3
A NATIONAL CYBERSECURITY STRATEGY
The approach described in this guide embraces the Principles of Commonwealth
Cybergovernance and draws on published Cybersecurity strategies and good practice from
a range of countries. Accordingly, it outlines the key components a National
Cybersecurity Strategy should address. The framework offers guidance to countries in the
development and modification of their national Cybersecurity Strategies, emphasising the
need for each country to take into account its culture, its national priorities, the risks it
faces and the impact of its strategy both regionally and globally.
3.1 Development of the Strategy
The success of any national strategy depends on the practical circumstances within the
government and the country. It is important that the project to develop a national
Cybersecurity strategy attracts the strong and visible support of highest levels of
Government. However, due to the nature of Cybersecurity, it is also imperative that the
National Cybersecurity strategy is developed in a multi-stakeholder partnership that
brings together the public sector, private sector and the civil society while also drawing
on the knowledge, expertise and competencies of the international community. This
requires a delicate balance of strong leadership coupled with an inclusive approach.
The exercise of developing the strategy will benefit all participating stakeholders by
improving awareness and mutual understanding of the disparate opportunities, risks,
needs and capabilities of the different stakeholders. Reflecting the global and connected
nature of Cyberspace, these stakeholders may be national and international bodies, both
regional and global, both public and private sector plus civil society.
The choice of vocabulary used in Cybersecurity can represent a challenge because in
English some words related to Cybersecurity can convey quite different meanings to
different audiences. Further, nuances are often lost in translation between languages. It
is important that the specialist Cybersecurity words used in the national strategy are
defined, in consultation with the key stakeholders, and recorded in a glossary. An
example glossary accompanies this guide as appendix 1.
In preparation for launching a national Cybersecurity strategy and throughout its delivery,
it may be beneficial to inform and educate media, politicians and other influential
individuals, to harness their ability to influence the wider audience whose support will
contribute to the strategy’s success.
3.2 Resources and market forces
Some actions called for by the strategy will be delivered under the direct control of
government agencies but those agencies are quite likely to lack the necessary skills and
resources. Therefore, a key part of the strategy’s design should consider including, where
necessary, the allocation and development of those resources in order to respond to the
strategy. Some actions will fall on the private sector and it is important that expectations
are realistic and sympathetic to their commercial environment, to avoid perverse
outcomes that may result when market forces respond to ill-considered government
Page 5 of 33
www.cto.int