For many national strategies, these goals are combined to form the pillars on which the strategy is built. They are chosen carefully to offer a simple-to-grasp expression of what the strategy seeks to achieve. These strategic goals can be a powerful aid in communicating the strategy to a wider audience. Some countries may want to define a vision or mission statement. This is a matter of choice and can also be a powerful aid in communicating the strategy by describing the end-state of the activities called for by the strategy in a more discursive form. Canada has the following strategic Cybersecurity goals: • Secure government systems; • Partner to secure vital cyber systems outside the federal government; and • Help Canadians to be secure online. “Our vision is for the UK in 2015 to derive huge economic and social value from a vibrant, resilient and secure cyberspace, where our actions, guided by our core values of liberty, fairness, transparency and the rule of law, enhance prosperity, national security and a strong society.” UK Cybersecurity Strategy 4.4 Risk-management section – setting objectives and priorities Within the framework created by those high-level goals, more detailed and clearly articulated objectives are important in order to set the relative priorities at a more tangible level. These should be derived from a risk-based assessment that considers the assets and services that are important to the country in the delivery of its national strategic goals, set against the prevailing Cyberspace threats and the mitigations that the strategy can practically put in place. The strategy should describe its risk management method including understanding threats and vulnerabilities. The strategy may separate risks into categories, indicating that some can be managed or mitigated while others must be accepted because there is no practical treatment. In the latter case, the country’s energy and resources may be better spent in preparing to remediate in the event of an incident. Countries should avoid creating their own Cybersecurity standards where possible because this will increase costs and risks for delivery of ICT systems and services from the global supply chain. There is a range of technology-neutral Cybersecurity standards and good-practice, starting with the internationally-recognised ISO-27000 series, augmented by more detailed controls, such as the Information Security Forum’s Standard of Good Practice, listed in appendix 4. Figure 1 illustrates the central importance of assessing risk, setting priorities and monitoring implementation, within well-defined governance and management. Page 9 of 33 www.cto.int

Select target paragraph3