Cybersecurity guide for developing countries
Section I.2 – Cybersecurity
I.2.1
The security context of the communication infrastructure
There is increasing awareness of the importance of mastering operational IT risks, with the growing
utilization of new technologies, the existence of a global IT infrastructure, and the emergence of new
risks.
The transformation of societies into an information society, made possible by the integration of new
technologies in every sphere of activity and every type of infrastructure, increases the dependence of
individuals, organizations and countries on information systems and networks. This is a major source
of risk, which must be treated as a security risk.
The developing countries are faced with the problem of needing to join the information society
without ignoring the risks of becoming dependent on technologies and technology providers, and
avoiding the danger that the digital divide gives rise to a security divide or even a heightened
dependency on entities that control their needs and the means of IT security1.
The telecommunication infrastructures and the services and activities that they make possible have to
be conceived, designed, set up and managed with security in mind. Security is the cornerstone of any
activity; it should be viewed as a service that makes it possible to create other services and generate
value (e.g. e-government, e-health, e-learning). It is not a matter of technology alone2. Until now,
however, the basic communication tools that have been made available have not come with the
resources that are both necessary and sufficient to provide or to guarantee a minimum level of
security.
Networked IT systems are resources that can be accessed remotely; as such, they are potential targets
for a cyberattack. Systems are exposed to a heightened risk of intrusion, and opportunities multiply for
attacks to be launched and crimes to be committed. While systems are the targets of attacks, the prize
that the attackers pursue is the information being processed (Figure I.2). Attacks can affect the ability
to process, store and share information capital, and they can inflict damage on intangible and symbolic
goods, production processes, and the decision-making processes of the organization. Cybersystems
introduce an operational risk in the operation of the organizations that own them.
Dealing with the complex, multifaceted cybersecurity problems raised by telecommunication networks
and open systems can thus be relatively difficult, and the potential repercussions and impact on the
operation of organizations and countries can be devastating. Factors that are crucial to the success of
economies may depend on the ability to provide security for information, processes, systems and infrastructure.
Widespread system interconnection, increasing linkage between infrastructures, growing dependence
on digital technologies, and the growth of threats and risks, make it necessary for individuals,
organizations and countries to take steps, adopt procedures and acquire tools to improve the way that
technological and cyber-risks are managed. The challenges of the struggle to contain the technological
risks are those of the 21st century itself. They call for a comprehensive global approach to security that
will include the developing countries.
1 S. Ghernaouti-Hélie: “From digital divide to digital unsecurity: challenges to develop and deploy an unified e-security
framework in a multidimensional context”, in International Cooperation and the Information Society, section of the Swiss
development policy directory, IUED publications. Geneva, November 2003.
2 A. Ntoko: “Mandate and activities in cybersecurity – ITU-D”. WSIS thematic meeting on cybersecurity. ITU, Geneva
28 June-1 July 2005.
6
Cybersecurity