Protection of Critical National Infrastructure APT-ITU workshop on the International Telecommunications Regulations Bangkok, 6-8 February 2012 Preetam.

Slides:



Advertisements
Similar presentations
South-South Cooperation and Public-Private Partnership for Development by Bader Al Dafa Under Secretary General Executive Secretary, UNESCWA October 2007.
Advertisements

AIRLINE VIEWS ON THE PROPOSED GATS TOURISM ANNEX Richard Smithies Director, Policy Analysis Government & Industry Affairs - IATA SYMPOSIUM ON TOURISM SERVICES.
Critical Infrastructure Protection Policy Priorities Sara Pinheiro European Commission DG Home Affairs.
International Telecommunication Union Accra, Ghana, June 2009 Conformance and Interoperability Testing: (WTSA-08) Resolution 76 Joshua Peprah Director,
Security in the use of ICTs APT-ITU workshop on the International Telecommunications Regulations Bangkok, 6-8 February 2012 Preetam Maloor, ITU.
Overview of Convergence APT-ITU workshop on the International Telecommunications Regulations Bangkok, 6-8 February 2012 Preetam Maloor, ITU.
The Human Right to Access Communications References and Principles. APT-ITU workshop on the International Telecommunications Regulations Bangkok, 6-8 February.
Inter-American Telecommunication Commission (CITEL) 1 INTER-AMERICAN PROPOSALS FOR WCIT-12 CITEL (May 2012)
Enforcement issues, including status of ITU-T Recommendations APT-ITU workshop on the International Telecommunications Regulations Bangkok, 6-8 February.
International Telecommunication Union An Insight into BDT Programme 3 Marco Obiso ICT Applications and Cybersecurity Division Telecommunication Development.
Evolution of NGN and NGA scenario in Nepal Nepal Telecommunications Authority.
Agrobiodiversity and Intellectual Property Rights: Selected Issues under the FAO International Treaty on Plant Genetic Resources for Food and Agriculture.
Botswana Policy Statement at the WSIS+10 Honourable Nonofo E. Molefhi Minister of Transport and Communications.
Lisbon, Portugal 22 April 2009 Alexander Ntoko Head, Corporate Strategy Division International Telecommunication Secretary-General’s Report to WTPF 2009.
Aftermath Debriefing Meeting, Durban, South Africa July, 10 th, 2013.
COMPETITION POLICY AND ECONOMIC DEVELOPMENT PRESENTATION AT CUTS-ARC CAPACITY BUILDING WORKSHOP, LUSAKA 7 TH MARCH, 2011 BY SAJEEV NAIR, COMPETITION POLICY.
ICS 417: The ethics of ICT 4.2 The Ethics of Information and Communication Technologies (ICT) in Business by Simon Rogerson IMIS Journal May 1998.
Geneva, Switzerland, 2 June 2014 The Regulatory aspects of CPND, CLI and OI “the ITRs” Sherif Guinena SG2 Chairman ITU Workshop on “Caller ID Spoofing”
29 May 2006RNSA Workshop 1 Social Implication of National Security RNSA Workshop The risk of public data availability on critical infrastructure protection.
Swedish Post and Telecom Authority World Conference on International Telecommunications (WCIT-12) Revision of the International Telecommunication Regulations.
 Background  Why the ITRs are important  The need to revise the ITRs  Preparatory process  Some key proposals  Expectations for WCIT-12.
Creating Trust in Critical Network Infrastructures Canadian Case Study Michael Harrop.
Geneva, Switzerland, 2 June 2014 SG2: WTSA and PP Resolutions “Recommendation E.157” Sherif Guinena SG2 Chairman ITU Workshop on “Caller ID Spoofing” (Geneva,
Space Systems as Critical Infrastructure Iulia-Elena Jivanescu 1st Space Retreat, Tenerife, Spain, 8-22 January, 2013.
Cartagena protocol on Biosafety to the Convention on Biological Diversity and the International debates (COP- MOP) Stakeholders’ workshop on the Biosafety.
WCIT Sally Wentworth Internet Society 1. What we will cover Context – setting the stage WCIT – background and preparations WCIT what happened 2012 ITRs.
IAEA International Atomic Energy Agency Overview of legal framework Regional Workshop - School for Drafting Regulations 3-14 November 2014 Abdelmadjid.
Isdefe ISXXXX XX Your best ally Panel: Future scenarios for European critical infrastructures protection Carlos Martí Sempere. Essen.
International Telecommunication Union ICTs and Climate Change Adaptation Angelica V Ospina, University of Manchester, UK Cristina Bueti, International.
