intervention. A collaborative multi-stakeholder approach is vital to avoid such damaging
outcomes.
3.3 Delivering the Strategy
Once adopted, a national Cybersecurity strategy sets the direction for all participating
stakeholders to follow and provides a vital communication of intention to the wider
audience. Continuing professional public communication on progress is important to
maintain that engagement and avoid a loss of confidence in the strategy’s delivery.
A predominant and continuing risk to delivery of the national Cybersecurity strategy will
be the continuing and new fragmentation of stakeholders when they discover the details
of its delivery to be in direct conflict with their other priorities. This fragmentation may
occur between departments within the same government, between private sector
interests, or any other combination. The strategy cannot be written to mitigate this risk
entirely and governance mechanisms must provide the means to resolve these tensions.
It is quite likely to require the appointment of a lead organisation or institution, ideally
supported by respected and independent experts.
The authority, design and operation of this multi-stakeholder governance mechanism is a
key factor in the success of the strategy and should take into account the particular
needs and circumstances of each country, guided by the
principles of the Cybergovernance Model and the values of
Trinidad and Tobago
established the
the Commonwealth. The design of sub-committees and
Trinidad and Tobago
stakeholder engagement activities should be chosen
Cyber Security Agency
carefully to reflect the goals and objectives (to be covered
(TTCSA)
below) and how they fall across existing activities,
relationships and structures in the country.
3.4 Reviewing the Strategy
To ensure the objectives of the national Cybersecurity strategy are being achieved,
appropriate mechanisms should be put in place to monitor and validate its
implementation. Monitoring the implementation of the strategy helps identify gaps that
may exist within the strategy for future review. The outcomes of the monitoring and
evaluation should feed back into the strategy so that it is continuously improved. Given
the rate of change of the underlying technology upon which Cyberspace operates, the
strategy is likely to require reviewing and refreshing every 3 or 4 years. It may be most
effective to align this to national budgetary and planning cycles. Within that cycle, some
aspects of the strategy’s delivery may require more frequent monitoring and revision,
even quarterly. This will reflect the urgency of some tasks, the rapid rate of development
of the threat and the developing skills and knowledge of the participants.
Page 6 of 33
www.cto.int