APPENDIX A
A COMPREHENSIVE INTER-AMERICAN CYBERSECURITY STRATEGY:
A MULTIDIMENSIONAL AND MULTIDISCIPLINARY APPROACH
TO CREATING A CULTURE OF CYBERSECURITY
INTRODUCTION
The Internet and related networks and technologies have become indispensable tools for OAS
member states. The Internet has spurred tremendous growth in the global economy and prompted
gains in efficiency, productivity, and creativity across the Hemisphere. Individuals, businesses, and
governments increasingly use the information networks that comprise the Internet to, inter alia,
conduct business; manage personal, industrial, and governmental activities; transmit communications;
and perform research. Moreover, at the Third Summit of the Americas, held in Quebec City, Canada,
in 2001, our leaders committed to further increasing connectivity in the Americas.
Unfortunately, the Internet has also spawned new threats that endanger the entire global
community of Internet users. Information that transits the Internet can be misappropriated and
manipulated to invade users’ privacy and defraud businesses. The destruction of data that reside on
computers linked by the Internet can stymie government functions and disrupt public
telecommunications service and other critical infrastructures. Such threats to our citizens, economies,
and essential services, such as electricity networks, airports, or water supplies, cannot be addressed by
a single government or combated using a solitary discipline or practice.
As recognized by the General Assembly in resolution AG/RES. 1939 (XXXIII-O/03),
“Development of an Inter-American Strategy to Combat Threats to Cybersecurity,” a comprehensive
strategy for protecting information infrastructures that adopts an integral, international, and
multidisciplinary approach is needed. The OAS is committed to the development and implementation
of such a cybersecurity strategy and, in furtherance of this, held a Conference on Cybersecurity
(Buenos Aires, Argentina, July 28-29, 2003) that demonstrated the gravity of cybersecurity threats to
the security of critical information systems, critical infrastructures, and economies throughout the
world, and underscored that effective action to deal with this issue must involve intersectoral
cooperation and coordination among a broad range of governmental and nongovernmental entities.1/
Similarly, at the Special Conference on Security (Mexico City, Mexico, October 28-29, 2003)
the member states considered the cybersecurity issue and agreed as follows:
"We will develop a culture of cybersecurity in the Americas by taking effective
preventive measures to anticipate, address, and respond to cyberattacks, whatever their
origin, fighting against cyber threats and cybercrime, criminalizing attacks against
cyberspace, protecting critical infrastructure and securing networked systems. We
reaffirm our commitment to develop and implement an integral OAS cybersecurity
strategy, utilizing the contributions and recommendations developed jointly by member
state experts and the REMJA Governmental Experts Group on Cybercrime, CICTE, the
Inter-American Telecommunication Commission (CITEL), and other appropriate organs,
1
.
Report on the Conference on Cybersecurity, document OEA/Ser.L/X.5, CICTE/CS/doc.2/03.