“ The art of war teaches us to rely not on the likelihood of the enemy’s not coming, but on
our own readiness to receive him; not on the chance of his not attacking, but rather on the
fact that we have made our position unassailable.”
Sun Tzu, the Art of War
Introduction
The use of information and communication technologies has been spreading rapidly in
Afghanistan and ICTs are playing important roles in all aspects of our lives. Alongside the
public sector, entities that provide services in critical infrastructure sectors like energy, health,
aviation, communication and financial services have also been heavily using information and
communication systems. These systems improve the quality and the speed of the services
delivery - thus helping organizations work more productively, efficiently and contributing to
the improvement of living standards.
As our public sector organizations use ICTs to provide services at an increasing rate, it has
become an important aspect of our national security and competitiveness to ensure the
security of information and communication technologies. The vulnerabilities inherent in ICTs
may cause denial of service or abuse of service attacks, resulting in high scale economic
losses, disturbance of public order and/or threats to national security.
It is a fact that cyber space offers opportunities of anonymity and deniability for attacks on
information systems and data. The tools and knowledge required for attacks are often cheap
and easy to get, and it has been observed that anyone or any systems across the world can
participate in cyber-attacks, either knowingly or unknowingly. And it is deemed almost
impossible to determine who finances and organizes these enduring and advanced cyberattacks that target the information systems and data of critical infrastructures. These facts and
conditions reveal the asymmetrical nature of the risks and threats in cyber space, making them
even more difficult to tackle.
Information
Systems
Security
Directorate
-‐
MCIT