Table of Contents
The Five "Ideals"
The U.S. and other liberal-democratic nation-states make reference to an internet that is, in some combination, free, open, interoperable, secure, and resilient. The precise meanings of these terms are unclear. However, as we interpret them based on existing policy documents, these terms mean:
- Free: Any user can access and exchange information on and through the internet without unreasonable restriction.
- Open: Systems and infrastructure are merely conduits for data transmission; they are net neutral and oblivious to what goes through them.
- Interoperable: Parts of the global system (network) work with other parts of the global system (network); A can easily move or convert to B.
- Secure: The system upholds the confidentiality, integrity, and availability (CIA) of its users, its data, and itself.
- Resilient: No single points of failure exist in the network; systems do their intended job despite impediments.
Here we provide an elaboration on how we arrived at these definitions and some of the nuance behind them. These definitions are of course subjective, particularly in their original usage by each government, but there is relatively consistent usage among liberal-democratic nation-states which we attempted to extract.
Free
In 2011, the United States鈥 International Strategy for Cyberspace asserted that 鈥渢he more freely information flows, the stronger our societies become.鈥1 It also noted that 鈥渢he ability to seek, receive and impart information and ideas through any medium and regardless of frontiers has never been more relevant.鈥2 France produced a document that same year which stated, 鈥淔rance condemns all censorship and arbitrary or general restriction of Internet access and seeks to promote freedom of opinion, expression, information, assembly and association on the Internet.鈥3 A 2012 report to the U.S. House Committee on Energy and Commerce held that any deviation from the 鈥渢he free flow of commerce and ideas鈥 would harm the internet鈥檚 鈥渁bility to spread both prosperity and freedom.鈥4 France鈥檚 2015 National Digital Security Strategy writes that the internet should remain 鈥渁 place of free expression for all citizens, where abuses can only be prevented within the limits set by the law and in line with our international agreements.鈥5 Israel鈥檚 2017 National Digital Program says that 鈥渇reedom of expression and free access to information, which are vitally important for the social resilience of the State of Israel and its democratic nature, must be ensured.鈥6 Australia explicitly defines internet freedom as a state where 鈥減eople are not burdened by undue restrictions on their access to and use of cyberspace; and their human rights are protected online as they are offline so that cyberspace remains a vibrant force for economic, social and cultural development.鈥7 And a 2017 address of the European Commission by the Greek Vice-President even discussed Greece鈥檚 backing of the free flow of internet data.8 Our definition is based on these (and many other) references to freedom tying into the ability to access and share information online. Most often, this principle of internet freedom is impacted by laws, regulations, social norms, and political actions.
Open
Australia defines an open internet as 鈥渋nteroperable across borders and accessible to all; it facilitates unrestricted participation and the free flow of information, driving inclusive online collaboration, innovation and growth.鈥9 France鈥檚 2017 international digital strategy discusses the importance of openness and network neutrality, guaranteed by decentralized internet architecture.10 The Italian government sets 鈥渘et neutrality, open networks, [and] equivalent and non-discriminatory access conditions鈥 as key goals of its internet strategy, adding the importance of 鈥渁 technical solution completely open and neutral, deploying only passive infrastructures and laying optic fiber according to a fiber-to-the-building (FTTB) reference architecture to allow the wholesale unbundled access to all operators.鈥11 The U.S. Federal Communications Commission (FCC) stated in 2016 that openness more or less refers to net neutrality, which ensures that 鈥渂roadband service providers cannot block or deliberately slow speeds for internet services or apps, favor some internet traffic in exchange for consideration, or engage in other practices that harm internet openness.鈥12 Our definition is therefore oriented to a non-discriminatory architecture that is net-neutral. What this means in practice is that the internet infrastructure is oblivious to the nature of the data or traffic flowing through it. Regardless of what the data is, it will be treated the same way by the infrastructure. Often, violations of internet freedom (e.g., passage of a censorship law) are what prompt violations of openness in architecture (e.g., corresponding filtering on the part of internet service providers [ISPs]).
Interoperable
The United States鈥 FCC discussed interoperability as far back as 2003 in the context of signaling architectures, call control architectures, voice over wireless, inter-provider interfaces, directory services, and safety and security features, broadly referring to features by which different networks and systems interact.13 Australia鈥檚 recent international cyberspace strategy links interoperability with the harmonization of global internet standards (e.g., through organizations such as the International Organization for Standardization).14 A 2014 paper from the U.K.鈥檚 Chief Scientific Adviser frames interoperability the same way: compelled by universally-recognized standards.15 The United States鈥 Computer Emergency Readiness Team (US-CERT) defines interoperability as 鈥渢he ability of two or more systems or components to exchange information and to use the information that has been exchanged.鈥16 The European Commission expands upon all of these definitions, asserting that 鈥渋nteroperability is not simply a technical issue concerned with linking up computer networks. It goes beyond this to include the sharing of information between networks and the reorganisation of administrative processes to support the seamless delivery of eGovernment services.鈥17 Our definition therefore broadly refers to the ability of different components of a given system鈥攊n this case, the global internet鈥攖o interact without failure.
