Cybersecurity guide for developing countries Section I.2 – Cybersecurity I.2.1 The security context of the communication infrastructure There is increasing awareness of the importance of mastering operational IT risks, with the growing utilization of new technologies, the existence of a global IT infrastructure, and the emergence of new risks. The transformation of societies into an information society, made possible by the integration of new technologies in every sphere of activity and every type of infrastructure, increases the dependence of individuals, organizations and countries on information systems and networks. This is a major source of risk, which must be treated as a security risk. The developing countries are faced with the problem of needing to join the information society without ignoring the risks of becoming dependent on technologies and technology providers, and avoiding the danger that the digital divide gives rise to a security divide or even a heightened dependency on entities that control their needs and the means of IT security1. The telecommunication infrastructures and the services and activities that they make possible have to be conceived, designed, set up and managed with security in mind. Security is the cornerstone of any activity; it should be viewed as a service that makes it possible to create other services and generate value (e.g. e-government, e-health, e-learning). It is not a matter of technology alone2. Until now, however, the basic communication tools that have been made available have not come with the resources that are both necessary and sufficient to provide or to guarantee a minimum level of security. Networked IT systems are resources that can be accessed remotely; as such, they are potential targets for a cyberattack. Systems are exposed to a heightened risk of intrusion, and opportunities multiply for attacks to be launched and crimes to be committed. While systems are the targets of attacks, the prize that the attackers pursue is the information being processed (Figure I.2). Attacks can affect the ability to process, store and share information capital, and they can inflict damage on intangible and symbolic goods, production processes, and the decision-making processes of the organization. Cybersystems introduce an operational risk in the operation of the organizations that own them. Dealing with the complex, multifaceted cybersecurity problems raised by telecommunication networks and open systems can thus be relatively difficult, and the potential repercussions and impact on the operation of organizations and countries can be devastating. Factors that are crucial to the success of economies may depend on the ability to provide security for information, processes, systems and infrastructure. Widespread system interconnection, increasing linkage between infrastructures, growing dependence on digital technologies, and the growth of threats and risks, make it necessary for individuals, organizations and countries to take steps, adopt procedures and acquire tools to improve the way that technological and cyber-risks are managed. The challenges of the struggle to contain the technological risks are those of the 21st century itself. They call for a comprehensive global approach to security that will include the developing countries. 1 S. Ghernaouti-Hélie: “From digital divide to digital unsecurity: challenges to develop and deploy an unified e-security framework in a multidimensional context”, in International Cooperation and the Information Society, section of the Swiss development policy directory, IUED publications. Geneva, November 2003. 2 A. Ntoko: “Mandate and activities in cybersecurity – ITU-D”. WSIS thematic meeting on cybersecurity. ITU, Geneva 28 June-1 July 2005. 6 Cybersecurity

Select target paragraph3