60 CYBER CRIME & CYBER SECURITY TRENDS IN AFRICA Crime, which reports directly to the Ministry of Territorial Administration and Internal Security (MATSI). The country has established numerous informal mechanisms for responding to cyber incidents but has not yet established into law formal procedures and policies to do so. The Government of Burkina Faso has established and operated a national-level CIRT (BF-CIRT) for several years. The primary role of Burkina Faso’s CIRT is to coordinate and assist government agencies in implementing services and technical guidance to lower the risk of computer security incidents as well as respond to mitigate such incidents when they occur. Another primary role for CIRT-BF is to develop and conduct awareness campaigns to help educate the local population about the dangers of cyber threats and cyber crime. Lastly, CIRT-BF disseminates timely cyber threat advisories to all national constituents. In addition, BF-CIRT is planning to evolve into an Agency level organization named the Security Agency of Information. Once established, this Agency will have additional tasks assigned to them including to ensure the effective implementation of national policy and to establish specific national standards for information security. Burkina Faso developed their national cyber security strategy called the National Plan for Cyber Security in 2010 at the request of the Electric Communications Regulatory Authority with the support of the International Telecommunications Union (ITU). The primary objective of the national strategy is to “engage and authorize each Burkinabe government agency to secure the portion of cyberspace that controls and manages or with which it interacts.” In addition, the national plan seeks to provide a strategy to reduce vulnerabilities in cyberspace, conduct effective incident management, and to strengthen the overall culture of cyber security through awareness initiatives. Two notable actions stemming from the Cyber Security National Plan was the creation of a National Security Agency Information Systems (ANSSI) in 2013, and the National Incident Response Centre (BF-CIRT). Government agencies have not been actively promoting cyber resilience or cyber security awareness or carried out activities involved in cyber resilience. Several challenges have been identified by the government in effectively implementing the National Cyber Security Policy. The primary challenges faced by the government in implementing a national cyber security policy are the establishment of standards for action, budgetary constraints, and lack of local cyber expertise. The government of Burkina Faso has not yet begun to work with NGOs to educate and raise awareness of cyber risks. Nor has the government established cyber security education and training centers due to a number of obstacles including budgetary constraints and lack of local expertise. Over the last few years, Burkina Faso has experienced an increase in the number and severity of cyber incidents. In particular, there has been a dramatic increase in the number of attacks against websites. Unfortunately, there is a lack of reporting of incidents by victims and therefore estimates remain artificially low. But already in the first half of the year, the number of recorded attacks exceeded the total number of attacks in the previous year. Some public sources exist that provide limited data on attacks against websites in Burkina Faso, such as www.zone-h.org. The most serious cyber security incident occurred in April of 2015 when 56 government websites were defaced. While the perpetrators have not been identified, most indicators, such as indicators of compromise and IP addresses, suggest that the criminals came from outside of Burkina. While no formal working framework has been established to partner with the private sector, a number of private entities have been identified as primary stakeholders in Burkina Faso’s national CIRT, BF-CIRT. The actions that can be taken in order to effectively partner with the private sector should be clearly established in the national strategy and policy documents and agreements that are non-existent at the moment. At this time, Burkina Faso has no formal partnership arrangements signed with other countries. However, they do have several technical information exchanges established with organizations including the US-CERT, France’s ANSSI, Tunisia’s ANSI, and the Ivory Coast CERT In principle, based on the public channels established by the various national agencies responsible for the management of cyber security incidents, Burkina Faso is able to exchange cyber threat information. They have taken a number of steps to establish structures that have enabled them to process tasks and share cyber threat information. These entities include the National Security Agency Information

Select target paragraph3