personnel (e.g., best practices) safeguards. For example measures may include
promoting government and private sector to adopt international standards related to
cyber security (e.g., ISO 27001 on Information Security Management System).
4.3.10
Academia
Academic institutions will play an important role in the implementation of the national
cybersecurity strategy. Academic institutions educate the technical, management and
information assurance experts required to execute cyber security strategies. In addition,
research and development (R&D) activities, need to be carried out on cybersecurity and
the protection of information infrastructures. Through partnerships with the private
sector and governments the Academia can assist in the development of cybersecurity
related technologies, techniques, standards and processes that further the national
cybersecurity agenda. The Academia institutions may also have cybersecurity forensics
laboratories which may assist on the investigation and enforcement of cybersecurity
legislations
4.3.11
Civil Society
Civil society will play an important role in ensuring that there is a right balance in terms
of protection civil liberties, privacy and human rights etc. as we implement the national
cyber security strategy. The civil society needs to form part of the stakeholders in order
to provide confidence and integrity that the national cybersecurity strategy
implementation does not tramp on civil liberties. For example monitoring cyberspace
has to be done in a manner which does not invade personal privacy. Internationally a
number of civil society not-for profit organisations have also been established around
the issue of cybersecurity and cybercrime for example those dealing with child online
protection (COP). Therefore it is very important that collaboration is established with
international civic society to assist also on the consumer education.
4.3.12
Private Sector (Industry)
Businesses are expected to implement an adequate level of cyber security safeguards
into their business operation and practices. Such safeguards typically involve the
installation of technical solutions and the adoption of best practice secure business
processes. For example, the financial and banking sector, with its dependency on
international clearing and central banking, and its links to international financial market
systems, cyber security concerns should be accorded high priority.
On a collective level, the private sector has an important role to play in its own right
and in cooperation with government in developing cyber security business norms,
standards and codes of conduct, as well as in identifying and encouraging the adoption
of good practices. By taking part in relevant forums or standards-development
35 | P a g e
National Cybersecurity Strategy