Part One
Policy and Strategy Need, Vision, Mission, and Objectives
1.1. The Need for the NCSPS
The NCSPS has been developed as it is deemed important because of the following reasons:
1. As the overall situation and behavior of cyber security has changed with the development
of ICT, we have reached the point where it is progressively challenging to properly
protect the sovereignty and security of a country. Consequently, Ethiopia is cognizant that
it needs an up to date cyber security policy and strategy to protect the security of the
complex, dynamic, unpredictable, and high-tech prone cyber,
to be able to
take
advantage of the enormous opportunities that cyber brings with it, and to mitigate the
risks therein;
2. As cyberspace is gaining a big share in Ethiopia's socio-cultural, political, economic, and
security arena, and creating a tangible influence than ever before, it is important to set
cyber security policy directions and strategies that consider the existing situation;
3. Due to the increased risks, vulnerabilities, and attacks to cyber security as the result of the
expansion and digitalization of key infrastructures and systems by which the country's
information is stored, analyzed, and disseminated;
4. For cyber security by its very nature is not the role and responsibility exclusive to
government, there is a need to increase coordination and partnership between public and
private institutions and other stakeholders;
5. Given the multifaceted potential of the private sector in cyber security as seen in the
realities of the rest of the world and its growing involvement in key infrastructures in our
country, it is necessary to administer the role of the private sector with that of the
government institutions in a reasonable and complementary fashion;
6. Considering the apparent global cyber security threats and vulnerabilities, it is deemed
necessary to know and use the up to date technologies, to establish legal and regulatory
frameworks, to build research and development capacity, to raise awareness; and to state
policy directions and strategies that take into account the existing and imminent cyber
security threats, and to establish a monitoring and evaluation system;
3