{"id":1964,"date":"2020-03-27T12:20:26","date_gmt":"2020-03-27T11:20:26","guid":{"rendered":"http:\/\/blogs.ifla.org\/lpa\/?p=1964"},"modified":"2020-03-27T12:24:21","modified_gmt":"2020-03-27T11:24:21","slug":"awareness-planning-resilience-thoughts-on-libraries-cyber-defense-in-2020","status":"publish","type":"post","link":"https:\/\/blogs.ifla.org\/lpa\/2020\/03\/27\/awareness-planning-resilience-thoughts-on-libraries-cyber-defense-in-2020\/","title":{"rendered":"Awareness, Planning, Resilience: Thoughts on Libraries\u2019 Cyber Defense in 2020"},"content":{"rendered":"<p><em>Digital vulnerabilities pose serious challenges for organisations, governments, companies and the wider public \u2013 libraries included. Cyberattacks and data breaches made headlines many times throughout 2019, <a href=\"https:\/\/en.wikipedia.org\/wiki\/List_of_data_breaches\" target=\"_blank\" rel=\"noopener\">from social media and popular software to public agencies<\/a>. As <a href=\"https:\/\/digitalcooperation.org\/wp-content\/uploads\/2019\/06\/DigitalCooperation-report-web-FINAL-1.pdf\" target=\"_blank\" rel=\"noopener\">a landmark 2019 report of the UN Secretary-General\u2019s High-level Panel on Digital Cooperation<\/a> pointed out, both the scope of threats and the range of targets for such attacks is rapidly growing.<\/em><\/p>\n<p>For libraries, the importance of protecting the data and information they work with every day is readily apparent. Less than a week into 2020, <a href=\"https:\/\/ccclib.org\/news\/library-services-impacted-by-cyber-security-attack\/\" target=\"_blank\" rel=\"noopener\">the Contra Costa County Library in the US experienced a ransomware<\/a> attack, impacting a number of library services.<\/p>\n<p>From <a href=\"https:\/\/www.itworldcanada.com\/article\/cyber-security-today-university-library-password-scam-police-break-up-email-fraud-racket-and-just-say-no\/421761\" target=\"_blank\" rel=\"noopener\">email scams<\/a> to <a href=\"https:\/\/www.sunderlandecho.com\/news\/politics\/council\/cyber-attack-sunderland-city-council-database-investigation-after-library-users-personal-data-accessed-hackers-117103\" target=\"_blank\" rel=\"noopener\">hacks into a library user database<\/a>, library systems can become targets \u2013 and as the COVID-19 outbreak puts more pressure on online library resources, securing their digital assets and services, not least in order to protect staff and users, is a high priority. What is at stake, and what suggestions and tips for boosting libraries\u2019 security can we draw from broader literature and available toolkits?<\/p>\n<p><strong>The Broader Context<\/strong><\/p>\n<p>Broadly in the field of security, you can think of three types of threats towards data:\u00a0 <a href=\"https:\/\/www.idealware.org\/reports\/legal-aid-technology-toolkit-information-security\/\" target=\"_blank\" rel=\"noopener\">it can be lost, exposed, or made inaccessible (known as the CIA triad \u2013 confidentiality, integrity and accessibility)<\/a>. A poll among cybersecurity professionals, for example, shows that the three biggest expected threats in 2020 are \u201cweaponized email attachments and links (74%), ransomware (71%), banking trojans and other browser-based password hijackers (67%)\u201d.<\/p>\n<p>An alternative top-level taxonomy of threats (borrowing from <a href=\"https:\/\/www.enisa.europa.eu\/publications\/good-practices-for-the-security-of-healthcare-services\" target=\"_blank\" rel=\"noopener\">ENISA guidelines<\/a> for a different sector) identifies: malicious actions (as described above), supply chain failure (e.g. cloud service provider failure), systems failure (e.g. software of device failure), as well as threats stemming from human errors or other phenomena. All, clearly, can have negative impacts.