(HLEG) Global Strategic Report
Total Page:16
File Type:pdf, Size:1020Kb
© ITU 2008 International Telecommunication Union Place des Nations, 1211 Geneva, Switzerland. First printing 2008 Legal Notice The information contained in this publication has been contributed by members of the High-Level Experts Group (HLEG) on the basis of information that is publicly available. Neither ITU nor any person acting on its behalf is responsible for any use that might be made of the information contained in this Report. ITU is not responsible for the content or the external websites referred to in this Report. The views expressed in this publication are those of the authors only and do not reflect in any way the official views of ITU or its membership or engage the ITU in any way. Denominations and classifications employed in this publication do not imply any opinion on the part of the ITU concerning the legal or other status of any territory or any endorsement or acceptance of any boundary. No part of this publication may be reproduced, except as authorized by written permission and provided that the source is acknowledged. Persons interested in quoting this publica- tion should first seek permission from: [email protected]. Acknowledgements Introduction Contributing authors: GCA Secretariat and all work area leaders. Chapter 1: Strategic Report WA1 Main author & editor: Stein Schjolberg, Chief Judge, Moss District Court, Norway. Contributing authors: Dr. Marco Gercke, Senior Researcher University of Cologne, Germany: Section 1.6 (except 1.6.1.6. and 1.6.3.3.), Section 1.7 (except 1.7.8.), Section 1.10 (except 1.10.2) and co-author of Section 1.1. Scott Stein: Section 1.9 and Section 1.14. Gillian Murray, Focal Point for Cybercrime, UNODC: Section 1.3 (except 1.3.3). Marc Goodman, Senior Advisor to Interpol’s Steering Committee on Information Technology Crime: Section 1.8. Toomas Viira, Information Security Manager in Estonian Informatics Centre, Estonian Ministry of Economic Affairs and Communications, contributed to Section 1.6.1. Graham Butler, President and CEO, Bitek International Inc: Section 1.7.8. Tony Rutkowski, Vice-President for Regulatory Affairs and Standards at VeriSign, Inc: Section 1.12, Section 1.13 and Section 1.10.2. Senior Legal Adviser Rajka Vlahovic of UNODC has made comments and updated Section 1.9. Section 1.2.4 was updated based on comments by Jinhyun Cho, senior researcher at the Rep. of Korea’s CERT/ CC and deputy convenor of APECTEL SPSG. Section 1.1.11 was updated based on comments by Yuan Xu, China. Section 1.8.9 was updated based on comments by Noboru Nakatani, Interpol. Jody Westby has provided us with valuable information and additional resources. We enjoyed clarifying discussions with Professor Ulrich Sieber. Chapter 2: Strategic Report WA2 Contributing authors: Mr. Jaak Tepandi, Professor of Knowledge Based Systems, Institute of Informatics, Tallinn University of Technology, Estonia and Mr. Justin Rattner, Chief Technology Officer, Intel Corp. Chapter 3: Strategic Report WA3 Contributing authors: Taieb Debbagh, General Secretary of the Ministry of Telecommunications and ICT of Morocco, Solange Ghernaouti Hélie, Professeure Présidente de la Commission Sociale at the University of Lausanne, Business & Economics. Chapter 4: Strategic Report WA4 Contributing authors: Solange Ghernaouti Hélie, Professeure Présidente de la commission Sociale at the University of Lausanne, Business & Economics, & Ivar Tallo, Senior Programme Officer, UNITAR. Chapter 5: Strategic Report WA5 Contributing authors: Mr. Shamsul Jafni Shafie, Director, Security, Trust and Governance Department, Content, Consumer and Network Security Division, Malaysian Communications and Multimedia Commission and Mr. Zane Cleophas, Chief Director, Border Control Operational Coordinating Committee (BCOCC), Department of Home Affairs of South Africa. Message from the Secretary - General Dr Hamadoun I. Touré Building confidence and security in the use of Information and Communication Technologies (ICTs) is one of the most important, and most complex, challenges we face today. Promoting cybersecurity is a top priority, if we are to reap the full benefits of the digi- tal revolution and the new and evolving communication technologies coming onto the market. At the same time, maintaining cybersecurity is a culture, spanning different disciplines, that needs to be built into our approach towards, and our adoption of, these new technologies. This is why I am convinced that ITU, with its tradition as an international forum for cooperation and its important work in technical standards for security, has a vital contribution to make in promoting cybersecurity. ITU can draw on its expertise in standardization specifications and communications engi- neering, as well as its experience in