1 Information System Security Assurance Architecture A Proposed IEEE Standard for Managing Enterprise Risk February 7, 2005 Dr. Ron Ross Computer Security.
The NIGF CONFERENCE © 2013 ADDRESSING THE VULNERABILITY OF CRITICAL ICT INFRASTRUCTURE by Ernest Ndukwe, OFR Chairman Openmedia Communications Ltd 18 th.
Catastrophe Readiness and Response Session 7b 1 Session 7b Critical Infrastructure Drew Bumbak.
Making South Africa a Global Leader in Harnessing ICTs for Socio-economic Development SECRET 1 PRESENTATION TO THE PORTFOLIO COMMITTEE ON COMMUNICATIONS:
World summit on the information society 1 WSIS: Internet Governance President of the WSIS Phase II Preparatory Committee Ambassador Janis Karklins April.
1 Session 7, Section 2 Critical Infrastructure Drew Bumbak.
CARTAGENA PROTOCOL ON BIOSAFETY NDA- DEAT BILATERAL MEETING 1 August 2003 Presenter : M. Mbengashe.
Overview of Issues and Interests in Standards and Interoperability Mary Saunders Chief, Standards Services Division NIST.
Durban, South Africa, 8 July 2013 Outcome of WTSA-12 on spam Xiaoya Yang, Head, WTSA Programmes Division ITU-TSB ITU Workshop on “Countering.
ITU CoE/ARB 11 th Annual Meeting of the Arab Network for Human Resources 16 – 18 December 2003; Khartoum - Sudan 1 The content is based on New OECD Guidelines.
Close to Nature Forestry and Forest Policy Challenges in Europe Ilpo Tikkanen, European Forest Institute Zvolen, Slovakia October, 2003 Together.
Aiia : voice of the digital economy ASR: voice of services in Australia Presented by Kaaren Koomen Director, Australian Services Roundtable Director (Alternate),
Threat Prevention and Detection (within Critical Infrastructures) under EU Data Protection Legislation– Purpose Specification and Limitation. Laurens Naudts.
Erman Taşkın. Information security aspects of business continuity management Objective: To counteract interruptions to business activities and to protect.
Regional Action Plan for Sustainable Transport of Dangerous Goods along the Mekong River Final Regional Workshop, October 2014 Bangkok, Thailand.
International Telecommunication Union Committed to connecting the world Shaping tomorrow’s smart sustainable cities today Nasser Saleh Al Marzouqi Chairman,
International Telecommunication Union Arab Regional Preparatory Meeting for the World Conference on International Telecommunications (WCIT-12) Cairo, Egypt,
Slide 1 of 16. Slide 2 of 16 First African Preparatory Meeting Was held in Cairo November 2011 with invitation from the African Telecommunication.
RCC Preparations WCIT-12 Dmitry Cherkesov (Russia) Deputy Head of RCC WP for WCIT-12 Com-ITU Meeting 6 – 8 September 2011 Lisbon, Portugal.
1 Regional Commonwealth in the field of Communications RCC PREPARATION FOR THE WORLD CONFERENCE ON INTERNATIONAL TELECOMMUNICATIONS
POLS 304 Local Government & Governance Multilevel Governance in the European Union and Governance in Turkey.
Regional Commonwealth in the field of Communications
Richard Hill Counsellor ITU/TSB
Inter-American Telecommunication Commission (CITEL)
4th SG13 Regional Workshop for Africa on “Future Networks for a better Africa: IMT-2020, Trust, Cloud Computing and Big Data” (Accra, Ghana, March.
European preparations for the WCIT
Nuclear and Treaty Law Section Office of Legal Affairs
French Port Cybersecurity Initiative
INTERCONNECTION GUIDELINES
Nuclear and Treaty Law Section Office of Legal Affairs
Richard Hill Counsellor ITU/TSB Presented by Paolo Rosa ITU
Critical Infrastructure Protection Policy Priorities
Cybersecurity in Belarus a general overview of support areas
Perspectives on ITRs Thomas Wilson
Protection of Critical National Infrastructure
Road Infrastructure for Road Vehicles Automation
Interconnection and Interoperability APT-ITU workshop on International Telecommunications Regulations Bangkok, 6-8 February 2012 Richard Hill, ITU.
WCIT12 Update Planning & International Relations Department
European Programme for Critical Infrastructure Protection (EPCIP)
NS4960 Spring Term 2017 Mexico: Poor Regulation Risks Investment Projects Oxford Analytica, Mexico: Electricity Rate Increases May Harm Industry, March.
THE EU LEGAL FRAMEWORK ON EMPLOYEE INVOLVEMENT
Presentation transcript:

