5.4.1
Purpose of Strategy Process Flowchart
We depict the strategy process in the Figure 5 cross-functional flowchart. The flowchart
provides a high-level view of the process including functions and activities. As national
governance structures, capabilities and needs vary, the flowchart is illustrative only. We
briefly discuss the five steps of the flowchart that we highlight.
5.4.2
Stage 0 – Cybersecurity Strategy Driver
A number of events may spur cybersecurity strategy activities. The actions include major
data leakages and national policies. Data leakages include deliberate or accidental loss
of government and/or personal data. Stakeholders such as the Executive, legislature and
citizens groups may demand action in response to the leakage that later serves to spur
the cybersecurity strategy process. In addition, policies such as national development
34
35
plans and national security strategies spur cybersecurity strategy activity. The policies
classify cyberspace as a domain vital to achieving national economic and security goals.
Therefore, the national policies may require action to improve the country’s ability to
exploit cyberspace with confidence and trust. Whatever the spur of the action on the
national cybersecurity strategy, we recommend that promoters of the strategy develop a
case for action that shows all stakeholders the benefits of the coordinated approach.
5.4.3
Stage 1 – Direct and Coordinate Elaboration
The Executive is accountable for leading the elaboration of the cybersecurity strategy.
Whilst the government may require stakeholder participation, our experience shows that
a collaborative approach may offer more sustainable benefits. Government can win the
support of other stakeholders by emphasising the mutual benefits of working together.
Whilst every State has a right to choose the most efficacious approach, we recommend
that Governments focus on setting the agenda and the conditions for all stakeholders to
work together. The agreed strategy sets a stage for national and global cooperation.
5.4.4
Stage 2 – Define and Issue Strategy
This stage sees the publication of the cybersecurity strategy. The focal organisation for
cybersecurity should highlight the roles and responsibilities of major stakeholders. Vitally,
the publicity should stress that every government department, business, organisation,
owner, and individual user of ICTs has a role to play in securing national cyberspace.
5.4.5
Stage 3 – Sector or GCA Pillar-specific Strategies
The national cybersecurity strategy sets a vision for cybersecurity action. The document
does not focus on sector or GCA pillar-specific issues. For example, States may allocate
34
For example, the Botswana National Development Plan (2010) sees improvement of the ICT infrastructure for all businesses
as critical increase those service exports, which rely on improved access to the internet. Obtain a copy here:
http://www.finance.gov.bw/index.php?option=com_content1&parent_id=334&id=338
35
As we shall see later, many countries regard cyber attacks as a priority risk to achieving national security objectives.