 A programme to share lessons learned from cybercrime and attacks. 4. REDUCING CYBERSECURITY THREATS AND VULNERABILITIES 4.1 In recognition of the challenges that cybersecurity presents for ICT, the ITU has been mandated to develop guidelines and strategies to assist member states with putting in place measures to deal with these issues. 4.2 Threats to Critical Information Infrastructure (CII) can be either intentional or unintentional targeted or non-targeted, and can originate from sources such as dissatisfied employees, criminals, hackers, virus writers, competitors or even espionage operatives. The unavailability of Critical Information Infrastructure (CII) can impact South Africa in terms on its social, economic and national security needs, and this can vary from negligible to severe with potential for serious social, economic and even national security implications. South Africa therefore needs to develop regulations and strategies to identify and protect CII. 4.3 The need for a vigilant approach to information security through continuous mapping, assessing and forecasting of threats and vulnerabilities has been demonstrated by cyber attacks on some critical information infrastructure of some countries. It is imperative that requisite interventions are put in place to ensure South African cyberspace is always secure. 4.4 In order to ensure reduction of cybersecurity threats and vulnerabilities, this policy provides for the:  Minister of Communications develop regulations to ensure the protection and identification of CII.  Development strategies and plans to ensure the identification and protection of CII.  Development of measures to prevent and combat cyber crime through reviewing of relevant legislation for improved security, intelligence gathering, detection of cyber crime, law enforcement, reporting of crime, investigation, digital forensics, prosecution, adjudication and conviction. 5. COORDINATED LOCAL AND INTERNATIONAL PARTNERSHIPS The fight against cyber threats and crime requires a partnership between citizen, business and government. However given the borderless nature of cyberspace, national efforts are not always adequate. This policy seeks to: 11

Select target paragraph3