4 KEY ELEMENTS OF A CYBERSECURITY STRATEGY This chapter of the guide offers a recommended structure for a National Cybersecurity Strategy and each of the following sub-chapters offers a short commentary on the purpose of the strategy’s sections. Examples are provided to illustrate how some countries have approached particular aspects in their own national strategies, tailored to their needs. Appendix 2 provides a more detailed guide on the contents of each section including further examples from published strategies and other good practice. 4.1 Introduction and background section Providing a broad context for a reader that is not immersed in the subject, this section explains the importance of Cybersecurity to national social and economic development, summarising background information on the use of Cyberspace, the risks and opportunities facing the country. This section should include an explicit assessment of the current state of Cybersecurity in the country, outlining the challenges being faced in securing Cyberspace, providing the justification for developing the Cybersecurity strategy. This section should also explain how the Cybersecurity strategy aligns to the country’s development goals and plans; and how it relates to any other relevant national strategies and initiatives such as for broader national security, telecommunications, education, energy, trade and industry, tourism, law enforcement and defence. 4.2 Guiding principles section The strategy should be rooted in the cultural values of the country and be based on principles against which choices can be judged. The Commonwealth Cybergovernance Model has been accepted by Commonwealth Ministers as a foundation upon which to build the Commonwealth’s strategic approach to Cyberspace. This section should therefore reflect the culture of the country expressed as some national principles and those Commonwealth Cybergovernance principles as the guidance in the development of national strategic goals. In particular, the strategy should reflect the conscious and continuous balance of the achievement of security goals while respecting privacy and the protection of civil liberties. This section should explain how this active balance will be maintained. Additionally, this section may wish to set out some further principles for the approach adopted for the strategy’s design and delivery. The following are recommended, based on guidance published by Microsoft, listed as a source of best practice in appendix 3: • • • Risk-based. Assess risk by identifying threats, vulnerabilities, and consequences, then manage the risk through mitigations, controls, costs, and similar measures. Outcome-focused. Focus on the desired end state rather than prescribing the means to achieve it, and measure progress towards that end state. Prioritised. Adopt a graduated approach and focus on what is critical, recognising that the impact of disruption or failure is not uniform among assets or sectors. Page 7 of 33 www.cto.int

Select target paragraph3