STRATEGY COMPONENTS
ASPECTS TO CONSIDER
EXAMPLE TEXT FROM PUBLISHED STRATEGIES AND BEST
PRACTICE
3. Strategic goals and vision
•
Australia’s vision: “The maintenance of a secure, resilient and trusted
electronic operating environment that supports Australia’s national
security and maximises the benefits of the digital economy”
This section defines what
success looks like in broad
summary terms and reflects the •
country’s priorities.
•
4. Risk-management – how the
process works, then setting
objectives and priorities
•
This section describes how risk
management is performed and
provides a top-level analysis.
•
Make a clear statement of
the country’s commitment
to protecting the use of its
Cyberspace
Emphasise the breadth of
the use of Cyberspace:
covering social and
economic activity
Include text that can be
quoted as part of the
communication with wider
stakeholders, e.g. a vision
statement.
How risk management is
currently performed, for
example for national
security.
Sources of threat
information and of major
vulnerabilities.
Three pillars of the Australian strategy:
• All Australians are aware of cyber risks, secure their computers
and take steps to protect their identities, privacy and finances
online;
• Australian businesses operate secure and resilient information and
communications technologies to protect the integrity of their own
operations and the identity and privacy of their customers;
• The Australian Government ensures its information and
communications technologies are secure and resilient.”
Four pillars of the UK strategy:
• Tackle cybercrime and be one of the most secure places in the
world to do business in cyberspace;
• To be more resilient to cyber attacks and better able to protect our
interests in cyberspace;
• To have helped shape an open, stable and vibrant cyberspace
which the UK public can use safely and that supports open
societies;
• To have the cross-cutting knowledge, skills and capability it needs
to underpin all our Cybersecurity objectives.
From Microsoft’s guidance, listed in appendix 3:
• A clear structure for assessing and managing risk
• Understand national threats and major vulnerabilities
• Document and review risk acceptance and exceptions
• Set clear security priorities consistent with the principles
• Make national cyber risk assessment an ongoing process
Page 19 of 33
www.cto.int