29/11/2018
Roadmap for a national Cybersecurity strategy Dr. Lina Oueidat Advisor to the Prime Minister Saad HARIRI on ICT national projects Cyber Security Focal Point 29 November 2018 29/11/2018
Overview The development of government, business, and personal digital services present increasing risks of unauthorized and malicious data access and tampering It is the responsibility of the government to put in place a national cyber security strategy to face these challenges and to reflect on the ways to institutionalize this work to ensure its sustainability 29/11/2018
ORGANIZATIONAL MEASURES Weaknesses as reported in the Global Cybersecurity Index 2017 for Lebanon (ITU) LEGAL MEASURES TECHNICAL MEASURES ORGANIZATIONAL MEASURES CAPACITY BUILDING COOPERATION Cybercriminal legislation Cybersecurity legislation Cybersecurity training National CERT/CIRT/CSIRT Government CERT/CIRT/CSIRT Sectoral CERT/CIRT/CSIRT Standards for organizations Standards for professionals Child online protection Strategy Responsible agency Cybersecurity metrics Standardization bodies Cybersecurity good practices R&D programs Public awareness campaigns Professional training courses Education programs Incentive mechanisms Homegrown industry Bilateral agreements Multilateral agreements International participation Public-private partnership Interagency partnerships Rank: 119/165 29/11/2018
Context The General Secretariat of the High Council of Defense (GSHCD), which reports directly to the Prime Minister, has worked tirelessly to raise the level of awareness in the field of cybersecurity EU presented a methodology for developing the cybersecurity strategy and expressed its willingness to assist the Lebanese government, provided the relationship EU/government is centralized to avoid fragmentation of efforts The government is expressing accurately its needs 29/11/2018
Context EU has already drawn up guidelines to support this vision of development for the benefit of military, security and judicial institutions, EU ready to mobilize the necessary expertise of member states in favor of a centralized initiative presented by the Lebanese State in this regard The Government General Secretary of PCM (GGS) drafts a plan for the gradual modernization of the PCM with the aim of transforming it into a state-of-the-art institution at national level (Tenders are already drafted) 29/11/2018
Context The plan provides for a modernization of the PCM structure takes into consideration ICT and Cyber security dimension through centralization and data security. PPP is working on a National Data Center with an effort on the Regulatory frame Work OMSAR is working on a Digital Transformation Strategy National Civil Registry Automation – Unique ID law Fragmented initiatives in most of the Ministries etc…. 29/11/2018
Context -Cybercrime actors (independent initiatives) General Secretariat of the Higher Defense Council Ministry of National Defense – Army Command – Directorate of Intelligence Ministry of Interior & Municipalities – General Directorate of General Security All IT related activities Internal Security Forces Information branch Judiciary police (8 branches) Cybercrime bureau Identification bureau Criminal records Etc…. General Directorate of State Security Ministry of Telecommunications (General Directorates – OGERO) Banque du Liban – Banking sector SPECIAL INVESTIGATION COMMITTEE 29/11/2018
Roadmap for a national cyber security strategy The working team- August 2018 Launching November 2019 Establishment of a national commission tasked with the following missions: Develop of a national cybersecurity strategy Participate in the establishment of the national institution, placed under the authority of the PCM, responsible for the implementation of the national cybersecurity strategy Invite the stakeholders in public civil and military administrations to delegate each a representative to the national commission Ensure largest participation possible Enforce adhesion to the commission directives 29/11/2018
Roadmap for a national cybersecurity strategy The working team- August 2018 29/11/2018
Axes of the strategy (1) Promote the role of the security and intelligence services and strengthen their mutual coordination with the support and supervision of higher authorities (PCM and its associated bodies in particular the GSCM under the authority of the PM) Develop the human resources, tools, technological components and their use, in partnership with the IT sector in public and private institutions, universities and associations 29/11/2018
Axes of the strategy (2) Institutionalize the centralization of cybersecurity activities within the PCM. Ensuring cybersecurity at the national level requires: Centralization of means of surveillance Exchange of experience and information among government agencies Capitalization of skills Technical support Technological monitoring of developments in the field Fight against terrorism and organized crime and their ramifications 29/11/2018
Axes of the strategy (3) Defense, deterrence and reinforcement against threats from inside and outside Raise the level of computerization in public administrations through validated and systematized automation processes and methodologies 29/11/2018
Axes of the strategy (4) Continuous development of State capacities to support the development of ICT. The State has the following missions: Protect government assets against various electronic threats Withstand and mitigate the effects of attacks Recover resiliently and rapidly its functions. Ensure the quality, integrity, and reliability of its data, especially when embarking on a rapid transformation to digital Enact the legal, administrative and technical measures related to e-government. 29/11/2018
Commission members Presidency of the Republic Presidency of the Parliament Presidency of the Council of Ministers – National ICT coordinator General Secretariat of the Higher Defense Council High Council for Privatization Ministry of Finance Ministry of Foreign Affairs Ministry of National Defense – Army Command – Directorate of Intelligence Ministry of Interior & Municipalities ISF -GS– General Directorate of State Security Office of the Minister of State for Administrative Reform Ministry of Telecommunications (General directorates – OGERO) Banque du Liban SPECIAL INVESTIGATION COMMITTEE 29/11/2018
Commission assistants Ministry of Economy and Trade Ministry of Industry Economic and Social Council Telecommunications Regulatory Authority Ministry of Education and Higher Education Lebanese University Other institutions and organizations 29/11/2018
Calendar 09/2018 No Yes 15/11/2018 ??/???? Key actors 6 months PM decision to establish NCS Commission Calendar New government? No Yes 15/11/2018 PM decision nat. ICT coordinator start work on Commission Final decision with new government ??/???? TAIEX missions Key actors GSHCD Coordinators EU Experts Institutions Working group 6 months Seminars Training 29/11/2018
Thank you 29/11/2018