STRATEGY COMPONENTS ASPECTS TO CONSIDER • • 6.2 Legal and regulatory Framework This section describes any legislative programme needed to define serious malicious acts in Cyberspace as prohibited criminal acts. It also describes legal, policy and regulatory measures to enable or compel desirable behaviours. 6.3 Capacity Building This section set out the actions to develop human and institutional capacity to deliver the strategy and continue to develop to deliver the 3 • • • • EXAMPLE TEXT FROM PUBLISHED STRATEGIES AND BEST PRACTICE Adopt measures to foster institutional and technical collaboration. Consider creating centres of excellence in cyber security. Review existing criminal codes regarding Cybercrime and amend as necessary to meet global best practice. Review legislation and consequent regulation concerning protection of the Critical Infrastructure. Harmonise and develop legislation to facilitate collaboration and information-sharing between institutions. Provide protection for intellectual property. For people: • Perform training needs analyses for all relevant sectors and institutions. • Design capacity building programmes. For institutions: Harmonise existing national security laws with Cybersecurity laws to facilitate collaboration and implementation among relevant institutions. Develop/review appropriate mechanisms to enforce cybercrime legislation. Translate policies into legislations, where appropriate, to make them legally binding. Develop regulation necessary for Critical Information Infrastructure Protection (CIIP 3). • • • Develop courses to train Cybersecurity experts with special attention on critical sectors, i.e. international standards, legal and regulatory. Develop recruitment and retention strategies aimed at ensuring a sufficient level of technical expertise is developed and maintained within government agencies – Australia Provide for acquiring information security officers in Government Ministries, Departments and Agencies – Uganda Critical Information Infrastructure Protection is explained by many sources including at http://www.oecd.org/sti/ieconomy/ciip.htm Page 22 of 33 www.cto.int

Select target paragraph3