Protection of Critical National Infrastructure APT-ITU workshop on the International Telecommunications Regulations Bangkok, 6-8 February 2012 Preetam Maloor, ITU

Background : References in ITUs Basic text Critical national infrastructure has not been explicitly defined in ITUs Basic Text or decisions made by ITU bodies. However, many references to the protection of critical national infrastructure exist especially in the context of security of telecommunications/ICT networks and services. 2 ITU CS/Art.38 emphasizes the importance of the protection of a nations telecommunication infrastructure in order to ensure the stability and reliability of international telecommunications ITU CS/Art.34 which provides that Member States may cut off, in accordance with their national law, any private telecommunications which may appear dangerous to the security of the State or contrary to its laws, to public order or to decency ITU CS/Art.35 on the right of a Member State to suspend its international telecommunication service. ITU CS/Art.38 emphasizes the importance of the protection of a nations telecommunication infrastructure in order to ensure the stability and reliability of international telecommunications ITU CS/Art.34 which provides that Member States may cut off, in accordance with their national law, any private telecommunications which may appear dangerous to the security of the State or contrary to its laws, to public order or to decency ITU CS/Art.35 on the right of a Member State to suspend its international telecommunication service. PP-10 Res. 130 (Strengthening the role of ITU in building confidence and security in the use of information and communication technologies) PP-10 Res. 174 (ITU's role with regard to international public policy issues relating to the risk of illicit use of information and communication technologies) PP-10 Res. 130 (Strengthening the role of ITU in building confidence and security in the use of information and communication technologies) PP-10 Res. 174 (ITU's role with regard to international public policy issues relating to the risk of illicit use of information and communication technologies) ITU CS/CV contains references to the acknowledgement of the right of a Member State over its telecommunications and related infrastructure, considered critical national infrastructure

Background : References in current ITRs Protection of telecommunication/ICTs as a critical national infrastructure not explicitly mentioned in the current ITRs Implicit references include: – the acknowledgement of the right of a Member State over its telecommunications and related infrastructure – the need for a Member State to take into consideration the global implications of its actions concerning its national telecommunications infrastructure 3 ITRs/Art.7 (Suspension of Services) which refers to the right of a Member State to suspend its international telecommunication services partially or totally, while also ensuring the need for appropriate timely notification of this action ITRs/Art. 9 (Special Arrangements) which provides that any such special arrangements should avoid technical harm to the operation of the telecommunication facilities of third countries ITRs/Art.7 (Suspension of Services) which refers to the right of a Member State to suspend its international telecommunication services partially or totally, while also ensuring the need for appropriate timely notification of this action ITRs/Art. 9 (Special Arrangements) which provides that any such special arrangements should avoid technical harm to the operation of the telecommunication facilities of third countries

Overview of global precedents and challenges - Definitions Critical Resources Critical (national) Infrastructure Critical Information Infrastructure

Definition: Critical Resources Most expansive of all the terms. Includes those assets within the sphere of critical infrastructure and critical information infrastructure Has been defined by some national governments to include – natural and environmental resources such agriculture, energy, freshwater, rainforests, etc. – national monuments and icons which have been defined as a physical structure or object recognized both nationally and internationally as representing a nations heritage, traditions and/or values.

Definition: Critical Infrastructure Primarily defined in the context of – the adequacy of a nations public works, e.g. bridges, roads, airports, dams, etc. – includes telecommunications, in particular major national and international switches and connections. Many countries, in defining critical infrastructure, include in the definition a reference to that nation Many other countries have specifically included the national component in the term itself (e.g. UK)

Definition of Critical Infrastructure : Examples from Member States, Regional groups

Definition: Critical Information Infrastructure Increasing reliance on IP-based and other networks as an ubiquitous aspect of social and economic activities of nations – a fundamental component in the design and operation of all forms of traditional critical infrastructure (e.g. electricity grids, transportation systems, water supply etc.) Therefore, some have proposed the introduction of a new term, Critical Information Infrastructure. In Germany, the majority of information infrastructures are run by private companies. Hence, protecting these infrastructures is primarily the task of private operators and service providers. However, given the dramatic consequences damage to those infrastructures might have for the state, the economy and large parts of the population, sole responsibilities of individual operators is neither sufficient nor appropriate. This holds true also for critical infrastructures in Germany*. *Germanys Federal Ministry of the Interior in a 17 June 2009 report entitled National Strategy for Critical Infrastructure Protection

