ITU Global Cybersecurity Index

Similar documents
ITU. The New Global Challenges in Cybersecurity 30 October 2017 Bucharest, Romania

ITU Plenipotentiary 2018

Europol The Police Intelligence Agency of the European Union

THE REGULATORY ENVIRONMENT IN EUROPE

GLOBAL CYBERSECURITY INDEX 2016

Map Reconfiguration User Guide

DataKom Vodafone Mobile Tariff Minimum 30 day end of month notice cancellation - Subject to contract. DataKom O2 Mobile Tariff. All prices exclude VAT

BI Building Integrity

Enterprise price plan guide Vodafone One Net Business

Spoka Meet Audio Calls Rates Dial-In UK

EU Cybersecurity Certification Framework

ETSI Governance and Decision Making

Patent Portfolio Overview May The data in this presentation is current as of this date.

Connected for less around the world Swisscom lowers its roaming tariffs again. Media teleconference 12 May 2009

Implementation of WTDC-14 Regional Initiatives for Europe

Map Reconfiguration Dealer Guide

Business Mobile Plans

The Canadian Experience

Business Mobile Plans

MINUTES AND TEXTS CUSTOMER MOBILE BOLT-ON GUIDE JUNE 2018 BOLT-ON WILL KEEP YOU IN CONTROL OF YOUR COSTS. INTERNATIONAL NUMBERS FROM YOUR MOBILE, THIS

Collaborative Regulation in the APP Economy

No Purchase needed

OSCE-UNECE. Pkt 2. Pkt 3. Pkt 1. Bernhard Schrempf - KISC -

PLEASE NOTE: firms may submit one set of research questionnaires covering both China and Hong Kong or separate sets for each jurisdiction

EUREKA European Network in international R&D Cooperation

Unlimited UK mobile calls and unlimited UK texts Bolt On: Unlimited landlines Poland Bundle (400 minutes to mobiles & landlines) 3.

Moving Professionals Forward. World Leader In Competence Based Certification

Friedrich Smaxwil CEN President. CEN European Committee for Standardization

NATO Science for Peace and Security (SPS) Programme. Emerging Security Challenges Division NATO

OnAudience.com I Report 2017 Ad blocking in the Internet

Carrier Services. Intelligent telephony. for over COUNTRIES DID NUMBERS. All IP

National CIRT - Montenegro. Ministry for Information Society and Telecommunications

Digital EAGLEs. Outlook and perspectives

Appendix G. Percentiles and Standard Deviations of Science Achievement TIMSS 2011 INTERNATIONAL RESULTS IN SCIENCE APPENDIX G 495

The Critical Importance of CIIP to Cybersecurity

Mapping of the CVD models in Europe

Patent Portfolio Overview July The data in this presentation is current as of this date.

Service withdrawal: Selected IBM ServicePac offerings

For: Ministry of Education From Date: 19 November 18-2 December 18 Venue: M1 Shops

Combating Pharmacrime AGENDA

European Cybersecurity cppp and ECSO. org.eu

Out of Bundle Vodafone

IMPLEMENTATION PLAN REGIONAL INITIATIVES FOR EUROPE

IBM offers Software Maintenance for additional Licensed Program Products

Transparency through Information

GLOBAL INITIATIVE TO COMBAT NUCLEAR TERRORISM

The Guide Everything you need to know about our mobile services

Cybersecurity in Asia-Pacific State of play, key issues for trade and e-commerce

MANUAL VOICE/DATA SIMCARD CANADA

Global Project on Cybercrime European Union Cybercrime Task Force. Strasbourg, November 21-23, 2011

ICT Connectivity for Trade & Development

CSIRT capacity building Andrea Dufkova CSIRT-relations, COD1 NLO meeting Athens June 8. European Union Agency for Network and Information Security

VOICE/DATA SIMCARD USA UNLIMITED

Ibis SIM PARTNERSHIP PROGRAM. June 2016

Price Plan Guide Vodafone 4G RED and 4G RED Business Enterprise Customers

Navigation System Digital Maps Portable Electronics. NAVITEL s.r.o., U Habrovky 247/11, Praha 4, Czech Republic

Measures to Maintain Post-Nuclear Security Summit Momentum for Continuously Enhancing Nuclear Security

Automation DriveServer

Regional Workshop on Cybercrime, Tbilisi, Georgia 13 May 2010

European Standardization & Digital Transformation. Ashok GANESH Director Innovation ETICS Management Committee

Achieving Global Cyber Security Through Collaboration

Kapsch CarrierCom. We drive innovation to drive your business.

