have the responsibility for designing and implementing cyber security programs in
consistence with this NCSPS and international standards.
3.4. Monitoring and Evaluation
To measure the effectiveness of the NCSPS at all levels and to realize the execution process,
a monitoring and evaluation system which includes the following key issues will be in place:
1. An action plan for the implementation of the policy and strategy will be prepared by
INSA; the Cyber Security Council will play its role in the implementation.
2. A monitoring and evaluation system shall be established to ensure that public and
private institutions and other stakeholders carry out the relevant activities specified in
the NCSPS, perform activities listed in NCSP implementation frameworks, establish
the necessary institutional structure, and allocate the required budget and resources;
3. For the implementation of NCSPS, data collection, organization, and analysis
activities will be carried out and a reporting system will be established with
coordination of INSA;
4. An annual stakeholders meeting will be organized by INSA to evaluate the
implementation of the NCSPS;
5. Based on the results of NCSPS monitoring and evaluation, directions to develop other
necessary frameworks and, if need be, to revise the NCSPS will be given.
3.5. Legal Issues
1. This NCSPS shall be implemented upon approval by the House of Representatives;
2. The NCSPS shall legally be binding on all parties directly or indirectly referred to in
this document;
3. Legislation may be enacted to hold those who fail to implement this NCSPS
accountable;
3.6. Financial Issues
1. The budget required to implement the NCSPS and to carry out other related activities
shall mainly be allocated by the government;
2. The budget allocated for the implementation of the NCSPS shall be run following the
monitoring and evaluation system set in the policy and strategy and by the decision of
the body endowed with a legal responsibility to oversee the NCSPS.
24