6.2.2.1.1 Example: Values guiding UK Cybersecurity Strategy 39 The UK Cyber Security Strategy shows how national values may shape a cybersecurity approach. The UK strategy states that the cyber approach is consistent with overarching principles of the National Security Strategy. The national security approach itself relies on core values including: human rights, the rule of law, legitimate and accountable government, justice, freedom, tolerance and opportunity for all. Applied to cybersecurity, the document states, “The Government believes that the continuing openness of the Internet and cyber space is fundamental to our way of life, promoting the free flow of ideas to strengthen democratic ideals and deliver the economic benefits of globalisation.” It continues that, “Our approach seeks to preserve and protect the rights to which we are accustomed (including privacy and civil liberties) because it is on these rights that our freedoms depend.” The strategy recognises the fundamental challenge of balancing the measures intended to protect security and the right to life with the impact they have on other rights that the UK cherishes and form the basis of society (UK 2009). 6.2.2.2 Systematic National Leadership This principle aims to ensure that national strategies tackle cybersecurity holistically and avoid the duplication of resources and efforts. Therefore, this principle sees it as a government responsibility to address cyber threats systematically and nationally in coordination with all relevant stakeholders. 6.2.2.3 Shared Responsibility Cybersecurity strategies also work on the premise of shared responsibility. This principle implies that in a manner appropriate to their roles, Governments, business, organisations and individual owners and users of cyberspace should assume responsibility and take reasonable steps to enhance cybersecurity. The principle also requires all stakeholders to be aware of relevant risks, preventive measures and effective responses to threats. 6.2.2.4 A Multi-stakeholder Approach Cybersecurity strategies further assume a multi-stakeholder approach. This is a belief that no country, company or individual can surmount the cybersecurity challenge alone. Thus, every stakeholder has a role to play in creating a safe environment for all. 6.2.2.5 Risk Management Cyberspace is never risk free. Therefore, the principle cautions against aiming to prevent all cyber threats and vulnerabilities from becoming cyber risks. It is costly and often not required. Instead, cybersecurity strategies should focus on tackling threats most likely to prevent government agencies and businesses from carrying out critical missions. 39 Obtain a copy of the UK Cybersecurity Strategy here: http://www.official-documents.gov.uk/document/cm76/7642/7642.pdf 38

Select target paragraph3