1 EXECUTIVE SUMMARY 1.1 OVERVIEW We use the term cyberspace to describe systems and services connected either directly to or indirectly to the Internet, telecommunications and computer networks. Modern life depends upon the timely, adequate and confidential performance of cyberspace. Thus, cybersecurity is important to all States because it endeavours to ensure that cyberspace continues to work when and as expected even under attack. We argue that cybersecurity is no longer a pure computer security issue. Instead, we see cybersecurity as a national policy matter because the illicit use of cyberspace could hamper economic, public health, safety and national security activities. Since governments mainly exist to maintain social order, protect the lives and property of their citizens and enable commerce, then national leaders are accountable for cybersecurity as it supports all the aforementioned services. We, thus, recommend that governments use all instruments of national power to reduce cyber risks appropriately. In particular, national leaders have accountability for devising a cybersecurity strategy and fostering local, national and global cross-sector cooperation. This document is a reference model for national cybersecurity strategy elaboration. We discuss what constitutes a national cybersecurity strategy; the typical ends it seeks to accomplish and the context that influences its execution. The Guide also discusses how States and other relevant stakeholders such as private sector organisations can build capacity to execute a cybersecurity strategy and the resources required to address risks. 1.2 SCOPE OF GUIDE This document focuses on the issues that countries should consider when elaborating or reviewing national cybersecurity strategies. As national capabilities, needs and threats vary, we recommend that countries use national values as the basis for strategies for two main reasons. Firstly, culture and national interests influence the perception of risk and the relative success of defences against cyber threats. Secondly, a strategy rooted in national values is likely to gain support of stakeholders such as the judiciary and private sector. Cognisant of the multi-stakeholder nature of cybersecurity, we derive principles from the ITU Global Cybersecurity Agenda (GCA). The GCA is a holistic framework for coordinating, developing and implementing a robust global culture of cybersecurity. Since we consider cybersecurity as a national policy issue, we adopt the Ends-WaysMeans strategy paradigm due to its popularity with national policy makers. Lastly, since cybersecurity is a branch of information security, we adopt global security standards. 1.3 AUDIENCE The primary audience for this Guide are parties that have responsibility for, or an interest in, cybersecurity. Inevitably, this audience is broad as cybersecurity touches practically all forms of social, economic and national security activity. Thus, this Guide will benefit anyone interested in the considerations for elaborating a national cybersecurity strategy. Beneficiaries include top government leaders, legislators, regulators, service providers and accreditors. We consider it important, at the outset, to emphasise that the success of strategies depends upon focusing on the right risks and involvement of all stakeholders. 5

Select target paragraph3