international cooperation and collaboration plays a central role in the National Cybersecurity Strategy (NCS). An open and free internet, the protection of personal data as well as the integrity of interconnected networks are critical for overall prosperity, security and the promotion of human rights in Botswana. This strategy provides a multi-stakeholder framework for ensuring the safety, security and reliability of Botswana’s cyberspace. 1.2 Situational Analysis In 2012 the country carried out cyber security assessment assisted by the International Telecommunication Union (ITU) and International Multilateral Partnership Against Cyber Threats (IMPACT) to assess the country’s readiness for establishing a National Computer Incident Response Team (CIRT), which will assist in responding to the cyber security threats1. The study found that Botswana has a well-developed ICT infrastructure with fibre-optic cables linking the major population centres. In addition the country has international connectivity through WACS, SEACOM and EASSY undersea cables. The community is well connected with mobile network covering more than 90% of the population. Internet usage is increasing throughout the country with many people using the mobile services to access the Internet, more especially the social media; the country’s mobile broadband subscription was 1 409,274 as of Dec 2016. 1.2.1 Summary of the Key Findings of the Assessment i) Cyber security is not allocated sufficient priority in policy making and on the ongoing ICT projects. Also, Cyber security principles are not adopted by government in all the projects related to ICT. ii) Critical National Information Infrastructure (CNII) has not been identified and there is no defined cyber security strategy in place to manage and mitigate cyber security incidents in case of a coordinated cyber-attack on the critical national information infrastructure. It was recommended that the Country should develop a National Cyber Security Strategy that will clearly define roles of the various stakeholders and develop measures and procedures for the protection of CNII iii) Appropriate legislation, policies and regulations on cyber security are inadequate to address the current cyber security challenges. iv) Training, specifically in the area of cyber security needs to be improved; all stakeholders such as regulators, Law Enforcement Agencies, Judiciary, Prosecutors, Service providers, Financial Institutions, service providers need to have adequate capacity and capability to handle matters related to cyber security. 1 The Full report of ITU/Impact CIRT Readiness assessment Report can be assessed at www.bocra.org.bw 9 | Page National Cybersecurity Strategy

Select target paragraph3