Objectives Activities Timeline Lead Role Medium-Long Term MSTEM, CIRT, Private Sector Medium Term MSTEM, MNS, ODPP, MFAFT, MOJ, CIRT 5. Provide future threats analysis to critical stakeholders and provide information to decision makers to guide the allocation of key assets. 6. Establish a line of communication between the CIRT and law enforcement when cyber incidents are detected for their investigation and conversely to the CIRT whenever a threat is detected by law enforcement. 7. Development of contingency planning methodologies for various sectors especially for critical and essential services. 8. Conduct cyber incident response exercises. A risk based approach is applied in establishing IT and information security standards, policies and guidelines for ICT infrastructure and cyber security governance 1. Assess and research existing IT and Information Security standards for the protection ICT infrastructure. 2. Conduct a national vulnerability assessment and develop and publish standards and guidelines based on the results of the assessment. 3. Implement Government wide IT and Information Security standards, policies and guidelines and monitor and enforce their implementation. 4. Encourage the adoption and implementation of stipulated IT and Information security standards, policies and guidelines by all individuals and institutions. Leveraging regional and international partnerships 1. Conduct a stakeholder mapping exercise and develop a strategic outreach programme for the engagement of regional and international partners. 2. Utilize regional and international cooperation to improve the technical capacity of cyber security professionals within the government and private sector to enhance the capability to respond to cyber threats. 3. Establish mechanisms for secure information sharing with regional and international stakeholders. 4. Pursue areas of collaboration with other CIRTs (regionally and internationally). 35 National Cyber Security Strategy Government of Jamaica

Select target paragraph3