Go Top
Go Top

Committed to connecting the world

Archived Newsroom

Share
Working Together to Secure the Global Information Society: ITU’s Global Cybersecurity Agenda

"Cyberspace has no borders, no constraining frontiers. The global nature of today's threats means no country can regard itself as an island."

- Dr. Hamadoun Touré, ITU Secretary-General

 

From its origins as a dedicated defense research network, the Internet has transformed modern lifestyles with its promise of open, real-time communications and limitless information. We have come to rely on the smooth and secure operation of networks in our online activities at work, at home and as consumers. And yet, at the same time, the rapid growth of ICT networks has also opened up new opportunities for criminals to exploit online vulnerabilities and attack countries' critical infrastructure. Confidence and security in using ICTs are vital for building an inclusive, secure and global Information Society. But increasingly sophisticated, well-organized cybercriminals are seriously undermining the future growth and potential of the online environment.

ITU and cybersecurity

In the areas of radiocommunication and standardization, ITU has carried out significant work in security architecture, encryption and authentication and information security management systems. Safeguarding quality of service against degradation or denial of service is vital for the secure operation of networks in data transmission and service provision and many of ITU's Radio Recommendations on generic requirements and the protection of radiocommunications against interference are relevant to security. ITU has issued recommendations on security principles for IMT-2000, with references to standards maintained by National and Regional Standards Development Organizations. ITU has also published a substantial number of security-related recommendations, as well as an ICT Security Standards Roadmap, a database for approved ICT security standards and a Security Manual: Security in Telecommunications and Information Technology.

"Everything in today's world is interconnected, and protecting each component of the ecosystem is equally important. If we have strong security in the network, but end user devices are less secure, it is like enabling a powerful home security system, and leaving all the doors open."

- Justin Rattner, Intel's Chief Technology Officer

Work with developing countries

ICTs are the engine driving many other economic sectors. In developing countries, the ICT sector has enabled a faster development rate than was previously permitted by pure industrialization. However, developing countries are deeply concerned about minimizing the risks that participation in the global Information Society can entail, with cybercrime topping the list of serious concerns. In its development work, ITU has long been engaged in building capacity to promote cybersecurity by providing technical assistance, implementing projects using advanced cybersecurity technologies, organizing capacity-building cybersecurity forums, and even releasing a national self-assessment toolkit to help governments evaluate their readiness with regard to national capacity in cybersecurity. Other ITU initiatives include a global anti-spam legislative survey, publications on cybersecurity and cybercrime, research on the financial impact of network security, and a variety of toolkits on botnet mitigation, cybercrime legislation, Computer Incidents Response Teams (CIRTs), and the promotion of a cybersecurity culture.

Global Cybersecurity Agenda (GCA)

 

Like its logo, the GCA is designed around five major pillars:

  1. Legal Measures

  2. Technical and Procedural Measures

  3. Organizational Structures

  4. Capacity Building

  5. International Cooperation

 

Despite ITU's active involvement in cybersecurity, much more can be achieved. Given ITU's long and successful history of forging consensus on how the world should manage global resources relating to ICTs such as satellite orbits and radiofrequency spectrum at the Tunis Phase of the World Summit on the Information Society (WSIS) in 2005, ITU was entrusted with the responsibility to lead international efforts to build confidence and security in the use of ICTs.

In response, ITU launched the Global Cybersecurity Agenda (GCA) in March 2007. A High-Level Experts Group (HLEG) was established to provide expert advice and guidance to the ITU Secretary-General on strategies to promote cybersecurity. This expert panel attracted top specialists from the likes of AT&T, Intel, Microsoft, Interpol, Verisign, as well as high-level government, academic and industry representatives from across the world, who contributed their insights and thought leadership on how best to tackle the growing challenges to the security of the online world.

What makes the GCA unique?

