Cybersecurity guide for developing countries needed to respond to attacks and prosecute the attackers. For this, back-up and continuity plans must be designed and put into place, incorporating the constraints related to the investigation and prosecution of cybercrime within the different work processes and objectives, with specific time-scales. I.2.6 The political dimension I.2.6.1 Responsibility of the State The State possesses considerable responsibility for making digital security a reality. This is particularly true for the definition of an appropriate legal framework, one that is unified and practical. The State should not merely promote and encourage research and development in security but also promote a security culture and demand compliance with minimum security standards (security should be built into products and services), while strengthening law enforcement in respect of cybercrime. This raises the question of the underlying financial model and public-private partnership for national and international action plans. At the strategic level it is necessary to ensure prevention, reporting, information sharing and alert management. It is also necessary to raise awareness of best practices in risk management and security. Another important requirement is for coordination and harmonization of legal systems. Assistance to promote law enforcement and security, the elaboration of proposed cooperative ventures (formal/informal, multilateral/bilateral, active/passive, national/international) must also be defined. At the same time, it is essential to provide education, information and training in information processing and communication technologies, not merely security and deterrent measures. Building awareness of security issues should not be limited to the promotion of a particular security culture and cyber code of conduct. The security culture must be underpinned, upstream, by an IT culture. The different players must be given the means to learn to manage the technological, operational and information risks that threaten them in connection with the use of new technologies. In this context, the State must also encourage reporting of instances of cybercrime and ensure that there is trust between the various players of the economic world and the legal and law-enforcement authorities. Those authorities, but also the civil-defence authorities, emergency services, armed forces and security forces, have a tactical and operational role to play as well, in the struggle against cybercrime, in order to protect, prosecute and repair. Surveillance, detection and information centres for IT and criminal risks must be made operational in order to provide prevention, necessary for the control of those risks. It is up to each State to define a development policy for the information society reflecting its own particular values, and to provide the resources necessary to make it a reality. This includes the means for protection and the struggle against cybercrime. To contain cybercrime in a global, centralized and coordinated manner, a response is needed at the political, economic, legal and technological level, a single response that can be adopted by all of the players in the digital chain as fellow partners in security. I.2.6.2 State sovereignty The desire for simplicity and effectiveness in security is at odds with the complexity of needs and environments, and makes the outsourcing of services and system and information security to specialized providers more attractive. This tendency creates a high, or total, degree of dependence. Cybersecurity 15

Select target paragraph3