<\/p>\n<p>On the positive side, however, <a href=\"https:\/\/internethealthreport.org\/2019\/understand-the-issue-privacy-and-security\/\" target=\"_blank\" rel=\"noopener\">public awareness on digital security and privacy matters<\/a> has fundamentally shifted in the recent years, and more and more organisations and companies put a high priority on addressing these issues. In the UK alone, for example, <a href=\"https:\/\/assets.publishing.service.gov.uk\/government\/uploads\/system\/uploads\/attachment_data\/file\/813599\/Cyber_Security_Breaches_Survey_2019_-_Main_Report.pdf\" target=\"_blank\" rel=\"noopener\">about three-quarters of charities and businesses<\/a> in 2019 reported that cybersecurity is a \u201chigh or very high priority\u201d.<\/p>\n<p>It is not just public attitudes that are changing. As the <a href=\"https:\/\/www.internetjurisdiction.net\/news\/release-of-worlds-first-internet-jurisdiction-global-status-report\">2019 Internet and Jurisdiction report<\/a> points out, security regulations are increasingly often linked to other fields of government regulation \u2013 especially data privacy. This can impact libraries: for instance, <a href=\"http:\/\/www.cde.state.co.us\/cdelib\/fact-sheet-protecting-personal-information-library-users\" target=\"_blank\" rel=\"noopener\">a 2019 publication by the Colorado\u00a0 State\u00a0 Library<\/a> discussed how the recently introduced state regulation on personal information creates obligations for libraries to, inter alia, \u2018implement reasonable security procedures and practices\u2019. Similarly, under the EU GDPR <a href=\"https:\/\/princh.com\/gdpr-compliance-for-libraries-5-general-aspects-that-you-need-to-cover\/\" target=\"_blank\" rel=\"noopener\">libraries as data controllers have a responsibility to<\/a>, inter alia, prevent, detect and report attacks and security breaches.<\/p>\n<p>These regulations point to the fact that security concerns for libraries will always be particularly pressing when dealing with personally identifiable information (<a href=\"https:\/\/www.councilofnonprofits.org\/tools-resources\/cybersecurity-nonprofits\" target=\"_blank\" rel=\"noopener\">as well as, arguably, information on the habits and preferences of their users<\/a>). So how to respond?<\/p>\n<p><strong>Assess and plan: key questions to ask <\/strong><\/p>\n<p><em>Map the assets, know the threats<\/em><\/p>\n<p>A first key step to boosting a library\u2019s cyber defence, as suggested in a number of recommendations and broader literature, is to take stock of your assets and digital systems. Map your entire system to see what needs to be protected: <a href=\"https:\/\/www.railslibraries.info\/system\/files\/Anyone\/mtg\/135822\/IT%20Security%20Part%201%20slides.pdf#page=8\" target=\"_blank\" rel=\"noopener\">the Integrated Library System, the data you store, staff and patron computers, tablets and other devices, the library website, the network<\/a>\u2026 Whenever applicable, this can also <a href=\"https:\/\/www.cnet.com\/news\/what-e-books-at-the-library-mean-for-your-privacy\/\" target=\"_blank\" rel=\"noopener\">include apps and cloud services<\/a>, since those can also contain vulnerabilities.<\/p>\n<p>Once you know your assets, consider the vulnerabilities, priorities and risks. <a href=\"https:\/\/scottishlibraries.org\/media\/2073\/libraries-for-privacy-toolkit-digital.pdf\" target=\"_blank\" rel=\"noopener\">A toolkit published by <em>Scottish PEN<\/em><\/a> adapts an <em>Electronic Frontier Foundation<\/em> guide to highlight the key questions to consider:<\/p>\n<ol>\n<li>\u201cWhat do you want to protect?&#8221;<\/li>\n<li>\u201cWho do you want to protect it from?\u201d<\/li>\n<li>\u201cHow likely is it that you will need to protect it?\u201d<\/li>\n<li>\u201cHow bad are the consequences if you fail?\u201d<\/li>\n<li>\u201cHow much trouble are you willing to go through in order to try to prevent those?\u201d<\/li>\n<\/ol>\n<p><a href=\"https:\/\/www.idealware.org\/reports\/legal-aid-technology-toolkit-information-security\/\" target=\"_blank\" rel=\"noopener\">You can also consider<\/a> who has access to the assets you want to protect, and how you would know and respond if something goes wrong.<\/p>\n<p>These questions can help you decide what measures to take to safeguard both privacy and security.