The Quest for Cyber Confidence
Total Page:16
File Type:pdf, Size:1020Kb
Contact Information: International Telecommunication Union Place des Nations - 1211 Geneva 20 Switzerland E-mail: [email protected] Website: www.itu.int/cybersecurity 4 ember 201 November 2014 November Nov | CE THE QUEST FOR ISBN 978-92-61-15301-4 NFIDEN CO CONFIDENCE CYBER CONFIDENCE 9 7 8 9 2 6 1 1 5 3 0 1 4 Price: 79 CHF Printed in Switzerland Geneva, November 2014 4 Photo credits: Shutterstock 11/2014 THE QUEST FOR CYBER FOR CYBER FOR CYBER THE QUEST QUEST Couv_cyber-confidence_371690_Ed.indd 2 13/11/2014 14:22:42 International Telecommunication Union THE QUEST FOR CYBER CONFIDENCE By Dr Hamadoun I. Touré Secretary-General of the International Telecommunication Union and the Permanent Monitoring Panel on Information Security World Federation of Scientists NOVEMBER 2014 Legal notice Authors individually retain copyright to their work. Third-party sources are quoted as appropriate. The International Telecommunication Union (ITU) is not responsible for the content of external sources including external websites referenced in this publication. Neither ITU nor any person acting on its behalf is responsible for the use that might be made of the information contained in this publication. Disclaimer The chapters in this publication represent the views of the individual authors, which are not endorsed by or intended to represent the views of any organization they may be employed by or affiliated with. Mention of and references to specific countries, companies, products, initiatives or guidelines do not in any way imply that they are endorsed or recommended by ITU, the authors, or any other organization that the authors are affiliated with, in preference to others of a similar nature that are not mentioned. Acknowledgements The ITU Secretary-General and the World Federation of Scientists would like to thank Henning Wegener, and all the authors who have made it possible to put together their views on this emerging global concern. The Secretary-General expresses gratitude to Prof. Antonino Zichichi, President of WFS. His sincere thanks go to Marco Obiso who led and coordinated this publication and the ITU Cybersecurity team, particularly Alex Gamero Garrido, Aliya Abdul Razack, Despoina Sareidaki, Anthony Drummond, Preetam Maloor and Rosheen Awotar- Mauree as well as many others in ITU and WFS without whose contribution this publication would not have been possible. If you have any comments, please contact the Cybersecurity team, International Telecommunication Union, at [email protected]. Copyright to Collective Work © 2014, International Telecommunication Union & World Federation of Scientists All rights reserved. No part of this publication may be reproduced, by any means whatsoever, without the prior written permission of ITU. The Quest for Cyber Confidence TABLE OF CONTENTS Page Preface by ITU Secretary-General Dr Hamadoun I. Touré .................................... 1 Preface by World Federation of Scientists President Professor Antonino Zichichi....................................................................................................... 2 Introduction: The Crisis of Cyber Confidence (by Henning Wegener) .................. 3 Chapter I: Cyber Norms ......................................................................................... 9 Introduction .............................................................................................. 9 1.1 The role of CBMs in a renewed vision of international cybersecurity: prospects for a global response and an international treaty (by Solange Ghernaouti) ........................... 10 1.2 UN and Member States’ Approach to Internet Norms, Rules and Principles: Evaluation of the Report of the UN Group of Governmental Experts (by Henning Wegener) .......................... 22 1.3 Does International Law Apply to Cyberspace? (by Gábor Iklódy) .. 31 1.4 United Nations Vision on Cybersecurity (by Hamadoun I. Touré)......................................................................................... 42 Chapter II: Cyber Resilience ................................................................................... 51 Introduction .............................................................................................. 51 2.1 Foundations of Cyber Resilience (by Axel Lehmann) ..................... 53 2.2 Heightening the Resilience of Cloud Computing and Big Data Systems (by Vladimir Britkov) .................................................... 62 2.3 Towards Resilient Cyber Control Systems (by Stefan Lüders) ........ 66 2.4 Cyber Resilience from the Private Sector Perspective (by Danil Kerimi) ........................................................................................ 