4
KEY ELEMENTS OF A CYBERSECURITY STRATEGY
This chapter of the guide offers a recommended structure for a National Cybersecurity
Strategy and each of the following sub-chapters offers a short commentary on the
purpose of the strategy’s sections. Examples are provided to illustrate how some
countries have approached particular aspects in their own national strategies, tailored to
their needs. Appendix 2 provides a more detailed guide on the contents of each section
including further examples from published strategies and other good practice.
4.1 Introduction and background section
Providing a broad context for a reader that is not immersed in the subject, this section
explains the importance of Cybersecurity to national social and economic development,
summarising background information on the use of Cyberspace, the risks and
opportunities facing the country. This section should include an explicit assessment of
the current state of Cybersecurity in the country, outlining the challenges being faced in
securing Cyberspace, providing the justification for developing the Cybersecurity strategy.
This section should also explain how the Cybersecurity strategy aligns to the country’s
development goals and plans; and how it relates to any other relevant national strategies
and initiatives such as for broader national security, telecommunications, education,
energy, trade and industry, tourism, law enforcement and defence.
4.2 Guiding principles section
The strategy should be rooted in the cultural values of the country and be based on
principles against which choices can be judged. The Commonwealth Cybergovernance
Model has been accepted by Commonwealth Ministers as a foundation upon which to
build the Commonwealth’s strategic approach to Cyberspace. This section should
therefore reflect the culture of the country expressed as some national principles and
those Commonwealth Cybergovernance principles as the guidance in the development of
national strategic goals.
In particular, the strategy should reflect the conscious and continuous balance of the
achievement of security goals while respecting privacy and the protection of civil
liberties. This section should explain how this active balance will be maintained.
Additionally, this section may wish to set out some further principles for the approach
adopted for the strategy’s design and delivery. The following are recommended, based on
guidance published by Microsoft, listed as a source of best practice in appendix 3:
•
•
•
Risk-based. Assess risk by identifying threats, vulnerabilities, and consequences,
then manage the risk through mitigations, controls, costs, and similar measures.
Outcome-focused. Focus on the desired end state rather than prescribing the means
to achieve it, and measure progress towards that end state.
Prioritised. Adopt a graduated approach and focus on what is critical, recognising
that the impact of disruption or failure is not uniform among assets or sectors.
Page 7 of 33
www.cto.int