•
•
Practicable. Optimise for adoption by the largest possible group of critical assets and
realistic implementation across the broadest range of critical sectors.
Globally relevant. Integrate international standards to the maximum extent possible,
keeping the goal of harmonization in mind wherever possible.
In particular, in order to focus its investment effectively, the strategy must be informed
by the prevailing risks, which will likely change during the period of the strategy’s
delivery. It is important that the strategy can be reprioritised as circumstances change.
4.3 Vision and strategic goals section
Framed by the principles set out above, the national Cybersecurity strategy should set a
clear direction to establish and improve Cybersecurity for government, academia,
consumers and service-providers who serve those communities. This will be expressed as
a set of strategic goals. Examples, from a range of sources in appendix 3, include:
•
•
•
•
•
•
•
•
Promote economic development. Providing a safe environment for users of
Cyberspace engenders a level of trust among international business community to
develop, with confidence, trade relations with such countries. In the long run, this
contributes towards the economic development of the country;
Provide national leadership. This demonstrates a strong commitment of government
to work with and bring cohesion to the necessary stakeholders in addressing
Cybersecurity;
Tackle Cybercrime. For many countries, this is a priority, to reduce the corrosive and
pernicious effects of on-line crime;
Strengthen the critical infrastructure. Identifying the scale, scope and approach to
securing the country’s critical national infrastructure;
Raise and maintain awareness. One major challenge facing national economies in
addressing the subject of Cybersecurity is the low knowledge levels of users in
Cyberspace. With improved awareness, Cyberhygiene improves;
Achieve shared responsibility. Citizens and
Austria has declared a goal of using
businesses have a responsibility, with their
“self-regulation” to encourage the
service providers, for their own security. The
private sector to set its own detailed
owners of ICT networks bear the
standards on Cybersecurity whilst the
responsibility, with their suppliers, of putting
state creates the necessary overarching
the necessary measures in place to secure
regulatory framework.
their own systems;
Defend the value of Human Rights. It is
important to achieve the right balance
between national security objectives and citizens’ right to freedom of expression, to
privacy and access to information. Countries that want to address concerns about
inappropriate use of social media will want to avoid introducing disproportionate
internet censorship;
Develop national and international partnerships. A key component in delivering
security in Cyberspace is the collaboration within and beyond national boundaries.
This covers national and international initiatives;
Page 8 of 33
www.cto.int