Global Cybersecurity Index - Overview North
Description: Global Cybersecurity Index - Overview North Macedonia May 2024 itu.intgci Note: scores and analysis may change based on GCI 2024 The ITU Global Cybersecurity Index is a composite index that measures key aspects of state-level cybersecurity
Related Topics
Download Presentation
"Global Cybersecurity Index - Overview North" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.
Presentation Transcript
slide1. Global Cybersecurity Index - OverviewNorth Macedonia May 2024
itu.int/gci
Note: scores and analysis may change based on GCI 2024<br>
slide2. The ITU Global Cybersecurity Index is a composite index that measures key aspects of state-level cybersecurity practices The GCI is designed to
Drive awareness global cybersecurity
Share best practices
Drive continuous cybersecurity improvement
Build capacity in ITU Members
Key Statistics
First released: 2015
Member States Participating: 172 (of 194)
Mentions in scholarly articles: >2 700*
Current questionnaire: 82 questions
GCI 2020 Report Available at: https://www.itu.int/hub/publication/d-str-gci-01-2021/ 2<br>
slide3. North Macedonia can improve Cooperation, Capacity Development, and Technical Measures 3 *The Global Cybersecurity Index Questionnaire is updated between editions to better reflect current considerations in cybersecurity Averages weighted by number of internet users<br>
slide4. North Macedonia can work to ensure its laws and regulations are effective in addressing current cybersecurity issues Legal Measures: the existence of legal institutions and effective frameworks dealing with cybersecurity and cybercrime.
North Macedonia has implemented a number of laws addressing cybersecurity, including Criminal Code of North Macedonia, amended in 2019; Law on Electronic Communications; Law on Personal Data Protection; Law on Cybercrime; Law on Copyright and Related Rights,
North Macedonia is party to the Budapest Convention
The Law on Electronic Documents, Electronic Identification and Trust Services, adopted in 2019 defines online identity
The Criminal Code of North Macedonia addresses online racist and xenophobic behaviors, as well as harassment, abuse
Child online protection is regulated through the Law on Protection of Children from Harmful Content on the Internet
Areas of improvement:
Clarify national policy and regulations relevant to the identification and protection of critical infrastructure<br>
slide5. North Macedonia build on its national CIRT work to target sectorial needs Technical Measures: the existence of technical institutions and frameworks dealing with cybersecurity endorsed or created by the Member State.Â
MKD-CIRT is a separate organizational unit within the Agency for Electronic Communications, and is accredited with FIRST. It conducts a variety cyber awareness activities cyber exercises, public advisories
Areas of improvement:
MKD-CIRT can work to become affiliated with a regional CERT
Develop sectorial CIRTs/CSIRTs/CERTs domestically or in collaboration with other countries, and carry out cyber awareness activities and cyber drills targeting sectors
Develop a comprehensive the implementation of internationally recognized standards in cybersecurity<br>
slide6. North Macedonia can work to enhance and refine its existing national cybersecurity strategy Organizational Measure: the existence and number of institutions and strategies organizing cybersecurity development at the national level.Â
North Macedonia’s National Cybersecurity Strategy 2023-2027 is periodically updated to reflect changing cyber threats, and addresses the protection of critical infrastructure, life cycle management, as well as consultation with national experts, and as an associated Action Plan.
The Agency for Electronic Communications (AEK), Ministry of Interior, National Security Agency, and Ministry of Transport and Communications have responsibilities for cybersecurity at the national level
National Coordination Body for the Protection of Children from Sexual Exploitation and Abuse Online (NCB) is responsible for Child Online Protection initiatives
North Macedonia uses a variety of metrics to assess cybersecurity at the national level, including the National Vulnerability Database and Common Vulnerability Society System
Areas of improvement:
Complete clarification in NCS which agency or ministry has the responsibility for cybersecurity related to National Critical Infrastructure Protection
Clarify in NCS which agency or ministry has the responsibility for cybersecurity capacity development
Conduct regular cybersecurity audits at the national level
Expand on metrics/tools used for assessing risks at a national level<br>
slide7. North Macedonia can expand trainings as part of its cybersecurity capacity development Capacity Development Measures: include numerous socio-economic and political implications are applicable in the cybersecurity field. Â
North Macedonia has developed cybersecurity awareness campaigns targeting the general population, MSMEs, the private sector in general, as well as educators, parents, and children relevant to Child Online Protection
Specialized trainings are available for financial, telecommunications, transport, and energy sector actors, as well as for educators on Child Online Protection
Universities offer courses on cybersecurity
The Macedonian Information Security Society (MISI) promotes the national cybersecurity industry, as well as providing trainings, certifications, and networking opportunities
Areas of improvement:
Develop cybersecurity awareness activities targeting the needs of specific consistencies, including public sector agencies, civil society, older persons, persons with disabilities
Develop and/or support trainings for cybersecurity professionals, judicial actors, private sector actors
Develop and/or support educational programmes for students
Support development of a national cybersecurity industry, as well as R&D activities 7<br>
slide8. North Macedonia can expand its international and domestic collaborations on cybersecurity Cooperation Measures: enhance dialogue and coordination, enabling the creation of a more comprehensive cybersecurity field of application.
