A/RES/64/211
cybersecurity consistent with free speech, the free flow of information and due
process of law,
Recognizing that national efforts to protect critical information infrastructures
benefit from a periodic assessment of their progress,
1.
Invites Member States to use, if and when they deem appropriate, the
annexed voluntary self-assessment tool for national efforts to protect critical
information infrastructures in order to assist in assessing their efforts in this regard
to strengthen their cybersecurity, so as to highlight areas for further action, with the
goal of increasing the global culture of cybersecurity;
Encourages Member States and relevant regional and international
2.
organizations that have developed strategies to deal with cybersecurity and the
protection of critical information infrastructures to share their best practices and
measures that could assist other Member States in their efforts to facilitate the
achievement of cybersecurity by providing such information to the SecretaryGeneral for compilation and dissemination to Member States.
66th plenary meeting
21 December 2009
Annex
Voluntary self-assessment tool for national efforts to protect critical
information infrastructures 2
1F
Taking stock of cybersecurity needs and strategies
1.
Assess the role of information and communications technologies in your
national economy, national security, critical infrastructures (such as transportation,
water and food supplies, public health, energy, finance, emergency services) and
civil society.
2.
Determine the cybersecurity and critical information infrastructure protection
risks to your economy, national security, critical infrastructures and civil society that
must be managed.
3.
Understand the vulnerabilities of the networks in use, the relative levels of
threat faced by each sector at present and the current management plan; note how
changes in the economic environment, national security priorities and civil society
needs affect these calculations.
4.
Determine the goals of the national cybersecurity and critical information
infrastructure protection strategy; describe its goals, the current level of
implementation, measures that exist to gauge its progress, its relation to other
national policy objectives and how such a strategy fits within regional and
international initiatives.
_______________
2
This is a voluntary tool that may be used by Member States, in part or in its entirety, if and when they
deem appropriate, in order to assist in their efforts to protect their critical information infrastructures and
strengthen their cybersecurity.
3