Cybersecurity guide for developing countries
IT risks are operational risks, which need to be mastered. At the heart of risk management is an
analysis of security needs, which makes it possible to define a security strategy and security policy. A
number of questions need to be asked at this stage:
–
–
–
–
–
–
–
Who will be in charge of the risk analysis and risk management?
What is the best way to conduct the analysis?
What tools and methods are available?
How reliable are they?
How much emphasis will there be on results? What are the costs?
Would it be better to outsource this function ?
Etc.
Risk may be defined as a danger that can be anticipated to some extent. It is quantified by the
likelihood of damage and the resulting harm. Risk expresses the probability of an asset or value being
lost due to a vulnerability connected with some hazard or danger.
In deciding on the desired level of protection and the types of security measures to put in place, it is
necessary to balance the magnitude of the risk (in financial terms) against what it would cost to reduce
it (see Figure I.5). As a minimum, the assets to be protected must be identified, along with the
rationale for protecting them, depending on actual constraints and the available organizational,
financial, human and technical resources. The measures taken must be effective, and must reflect a
balance between performance and cost-effectiveness.
For an organization, mastering IT risks means elaborating a strategy, defining a security policy and
deciding on its tactical and operational implementation.
Figure
II.4 Différents
compromis
la maîtrise des risques : un choix politique
Figure I.5 – Trade-offs in
controlling
risk:
a policypour
decision
Risks
Risques
IT and
Infrastructure
telecommunication
Informatique
infrastructure
&
Télécommunication
maîtrise du
risque
Reduce risks to an
Réduire les risques
acceptable
level
à un niveau acceptable
Maîtrise
des
Risk control
risques
Cost
Coûtofdurisk
Risquecost
versus
ofVersus
controlling
Coût de
risk
Besoin
de protection
Protection
Versus
versus
Besoin de production
production
Politique
sécurité
Security de
policy
Minimiser les
pertes
Minimize
losses
Permettre un usage
efficace
des
Make sure
technology
can betechnologies
used effectively
I.2.4.3
Define a security policy
The security policy translates what is understood about the risks and their impact into security
measures for implementation. It facilitates both prevention and remedial action in response to security
problems, and helps to reduce the risks and their impact.
Cybersecurity
11