Africa. Africa is becoming more and more connected to the Internet. Businesses, infrastructures, governments, citizens and key industries are all becoming linked to the Internet. As the continent increasingly relies upon the Internet, protecting its critical elements becomes vital. African stakeholders in the Internet ecosystem must work together to protect the interconnected Internet infrastructure while preserving the fundamental properties of the Internet5 and upholding fundamental rights. Internet infrastructure security is a domain of paramount importance and magnitude. The Guidelines address areas that are relevant and specific to essential current needs in Africa. 2 3 4 5 See https://www.thegfce.com/initiatives/c/cybersecurity-and-cybercrime-trends-in-africa/documents/publications/2017/03/10/report-cybertrends-in-africa. See https://www.mcafee.com/ca/security-awareness/articles/mcafee-labs-threats-report-mar-2017.aspx See Annex I: Internet and Security-Related Terms for more information concerning threats, threat agents, vulnerabilities, and attacks. See https://www.internetsociety.org/internet-invariants-what-really-matters and http://www.internetsociety.org/policybriefs/ internetinvariants internetsociety.org Internet Infrastructure Security Guidelines for Africa 7

Select target paragraph3