8 WAYS – PRIORITIES Our national cybersecurity strategy model chose the five pillars of the GCA as the forms through which States may pursue national cybersecurity strategies. Therefore, the ways identify the strategic activities to help countries govern the pillars. Governance defines how nations may use the resources in the five pillars to attain the outcomes that the ends envisage. In the multi-stakeholder domain of cybersecurity, the ways define how nations may allocate resources, coordinate and control the activities of all relevant stakeholders. Allocating roles and responsibilities clearly prevents overlapping and often contradictory mandates that paralyse many national cybersecurity programmes. Clear governance structures further confer legitimacy on stakeholders including government. Importantly, the ways define expectations for activities and thus are a basis for verifying performance. 9 PRIORITY 1 – LEGAL MEASURES Gaps in national and regional legislation make cybercrime a low risk and lucrative undertaking. In keeping with the first GCA pillar, this priority aims to help devise strategies to govern the development of cybercrime legislation that is globally applicable and interoperable with existing national and regional legislative measures. We align this priority with GCA strategic goals relevant to the Legal Measures pillar as follows: GCA PILLAR: LEGAL MEASURES Corresponding GCA Goals Goal 1 Elaboration of strategies for the development of a model cybercrime legislation that is globally applicable and interoperable with existing national and regional legislative measures. Goal 7 Proposals on a framework for a global multi-stakeholder strategy for international cooperation, dialogue and coordination in all the above-mentioned areas. Figure 15 – Legal Measures Pillar and related GCA goal We now propose the forms through which States may consider pursuing the national cybersecurity strategies under this pillar. 9.1 LEGAL MEASURES STRATEGY Nations should strengthen their capacity to regulate cyberspace. Nations may adopt the strategy formulation process that we presented in Figure 5. In particular, stage 3 of the flowchart deals with sector or GCA-pillar specific strategies. The flowchart shows how the executive, law enforcement, the judiciary, the private sector, and other stakeholders could support of the legal strategy. Due to transnational nature of cyber threats, our 48

Select target paragraph3