During recent research regarding Cybersecurity Policy in the national context and the efforts being made in developed economies such as the U.S., the U.K. and Canada and others, I had the opportunity to delve into some of the strategies put forth by the U.K., for example,
the UK National Cybersecurity Strategy 2016-2021, in contrast to similar efforts in the U.S. via
the NIST Framework for Improving Critical Infrastructure Cybersecurity.
Also,
I think that before such comparisons can be made, a proper context is needed as
to why these national level policies are required in the first place. According
to security experts, it has long been established that since its inception the
internet has been inherently insecure.11 The evolution from
self-contained operating environments, in the
mid-1990s, when organizations--banks, universities, government agencies and
others—conducted online business within their own computer networks with
relative isolation from the outside world, to highly interconnected networks
way beyond geographical boundaries just a decade later in the 2000s. At that
time cyberattacks or break-ins were thought of as pranks and gradually these
behaviors grew into more serious data breaches with limited financial loss but
with the reputation of victimized organizations tarnished.
Now
fast forward to 2016’s cyberattacks in Ukraine13, in which according
to security experts, in 2015 power plants and utilities in the U.S. and Ukraine
were penetrated by Russian hackers who were able to gain access to critical
control systems and remotely actuated mechanical and electrical components to
effectively shut down switchgear stations and caused power outages in the Ukraine.
In the U.S. this incident raised serious concerns about the possibility of such
attacks putting the U.S. electric grid at risk.13 And, most recently
there’s strong evidence of Russia’s continued attempts to infiltrate U.S.
critical infrastructures.14
And,
when it comes to nation-state sponsored cyberattacks, North Korea is being
considered a growing security threat.1 According to a recent page 1
story in a major news media, “…the nation’s fingerprints have appeared in an
increasing number of cyberattacks, the skill level of its hackers has rapidly
improved and their targets have become worrisome…,”5 said the
Journal.
Now,
regarding the UK National Cybersecurity Strategy 2016-2021, I think like the
NIST framework above, at the highest level it aims to ensure the security of
the UK, its digital foundations and its economy and the privacy of its
citizens. The UK policy states that, “The cyber threat impacts the whole of our
society, so we want to make very clear that everyone has a part to play in our
national response.”11 This strategy is a continuation of similar
efforts undertaken five years earlier, in 2011, which created the foundation
for this new plan.
Also,
the policy is a five year strategy intended to strengthen their systems,
infrastructures and defense mechanism, cyber-physical and cyberspace, across
all sectors of its society—private and public—by enforcing positive behaviors
to business, organizations and individuals to reduce the risks of cyber threats.
So,
the main objectives driving this policy to achieve its vision include the
following; Defend, Deter and Develop. These objectives represent a three-prong approach;
first, is to protect the UK networks, data and systems. Second, is to serve as
deterrence to prevent cyber threats and provide the necessary means for
counterattacks. And, third, is to develop a sustainable, domestic cyber
security industry to spur research and development and technical skills to stay
ahead of future sophisticated threads through breakthrough technologies.
In
addition, the UK designated a new National Cyber Security Center (NCSC) as the
governing body and overseer of its national cybersecurity strategy to safeguard
its Critical National Infrastructure (CNI) and it works with other
organizations to achieve its objectives, such as the Computer Emergency
Response Team (CERT-UK), the Center for Cyber Assessment (CCA) and others.
So,
how are these policies implemented? I believe that in the U.S., via the NIST
framework, it’s up to every organization to determine course of actions based
on their respective Framework Profiles and organizational goals, whereas in the
UK, it’s implemented through recommended actions and action plans under its
well defined three main objectives. Also, it extends internationally through
partnerships with other allied countries with similar national security
interests and multilateral organizations such as the United Nations (UN), the European
Union (EU) and NATO and others.
In
the final analysis, I think both the NIST framework and the UK strategy provide
overarching high-level objectives and underlying processes and procedures to
enable organizations with policy-making at the enterprise and national level.
Finally, I think that
the NIST Framework in the U.S., and beyond, and the UK Cybersecurity Strategy
are just two examples of not only policy-making at a national level But a clear
illustration as to how strategic planning enables these nations to develop policy
at a national level taking into consideration many factors beyond the
underlying technologies, which impact our daily lives.
3.
“Security and Privacy,” IEEE
Computer Society, Computing Edge, Pub January 2018, pp. 8-14.
4.
“Information Technology,”
IEEE Computer Society, Computing Edge, Pub November 2017, p. 22-27.
5.
Peltier, T. R., (2004). Information Security Policies and
Procedures: A Practitioner's Reference. New York, NY: Auerbach Publications.
13. Cyberattacks Raise
Alarm for U.S. Power Grid, published on Wall Street Journal, December 31, 2016.