STRATEGY COMPONENTS ASPECTS TO CONSIDER EXAMPLE TEXT FROM PUBLISHED STRATEGIES AND BEST PRACTICE 3. Strategic goals and vision • Australia’s vision: “The maintenance of a secure, resilient and trusted electronic operating environment that supports Australia’s national security and maximises the benefits of the digital economy” This section defines what success looks like in broad summary terms and reflects the • country’s priorities. • 4. Risk-management – how the process works, then setting objectives and priorities • This section describes how risk management is performed and provides a top-level analysis. • Make a clear statement of the country’s commitment to protecting the use of its Cyberspace Emphasise the breadth of the use of Cyberspace: covering social and economic activity Include text that can be quoted as part of the communication with wider stakeholders, e.g. a vision statement. How risk management is currently performed, for example for national security. Sources of threat information and of major vulnerabilities. Three pillars of the Australian strategy: • All Australians are aware of cyber risks, secure their computers and take steps to protect their identities, privacy and finances online; • Australian businesses operate secure and resilient information and communications technologies to protect the integrity of their own operations and the identity and privacy of their customers; • The Australian Government ensures its information and communications technologies are secure and resilient.” Four pillars of the UK strategy: • Tackle cybercrime and be one of the most secure places in the world to do business in cyberspace; • To be more resilient to cyber attacks and better able to protect our interests in cyberspace; • To have helped shape an open, stable and vibrant cyberspace which the UK public can use safely and that supports open societies; • To have the cross-cutting knowledge, skills and capability it needs to underpin all our Cybersecurity objectives. From Microsoft’s guidance, listed in appendix 3: • A clear structure for assessing and managing risk • Understand national threats and major vulnerabilities • Document and review risk acceptance and exceptions • Set clear security priorities consistent with the principles • Make national cyber risk assessment an ongoing process Page 19 of 33 www.cto.int

Select target paragraph3