strategy flowchart expects input from allies and other international partners. Global
harmonisation is important because gaps in national legislation abet cybercrime. As we
see under the international cooperation pillar, the strategy may visualise and support the
adoption of cybercrime conventions at the United Nations. Naturally, every country
should select an approach that best fits its local needs and conditions. We identify the
main aspect of the strategy next.
9.1.1
Government Legal Authority
We have noted that national administrations are accountable for cybersecurity because
cyber attacks threaten national interests in economic, diplomatic and national security
spheres. However, national governments often lack the legal authority to run coherent
national cybersecurity programmes for the following reasons. First, the commercial
sector owns the majority of the critical information infrastructure. Second, cyberspace
blurs the line between normal law enforcement and military operations. Third, global
cooperation on cybercrime requires treaties on extradition and cross-border Internet
searches that may not exist. Therefore, we advise that the legal measures strategy
contains a governance structure to provide the Executive the legal mandate to mobilise
all resources against cyber threats. Whilst local conditions differ, the mandate typically:
9.1.2
Provides the Head of Government the legal authority to create and fund a national
cybersecurity programme;
Defines the legal basis for creating a national Computer Incident Response Team;
Grants powers to shutdown a critical infrastructure asset if at risk of a cyber attack;
Provides the basis for promoting cybersecurity skills, training and awareness;
Defines the legal and operational basis for an integrated and fully coordinated publicprivate sector partnership on cybersecurity;
Fosters innovation in cybersecurity to help develop long-term solutions; and
Grants the government powers to participate in international cooperation, dialogue
and coordination activities focused on cybersecurity such as mutual assistance
Parliamentary Cybersecurity Process
In sub-section 5.3.2, we noted that the legislature plays a crucial role in providing the
Executive the tools to ensure that cyberspace keeps a country secure and prosperous.
Parliament also maintains oversight over national cybersecurity programmes to ensure
that efforts to secure critical information infrastructure do not infringe on national values
such as civil liberties. Parliament further harmonises national legislation with international
conventions and treaties on cybercrime. However, parliaments may lack the requisite
governance structures to handle cybercrime legislation quickly because they typically
work in committees. Thus, different committees have jurisdiction over economic, social,
48
diplomatic and national security matters. Important cybersecurity committees include
information and communications; science; constitutional affairs; judiciary; homeland
security; education and media. The approach often fragments cybersecurity legislative
activities as no single committee may have the powers to provide the Executive the
resources required to defend national cyberspace. We, thus, believe that streamlining
48
Data from the “Fourth Parliamentary Forum on Shaping the Information Society: The Triple Challenge of Cyber-Security:
Information, Citizens and Infrastructure.” Obtain a list of participants at: http://www.ictparliament.org/parliamentaryforum2011
49