10
PRIORITY 2 – TECHNICAL AND
PROCEDURAL MEASURES
All stakeholders have an interest in increasing the resiliency and reliability of critical
information infrastructure. In keeping with the second GCA pillar, this priority focuses on
the development of measures for addressing vulnerabilities in hardware and software
products. The measures are critical because whereas threats and threat actors change,
security vulnerabilities exist throughout the life of a system or protocol unless addressed.
Therefore, global security standards offer the best defence against shared vulnerabilities.
10.1
PROCEDURAL MEASURES
Simply put, procedural measures are processes that help preserve the security around
physical and information assets. Whilst this is a technical and procedural priority, we
present the Procedural Measures first because they provide the operational context for
technical measures. Security goals or context informs the selection of Procedural and
Technical Measures. Without clear security goals, organisations typically fail to make
effective use of security tools as it unclear what to check for and the restrictions to
impose (IETF 1997). We align this priority with the strategic goals related to the
Technical and Procedural Measures Pillar of the GCA as follows:
GCA PILLAR: TECHNICAL AND PROCEDURAL MEASURES
Corresponding
GCA Goal –
Procedural
Measures
Goal 3
Goal 5
Development of a strategy for the establishment of
globally accepted minimum security criteria and
accreditation schemes for hardware and software
applications and systems.
Development of global strategies for the creation
and endorsement of a generic and universal digital
identity system and the necessary organisational
structures to ensure the recognition of digital
credentials across geographical boundaries.
Figure 16 – Procedural Measures and related GCA goals
10.1.1
Cybersecurity Goals
We feel that cybersecurity goals should precede the adoption of technical and procedural
measures. We hold this opinion because cybersecurity goals define the overall risk
50
tolerance . Without defining the goals, relevant stakeholders can never know when a
system is sufficiently secure. We adopt the cybersecurity goals we use here from the
50
Defined simply, risk tolerance means the degree of exposure to security risk acceptable to policy makers/business owners.
51