Secure
Germany鈥檚 2011 Cyber Security Strategy defines security in context as 鈥渢he sum of all national and international measures taken to protect the availability of information and communications technology and the integrity, authenticity and confidentiality of data in cyberspace.鈥18 Australia鈥檚 government holds that 鈥渁 secure cyberspace is safe, reliable and resilient; it fosters an environment of trust so that individuals, businesses and governments can engage online with confidence and realise the opportunities and minimise the risks of the digital age.鈥19 Canada鈥檚 recent Cyber Security Strategy categorizes cybersecurity as response and mitigation measures to unauthorized data access and electronic attacks.20 The Spanish government discusses cybersecurity as a broad objective to 鈥渆nsure that Spain makes secure use of the Information and Telecommunications Systems, strengthening cyber-attack prevention, defence, detection, analysis, investigation, recovery and response capabilities.鈥21 And US-CERT defines cybersecurity as 鈥渢he activity or process, ability or capability, or state whereby information and communications systems and the information contained therein are protected from and/or defended against damage, unauthorized use or modification, or exploitation.鈥22 Our definition comes from these and other references, which in aggregate aim to protect the confidentiality, integrity, and authenticity (CIA) of the global internet and its related components鈥攆rom broad strategy down to highly-technical processes.
Resilient
Israel鈥檚 previously-mentioned National Digital Program ties the internet directly into the social resilience of the nation-state.23 The U.S. President鈥檚 National Security Telecommunications Advisory Committee (NSTAC) issued a 2017 report on resiliency that linked it to network redundancy and the security of communications and infrastructure.24 The U.S. Department of Homeland Security discusses resilience in context with technical and operational resistance to cyber attacks.25 Spain鈥檚 Ministry of Defence defines resilience as 鈥渢he defensively oriented policy that maximizes the ability of possible target systems to prevent, deter and withstand cyber attacks and, if they occur, to minimize and mitigate their effects鈥 which 鈥渋s a multidimensional concept and has technical, organizational, political and legal components that need to be combined to be effective.鈥26 France鈥檚 Internet Resilience Observatory most recently defined resilience on the internet as 鈥渢he ability [for the internet] to operate during an incident and return to the nominal state. It can be characterized by measurable indicators, some of which come directly from engineering rules called best practices.鈥27 Our definition aims to encompass the underlying thread in these and other definitions, which center around the ability of a system to essentially route around failure, regardless of the underlying cause.
An Idealized Picture
Even in an idealized version of a global internet, not every dimension or element in our framework necessarily needs to contain or implicate all five of these ideal principles. However, in the idealized version of the internet in our framework, we provide a description of a global network that we believe captures the vision of a free, open, interoperable, secure, and resilient global internet. It is our hope that this mapping further clarifies the definitions and our interpretations of free, open, interoperable, secure, and resilient and provides an idealized archetype from which we are able to identify real departures.
Citations
- The White House, 鈥淚nternational Strategy for Cyberspace: Prosperity, Security, and Openness in a Networked World,鈥 2011, , 4.
- Ibid., 5.
- Government of France, 鈥淔rance and the Global Challenges of Information and Communications Technologies,鈥 2011, , 3.
- United States House Committee on Energy and Commerce: Majority Committee Staff, 鈥淗earing on International Proposals to Regulate the Internet,鈥 2012, , 2.
- Government of France, 鈥淔rench National Digital Security Strategy,鈥 2015, , 3.
- Government of Israel, 鈥淭he Digital Israel National Initiative: The National Digital Program of the Government of Israel,鈥 2017, , 63.
- Government of Australia, 鈥淎ustralia鈥檚 International Cyber Engagement Strategy,鈥 2017, , 57.
- European Commission, 鈥淪peech by Vice-President Ansip in Athens on 鈥楢 Digital Strategy for Greece: Path to Growth,鈥欌 May 10 2017, .
- Government of Australia, 鈥淎ustralia鈥檚 International Cyber Engagement Strategy,鈥 2017, , 57.
- Government of France, 鈥淪trat茅gie Internationale de la France pour le Num茅rique,鈥 2017, , 4.
- Government of Italy, 鈥淭he Italian Strategy for Next Generation Access Network,鈥 2015, , 17 & 62.
- Federal Communications Commission, 鈥淐onsumer Guide: Open Internet,鈥 2016, , 1.
- Network Reliability and Interoperability Council VI: Focus Group 3, 鈥淣etwork Interoperability,鈥 2003, , 4.
- Government of Australia, 鈥淎ustralia鈥檚 International Cyber Engagement Strategy,鈥 2017, , 17.
- Government of the United Kingdom, 鈥淭he Internet of Things: Making the Most of the Second Digital Revolution,鈥 2014, , 30.
- National Initiative for Cybersecurity Careers and Studies, 鈥淎 Glossary of Common Cybersecurity Terminology,鈥 n.d., .
- Commission of the European Communities, 鈥淟inking Up Europe: The Importance of Interoperability for eGovernment Services,鈥 2003, , 3.
- Government of Germany, 鈥淐yber Security Strategy for Germany,鈥 2011, , 4.
- Government of Australia, 鈥淎ustralia鈥檚 International Cyber Engagement Strategy,鈥 2017, , 57.
- Government of Canda, 鈥淐anada鈥檚 Cyber Security Strategy,鈥 2018, , 3.
- Government of Spain, 鈥淣ational Cyber Security Strategy,鈥 2013, , 3-4.
- National Initiative for Cybersecurity Careers and Studies, 鈥淎 Glossary of Common Cybersecurity Terminology,鈥 n.d., .
- Government of Israel, 鈥淭he Digital Israel National Initiative: The National Digital Program of the Government of Israel,鈥 2017, , 2 & 63.
- U.S. National Security Telecommunications Advisory Committee, 鈥淣STAC Report to the President on Internet and Communications Resilience,鈥 2017, , 18.
- U.S. Department of Homeland Security, 鈥淐ybersecurity Strategy,鈥 2018, , 23.
- Spanish Institute for Strategic Studies, 鈥淪trategic Dossier 162 B: Economic Intelligence in a Global World,鈥 2013, , 191.
- Agence Nationale de la S茅curit茅 des Syst猫mes d’Information, 鈥淚nternet Resilience in France: 2015,鈥 2015, , 5.