The GCA seeks to link existing initiatives and provide an overarching framework for consensus. This allows each stakeholder Group to focus on its own mandate, while ensuring cooperation with other stakeholders. The GCA already has Interpol the global organization for international law enforcement, with 186 member states sharing ideas with UNODC, the United Nations Office on Drugs and Crime. Both these organizations are putting heads together with the likes of APECTEL (Asia Pacific Economic Telecommunications and Information Working Group) and UNITAR (United Nations Institute for Training and Research). By working together, our chances of success in promoting cybersecurity and beating cybercrime on an international level are increased significantly. By involving global experts in the process from the beginning, we help to ensure that the solutions decided upon get implemented properly. Everyone recognizes that working together is the only way forward. A piecemeal approach to cybercrime is like the proverbial chain it is only as strong as its weakest link.

From idea to practice

ITU has carried out several activities to further apply principles, strategies and ideas behind the GCA. For example, the Child Online Protection (COP) Initiative to provide children everywhere with a safe and secure online experience and the International Multilateral Partnership against Cyber Threats (IMPACT) as the first global public-private initiative against cyber threats.

The latter initiative has been conceived as a framework for international cooperation aimed at bringing key stakeholders and partners from governments, private sector companies and academia together to provide ITU Member States with the expertise, facilities and resources to effectively address cyber threats The five work areas of the GCA are being addressed by IMPACT’s key tracks: the Global Response Centre (GRC), the Centre for Policy and International Cooperation, the Centre for Training and Skills Development and the Centre for Security Assurance and Research.

Working with leading partners, the GRC provides the global community with a real-time aggregated early warning system and access to specialized tools for authorized cyber-experts to respond immediately to cyber threats, especially during crisis situations. As of today, 137 countries are already members of the ITU IMPACT and a wide range of activities have been built upon five strategic pillars of the GCA framework.

In response to the need for establishing appropriate and dedicated organizational structures at a global level, and in order to identify, respond to and manage cyber threats, ITU and IMPACT have defined a strategy for helping Member States to establish their own National Computer Incident Response Team (CIRT), through a CIRT Lite solution, fully compliant and integrated with the GRC. Technical assessment has already been undertaken by ITU-IMPACT for some countries and has to date completed CIRT assessments for 29 countries. ITU-IMPACT has planned to conduct assessments in other regions such as South America and the Arab States. Zambia, Kenya, Montenegro, Uganda are in the process of signing agreements and will soon receive assistance to develop their national CIRT.

To build capacity, ITU, through IMPACT’s Training and Skills Development Centre, conducts high-level briefings for the benefit of representatives of Member States, providing invaluable exposure and privileged private sector insight on latest trends, potential threats and emerging technologies:

  • over 200 cybersecurity professionals and practitioners trained
  • 155 training scholarships (SANS Institute & EC-Council) deployed to 29 Member States globally
  • 50 law enforcement officers trained worldwide on network investigation.

Furthermore, and with the aim of extending legislative resources for Member States, following the publication of ITU’s Understanding Cybercrime: A Guide for Developing Countries, and the Toolkit for Cybercrime Legislation in May 2011, ITU and UNODC signed an MoU to collaborate globally on assisting Member States in mitigating the risks posed by cybercrime with the objective of ensuring secure use of ICTs. The MoU enables the two bodies to work together on technical assistance to be provided to Member States on cybercrime and cybersecurity, making available the necessary expertise and resources to facilitate the establishment of legal measures and legislative frameworks at that national level, within the principle of international cooperation, for the benefit of all countries in the world.

On the capacity building side, in line with its long tradition of public-private partnership, ITU has signed an MoU with Symantec. ITU will use Symantec’s security intelligence, in the form of its quarterly Internet Security Threat Reports, to increase understanding of and readiness for cybersecurity risks.

By distributing this report – which captures data from across Symantec’s Global Intelligence Network – to interested Member States, ITU aims to help better prepare governments in developing and developed nations alike to respond to the ever-growing risk from malware, cyber attackers and information thieves.

