Stakeholders usually develop a sense of ownership for strategies they help form. The
support is critical during the implementation phase of the strategy. Second, national
governments may not be in a good position to dictate strategy because the stakeholders
actually own and operate the infrastructure. Crucially, the other stakeholders normally
possess skills outside the core competencies of most governments. Thus, the external
30
players know what works in practice. We now consider the parties that often shape
national cybersecurity strategies. Naturally, the stakeholders may vary across countries.
5.3.1
Executive Branch of Government
Governments have a duty to ensure the prosperity and security of nations. Therefore, the
Executive is accountable for setting the agenda for securing all national security domains
including cyberspace. Ideally, the Executive performs the following roles:
Definition of the role of cyberspace in achieving national development goals;
Identification, analysis and mitigation of risks to achieving national interests;
Sponsoring and resourcing national cybersecurity programmes;
Developing cybercrime legislation that is globally applicable and interoperable;
Encouraging the development of secure technologies such as cryptography;
Managing human and institutional capacity building programmes;
Signing cybersecurity related international treaties and conventions; and
Formulating and defending cybersecurity positions at regional and global fora.
Governments draw on legislative powers and economic incentives to help ensure that all
stakeholders accept responsibility and take steps to defend their part of cyberspace.
5.3.2
Legislative Branch of Government
Parliament plays a crucial role in providing the Executive the tools needed to ensure that
cyberspace keeps a country secure and prosperous. As Section 5.4 shows, legislatures
may trigger national cybersecurity strategies by passing legislation and treaties. The
legislature may also ensure that cyber programmes have sufficient funding by approving
budgets. Legislatures further review embryonic strategies to ensure that the defence of
cyberspace does not infringe on national values such as freedom of expression.
5.3.3
Critical Infrastructure Owners and Operators
It is almost impossible to over-emphasise the importance of critical infrastructure owners
and operators to the elaboration and implementation of national cybersecurity strategies.
The organisations should contribute to the national strategy elaboration because of their
direct economic interest in the success of national cybersecurity programmes. States
may deploy legal and regulatory measures to compel the organisations’ compliance with
cybersecurity requirements. In our experience, the willing participation of the owners and
30
The Carnegie Mellon document entitled “Best Practices for National Cybersecurity: Building a National Computer Security
Incident Management Capability” presents a comprehensive list of national cybersecurity stakeholders. We adopt this list.
28