PIRLS 2016 INTERNATIONAL RESULTS IN READING

Turquoise Terminal Returns User Guide for Creating & Uploading a Turquoise Terminal Return

Enterprise price plan guide Vodafone One Net Business

Step 1 Step 2. Name Minutes * Texts *

NIS Country Reports Overview Document

Signatories. to the EA Multilateral. and Bilateral Agreements

PIRLS International Report PIRLS. Appendix B

BUSINESS CUSTOMERS MORE FLEXIBILITY, CUSTOMER MOBILE TARIFF GUIDE MORE CHOICE EXPECT MORE MORE DATA, NOVEMBER 2018

This document is a preview generated by EVS

Reducing Risk and Building Capacity

International Packets

ehaction Joint Action to Support the ehealth Network

ENERGY TRAINING WEEK. Introduction to Energy Technology Policy. By Joining Forces We Multiply Results

Chapter 7. Teacher Preparation

OUR SHARERS MEAN BUSINESS. SHARER TARIFF RANGE CUSTOMER MOBILE TARIFF GUIDE JUNE 2018

Where is the EU in cloud security certification?: Main findings

ENISA & Cybersecurity. Steve Purser Head of Technical Competence Department December 2012

COCAINE (unless otherwise noted) amongst young people (ordered alphabetically by regions)

Cisco Aironet In-Building Wireless Solutions International Power Compliance Chart

The IECEE CB Scheme facilitates Global trade of Information Technology products.

Items exceeding one or more of the maximum weight and dimensions of a flat. For maximum dimensions please see the service user guide.

International Roaming Critical Information Summaries JULY 2017

Cyber Intel within European Cybercrime Center Ops

PAY MONTHLY ADDITIONAL SERVICES TERMS AND CONDITIONS

GDPR General Data Protection Regulation

International Business Parcels User Guide

Trade Up Program for Unix Server Program Description

Overcoming the Compliance Challenges of VAT Remittance. 12 April :55 to 16:30 (CEST)

BUSINESS CUSTOMERS MORE FLEXIBILITY, CUSTOMER MOBILE TARIFF GUIDE MORE CHOICE EXPECT MORE MORE DATA, APRIL 2018

This document is a preview generated by EVS

Signatories. to the EA Multilateral. and Bilateral Agreements

Sure Telephony Solutions Isle of Man Solutions that help you connect.

The Role of SANAS in Support of South African Regulatory Objectives. Mr. Mpho Phaloane South African National Accreditation System

WG EDI BEST PRACTICES

Mexico s Telecommunications Constitutional Reform, the Shared Network and the Public - Private Collaboration. MBB Forum Shanghai, China

Signatories. to the EA Multilateral. and Bilateral Agreements

Confirming its role as Italy s leading exhibition dedicated to security and fire prevention. 333 exhibitor companies

European Cybersecurity PPP European Cyber Security Organisation - ECSO November 2016

Transcription:

ITU Global Cybersecurity Index Joint ALERT Cyberdrill for Europe & CIS regions,chisinau 2017 Rosheen Awotar-Mauree Programme Officer ITU Office for Europe

2 ITU Overview

3 Services in Cybersecurity

ITU Office for Europe EURregion@itu.int 43 Countries : Albania, Andorra, Austria, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Israel, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, The Former Yugoslav Republic of Macedonia, Monaco, Montenegro, Netherlands, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovak Republic, Slovenia, Spain, Sweden, Switzerland, Turkey, Vatican, United Kingdom WTDC-14: 5 Regional Initiatives for 2014 to 2017 EUR1: Spectrum management and transition to digital broadcasting EUR2: Development of broadband access and adoption of broadband EUR3: Ensuring access to telecommunications/icts in particular for persons with disabilities EUR4: Building confidence and security in the use of telecommunications/icts WTDC-17: 5 Regional Initiatives for 2018 to 2021 4

