16 PRIORITY 2 – TECHNICAL AND PROCEDURAL MEASURES Actions under this priority address help create a generic and universal digital identity system and the necessary organisational structures to recognise digital credentials across jurisdictions through the following actions: 16.1 PROCEDURAL MEASURES Countries should consider the following actions under this priority/pillar: 16.1.1 Action 1: National Cybersecurity Framework A Cybersecurity Framework implements the vision outlined in the Cybersecurity strategy. The Framework is a standards-based but flexible model for establishing, implementing, operating, monitoring, reviewing, maintaining and improving Cybersecurity Programmes. The Framework outlines minimum-security measures that stakeholders must abide by to claim compliance with national cybersecurity requirements. Cognisant that cybersecurity is a global issue, this Guide defines a Framework modelled on ISO/IEC 27000 Series, the most widely recognised Information Security Management System (ISMS). 16.1.2 Cybersecurity Goals The eleven ISO/IEC 27002 security control clauses are a natural model for security goals because organisations that implement these clauses are on the way to meeting ISO/IEC 27001 requirements. This Guide adapts the control clauses to define four model security goals for the consideration of national administrations. The goals are not security policies for direct application by departments and agencies. Instead, the security goals define the minimum or mandatory security requirements. We provide an example below: 16.1.2.1 Goal 1: Governance and Risk Management Objective: Effective security results from a good governance structure as well as the selection of security controls based on sound risk management principles. 16.1.2.1.1 Governance This sub-goal coincides with the ISO/IEC 27002 “Organising Information Security” security control clause. The clause calls for the creation of a management framework to initiate and control the implementation of security within an organisation. This Guide recommends that the organisation serves as the focal point for all activities dealing with 75

Select target paragraph3