70 2.5 The Cybersecurity Continuum to Enhance Cyber Resilience (by Solange Ghernaouti) .................................................................. 76 Chapter III: Cyber Freedom ................................................................................... 83 Introduction .............................................................................................. 83 iii The Quest for Cyber Confidence Page 3.1 Cyber Freedom: Progress and Challenges (by Mona Al-Achkar) .... 85 3.2 Legal, Policy & Regulatory Frameworks for Internet Freedom & Big Data (by Pavan Duggal) ........................................................ 101 3.3 A Global Perspective of State Surveillance in Cyberspace (by Howard Schmidt) ....................................................................... 115 3.4 The Extent of State Surveillance in Cyberspace: A European Union Perspective (by Henning Wegener) ................................ 119 3.5 The Limits to Cyber Freedom: A Search for Criteria (by William A. Barletta) ................................................................................. 128 Table of Abbreviations........................................................................................... 141 iv The Quest for Cyber Confidence About the International Telecommunication Union The International Telecommunication Union (ITU) is the leading United Nations agency for information and communication technology issues, and the global focal point for governments and the private sector in developing networks and services. A fundamental role of ITU following the World Summit on the Information Society (WSIS) and the 2006 ITU Plenipotentiary Conference is to build confidence and security in the use of information and communication technologies (ICTs). Heads of States and government and other global leaders participating in WSIS, as well as ITU Member States, entrusted ITU to take concrete steps towards curbing the threats and insecurities related to the information society. To fulfill this mandate, ITU Secretary-General Dr Hamadoun I. Touré launched the Global Cybersecurity Agenda (GCA) as a framework for international multi-stakeholder cooperation in cybersecurity aimed at building synergies with current and future initiatives and partners. It focuses on the following five work areas: Legal measures, Technical and Procedural Measures, Organizational Structures, Capacity Building and International Cooperation. Some key initiatives to assist Members States in building capacity in Cybersecurity under the umbrella of the GCA and with the support of global partners include: The National CIRT programme (Computer Incident Response Team) Programme whereby National CIRT Assessments, National CIRT implementations and regional cyber drills are conducted following request from Member States. The establishment of Regional Cybersecurity Centres with the aim to serve as catalysts for enhancing regional cooperation, coordination and collaboration to address escalating cyber threats. “Enhancing Cybersecurity in Least Developed Countries” project through which ITU assists the LDCs to enhance their capabilities, capacity, readiness, skills and knowledge in the area of cybersecurity. The Global Cybersecurity Index (GCI), a measure of each nation state’s level of cybersecurity development. The GCI aims at providing the right motivation to countries to intensify their efforts in cybersecurity. The ultimate goal is to help foster a global culture of cybersecurity and its integration at the core of information and communication technologies. v The Quest for Cyber Confidence About the World Federation of Scientist The World Federation of Scientists (WFS) was founded in Erice, Sicily, in 1973, by a group of eminent scientists led by Isidor Isaac Rabi and Antonino Zichichi. Since then, many other scientists have affiliated themselves with the Federation, among them T. D. Lee, Laura Fermi, Eugene Wigner, Paul Dirac and Piotr Kapitza. The WFS is a free association, which has grown to include more than 10,000 scientists drawn from 110 countries. All members share the same aims and ideals and contribute voluntarily to uphold the Federation’s Principles. The Federation promotes international collaboration in science and technology between scientists and researchers from all parts of the world – North, South, East and West. The Federation and its members strive towards an ideal of free exchange of information, where scientific discoveries and advances are no longer restricted to a select few. The aim is to share this knowledge among the people of all nations, so that everyone may experience the benefits of the progress of science. The creation of the World Federation of Scientists was made possible by the existence, in Erice, of a centre for scientific culture named after the physicist Ettore Majorana, the Ettore