North Macedonia has a number of agreements with other countries on information sharing, including with the United States, EU and NATO
Areas of improvement:
Further develop agreements with the other countries and regional organizations, particularly on capacity development
Advance PPPs with domestic and foreign companies on cybersecurity
Develop inter-agency coordination processes on cybersecurity 8<br>
slide9. North Macedonia can expand its cybersecurity commitments to address areas for growth North Macedonia can work to enhance its existing cybersecurity-related legislation elements in place
North Macedonia can implement sectorial CIRT(s) activities
North Macedonia can work to enhance and refine its National Cybersecurity Strategy through its lifecycle management practices, and implement metrics and audits to track and assess technical outcomes
With 84% of the population currently online, cybersecurity awareness campaigns can help establish cybersecure behaviours 9 Averages weighted by number of internet users<br>
slide10. North Macedonia can improve across all GCI pillars Selected ITU cybersecurity programmes of potential interest include:
Technical improvement: CyberDrills offer opportunities for local CIRTs/CSIRTS/CERTs to improve and grow
Organizational improvement: National Cybersecurity Strategy (NCS) development and implementation: ITU’s new NCS lifecycle training course and the 2nd editions of the Guide are now available
Capacity Development improvement: Child Online Protection Guidelines for children, parents and educators, and policy makers are available 10 *The Global Cybersecurity Index Questionnaire is updated between editions to better reflect current considerations in cybersecurity. Averages weighted by number of internet users<br>
slide11. ITU
itu.int/cybersecurity
cybersecurity@itu.int<br>
itu.int/gci
Note: scores and analysis may change based on GCI 2024<br>
slide2. The ITU Global Cybersecurity Index is a composite index that measures key aspects of state-level cybersecurity practices The GCI is designed to
Drive awareness global cybersecurity
Share best practices
Drive continuous cybersecurity improvement
Build capacity in ITU Members
Key Statistics
First released: 2015
Member States Participating: 172 (of 194)
Mentions in scholarly articles: >2 700*
Current questionnaire: 82 questions
GCI 2020 Report Available at: https://www.itu.int/hub/publication/d-str-gci-01-2021/ 2<br>
slide3. North Macedonia can improve Cooperation, Capacity Development, and Technical Measures 3 *The Global Cybersecurity Index Questionnaire is updated between editions to better reflect current considerations in cybersecurity Averages weighted by number of internet users<br>
slide4. North Macedonia can work to ensure its laws and regulations are effective in addressing current cybersecurity issues Legal Measures: the existence of legal institutions and effective frameworks dealing with cybersecurity and cybercrime.
North Macedonia has implemented a number of laws addressing cybersecurity, including Criminal Code of North Macedonia, amended in 2019; Law on Electronic Communications; Law on Personal Data Protection; Law on Cybercrime; Law on Copyright and Related Rights,
North Macedonia is party to the Budapest Convention
The Law on Electronic Documents, Electronic Identification and Trust Services, adopted in 2019 defines online identity
The Criminal Code of North Macedonia addresses online racist and xenophobic behaviors, as well as harassment, abuse
Child online protection is regulated through the Law on Protection of Children from Harmful Content on the Internet
Areas of improvement:
Clarify national policy and regulations relevant to the identification and protection of critical infrastructure<br>
slide5. North Macedonia build on its national CIRT work to target sectorial needs Technical Measures: the existence of technical institutions and frameworks dealing with cybersecurity endorsed or created by the Member State.Â
MKD-CIRT is a separate organizational unit within the Agency for Electronic Communications, and is accredited with FIRST. It conducts a variety cyber awareness activities cyber exercises, public advisories
Areas of improvement:
MKD-CIRT can work to become affiliated with a regional CERT
Develop sectorial CIRTs/CSIRTs/CERTs domestically or in collaboration with other countries, and carry out cyber awareness activities and cyber drills targeting sectors
Develop a comprehensive the implementation of internationally recognized standards in cybersecurity<br>
slide6. North Macedonia can work to enhance and refine its existing national cybersecurity strategy Organizational Measure: the existence and number of institutions and strategies organizing cybersecurity development at the national level.Â
North Macedonia’s National Cybersecurity Strategy 2023-2027 is periodically updated to reflect changing cyber threats, and addresses the protection of critical infrastructure, life cycle management, as well as consultation with national experts, and as an associated Action Plan.
