STRATEGY COMPONENTS
ASPECTS TO CONSIDER
•
•
6.2 Legal and regulatory
Framework
This section describes
any legislative
programme needed to
define serious malicious
acts in Cyberspace as
prohibited criminal acts.
It also describes legal,
policy and regulatory
measures to enable or
compel desirable
behaviours.
6.3 Capacity Building
This section set out the
actions to develop
human and institutional
capacity to deliver the
strategy and continue to
develop to deliver the
3
•
•
•
•
EXAMPLE TEXT FROM PUBLISHED STRATEGIES AND BEST
PRACTICE
Adopt measures to foster
institutional and technical
collaboration.
Consider creating centres of
excellence in cyber security.
Review existing criminal
codes regarding Cybercrime
and amend as necessary to
meet global best practice.
Review legislation and
consequent regulation
concerning protection of the
Critical Infrastructure.
Harmonise and develop
legislation to facilitate
collaboration and
information-sharing between
institutions.
Provide protection for
intellectual property.
For people:
• Perform training needs
analyses for all relevant
sectors and institutions.
• Design capacity building
programmes.
For institutions:
Harmonise existing national security laws with Cybersecurity laws to
facilitate collaboration and implementation among relevant
institutions.
Develop/review appropriate mechanisms to enforce cybercrime
legislation.
Translate policies into legislations, where appropriate, to make them
legally binding.
Develop regulation necessary for Critical Information Infrastructure
Protection (CIIP 3).
•
•
•
Develop courses to train Cybersecurity experts with special
attention on critical sectors, i.e. international standards, legal and
regulatory.
Develop recruitment and retention strategies aimed at ensuring a
sufficient level of technical expertise is developed and maintained
within government agencies – Australia
Provide for acquiring information security officers in Government
Ministries, Departments and Agencies – Uganda
Critical Information Infrastructure Protection is explained by many sources including at http://www.oecd.org/sti/ieconomy/ciip.htm
Page 22 of 33
www.cto.int