6.1
INTRODUCTION
Having identified the parties that usually contribute to national strategy development and
proposed a process flowchart, we now present the strategy model. Our goal is to define
a reference model for countries elaborating new or improving existing national strategies
on cybersecurity. As Figure 6 shows, the Global Cybersecurity Agenda is at the heart of
our model. We use the GCA along with the Ends-Ways-Means strategy paradigm. We
see this is a vital combination as it sets the stage for collaboration between cybersecurity
strategists and a diverse group of stakeholders responsible for national policy.
6.1.1
Assumption of Cybersecurity Strategy Model
Given that cybersecurity drivers and threats vary across countries, it is essential to state
the assumptions behind our model. The model grew out of ITU Expert Missions that
used the GCA as a guiding framework. The main themes of these efforts included:
ICTs viewed as an engine for economic improvements that hold promise for citizens;
There was a need to encourage private sector investment in the information and
communications sector following liberalisation and de-monopolisation of the sector;
A desire to promulgate a comprehensive set of cybercrime legislation to preserve the
evidential weight and ensure admissibility of electronic data in Courts of Law;
A need to protect critical infrastructure in sectors such as banking, transport, energy
and utilities, communications and telecoms against major cyber attacks;
Ambitious eGovernment projects aimed at fighting corruption and inefficiency in the
public Administration system;
Cybersecurity regarded as critical to major education projects;
ICTs as tools for modernising inefficient governments that relied on insufficient and
unreliable information; and
National security concerns due to a weak classified information protection system
and thus risk of unauthorised access, modification and destruction of state secrets.