For many national strategies, these goals are
combined to form the pillars on which the
strategy is built. They are chosen carefully to
offer a simple-to-grasp expression of what the
strategy seeks to achieve. These strategic goals
can be a powerful aid in communicating the
strategy to a wider audience.
Some countries may want to define a
vision or mission statement. This is a
matter of choice and can also be a
powerful aid in communicating the
strategy by describing the end-state of the
activities called for by the strategy in a
more discursive form.
Canada has the following strategic
Cybersecurity goals:
• Secure government systems;
• Partner to secure vital cyber systems
outside the federal government; and
• Help Canadians to be secure online.
“Our vision is for the UK in 2015 to derive huge
economic and social value from a vibrant,
resilient and secure cyberspace, where our
actions, guided by our core values of liberty,
fairness, transparency and the rule of law,
enhance prosperity, national security and a
strong society.” UK Cybersecurity Strategy
4.4 Risk-management section – setting objectives and priorities
Within the framework created by those high-level goals, more detailed and clearly
articulated objectives are important in order to set the relative priorities at a more
tangible level. These should be derived from a risk-based assessment that considers the
assets and services that are important to the country in the delivery of its national
strategic goals, set against the prevailing Cyberspace threats and the mitigations that the
strategy can practically put in place. The strategy should describe its risk management
method including understanding threats and vulnerabilities. The strategy may separate
risks into categories, indicating that some can be managed or mitigated while others
must be accepted because there is no practical treatment. In the latter case, the
country’s energy and resources may be better spent in preparing to remediate in the
event of an incident.
Countries should avoid creating their own Cybersecurity standards where possible
because this will increase costs and risks for delivery of ICT systems and services from
the global supply chain. There is a range of technology-neutral Cybersecurity standards
and good-practice, starting with the internationally-recognised ISO-27000 series,
augmented by more detailed controls, such as the Information Security Forum’s
Standard of Good Practice, listed in appendix 4.
Figure 1 illustrates the central importance of assessing risk, setting priorities and
monitoring implementation, within well-defined governance and management.
Page 9 of 33
www.cto.int