1 INTRODUCTION ....................................................................................................................................... 3 2 THE COMMONWEALTH CYBERGOVERNANCE MODEL................................................................................. 3 Table 1: Commonwealth Cybergovernance Principles ............................................................................................ 4 3 A NATIONAL CYBERSECURITY STRATEGY ................................................................................................. 5 3.1 Development of the Strategy .................................................................................................................... 5 3.2 Resources and market forces ................................................................................................................... 5 3.3 Delivering the Strategy ............................................................................................................................ 6 3.4 Reviewing the Strategy ............................................................................................................................ 6 4 KEY ELEMENTS OF A CYBERSECURITY STRATEGY .................................................................................... 7 4.1 Introduction and background section ........................................................................................................ 7 4.2 Guiding principles section ....................................................................................................................... 7 4.4 Risk-management section – setting objectives and priorities ........................................................................ 9 4.5 Stakeholder section .............................................................................................................................. 11 4.6 Strategy implementation section ............................................................................................................ 11 4.6.1 Governance and management structure ............................................................................................ 11 4.6.2 Legal and regulatory framework ....................................................................................................... 11 4.6.3 Capacity Development .................................................................................................................... 12 4.6.4 Awareness ..................................................................................................................................... 12 4.6.5 Incident response .......................................................................................................................... 12 4.6.6 Stakeholder collaboration ............................................................................................................... 13 4.6.7 Research and Development (R&D) ................................................................................................... 13 4.6.8 Monitoring and evaluation............................................................................................................... 13 5. Conclusion and next steps ........................................................................................................................... 14 6. Acknowledgements ..................................................................................................................................... 14 Appendix 1 SAMPLE GLOSSARY ........................................................................................................... 15 Appendix 2 NATIONAL CYBERSECURITY STRATEGY – OUTLINE FRAMEWORK ........................................ 18 Appendix 3 LINKS TO NATIONAL STRATEGIES AND OTHER REFERENCES ............................................. 28 Appendix 4 INTERNATIONAL STANDARDS AND GOOD PRACTICE GUIDES FOR CYBERSECURITY ............ 31 Appendix 5 EXAMPLE RACI TABLE ....................................................................................................... 33 ABOUT COMMONWEALTH TELECOMMUNICATIONS ORGANISATION (CTO) The Commonwealth Telecommunications Organisation is the Commonwealth agency mandated in the field of Information and Communications Technology and works towards helping its members leverage ICTs for socio-economic development. Its two-tier membership facilitates consultations between Commonwealth countries, non-Commonwealth countries, industry and civil society to arrive at harmonised approaches on ICT related issues with Global implications. Page 2 of 33 www.cto.int

Select target paragraph3