3. Security cluster
The public policy issues in the security cluster aim to ensure functional and reliable use of the
Internet. The security cluster highlights cybersecurity as its main umbrella issue, and includes
other more specific Internet policy issues.
3.1 Cybersecurity
There is no agreed definition of what cybersecurity is. The broad understanding is that it
includes issues related to technical security of networks, national security and security for the
general public. It is an umbrella concept covering several areas: cybercrime, critical
information infrastructure protection (CIIP), and cyberconflicts. Most online threats come
about as a result of software and hardware vulnerabilities exploited by organised and
expanding global cybercrime communities. The international community still lacks a
systematic and decisive approach to combating these global cybercrime groups.
Status of governance mechanisms for cybersecurity
At national level, a growing volume of legislation and jurisprudence deals with cybersecurity,
with a focus on combating cybercrime and, increasingly, protecting the critical information
infrastructure from sabotage and attacks as a result of conflicts and terrorist attacks. At
regional levels, more and more organisations are realising the importance of cybersecurity
and are working on strategies, recommendations, and conventions, such as the Council of
Europe Convention on Cybercrime, the Asia-Pacific Economic Cooperation (APEC) Strategy
on Secure Online Space, the EU Cybersecurity Strategy, the OSCE Decision on ConfidenceBuilding measures, and the African Cybersecurity Convention.
At the international level, the UN General Assembly has passed several resolutions on a
yearly basis on ‘developments in the field of information and telecommunications in the
context of international security’. The ITU has produced a large number of security standards
and recommendations. A security on provision was included in the 2012 International
Telecommunication Regulations (ITRs). One of the main G8 developments in cybersecurity
was establishing 24/7 communication between the cybersecurity centres of member states.
The Forum of Incident Response and Security Teams (FIRST) is an international technical
network which coordinates the activities of national and regional Computer Emergency
Response Teams (CERTs). For the network security, a key existing mechanism is the
Security and Stability Advisory Committee (SSAC) under ICANN.
A series of Conferences on Cyberspace has been held in London (2011), Budapest (2012) and
Seoul (2013).
17