Figure 21 provides a high-level view of the national cybersecurity focal point roles. Let us briefly explore the numbered processes within the flowchart. 11.2.1 Stage 0 – Relevant Driver Focal points often grow out of national cybersecurity strategies and similar legislation. The focal organisation may take several forms. First, the law may create a brand new organisation to perform the role. Second, the law may designate an existing ministry as the focal point. Third, the functions in the model may reside with different government ministries. Lastly, an existing body such as ICT regulator may assume the role. 11.2.2 Stage 1 – Direct and Coordinate Cybersecurity The focal point coordinates the activities of all cybersecurity stakeholders. Directing and coordinating ensures that right actions occur at the right time on the right cybersecurity priorities. The focal point also participates in international cybersecurity activities. 11.2.3 Stage 2 – Strategic and Tactical Cybersecurity Advice The focal point helps with the strategic and tactical aspects of operating cybersecurity programmes. First, the organisation explains the purpose of the national cybersecurity as well as the obligations it places on individual stakeholders. Second, the focal point may help shape cybersecurity programmes of major stakeholders in public and private sectors. Third, the focal point may use its influence to promote the adoption of good practice models. Fourth, focal point may advise on operational aspects of cybersecurity. 11.2.4 Stage 3 – Coordinate Incident Response The focal point may not have overall technical responsibility for incident management. However, the focal point often ensures united local and global incident response. It may also have overall strategic ownership of major incidents. In addition, its strategic and tactical advice role helps organisations prevent, detect and recover from incidents. 11.2.5 Stage 4 – Training and Public Awareness The focal point ensures that all stakeholders understand the relevant cyber risks, trends and effective countermeasures. In terms of training, the focal point could encourage the development of cybersecurity as follows. First, the organisation may set and/or review technical training courses for professionals. Second, the focal point may require the inclusion of given technical security features for example, parent controls. In terms of public awareness, focal points often lead campaigns to build a culture of cybersecurity. The campaigns take the form of television, radio and internet advertisements. In addition, the focal point may evaluate training programmes, prepare materials and train trainers.

Select target paragraph3