6.2.2.1.1 Example: Values guiding UK Cybersecurity Strategy
39
The UK Cyber Security Strategy shows how national values may shape a cybersecurity
approach. The UK strategy states that the cyber approach is consistent with overarching
principles of the National Security Strategy. The national security approach itself relies
on core values including: human rights, the rule of law, legitimate and accountable
government, justice, freedom, tolerance and opportunity for all. Applied to cybersecurity,
the document states, “The Government believes that the continuing openness of the
Internet and cyber space is fundamental to our way of life, promoting the free flow of
ideas to strengthen democratic ideals and deliver the economic benefits of globalisation.”
It continues that, “Our approach seeks to preserve and protect the rights to which we are
accustomed (including privacy and civil liberties) because it is on these rights that our
freedoms depend.” The strategy recognises the fundamental challenge of balancing the
measures intended to protect security and the right to life with the impact they have on
other rights that the UK cherishes and form the basis of society (UK 2009).
6.2.2.2
Systematic National Leadership
This principle aims to ensure that national strategies tackle cybersecurity holistically and
avoid the duplication of resources and efforts. Therefore, this principle sees it as a
government responsibility to address cyber threats systematically and nationally in
coordination with all relevant stakeholders.
6.2.2.3
Shared Responsibility
Cybersecurity strategies also work on the premise of shared responsibility. This principle
implies that in a manner appropriate to their roles, Governments, business, organisations
and individual owners and users of cyberspace should assume responsibility and take
reasonable steps to enhance cybersecurity. The principle also requires all stakeholders
to be aware of relevant risks, preventive measures and effective responses to threats.
6.2.2.4
A Multi-stakeholder Approach
Cybersecurity strategies further assume a multi-stakeholder approach. This is a belief
that no country, company or individual can surmount the cybersecurity challenge alone.
Thus, every stakeholder has a role to play in creating a safe environment for all.
6.2.2.5
Risk Management
Cyberspace is never risk free. Therefore, the principle cautions against aiming to prevent
all cyber threats and vulnerabilities from becoming cyber risks. It is costly and often not
required. Instead, cybersecurity strategies should focus on tackling threats most likely to
prevent government agencies and businesses from carrying out critical missions.
39
Obtain a copy of the UK Cybersecurity Strategy here: http://www.official-documents.gov.uk/document/cm76/7642/7642.pdf
38