QATAR NATIONAL CYBER SECURITY STRATEGY 5. IMPLEMENTATION APPROACH Successful implementation of the NCSS requires continuous commitment, governance, and action by various stakeholders who are collectively responsible for the national approach to cyber security. These stakeholders are connected by a shared set of guiding principles that support Qatar’s cyber security vision. 5.1 Guiding Principles Qatar’s approach to cyber security is based on the following three principles: The Government Will Lead the Way. Governments have an important responsibility to safeguard government information, systems, and networks and ensure their confidentiality, integrity, and availability. The Qatari government will therefore lead by example, implementing cyber security requirements while building and adopting innovative and new technologies that provide the foundation for the economy. Cyber Security Is a Shared Responsibility. Cyber security should be the responsibility of all government entities, businesses, institutions, and individuals. §§The Qatari government is responsible for protecting its information, systems, and networks; investing in the people, processes, and technologies necessary to safeguard the services that society relies on; and setting the direction for Qatar’s continued economic development and growth. §§Businesses are responsible for protecting their information, systems, and networks from cyber threats; sharing information; and responding should cyber incidents and attacks occur. §§Individuals are responsible for being aware of threats; adopting best practices; understanding who is collecting their personal information; and securing their own information, systems, and networks. Fundamental Rights and Values will be Preserved. In cyberspace, security and privacy are tightly intertwined. Strong security measures and sound best practices are encouraged to protect personal or private information from unauthorized access or misuse. Qatar will pursue cyber security policies and initiatives that preserve society’s values and expectations, consistent with laws and regulations. VALUES IN CYBER SECURITY §§Protect government, businesses, institutions, and individuals from unacceptable online content and behaviors; §§Show tolerance and respect; §§Embrace innovation and the free flow of ideas and information; §§Suppor t collective and collaborative efforts to address complex cyber security challenges; and §§Promote an environment that rewards investment in security and technology. 5.2 Governance Strong governance is needed to implement and manage execution of the NCSS. To that end, Qatar will establish the Cyber Security Coordination Office (CSCO), which will report to the Prime Minister and be the focal point for cyber security activity across Qatar. The CSCO will be responsible for: (1) establishing priorities to promote the highest level of cyber security in Qatar, (2) providing strategic direction for Qatar’s cyber security efforts, and (3) working in close partnership with organizations with cyber security missions and mandates to fulfill the objectives of the NCSS. 17

Select target paragraph3