Cybersecurity guide for developing countries
The quality of IT security depends primarily on the identification and evaluation of the value of the
information assets, operational deployment of appropriate security measures based on a
well-conceived security policy, and effective management.
I.2.4.4
Deploy the solutions
Various types of measures need to be instituted to make the IT and telecommunication infrastructure
more secure. These include:
–
build awareness; educate and train all stakeholders for cybersecurity;
–
create units that can function as the national early-warning and crisis-response centre, pool the
resources necessary to do so effectively and share them across several countries, for a region;
–
institute surveillance and checks (analogous to road checks);
–
build expertise in a cyberpolice team that can contribute to a cooperative international effort
for the investigation and prosecution of computer-related crime;
–
develop technological solutions for identity management, access control, the use of secure
hardware and software platforms, back-up infrastructures, encryption protocols and
operational management.
I.2.5
The management perspective
I.2.5.1
Dynamic management5
Approaching security through a dynamic and continuous management process positions the
organization to deal with the dynamic nature of the risk and the evolving needs, by continuously
adapting and improving its solutions. The quality of the security management will determine the level
of security provided. The cybersecurity policy should be defined at the level of top management.
There are as many security strategies, policies, measures, procedures and solutions as there are
organizations with security needs that need to be met at any particular time.
For an example of the dynamic context within which security management must operate, consider the
process of detecting and patching security vulnerabilities. This is done by means of periodic issues of
security patches. Information newsletters, more or less customized, make it possible to stay informed
about vulnerabilities that have been detected and how to patch them up. If a minimum level of security
is to be maintained, the security administrator or system administrator will have to install the security
patches as they are issued. However, knowledge of dangerous system vulnerabilities is useful not just
to the security administrator, but also to hackers, who may attempt to exploit them before the patches
have been applied. It is therefore imperative to allocate sufficient resources to implement a dynamic
management that continuously updates the security solutions and thus maintains a consistent level of
security.
Published alerts and patches allow the administrator to control the update process (by choosing
whether to install those patches or not); it is also possible to do so in automatic mode, effectively
delegating the responsibility for regular and systematic patch installation to the software publisher.
This raises the question of responsibility. For example, what are the legal consequences of a software
update that has been declined, when problems arise from the exploitation of an uncorrected
vulnerability? Since numerous attacks do just that, the question of who decides, and the responsibility
of the system administrator, is a very pertinent one.
5 The following two sections are adapted from an article entitled “Sécurité informatique, la piège de la dépendance”,
A. Dufour, G. Ghernaouti-Hélie, Revue Information et Système, 2006.
Cybersecurity
13