A/RES/57/239
(d) Ethics. Given the pervasiveness of information systems and networks in
modern societies, participants need to respect the legitimate interests of others and
recognize that their action or inaction may harm others;
(e) Democracy. Security should be implemented in a manner consistent with
the values recognized by democratic societies, including the freedom to exchange
thoughts and ideas, the free flow of information, the confidentiality of information
and communication, the appropriate protection of personal information, openness
and transparency;
(f) Risk assessment. All participants should conduct periodic risk
assessments that identify threats and vulnerabilities; are sufficiently broad-based to
encompass key internal and external factors, such as technology, physical and
human factors, policies and third-party services with security implications; allow
determination of the acceptable level of risk; and assist in the selection of
appropriate controls to manage the risk of potential harm to information systems and
networks in the light of the nature and importance of the information to be
protected;
(g) Security design and implementation. Participants should incorporate
security as an essential element in the planning and design, operation and use of
information systems and networks;
(h) Security management. Participants should adopt a comprehensive
approach to security management based on risk assessment that is dynamic,
encompassing all levels of participants’ activities and all aspects of their operations;
(i) Reassessment. Participants should review and reassess the security of
information systems and networks and should make appropriate modifications to
security policies, practices, measures and procedures that include addressing new
and changing threats and vulnerabilities.
3