ITU Regional Initiative 4 in Europe (EUR4) Objective: To build confidence and security in the use of telecommunications /ICTs Some Actions 2016-2017 ITU Council of Europe: High Level Round Table on COP, 10 October 2016 ITU-ENISA Regional Cybersecurity Forum for Europe, 29-30 November 2016, Bulgaria Benchmark of national initiatives on COP in the Central and Eastern European Countries Central European Cybersecurity public-private dialogue platform, Romania [co-organized - annual] National CIRT Implementation, Cyprus [2017-2018] CIRT Assessment, Bosnia & Herzegovina, November-December 2017 International Conference "Keeping Children and Young People Safe Online, Poland [co-organized - annual] ITU ALERT International Cyber Drill Exercise for the Europe & CIS Regions, Moldova, 21-23 November 2017 Western European Cybersecurity public-private dialogue platform, Switzerland, 7-8 December 2017 5

GCI overall approach Objective The Global Cybersecurity Index (GCI) measures each ITU Member States level of cybersecurity commitment in 5 main areas Legal - Technical Organizational - Capacity Building - Cooperation Goals Help countries identify areas for improvement Motivate action to improve relative GCI rankings Raise the level of cybersecurity worldwide Help to identify and promote best practices Foster a global culture of cybersecurity 134 responses primary research 193 countries analysed - secondary research 6

GCI Indicators Legal Technical Organizational Capacity Building Cooperation Cybercriminal legislation Cybersecurity regulation Cybersecurity training on regulation and laws National CIRT Government CIRT Sectoral CIRT Standards implementation framework for organizations Standards and certification for professionals Strategy Responsible agency Cybersecurity metrics Standardization bodies Best practice R & D programmes Public awareness campaigns Professional training courses National education programmes and academic curricula Incentive mechanisms Home-grown cybersecurity industry Bilateral agreements Multilateral agreements International fora participation Public-private partnerships Interagency partnerships 7

Heat Map 8 Commitment levels High Medium Low

Global Top Ten Country GCI Score Legal Technical Organizational Capacity Building Cooperation Singapore 0.92 0.95 0.96 0.88 0.97 0.87 United States 0.91 1 0.96 0.92 1 0.73 Malaysia 0.89 0.87 0.96 0.77 1 0.87 Oman 0.87 0.98 0.82 0.85 0.95 0.75 Estonia 0.84 0.99 0.82 0.85 0.94 0.64 Mauritius 0.82 0.85 0.96 0.74 0.91 0.70 Australia 0.82 0.94 0.96 0.86 0.94 0.44 Georgia 0.81 0.91 0.77 0.82 0.90 0.70 France 0.81 0.94 0.96 0.60 1 0.61 Canada 0.81 0.94 0.93 0.71 0.82 0.70 9 Maximum score is 1

Heat map regional perspective 0.210 0.296 0.334 0.370 0.430 0.530 Regional Score on a maximum on 1 10

GCI for ITU Europe & CIS region 43 Countries EUROPE : Albania, Andorra, Austria, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Israel, Italy, Latvia, Liechtenstein, Lithuania,Luxembourg, Malta, The Former Yugoslav Republic of Macedonia, Monaco, Montenegro, Netherlands, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovak Republic, Slovenia, Spain, Sweden, Switzerland, Turkey, Vatican,United Kingdom 11 Countries CIS : Armenia, Azerbaijan, Belarus, Georgia, Kazakhstan, Moldova, Russian Federation, Tajikistan, Turkmenistan, Ukraine, Uzbekistan GCI TIERS out of 54 countries Leading stage refers to the 22 countries (i.e., GCI score in the 60 th percentile and higher) that demonstrate high commitment. Maturing stage refers to the 22 countries (i.e., GCI score between the 30 th and 59 th percentile) that have developed complex commitments, and engage in cybersecurity programmes and initiatives. Initiating stage refers to the 10 countries (i.e., GCI score less than the 30 th percentile) that have started to make commitments in cybersecurity. 11