Definition: Critical Internet Resources With emergence of a global information society, the term Critical Internet Resources is considered by many (e.g. CoE) as related to critical information infrastructure in the Internet era. Subject of intense discussions at WSIS and other international fora No consensus yet on the proper scope of these resources – general agreement on IP addresses, domain names, and root servers – More expansive view (e.g. CoE): includes backbone infrastructure and IXPs; broadband access Some argue that considering the dynamic nature of the internet, there should be no rigid definitions and specifically enumerated lists? – e.g. deployment of DNSSEC key signing keys in 2010

Critical Information Infrastructure as intangible assets E.g. telecommunication infrastructure and number portability – In many jurisdictions, it is not clear who owns the telephone number, that is, who has what rights over the number (e.g. can somebody sell or rent the number?). Similar issue is being faced by many countries on some Internet resources: – whether Internet names and addresses constitute an intangible property, or if it is a mere service which registrants enter into a contractual relationship with the provider

Evolution of Definitions to recognize Intangible Property (old) Canadas critical infrastructure consists of those physical and information technology facilities, networks, services and assets which, if disrupted or destroyed, would have a serious impact on the health, safety, security or economic well-being of Canadians or the effective functioning of governments in Canada. (current) Critical infrastructure refers to processes, systems, facilities, technologies, networks, assets and services essential to the health, safety, security or economic well-being of Canadians and the effective functioning of government. Critical infrastructure can be stand-alone or interconnected and interdependent within and across provinces, territories and national borders. Disruptions of critical infrastructure could result in catastrophic loss of life, adverse economic effects and significant harm to public confidence. (old) Critical infrastructure include those physical resources, services, and information technology facilities, networks and infrastructure assets which, if disrupted or destroyed, would have a serious impact on the health, safety, security or economic well-being of citizens or the effective functioning of governments. (current) critical infrastructure means an asset, system or part thereof located in Member States which is essential for the maintenance of vital societal functions, health, safety, security, economic or social well- being of people, and the disruption or destruction of which would have a significant impact in a Member State as a result of the failure to maintain those functions CANADACANADA EUEU

Bilateral Commercial Arrangements between parties as a critical resource ? CoE Secretariat report* includes information on the growing reliance of bilateral commercial arrangements between parties as a critical resource and their potential to significantly disrupt global connectivity and resolution. Some reasons cited: – Growing dominance of Internet Exchange Points – major ISPs unwillingness to enter into direct traffic exchange relationships The failure of these critical bi-lateral contract resources could significantly disrupt the operation of the Internet – E.g. a 2008 dispute between Cogent Communications, a US based internet service provider, and TeliaSonera, Swedens largest telecom company cut off access to certain websites to a significant customer base in both continents. * Internet governance and critical internet resources, Council of Europe Secretariat, April 2009

Multilateral Cooperation in the Protection of Critical National Infrastructure Nations consider protection of their critical infrastructure as closely linked to the protection of their national sovereignty and have a variety of national legislations in place to safeguard this infrastructure. General agreement that the protection of critical national infrastructure requires multilateral cooperation Canada-United States Action Plan for Critical Infrastructure :The complexity and interconnectedness of Canada-U.S. critical infrastructure requires that the Canada-U.S. Action Plan be implemented using organizational structures and partnerships committed to sharing and protecting information and managing risks Australia: Critical Information Resources is a shared responsibility across governments and the owners and operators of critical infrastructure NATO: Critical Infra. Protection (CIP) involves several stakeholders: public authorities - at the national and local levels, including various public agencies; critical infrastructure operators, which are often private sector firms; and the population at large. CIP has also increasingly gained an international dimension, which raises the question of international co-operation on CIP

Proposals made to CWG-WCIT ITRs do not explicitly refer to protection of critical resources or infrastructure. They do, as mentioned above, implicitly cover the concept. Some provisions of the current ITRs can be considered to specifically relate to the concept, – E.g. the provision in article 9 that special arrangements should avoid technical harm to the operation of the telecommunication facilities of third countries. – Various proposals have been made to modify or increase the scope of such provisions, for example to include avoidance of financial harm. Various proposals regarding the misuse of numbering resources could be considered as related to protection of critical information resources, if it is held that naming, numbering, addressing, and identification resources are such critical information resources. Some might consider that proposals to CWG-WCIT related to quality of service and international routes are related to protection of critical resources. There is no consensus yet on the proposals