4.5 Stakeholder section
The delivery of these objectives will involve a wide range of stakeholders, who should be
identified in this section of the national Cybersecurity strategy. The majority of the
technical infrastructure that comprises Cyberspace is designed, built, owned and
operated by the private sector. These companies are often multi-national with complex
international supply chains. The threats posed by Cybersecurity transcend national
borders and call for strong coordination mechanisms
nationally, regionally and internationally and across
“The
Government
of
the
sectors. In constructing the list of stakeholders, a wide
Republic of Trinidad and Tobago
(GoRTT) will partner with the
range of constituencies should be considered,
private sector and civil society in
including policy makers, officials from across most
the implementation of its cyber
government departments, specific agencies, private
security strategy”
sector representatives from many industries, civil
society, academics, international bodies and possibly
other countries. Appendix 2 offers a list of potential stakeholders to consider.
4.6 Strategy implementation section
Having set out the high-level objectives and identified the stakeholders, this section
should describe how the work is divided into manageable components. The following
headings are illustrative and the structure of each country’s strategy must reflect the
country’s needs, existing structures and immediate risk-based priorities for action.
4.6.1 Governance and management structure
Implementation requires a governance and management structure that brings together all
stakeholders and harnesses each stakeholder’s strengths and competencies. An effective
strategy will most likely depend on innovative and spontaneous collaboration between
stakeholders, without calling for the direct involvement of the management structure.
Nevertheless lines of authority and reporting should be clear and unambiguous. To
achieve both outcomes, it may be helpful to construct a table of stakeholders that
records the individuals who are responsible, accountable, consulted and informed about
the major topics of the strategy 2. It may require some debate to determine this structure.
Once finalised, it should be recorded in the strategy document. Appendix 5 offers an
example of a RACI table.
4.6.2 Legal and regulatory framework
The legal and regulatory framework is a foundation to any national strategy, particularly
for law enforcement activities, and must remain under continuous review in order to be
effective and to reflect the contemporary risks and opportunities of the rapid evolution of
Cyberspace. In this section, the national Cybersecurity strategy should describe how this
will be achieved and set targets to:
• Review existing frameworks and develop new ones to remain up-to-date with current
technological developments;
2
Responsible, Accountable, Consulted and Informed: the so-called RACI table. For more on this
approach, see http://en.wikipedia.org/wiki/Responsibility_assignment_matrix
Page 11 of 33
www.cto.int