The Agency for Electronic Communications (AEK), Ministry of Interior, National Security Agency, and Ministry of Transport and Communications have responsibilities for cybersecurity at the national level
National Coordination Body for the Protection of Children from Sexual Exploitation and Abuse Online (NCB) is responsible for Child Online Protection initiatives
North Macedonia uses a variety of metrics to assess cybersecurity at the national level, including the National Vulnerability Database and Common Vulnerability Society System
Areas of improvement:
Complete clarification in NCS which agency or ministry has the responsibility for cybersecurity related to National Critical Infrastructure Protection
Clarify in NCS which agency or ministry has the responsibility for cybersecurity capacity development
Conduct regular cybersecurity audits at the national level
Expand on metrics/tools used for assessing risks at a national level<br>
slide7. North Macedonia can expand trainings as part of its cybersecurity capacity development Capacity Development Measures: include numerous socio-economic and political implications are applicable in the cybersecurity field. Â
North Macedonia has developed cybersecurity awareness campaigns targeting the general population, MSMEs, the private sector in general, as well as educators, parents, and children relevant to Child Online Protection
Specialized trainings are available for financial, telecommunications, transport, and energy sector actors, as well as for educators on Child Online Protection
Universities offer courses on cybersecurity
The Macedonian Information Security Society (MISI) promotes the national cybersecurity industry, as well as providing trainings, certifications, and networking opportunities
Areas of improvement:
Develop cybersecurity awareness activities targeting the needs of specific consistencies, including public sector agencies, civil society, older persons, persons with disabilities
Develop and/or support trainings for cybersecurity professionals, judicial actors, private sector actors
Develop and/or support educational programmes for students
Support development of a national cybersecurity industry, as well as R&D activities 7<br>
slide8. North Macedonia can expand its international and domestic collaborations on cybersecurity Cooperation Measures: enhance dialogue and coordination, enabling the creation of a more comprehensive cybersecurity field of application.
North Macedonia has a number of agreements with other countries on information sharing, including with the United States, EU and NATO
Areas of improvement:
Further develop agreements with the other countries and regional organizations, particularly on capacity development
Advance PPPs with domestic and foreign companies on cybersecurity
Develop inter-agency coordination processes on cybersecurity 8<br>
slide9. North Macedonia can expand its cybersecurity commitments to address areas for growth North Macedonia can work to enhance its existing cybersecurity-related legislation elements in place
North Macedonia can implement sectorial CIRT(s) activities
North Macedonia can work to enhance and refine its National Cybersecurity Strategy through its lifecycle management practices, and implement metrics and audits to track and assess technical outcomes
With 84% of the population currently online, cybersecurity awareness campaigns can help establish cybersecure behaviours 9 Averages weighted by number of internet users<br>
slide10. North Macedonia can improve across all GCI pillars Selected ITU cybersecurity programmes of potential interest include:
Technical improvement: CyberDrills offer opportunities for local CIRTs/CSIRTS/CERTs to improve and grow
Organizational improvement: National Cybersecurity Strategy (NCS) development and implementation: ITU’s new NCS lifecycle training course and the 2nd editions of the Guide are now available
Capacity Development improvement: Child Online Protection Guidelines for children, parents and educators, and policy makers are available 10 *The Global Cybersecurity Index Questionnaire is updated between editions to better reflect current considerations in cybersecurity. Averages weighted by number of internet users<br>
slide11. ITU
itu.int/cybersecurity
cybersecurity@itu.int<br>