direct technical assistance to members, to build a multi-disciplinary approach towards maintaining cybersecu- rity. ITU’s significant work in the security of IMT (3G) mobile telephony and Public Key Infrastructure, enabling digital signatures, are just a few examples of our work to ensure secure, reliable and user-friendly communications. And yet, ITU must work alongside other key stakeholders in the field, if modern communication systems are to remain secure. And this is why the work of the High-Level Experts Group is highly significant. ITU’s Global Cybersecurity Agenda has benefited from the advice of a panel of key policy-makers and leading specialists from major private sector firms and academic institutions for debating the pivotal issues in cybersecurity and developing consensus on the way forward. By bringing together the major players, ITU sought to build their ownership and commitment to a cross-disciplinary consensus approach. These leading experts have freely given their time, knowledge and experience to establish a common understanding of the issues involved. I am convinced that their inspiring thought leadership and buy-in will benefit all, with recommendations on key steps forward for legislative frameworks, technical and procedural measures, organizational structures, capacity-building and international cooperation. The work of this High-Level Experts Group has ensured that the Global Cybersecurity Agenda will remain a key framework for international cooperation to promote cybersecurity going forward. I am deeply grateful to all members of the HLEG for their sincere efforts and commitment in advancing this key initiative of the ITU to promote cybsersecurity. Dr Hamadoun I. Touré Secretary-General, ITU Message from His Excellency the President of Burkina Faso Patron of the Global Cybersecurity Agenda Information and communication technologies (ICTs) play a decisive role in the development process. In order to take full advantage of all the opportunities, the time has therefore come to establish solid foundations more conducive to bringing about the desired economic growth. In Africa, and indeed worldwide, ever-increasing numbers of people are using ICTs and the services they enable. It is therefore both desirable and necessary to provide them with a safe and secure cyberenvironment. This is the main reason why I am pledging my personal support, and agreeing to serve as a patron, for the Global Cybersecurity Agenda, initiated by the International Telecommunication Union (ITU). Given the interdependencies that are created by information and communication technologies, I appeal to Member States to be unstinting in their commitment to ensuring the success of the Agenda as an appropriate framework for cooperation. Countries must focus their political responsibility and spare no effort on developing agreements that are sufficiently effective and flexible to stem cybercrime. It is in this spirit that Burkina Faso will make its contribution to ensuring full realization of the Global Cybersecurity Agenda in the interests of making the world a safer place. For my part, I will give all the necessary time and support to this undertaking, confident as I am of the backing of my African peers and the international community. Blaise Compoare President of Burkina Faso Message from the President of Costa-Rica Patron of the Global Cybersecurity Agenda Like any other technology, Information and Communication Technologies (ICTs) can be put to work for the greater good or for the greater evil. ICTs can be used to spread great knowl- edge, raise awareness and gain a university degree, but they can also be used to destroy someone’s reputation or create entrenched prejudice, by disseminating false and misleading information. ICTs can be used to the good for long-distance diagnosis and telemedicine in healthcare, but they also propagate dangerous computer viruses that can cause critical com- puter systems to crash and the loss of vital data. ICTs can allow business entrepreneurs to access new markets and sell goods abroad, but they also enable crooks to swindle trusting would-be customers out of millions of dollars. Like any other technology, ICTs offer bound- less opportunities that we are only just beginning to explore, but also various pitfalls and online dangers. Information is a vital weapon in war, where it is vital in shaping public perceptions and the will, and ability, of the international community to take action. However, new forms of information warfare are evolving rapidly, breaking new ground in the flow and control of information during conflict. ‘Hacktivism’ is now a recognized form of information warfare, from defacements of commercial websites and the downing of competitors’ sites and systems to attacks on minorities’ cultural and religious