STRATEGY COMPONENTS ASPECTS TO CONSIDER 6. Implementation • This section identifies activities in more detail. • 6.1 Governance and management structure This section describes the establishment of governance and management for the strategy, covering its development and delivery. This must include management of monitoring and improvement. • • • • • EXAMPLE TEXT FROM PUBLISHED STRATEGIES AND BEST PRACTICE Define practical actions to be undertaken. Group actions into categories convenient for their management. Establish a strong leadership role at the highest level to give priority and recognition to the strategy. Establish suitable multistakeholder governance of the strategy to cover all aspects. This should cover all economic sectors, civil society, private and public sectors. Identify and establish activities required to monitor and validate the strategy’s implementation. Note: the management and monitoring of the strategy’s delivery may require a small full-time staff. Management of crises (covered later) must be considered as part of the governance structure. “The Specialised Cyber Security Committee will support the National Security Council in performing its functions, particularly in assisting the Prime Minister in directing and coordinating the National Security Policy in the field of cyber security.” - Spain “The Specialised Situation Committee will be convened to manage crisis situations in the field of cyber security ...” - Spain “The Specialised Cyber Security Committee and the Specialised Situation Committee will act in a complementary manner, each in its own area of responsibility but under the same strategic and political direction of the National Security Council chaired by the Prime Minister.” - Spain Establishment of a Trinidad and Tobago Cyber Security Agency (TTCSA) – Trinidad and Tobago Establishing a Cyber Security Steering Group; Creating a structure for coordination at operational level; Establishing a Cyber Crisis Management – Austria Creation of an Information Security Advisory Group to provide advisory service to information security governance – Uganda Page 21 of 33 www.cto.int

Select target paragraph3