QATAR NATIONAL CYBER SECURITY STRATEGY
Appendix C. REFERENCES
1 Resilience is the ability to prepare for, adapt to, withstand, and rapidly recover from disruptions resulting
from deliberate attacks, accidents, or naturally occurring threats or incidents.
2 Qatar National Vision 2030 envisions a prosperous country in which there is economic and social justice
for all, and in which nature and man coexist harmoniously. It promotes human, social, economic, and
environmental development to provide educational opportunities, preserve Qatar’s national heritage,
and maintain financial and economic stability.
3 Networked Readiness Index 2014, World Economic Forum, http://www3.weforum.org/docs/WEF_
GlobalInformationTechnology_Report_2014.pdf.
4 “Percentage of Individuals Using the Internet,” International Telecommunication Union (ITU),
http://www.itu.int/en/ITU-D/Statistics/Documents/statistics/2013/Individuals_Internet_2000-2012.xls.
5 The National Broadband Plan for the State of Qatar provides the necessary actions to maximize the use
of broadband.
6 ictQatar, Qatar’s ICT Landscape 2013: Business; ictQatar, Qatar’s ICT Landscape 2013: Households and
Individuals.
7 Microsoft Security Intelligence Report, Volume 15 January through June, 2013 (http://www.microsoft.
com/security/sir/default.aspx)
8 April 2014 Threat Stats—SMS Spam Volume by month for each region, SC Magazine (http://www.
scmagazine.com/april-2014-threat-stats/slideshow/1906/#2)
9 TrendLabs 2013 Annual Security Roundup, Cashing in on Digital Information: An Onslaught of Online
Banking Malware and Ransomware, Trend Micro (http://www.trendmicro.com/cloud-content/us/pdfs/
security-intelligence/reports/rpt-cashing-in-on-digital-information.pdf)
10 “419 Scammers Planning Ahead with 2022 World Cup Scams,” Symantec, February 3, 2011, http://www.
symantec.com/connect/blogs/419-scammers-planning-ahead-2022-world-cup-scams
11 Unintentional insiders—those with authorized access to an organization’s network, system, or information—
can also represent a threat due to non-malicious action or inaction that causes harm or impacts the
confidentiality, integrity, or availability of networks, systems, or information.
12 For example, the European Union (EU) Data Protection Directive (Article 25[6] of directive 95/46/EC)
requires special precautions to be taken when transferring data outside EU countries. See http://
ec.europa.eu/justice/data-protection/data-collection/data-transfer/index_en.htm for more information.
13 ITU is a United Nations agency that specializes in ICT issues, particularly infrastructure development,
standardization, and international cooperation. FIRST is the global association of computer security incident
response teams; it promotes information sharing and promulgates computer security best practices
and tools for incident response. The Meridian Process facilitates cooperation among governments on
CII protection and provides participating countries with the opportunity to share best practices from
around the world.
14 Cyber security controls are safeguards or counter measures to ensure the confidentiality, integrity, and
availability of information assets, systems, or networks and mitigate the risk to those assets, systems,
and networks.
15 For example, firewall, intrusion detection system/intrusion prevention system, and proxy server logs.
16 Capabilities include people, processes, and technologies that support cyber security objectives.
17 Policies include types of instruments such as strategies, standards, frameworks, guidelines, or other
documents that establish, implement, guide, describe, or explain organizational responsibilities,
authorities, actions, and procedures.
18 Unofficial English translation of the Critical Information Infrastructure Protection Law.
19 Ibid.
20 Ibid.
21 “Overview of Cybersecurity,” International Telecommunication Union (ITU), ITU-T X.1205, http://www.
itu.int/en/ITU-T/studygroups/com17/Pages/cybersecurity.aspx.
25