<\/p>\n<p><em>Setting up a plan<\/em><\/p>\n<p>Having mapped the assets and considered the risks, you can develop a plan of security measures and risk mitigation strategies. Just like the assessment step, this is something to do together with your IT team \u2013 if your library has access to one! A <a href=\"https:\/\/vimeo.com\/346600263\" target=\"_blank\" rel=\"noopener\">2019 Library Freedom Institute lecture on cybersecurity<\/a>, for example, mentioned that some libraries might get IT support through their consortia or similar organisations, at a local City Hall, or elsewhere.<\/p>\n<p>Your security plan and risk mitigation strategy would be built with your assets and situation in mind. Some key elements to consider when developing your security regime and policies are as follows \u2013 as set out in the <a href=\"https:\/\/www.ncsc.gov.uk\/collection\/board-toolkit\" target=\"_blank\" rel=\"noopener\"><em>Cyber Security Toolkit for Boards<\/em><\/a> developed by the UK National Cyber Security Center:<\/p>\n<ul>\n<li>Network security<\/li>\n<li>User awareness and education<\/li>\n<li>Malware defense and prevention<\/li>\n<li>Access to removable media<\/li>\n<li>Maintaining the secure configuration of all systems<\/li>\n<li>Managing and limiting user privileges<\/li>\n<li>Incident management<\/li>\n<li>Monitoring<\/li>\n<li>Home and mobile working policy and security<\/li>\n<\/ul>\n<p><strong>Remembering the basics<\/strong><\/p>\n<p>Among these fundamental elements of the security regime, there are of course a few key concrete and tangible steps that can boost the security of your data, devices and processes. These are often mentioned when discussing the basics of cybersecurity, and you will likely have heard then often before:<\/p>\n<ul>\n<li><a href=\"https:\/\/americanlibrariesmagazine.org\/2018\/06\/01\/library-data-security\/\" target=\"_blank\" rel=\"noopener\">Creating backups of your systems is crucial<\/a>! A library that experiences a ransomware attack, for example, could be able to <a href=\"https:\/\/www.ncsc.gov.uk\/collection\/board-toolkit\" target=\"_blank\" rel=\"noopener\">restore their systems faster with the help of existing backups.<\/a> Have a backup plan and system that fits your needs and capacities.<\/li>\n<li>Keeping your software updated, installing all patches and updates is a key security measure.<\/li>\n<li>Setting up a password policy. See, for instance, the <a href=\"https:\/\/datadetoxkit.org\/en\/security\/passwords\" target=\"_blank\" rel=\"noopener\"><em>Tactical Tech Data Detox Kit<\/em><\/a> chapter on passwords to see what makes a good password (or better yet, a passphrase!)<\/li>\n<li>Website owners are encouraged to encrypt their website(s) and make use of HTTPS protocols instead of HTTP. HTTPS is a secure and encrypted protocol for communication between web browsers and websites \u2013 and <a href=\"https:\/\/www.eff.org\/encrypt-the-web\" target=\"_blank\" rel=\"noopener\">the <em>EFF<\/em> offers<\/a> some advice and resources for website owners on how to implement HTTPS by default. <a href=\"https:\/\/ejournals.bc.edu\/index.php\/ital\/article\/view\/10405\/pdf\" target=\"_blank\" rel=\"noopener\">A 2018 case study of one public library\u2019s HTTPS implementation<\/a> points out that it is important to make use of HTPPS and related security measures consistently and pervasively, across all web-based library applications and their elements.<\/li>\n<\/ul>\n<p><strong>Staff training: protecting the library together<\/strong><\/p>\n<p>A key part of a library\u2019s cyber defense \u2013 drawing on both broader literature and some library-focused overviews \u00a0\u2013 is making sure that all your staff is caught up on the basics of online security. This can help make sure that the whole team is more alert and aware, reducing the likelihood of some of the most common threats like phishing or malware distributed through emails.<\/p>\n<p>There are different resources available to start such training \u2013 such as <a href=\"https:\/\/sec.eff.org\/\" target=\"_blank\" rel=\"noopener\">those developed by the EFF.