1
EXECUTIVE SUMMARY
1.1
OVERVIEW
We use the term cyberspace to describe systems and services connected either directly
to or indirectly to the Internet, telecommunications and computer networks. Modern life
depends upon the timely, adequate and confidential performance of cyberspace. Thus,
cybersecurity is important to all States because it endeavours to ensure that cyberspace
continues to work when and as expected even under attack. We argue that cybersecurity
is no longer a pure computer security issue. Instead, we see cybersecurity as a national
policy matter because the illicit use of cyberspace could hamper economic, public health,
safety and national security activities. Since governments mainly exist to maintain social
order, protect the lives and property of their citizens and enable commerce, then national
leaders are accountable for cybersecurity as it supports all the aforementioned services.
We, thus, recommend that governments use all instruments of national power to reduce
cyber risks appropriately. In particular, national leaders have accountability for devising a
cybersecurity strategy and fostering local, national and global cross-sector cooperation.
This document is a reference model for national cybersecurity strategy elaboration. We
discuss what constitutes a national cybersecurity strategy; the typical ends it seeks to
accomplish and the context that influences its execution. The Guide also discusses how
States and other relevant stakeholders such as private sector organisations can build
capacity to execute a cybersecurity strategy and the resources required to address risks.
1.2
SCOPE OF GUIDE
This document focuses on the issues that countries should consider when elaborating or
reviewing national cybersecurity strategies. As national capabilities, needs and threats
vary, we recommend that countries use national values as the basis for strategies for two
main reasons. Firstly, culture and national interests influence the perception of risk and
the relative success of defences against cyber threats. Secondly, a strategy rooted in
national values is likely to gain support of stakeholders such as the judiciary and private
sector. Cognisant of the multi-stakeholder nature of cybersecurity, we derive principles
from the ITU Global Cybersecurity Agenda (GCA). The GCA is a holistic framework for
coordinating, developing and implementing a robust global culture of cybersecurity.
Since we consider cybersecurity as a national policy issue, we adopt the Ends-WaysMeans strategy paradigm due to its popularity with national policy makers. Lastly, since
cybersecurity is a branch of information security, we adopt global security standards.
1.3
AUDIENCE
The primary audience for this Guide are parties that have responsibility for, or an interest
in, cybersecurity. Inevitably, this audience is broad as cybersecurity touches practically
all forms of social, economic and national security activity. Thus, this Guide will benefit
anyone interested in the considerations for elaborating a national cybersecurity strategy.
Beneficiaries include top government leaders, legislators, regulators, service providers
and accreditors. We consider it important, at the outset, to emphasise that the success of
strategies depends upon focusing on the right risks and involvement of all stakeholders.
5