Page 41
2) The measures adopted as per paragraph 1 of this Article shall seek to establish
strong leadership and commitment in all aspects of the cyber security of
institutions and relevant professional bodies in a Member State. To this end,
Member States shall take appropriate measures to:
i.
Establish unambiguous responsibility in matters of cyber security at all levels
of Government and clearly define roles and responsibilities;
ii. Make an unambiguous, public and transparent commitment to cyber security;
iii. Encourage the private sector and solicit its commitment and participation in
government-led initiatives to promote cyber security.
3) Cyber security governance shall be established on the basis of a national
framework capable of responding to perceived challenges and to all issues
relating to information security at national level in the greatest possible number of
cyber security domains.
Article III – 1- 14: Institutional framework
1) Each Member State shall adopt such measures as its deems necessary to
establish appropriate institutions to combat cyber crime, conduct surveillance
in response to cyber crime incidents and early warning, for coordination of
national and cross-border cyber security problems and for global cooperation.
2) Organizational structures may assume any of the following forms: National
Cyber Security Council (NCC), National Cyber Security Authority (NCA) and a
National CERT and/or CSIRT. Each Member State may adapt its structures
for the purpose of introducing “a specific adjustment” depending on their level
of ICT development, availability of resources and of public-private
partnerships.
These structures may exist under other or different
nomenclatures.
3) It is recommended that Member States establish a national liaison centre or a
special organizational entity for the purpose of backstopping a national cyber
security policy and facilitating regional and international cooperation.
Article III – 1 -15: National Cyber Security Council (NCC)
AU Draft0 010111