<\/a> A <a href=\"https:\/\/ejournals.bc.edu\/index.php\/ital\/article\/view\/10973\" target=\"_blank\" rel=\"noopener\">2019 pilot study<\/a> published in <em>Information Technology and Libraries,<\/em> for example, provides initial evidence of how librarians taking part in online cybersecurity courses can utilise their knowledge to strengthen cybersecurity practices in their libraries.<\/p>\n<p><strong>Create learning opportunities for your communities<\/strong><\/p>\n<p>And finally, libraries can be well-positioned to help their community members learn essential skills to be safe online. There are different examples of how libraries have approached this task \u2013 from ad-hoc assistance or linking users to relevant educational materials, to dedicated workshops (see, for instance, <a href=\"https:\/\/www.tcpl.org\/events\/cybersecurity-essentials\" target=\"_blank\" rel=\"noopener\">a listing from the Tompkins County Public Library<\/a>) or offering full courses on cyber-security (e.g. in <a href=\"https:\/\/www.ifla.org\/files\/assets\/faife\/statements\/guidelines-on-public-internet-access.pdf\" target=\"_blank\" rel=\"noopener\">the Hague Public Library<\/a>).<\/p>\n<p>Libraries can partner with cybersecurity specialists and agencies to deliver such training \u2013 as well as <a href=\"http:\/\/www.ilovelibraries.org\/article\/libraries-offer-resources-during-national-cyber-security-awareness-month-ncsam\" target=\"_blank\" rel=\"noopener\">host dedicated awareness-raising campaigns<\/a>. Depending on capacity, a library can adopt some of the approaches listed above- or find their own ways to help their communities with learn essential cybersecurity skills.<\/p>\n<p>These are of course just a few broad elements highlighted in the broader literature to consider when creating a library\u2019s security strategy. With more demand for online library resources and services \u2013 and so more risk \u2013 it is worthwhile to go over your library\u2019s security plans and practices to be sure that your data, information and processes are safe and well!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Digital vulnerabilities pose serious challenges for organisations, governments, companies and the wider public \u2013 libraries included. Cyberattacks and data breaches made headlines many times throughout 2019, from social media and popular software to public agencies. For libraries, the importance of protecting the data and information they work with every day &#8211; not least in order to protect staff and users &#8211; is readily apparent. What is at stake, and what suggestions and tips for boosting libraries\u2019 security can be drawn from broader literature and available toolkits?<\/p>\n","protected":false},"author":810,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[18164,26830,26551,168],"class_list":["post-1964","post","type-post","status-publish","format-standard","hentry","category-general","tag-access-to-information","tag-cybersecurity","tag-digital-literacy","tag-internet"],"_links":{"self":[{"href":"https:\/\/blogs.ifla.org\/lpa\/wp-json\/wp\/v2\/posts\/1964","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.ifla.org\/lpa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.ifla.org\/lpa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.ifla.org\/lpa\/wp-json\/wp\/v2\/users\/810"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.ifla.org\/lpa\/wp-json\/wp\/v2\/comments?post=1964"}],"version-history":[{"count":5,"href":"https:\/\/blogs.ifla.org\/lpa\/wp-json\/wp\/v2\/posts\/1964\/revisions"}],"predecessor-version":[{"id":1982,"href":"https:\/\/blogs.ifla.org\/lpa\/wp-json\/wp\/v2\/posts\/1964\/revisions\/1982"}],"wp:attachment":[{"href":"https:\/\/blogs.ifla.org\/lpa\/wp-json\/wp\/v2\/media?parent=1964"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.ifla.org\/lpa\/wp-json\/wp\/v2\/categories?post=1964"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.ifla.org\/lpa\/wp-json\/wp\/v2\/tags?post=1964"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}