Cybersecurity 2020 - In Germany and the rest of the world

The International Telecommunication Union (ITU) of the United Nations published its Global Cybersecurity Index 2020 last week. Germany landed in 13th place. Although this is not at the bottom of the list, it is still behind countries such as India and Turkey.
Cybersecurity is a topic that is also relevant for systems engineering. Who came in first place and what else we can learn from the report is discussed below.
It is not really surprising that the USA has landed in first place. The differences compared to the last report in 2018 are also interesting. India, for example, climbed from 47th to tenth place in this period. The full list can be found in the report, which it here as a free download gives.
Sensitization
The report is not (just) a ranking, but a fundamental assessment of the nations surveyed. A panel of experts has developed 82 questions with which the index evaluates nations. There is good news: the median score for the 2020 index is 9.5 percent higher than in the 2018 edition. This means that nations are actively investing in cybersecurity.
The structure of the report and the questions can also be used in a different context, for example municipalities or organizations. Indicators are collected from the following five areas:
- Legal - Measuring cybercrime and cybersecurity laws and regulations
- Technical - Measuring the implementation of technical skills by national and sector-specific agencies
- Institutional- Measuring national strategies and organizations to implement cybersecurity
- Capacity - Amount of campaigns, training, education and incentives for cybersecurity capacity development
- Cooperation - Number and intensity of partnerships between agencies, companies and countries
Cybersecuity in systems engineering
About Cybersecuity I have already written several times in this blog. Two points are particularly important here: Firstly, systems engineering has a long tradition in the area of functional security. This is related to attack security, as attacks often exploit functional weaknesses. This means that a certain infrastructure already exists that can be used as a basis for cybersecurity.
Secondly, it is almost impossible to ensure attack security retrospectively. Therefore, product developers must consider security from the very beginning. Security must be anchored in the architecture of the product. And that is the task of the system architect. And I have explained exactly how they have to go about this in the article Security in systems engineering already described.
Image source: ITU






