12.2 JUDICIAL CAPACITY The judiciary enforces cybersecurity legal measures. However, the judiciary often lacks the skills required to prosecute criminal electronic investigations. Thus, we recommend that the cybersecurity strategy addresses the need to improve judicial capacity against cybercrime. Strategists should build capacity to enable judges and prosecutors to gain a reasonable understanding of computers, software, networks and electronic evidence. In the short-term, countries may consider instituting training courses. In the long-term, it is important to modify curricula to ensure that lawyers and prosecutors obtain grounding in computer-enabled crime. The judiciary requires training in methods of handling electronic evidence to ensure that it preserves its evidential weight and thus admissibility in Court. 12.3 NATIONAL CULTURE OF CYBERSECURITY National governments have ultimate responsibility for leading a systematic effort to bring about a cybersecurity culture in collaboration with other relevant stakeholders. A culture of security aligns with the sixth GCA Strategic goal that deals with capacity building mechanisms to raise awareness, transfer knowledge and boost cybersecurity on the national policy agenda. The United Nations General Assembly (UNGA) has also encouraged the promotion, development and implementation of a robust global culture of cybersecurity because confidence and security in the use of ICTs are among the main pillars of the information society (UN 2010). 12.4 CYBERSECURITY INNOVATION Cyberspace will underpin the prosperity of the global economy, government services and national security for many years to come. To build capability to secure cyberspace from attacks as well as exploit its potential in an internationally compatible way, countries should develop long-term strategies for enhancing knowledge and fostering innovation across sectors. For example, PP-10 Resolution 130 identifies the need for continual evolution in new technologies to support the early detection of, and coordinated and timely response to, events or incidents compromising computer security. 69

Select target paragraph3