compensate for the absence of coherent, rigorous management of security needs, measures, procedures
and tools. A disorganized stampede to get security tools will hinder use, weigh down operations and
impair the performance of IT systems. Proper IT security is a management issue, and the associated
tools and services are linked to operational system administration. For example, encrypting data for
the purpose of protecting them during transmission is a pointless task if they are subsequently stored in
a non-secure manner. Likewise, installing a firewall will be of little use if connections are permitted to
bypass this system.
If activities based on information processing are to grow and narrow the digital divide, this will
require:
–
reliable and secure information infrastructures (with guaranteed accessibility, availability,
dependability and continuity of services)
–
policies to create trust
–
an appropriate legal framework
–
judiciary and police authorities conversant with new technologies and able to cooperate with
their counterparts in other countries
–
information risk and security management tools;
–
security tools that will foster trust in the applications and services offered (commercial and
financial transactions, e-health, e-government, e-voting, etc.) and in procedures safeguarding
human rights, especially personal data privacy.
Good stewardship of digital information assets, the distribution of non-tangible goods, the exploitation
of content and the bridging of the digital divide are all examples of economic and social problems that
cannot be addressed by looking only at the technological side of IT security. A response that takes into
account the human, legal, economic and technological dimensions of the security needs of the digital
infrastructure and of users can help to foster confidence and lead to economic growth that will benefit
all of society.
vi
Executive Summary