intervention. A collaborative multi-stakeholder approach is vital to avoid such damaging outcomes. 3.3 Delivering the Strategy Once adopted, a national Cybersecurity strategy sets the direction for all participating stakeholders to follow and provides a vital communication of intention to the wider audience. Continuing professional public communication on progress is important to maintain that engagement and avoid a loss of confidence in the strategy’s delivery. A predominant and continuing risk to delivery of the national Cybersecurity strategy will be the continuing and new fragmentation of stakeholders when they discover the details of its delivery to be in direct conflict with their other priorities. This fragmentation may occur between departments within the same government, between private sector interests, or any other combination. The strategy cannot be written to mitigate this risk entirely and governance mechanisms must provide the means to resolve these tensions. It is quite likely to require the appointment of a lead organisation or institution, ideally supported by respected and independent experts. The authority, design and operation of this multi-stakeholder governance mechanism is a key factor in the success of the strategy and should take into account the particular needs and circumstances of each country, guided by the principles of the Cybergovernance Model and the values of Trinidad and Tobago established the the Commonwealth. The design of sub-committees and Trinidad and Tobago stakeholder engagement activities should be chosen Cyber Security Agency carefully to reflect the goals and objectives (to be covered (TTCSA) below) and how they fall across existing activities, relationships and structures in the country. 3.4 Reviewing the Strategy To ensure the objectives of the national Cybersecurity strategy are being achieved, appropriate mechanisms should be put in place to monitor and validate its implementation. Monitoring the implementation of the strategy helps identify gaps that may exist within the strategy for future review. The outcomes of the monitoring and evaluation should feed back into the strategy so that it is continuously improved. Given the rate of change of the underlying technology upon which Cyberspace operates, the strategy is likely to require reviewing and refreshing every 3 or 4 years. It may be most effective to align this to national budgetary and planning cycles. Within that cycle, some aspects of the strategy’s delivery may require more frequent monitoring and revision, even quarterly. This will reflect the urgency of some tasks, the rapid rate of development of the threat and the developing skills and knowledge of the participants. Page 6 of 33 www.cto.int

Select target paragraph3