A new publication has been developed by ITU with the name of National Cybersecurity Strategy Guide. The guide assists Member States in developing their national strategy by examining existing capacity for addressing challenges to cybersecurity and CIIP, identifying requirements and outlining a national response plan.

Moreover, the United Nations Chief Executive Board (CEB), the highest level coordination mechanism within the UN, has given high priority to cybersecurity, and it welcomed the GCA as a framework to be applied also within the UN so as to deliver security services to UN agencies (through ITU-IMPACT, and as a mechanism for inter-agency coordination).

At its 20th session, the High Level Committee on Programmes (HLCP) of the United Nations Chief Executive Board for Coordination (CEB) discussed the impact of cybercrime and cyber threats. HLCP requested ITU, in collaboration with UNODC, to organize a meeting of focal points to examine policy and technology issues together; the meeting took place 1 July 2011 with the participation of some 35 UN agencies.

The main objective of the meeting was to develop a harmonized policy framework for the UN system to combat cybercrime and ensure cybersecurity, and elaborate a possible establishment of one stream of work under the CEB, or a dedicated working group on policy issues. The summary of the meeting and related proposals was submitted to the HLPC for the September 2011 Session.

"In this new digital world, we all have a special responsibility to ensure the safety and security of young people in the online world, just as we do offline.”

- Dr. Hamadoun Touré, ITU Secretary-General

Within this GCA framework, ITU launched the Child Online Protection (COP) initiative in November 2008 as a multi-stakeholder effort, aimed at bringing together partners from all sectors of the global community to ensure a safe and secure online experience for children everywhere. COP was presented to the ITU Council in 2008 and was endorsed by the UN Secretary-General, Heads of State, Ministers and heads of international organizations from around the world.

Together with prominent COP partners, ITU has been working to establish an international collaborative network for promoting online child protection and information sharing, to provide guidance on safe online behavior and best practices and to help partners develop and implement effective plans within their particular needs and capabilities, all by working with other partners and United Nations (UN) agencies. The global COP Guidelines, for children, parents, industry and policy-makers, which were developed by a multistakeholder group of COP partners, are one such example.

ITU has been leading the discussion on protecting children online and raising awareness of COP issues through the organization of workshops, forums, strategic dialogues or surveys, plus international, regional and national events. ITU developed and distributed a national survey questionnaire which addressed a broad range of issues connected to the policy and practice in the field of child online safety. As of September 2011, 95 Member States have completed the COP National Survey and the comprehensive survey result is available on the COP website. In line with this COP Survey, ITU released the Child Online Protection Statistical Framework and Indicators in November 2010, which is the world’s first attempt to provide an overall statistical framework related to the measurement of child online safety, with a particular emphasis on measures that are suitable for international comparison.

Moreover, at the ITU Plenipotentiary Conference in 2010, Member States adopted new Resolution 179, ITU’s role in child online protection, seeking to establish a mandate for ITU’s work in this area and encourages ITU to continue its COP Initiative as a platform to raise awareness and educate stakeholders on this important issue.

Now, together with the new COP patron, H.E. Laura Chinchilla, President of Costa Rica, ITU has entered a new phase of concrete activities in order to implement COP Guidelines for national and societal benefits under the COP Global Initiative structure. Strategies for achieving these guidelines span five main areas: 1) legal measures; 2) technical and procedural measures; 3) organizational structures; 4) capacity building; and 5) international cooperation. ITU is also working towards the development of interoperable technical standards, establishment of national hotlines, development of national strategy guide and legislative toolkits, as well as training for parents, guardians and educators.

ITU’s COP Initiative will bring members of existing initiatives together, provide guidance for stakeholders in both capacity-building and awareness-raising and will foster cooperation and collaborative thinking between all those involved in the provision of services to children and young people.

 

 

Follow Us
Copyright © ITU 2026 All Rights Reserved Feedback  Contact Us  Accessibility