Stakeholders usually develop a sense of ownership for strategies they help form. The support is critical during the implementation phase of the strategy. Second, national governments may not be in a good position to dictate strategy because the stakeholders actually own and operate the infrastructure. Crucially, the other stakeholders normally possess skills outside the core competencies of most governments. Thus, the external 30 players know what works in practice. We now consider the parties that often shape national cybersecurity strategies. Naturally, the stakeholders may vary across countries. 5.3.1 Executive Branch of Government Governments have a duty to ensure the prosperity and security of nations. Therefore, the Executive is accountable for setting the agenda for securing all national security domains including cyberspace. Ideally, the Executive performs the following roles:  Definition of the role of cyberspace in achieving national development goals;  Identification, analysis and mitigation of risks to achieving national interests;  Sponsoring and resourcing national cybersecurity programmes;  Developing cybercrime legislation that is globally applicable and interoperable;  Encouraging the development of secure technologies such as cryptography;  Managing human and institutional capacity building programmes;  Signing cybersecurity related international treaties and conventions; and  Formulating and defending cybersecurity positions at regional and global fora. Governments draw on legislative powers and economic incentives to help ensure that all stakeholders accept responsibility and take steps to defend their part of cyberspace. 5.3.2 Legislative Branch of Government Parliament plays a crucial role in providing the Executive the tools needed to ensure that cyberspace keeps a country secure and prosperous. As Section 5.4 shows, legislatures may trigger national cybersecurity strategies by passing legislation and treaties. The legislature may also ensure that cyber programmes have sufficient funding by approving budgets. Legislatures further review embryonic strategies to ensure that the defence of cyberspace does not infringe on national values such as freedom of expression. 5.3.3 Critical Infrastructure Owners and Operators It is almost impossible to over-emphasise the importance of critical infrastructure owners and operators to the elaboration and implementation of national cybersecurity strategies. The organisations should contribute to the national strategy elaboration because of their direct economic interest in the success of national cybersecurity programmes. States may deploy legal and regulatory measures to compel the organisations’ compliance with cybersecurity requirements. In our experience, the willing participation of the owners and 30 The Carnegie Mellon document entitled “Best Practices for National Cybersecurity: Building a National Computer Security Incident Management Capability” presents a comprehensive list of national cybersecurity stakeholders. We adopt this list. 28

Select target paragraph3