A human rights respecting definition of cybersecurity

The term “cybersecurity” is used by different stakeholders to reference many different subjects often depending upon context, ranging from national security, to data security, to critical infrastructure security, and beyond. While it is true that numerous definitions relating to cybersecurity already exist, it is difficult to find any cybersecurity definitions that include clear commitments to and respect for human rights. Accordingly, the working group believed it crucial to put forth a human rights-respecting cybersecurity definition that others could adopt and integrate into policies and publications.

In developing the definition, the working group was driven by the belief that respecting human rights should be a central part of cybersecurity-related decision making. Raising the profile of human rights protections in existing cybersecurity policy-making was seen as necessary to offset the current trend of addressing cybersecurity through the lens of national and international security. It was also seen as instrumental in reminding policy makers that cybersecurity must take into account security for individuals. In short, the working group tried to put forward a framing of cybersecurity that aims to promote a shift in perspective from a systems approach towards an approach that recognizes individual security as a core component of cybersecurity.

In the fall of 2014, the working group developed and agreed to the following definition:

PREAMBLE: International human rights law and international humanitarian law apply online and well as offline. Cybersecurity must protect technological innovation and the exercise of human rights.

DEFINITION: Cybersecurity is the preservation – through policy, technology, and education – of the availability*, confidentiality* and integrity* of information and its underlying infrastructure so as to enhance the security of persons both online and offline.

*as defined by ISO 27000 standard which informed this process to ensure that the work of the technical community was adequately taken into account.

The definition includes three core elements:

  1. The ultimate goal of cybersecurity: “to enhance the security of persons both online and offline”;
  2. Articulation of how this ultimate goal and the dimensions of cybersecurity translate into technical terms: “cybersecurity is the preservation…of the availability, confidentiality and integrity of information and its underlying infrastructure”
  3. The means through which this goal is being achieved: “through policy, technology, and education” with the understanding that “policy” includes the law.

Supporting and building on existing cybersecurity efforts in international fora, the working group decided to include a preamble stating that; “International human rights law and international humanitarian law apply online as well as offline.” This sentence is intended to emphasize the landmark resolution (A/HRC/20/8) adopted by the UN Human Rights Council in 2012 “affirm[ing] that the same rights that people have offline must also be protected online.” It also underscores the conclusion reached in 2013 by the UN Group of Governmental Experts on Developments in the Field of Information and Telecommunications in the Context of International Security, that existing international law is applicable in cyberspace.

The definition also includes an assertion about the importance of technological innovation, which the working group sees as essential to the free flow of information, to the continued functioning of the open interoperable Internet as a platform for communication, and to the protection of both freedom and security.

Another intentional dimension of the definition was to include terminology that is well informed technically, and widely accepted by technical communities, so that it would provide a bridge between human rights policy and technical communities. The working group therefore relied on the International Organization of Standardization (ISO) 27000 standard to signal that the work of the technical community is adequately taken into account.

The definition supports the view that security and freedom (as well as cybersecurity and human rights) are deeply interrelated and synergistic, rather than zero-sum, and that cybersecurity and human rights protection are mutually reinforcing, interdependent, and both essential to promoting freedom and security.