Forward for National Cybersecurity strategies The Commonwealth is a body of states and peoples that share certain common values and principles, enshrined in the Charter signed by Her Majesty Queen Elizabeth II, Head of the Commonwealth, in 2013. The Charter expresses the commitment of member states to the development of free and democratic societies and the promotion of peace and prosperity to improve the lives of all peoples of the Commonwealth. It also acknowledges the role of civil society in supporting the goals and values of the Commonwealth. Governments, peoples, companies and civil society have all used Information and Communication Technologies (ICTs) over the last two decades dramatically to transform the world in which we live. These technologies can do much to support openness, democracy, peace and prosperity. However, they also contain within them the potential for negative impacts, and it is essential therefore that systems are put in place to ensure the safety, security and resilience of the infrastructure, as well as of the information content that runs through it. Likewise, users need to be assured that they too are safe when using the Cyberspace, especially in terms of their own private information that is shared through it. In March 2014, Commonwealth ICT Ministers participating in the first Commonwealth ICT Ministers Forum took the unprecedented step of agreeing to broad principles of Cybergovernance, linked specifically to the Commonwealth’s important agreed shared values. Building on this, the Commonwealth Telecommunication Organisation (CTO), its members and partners committed to design a framework for the development of National Cybersecurity Strategies, and this report is the outcome of that work. Its purpose is simple; to provide a framework and guidance for countries that wish to develop such strategies consonant with the overall principles of the Commonwealth. It is a guide for creating a cohesive and inclusive approach that will deliver safe, secure and resilient infrastructure and systems concerned with digital technologies and the Cyberspace. It is, of course, not only relevant to Commonwealth countries, and we hope that many others will begin to adopt it as a framework for developing their own national strategies in this area of critical contemporary importance. Many people have contributed to the development of this report, and I would particularly like to thank the UK Government for their funding and wider support for this initiative. Mr Mike St. John Green worked with the CTO Secretariat to craft the report, ably assisted by Ms. Roda Gavor (Assistant Director, Policy Planning in the Monitoring and Evaluation Directorate of the Ministry of Communications in Ghana) who was in receipt of a Professional Fellowship provided by the Commonwealth Scholarship Commission in the UK. Three organisations provided considerable inputs into the report, and I would especially therefore like to thank the International Telecommunication Union (ITU), the Inter-American Committee against Terrorism of the Organization of American States, and the Microsoft Corporation for these contributions. This effort will have all been in vain if this report is not actually used, and the CTO is therefore committed to working with Commonwealth countries to help ensure that they all do indeed have effective strategies in place. We are only as weak as our weakest link, and the mostconnected least-secure countries are those that are not only most likely to suffer most from systems that are not resilient, but that also provide the greatest risk to the rest of the world. We must work together to help ensure that the important principles and values of the Commonwealth can indeed be enhanced through an effective, safe and resilient Internet. Professor Tim Unwin Secretary General Commonwealth Telecommunications Organisation

Select target paragraph3