Some responses for Europe & CIS regions Out of 54 24 countries have Cybercriminal legislation 32 countries have Cybersecurity legislation 20 countries have Cybersecurity training on regulation and laws 35 countries have National CIRTs 43 countries have Government CIRTs 34 countries have sectoral CIRTs 38 countries have an entity responsible for Child Online Protection 7 countries use Cybersecurity metrics at national level 12 countries have standardization bodies handling Cybersecurity 23 countries have good practices in Cybersecurity 17 countries have R&D programmes in Cybersecurity 12

Some Noteworthy practices Georgia established cybercrime legislation in line with the principles and rules of the Budapest Convention both in terms of substantive and procedural aspects. Illegal access to information systems, data and system interference, and misuse of devices are criminalized by the Georgia criminal code. The Personal Data Protection Act was enacted by Parliament in 2011 and is intended to ensure protection of human rights and freedoms, including the right to privacy, in the course of personal data processing. United Kingdom issued in 2016 its second five years National Cyber Security Strategy. The strategy, issued by the Cabinet Office, aims to make the country one of the safest places in the world to carry out online business and doubles investment in cybersecurity compared to the first plan. 13

Some Noteworthy practices Netherlands uses metrics annually in order to measure cybersecurity development at a national level, summarized in the Cyber Security Assessment Netherlands report. The National Cyber Security Centre (NCSC) compiles disclosure reports, security advisories and incidents using a registration system. The metrics allow trends to be observed and acted on. UK and China agreed to establish a high-level security dialogue to strengthen exchanges and cooperation on security issues such as non-proliferation, organized crime, cyber crime and illegal immigration. The UK and China agree not to conduct or support cyber-enabled theft of intellectual property, trade secrets or confidential business information with the intent of providing competitive advantage Cyber Security information Sharing Partnership (CiSP) - https://www.cert.gov.uk/cisp/ 14

Some Noteworthy practices Switzerland has an association of experts. Privately managed companies and government agencies together in the event of a cyber incident, to quickly deliver a diagnosis in case of severe cyber incidents - https://www.swiss-cyberexperts.ch/cms/index-en.html Denmark, Finland, Iceland, Norway and Sweden Nordic National CERT Collaboration. This incudes technical cooperation and cybersecurity exercises to assess and strengthen cyber preparedness, examine incident response processes and enhance information sharing in the region. 15

Countries & GCI... Countries compare their own progress over time Questionnaire used as a basic roadmap to enhancing cybersecurity Identify and share practices Collaborate on the GCI initiative Open consultation for Questionnaire development Data sharing and validation 16

Cybersecurity Cooperation actions @ ITU PARTNERSHIPS for initiatives Global Cybersecurity Index call for new partners Australia Strategic Policy Institute, FIRST, Indiana University, INTERPOL, ITU-Arab Regional Cybersecurity Centre, Korea Internet & Security Agency, NTRA Egypt, Potomac Institute of Policy Studies, Red Team Cyber, UNICRI, University of Technology Jamaica, UNODC, World Bank National Cybersecurity Strategy Reference Guide CCI, CTO, ENISA, GCSP, GCSCC University of Oxford, Intellium, Microsoft, NATO CCDCOE, OECD, OAS, Potomac Institute, RAN D Europe, UNCTAD and World Bank Child Online Protection a whole community 17

Cybersecurity Cooperation actions @ ITU ITU STUDY GROUPS Membership driven ITU-D Study Group2 Question3 Securing information and communication networks: Best practices for developing a culture of cybersecurity new mandate ITU-T Study Group 17 : Security Develop recommendations for future standards including in Cybersecurity ITU-R Study Groups Securing radiocommunications 18

Thank you eurregion@itu.int www.itu.int