We invite you to read the opinion piece by our Director of New Technologies and AI, Juan Pablo González, on the new approach required by Chile’s Cybersecurity Framework Law.
The Cybersecurity Framework Law, No. 21,663—a pioneering piece of legislation in Latin America for establishing cybersecurity regulations in Chile, particularly regarding the obligation of certain providers of essential services and operators of vital importance to manage cybersecurity risks and report incidents with significant impact—entails a series of tasks for organizations to coordinate their processes and comply with the requirements of the regulation.
However, an important point to consider is that the regulations are not limited to protecting computer networks and systems, as well as the connected infrastructure of regulated entities; rather, as stated regarding the principle of cybersecurity: “The State shall ensure that all persons can participate in a secure cyberspace; therefore, it shall grant special protection to networks and systems containing information belonging to those groups that are most frequently targeted by cyberattacks.”
Consequently, the focus of the regulations is no longer solely on protection at the information infrastructure level, but also on the human element, as reflected in certain obligations of OIVs, specifically, “to have training, education, and continuing education programs for their employees and collaborators, including cyber hygiene campaigns” (Art. 8(h)).
In this regard, cybersecurity approached from a purely technical perspective has a design flaw; this is evident in the latest Concept Paper from the National Institute of Standards and Technology (NIST) of the U.S. Department of Commerce, titled “Human-Centered Cybersecurity Guidelines and Resources,” which centers on people and proposes a significant paradigm shift for those countries in the region that are currently debating their cybersecurity bills. In other words, it is about moving beyond the notion that the weakest link is the individual and also analyzing the systems, incentives, and conditions in which the individual operates—and, consequently, the cybersecurity risks to which they may be exposed.
Therefore, the design of an Information Security Management System—which is mandatory for OIVs under cybersecurity regulations—should not be limited to the technical elements of the organization’s technological environment. Rather, when designing security policies, processes, and technologies, it must focus on the needs, capabilities, and limitations of the people who make up that organization, thereby ensuring its practical applicability in that context.
A clear example of this relates to training sessions and certain exercises conducted within the organization to simulate potential cyberattacks. Rather than focusing on the number of people who participated—that is, on a purely metric approach—the analysis should focus on evaluating whether the procedure was understandable, participatory, and, therefore, commensurate with the risk it is intended to mitigate. In this way, we can come to understand the reasons that may ultimately lead to non-compliance with a particular control—whether because it disrupts work, increases the workload, or is simply incompatible with the performance metrics associated with their role.
Likewise, incorporating automation into certain cybersecurity controls does not mean disregarding the judgment of users or company employees, since, at the end of the day, they will be the ones to detect unusual behavior or identify situations for which no previously defined procedure exists—and the organization will then need to create one to address the situation; for this reason, it is important to remember that incorporating AI into processes—especially from an information security perspective—will be carried out by a person.
It is also important to remember that the selection, configuration, monitoring, and use of this type of technology are based on decisions that reflect an organization’s priorities and, consequently, its defined risk appetite in this area.
In conclusion, in a national regulatory environment where certain definitions from the National Cybersecurity Agency are still lacking (e.g., the regulations for the Certification Centers under Article 28 have not yet been issued, nor has the Multisectoral Cybersecurity Council been appointed) and discussions are ongoing regarding a possible extension of the effective date of the personal data regulations, the NIST Concept Paper invites us to assess the situation so that we can act more securely and, in doing so, help reduce the attack surface through a user-centered shift in approach—especially in an environment where the existence of many unenforced policies can be counterproductive.
Column written by:
Juan Pablo González | New Technologies and AI Director | jgonzalez@az.cl




