An effective cybersecurity strategy must recognize that the security of the network of information systems that comprise the Internet requires a partnership between government and industry. Both the telecommunications and information technology industries and the governments of OAS member states are seeking cost-effective comprehensive cybersecurity solutions. Security capabilities in computer products are crucial to the overall network security. However, as more technologies are produced and integrated into existing networks, their compatibility and interoperability--or the lack thereof--will determine their effectiveness. Security must be developed in a manner that promotes the integration of acceptable security capabilities into the overall network architecture. To achieve such integrated, technology-based cybersecurity solutions, network security should be designed around international standards developed in an open process. The development of standards for Internet security architecture will require a multi-step process to ensure that adequate agreement, planning, and acceptance are achieved among the various governmental and private entities that must play a role in the promulgation of such standards. Drawing upon the work of such standards development organizations as the Standardization Sector of the International Telecommunication Union (ITU-T), CITEL is identifying and evaluating technical standards to recommend their applicability to the Americas region, bearing in mind that the development of networks in some of the OAS member states has suffered some delays, which implies that for those countries, the achievement of a certain degree of quality for their networks will be important to fully realize adequately secure information exchange systems. CITEL is also establishing liaisons with other standards bodies and industry forums to obtain the participation and feedback of those parties. The identification of cybersecurity standards will also be a multi-step process. Once CITEL's evaluation of existing technical standards is completed, it will recommend the adoption of standards of particular importance to the region. It will also, on a timely and ongoing basis, identify obstacles to the implementation of those security standards in the networks of the region, and possible appropriate action that may be considered by member states. The development of technical standards is not a “one-size-fits-all” endeavor. CITEL will evaluate regional approaches to network security, deployment strategies, information exchange, and outreach to the public and the private sector. As part of this effort, CITEL will identify resources for best practices for network communication and technology-based infrastructure protection. This process will require that CITEL review the objectives, scope, expertise, technical frameworks, and guidelines associated with available resources, in order to determine their applicability within the Americas region to determine which ones are most appropriate. CITEL will continue to work with member states to assist them in the most appropriate and effective implementation. CITEL’s contribution to the Comprehensive Inter-American Cybersecurity Strategy will take a prospective approach and seek to foster information-sharing among member states to promote secure networks. It will identify and evaluate technical issues relating to standards required for the security of future communications networks across the region, as well as existing ones. This task will draw primarily on the work of ITU-T. Through CITEL, other existing standards-setting bodies will also be considered, as appropriate. Ultimately, CITEL will highlight security standards of particular importance and recommend that member states endorse those standards. It is also important to highlight the crucial role of CITEL in promoting capacity-building and training programs so as to advance the process of spreading technical and practical information related to cybersecurity issues.

Select target paragraph3