5.4.1 Purpose of Strategy Process Flowchart We depict the strategy process in the Figure 5 cross-functional flowchart. The flowchart provides a high-level view of the process including functions and activities. As national governance structures, capabilities and needs vary, the flowchart is illustrative only. We briefly discuss the five steps of the flowchart that we highlight. 5.4.2 Stage 0 – Cybersecurity Strategy Driver A number of events may spur cybersecurity strategy activities. The actions include major data leakages and national policies. Data leakages include deliberate or accidental loss of government and/or personal data. Stakeholders such as the Executive, legislature and citizens groups may demand action in response to the leakage that later serves to spur the cybersecurity strategy process. In addition, policies such as national development 34 35 plans and national security strategies spur cybersecurity strategy activity. The policies classify cyberspace as a domain vital to achieving national economic and security goals. Therefore, the national policies may require action to improve the country’s ability to exploit cyberspace with confidence and trust. Whatever the spur of the action on the national cybersecurity strategy, we recommend that promoters of the strategy develop a case for action that shows all stakeholders the benefits of the coordinated approach. 5.4.3 Stage 1 – Direct and Coordinate Elaboration The Executive is accountable for leading the elaboration of the cybersecurity strategy. Whilst the government may require stakeholder participation, our experience shows that a collaborative approach may offer more sustainable benefits. Government can win the support of other stakeholders by emphasising the mutual benefits of working together. Whilst every State has a right to choose the most efficacious approach, we recommend that Governments focus on setting the agenda and the conditions for all stakeholders to work together. The agreed strategy sets a stage for national and global cooperation. 5.4.4 Stage 2 – Define and Issue Strategy This stage sees the publication of the cybersecurity strategy. The focal organisation for cybersecurity should highlight the roles and responsibilities of major stakeholders. Vitally, the publicity should stress that every government department, business, organisation, owner, and individual user of ICTs has a role to play in securing national cyberspace. 5.4.5 Stage 3 – Sector or GCA Pillar-specific Strategies The national cybersecurity strategy sets a vision for cybersecurity action. The document does not focus on sector or GCA pillar-specific issues. For example, States may allocate 34 For example, the Botswana National Development Plan (2010) sees improvement of the ICT infrastructure for all businesses as critical increase those service exports, which rely on improved access to the internet. Obtain a copy here: http://www.finance.gov.bw/index.php?option=com_content1&parent_id=334&id=338 35 As we shall see later, many countries regard cyber attacks as a priority risk to achieving national security objectives.

Select target paragraph3