United Nations Mandate Source RegistryBeta Version
UN Secretariat MandatesUN System Mandates
United Nations (opens in new tab)
(opens in new tab) (opens in new tab) (opens in new tab) (opens in new tab) (opens in new tab)
Donate (opens in new tab)
  • A-Z Site Index (opens in new tab)
  • Contact (opens in new tab)
  • Copyright (opens in new tab)
  • FAQ (opens in new tab)
  • Fraud Alert (opens in new tab)
  • Privacy Notice (opens in new tab)
  • Terms of Use (opens in new tab)

Creation of a Global Culture of Cybersecurity and Taking Stock of National Efforts to Protect Critical Information Infrastructures

A/RES/64/211No PDF available

Who created this mandate?

A Resolution of the General Assembly, under agenda item 55cScience and technology for development, published in 2010.

What subjects does this mandate have?

5 topics
CybersecurityData ProtectionGuidelinesInformation DisseminationInformation Exchange

What does this mandate say?

2 operative paragraphs
1
Invites Member States to use, if and when they deem appropriate, the annexed voluntary self-assessment tool for national efforts to protect critical information infrastructures in order to assist in assessing their efforts in this regard to strengthen their cybersecurity, so as to highlight areas for further action, with the goal of increasing the global culture of cybersecurity;
2
Encourages Member States and relevant regional and international organizations that have developed strategies to deal with cybersecurity and the protection of critical information infrastructures to share their best practices and measures that could assist other Member States in their efforts to facilitate the achievement of cybersecurity by providing such information to the Secretary-General for compilation and dissemination to Member States.
Voluntary self-assessment tool for national efforts to protect critical information infrastructures
Taking stock of cybersecurity needs and strategies
1
Assess the role of information and communications technologies in your national economy, national security, critical infrastructures (such as transportation, water and food supplies, public health, energy, finance, emergency services) and civil society.
2
Determine the cybersecurity and critical information infrastructure protection risks to your economy, national security, critical infrastructures and civil society that must be managed.
3
Understand the vulnerabilities of the networks in use, the relative levels of threat faced by each sector at present and the current management plan; note how changes in the economic environment, national security priorities and civil society needs affect these calculations.
4
Determine the goals of the national cybersecurity and critical information infrastructure protection strategy; describe its goals, the current level of implementation, measures that exist to gauge its progress, its relation to other national policy objectives and how such a strategy fits within regional and international initiatives.
Stakeholder roles and responsibilities
5
Determine key stakeholders with a role in cybersecurity and critical information infrastructure protection and describe the role of each in the development of relevant policies and operations, including:
• National Government ministries or agencies, noting primary points of contact and responsibilities of each;
• Other government (local and regional) participants;
• Non-governmental actors, including industry, civil society and academia;
• Individual citizens, noting whether average users of the Internet have access to basic training in avoiding threats online and whether there is a national awareness-raising campaign regarding cybersecurity.
Policy processes and participation
6
Identify formal and informal venues that currently exist for Government-industry collaboration in the development of cybersecurity and critical information infrastructure protection policy and operations; determine participants, role(s) and objectives, methods for obtaining and addressing input, and adequacy in achieving relevant cybersecurity and critical information infrastructure protection goals.
7
Identify other forums or structures that may be needed to integrate the government and non-government perspectives and knowledge necessary to realize national cybersecurity and critical information infrastructure protection goals.
Public-private cooperation
8
Collect all actions taken and plans to develop collaboration between government and the private sector, including any arrangements for information-sharing and incident management.
9
Collect all current and planned initiatives to promote shared interests and address common challenges among both critical infrastructure participants and private-sector actors mutually dependent on the same interconnected critical infrastructure.
Incident management and recovery
10
Identify the Government agency that serves as the coordinator for incident management, including capability for watch, warning, response and recovery functions; the cooperating Government agencies; non-governmental cooperating participants, including industry and other partners; and any arrangements in place for cooperation and trusted information-sharing.
11
Separately, identify national-level computer incident response capacity, including any computer incident response team with national responsibilities and its roles and responsibilities, including existing tools and procedures for the protection of Government computer networks, and existing tools and procedures for the dissemination of incident-management information.
12
Identify networks and processes of international cooperation that may enhance incident response and contingency planning, identifying partners and arrangements for bilateral and multilateral cooperation, where appropriate.
Legal frameworks
13
Review and update legal authorities (including those related to cybercrime, privacy, data protection, commercial law, digital signatures and encryption) that may be outdated or obsolete as a result of the rapid uptake of and dependence upon new information and communications technologies, and use regional and international conventions, arrangements and precedents in these reviews. Ascertain whether your country has developed necessary legislation for the investigation and prosecution of cybercrime, noting existing frameworks, for example, General Assembly resolutions 55/63 and 56/121 on combating the criminal misuse of information technologies, and regional initiatives, including the Council of Europe Convention on Cybercrime.
14
Determine the current status of national cybercrime authorities and procedures, including legal authorities and national cybercrime units, and the level of understanding among prosecutors, judges and legislators of cybercrime issues.
15
Assess the adequacy of current legal codes and authorities in addressing the current and future challenges of cybercrime, and of cyberspace more generally.
16
Examine national participation in international efforts to combat cybercrime, such as the round-the-clock Cybercrime Point of Contact Network.
17
Determine the requirements for national law enforcement agencies to cooperate with international counterparts to investigate transnational cybercrime in those instances in which infrastructure is situated or perpetrators reside in national territory, but victims reside elsewhere.
Developing a global culture of cybersecurity
18
Summarize actions taken and plans to develop a national culture of cybersecurity referred to in General Assembly resolutions 57/239 and 58/199, including implementation of a cybersecurity plan for Government-operated systems, national awareness-raising programmes, outreach programmes to, among others, children and individual users, and national cybersecurity and critical information infrastructure protection training requirements.

iParagraph content is machine-extracted from UN documents. For authoritative content, please refer to the official UN document.

Table of contents