Overall, the hierarchy must be designed and developed in a thoughtful philosophical manner to cover all levels of Cyber and Information Security (IS). It is only through such development that proper incident response operations are able to address cyber-threats, attacks and issues. This is made easy by establishing a clear incident response mitigation plan and an incident response recovery plan. Furthermore it also provides the ability to further understand and identify cyber-threats that can aid effective decisions based on the structure established through the hierarchy. 3.6 The National Cyber Security Maturity Model A national economy values critical assessment mechanisms to stay healthy and in moving forward to building a stronger vibrant economy as well as a strong cyber security framework. In cyber security, maturity model assessments and certifications are a form of assessing the National Security status of a country. An ideal cyber security maturity model offers an accelerative pathway which enables Vanuatu to periodically assess where it is within the term of this cyber security strategy plan. The maturity model has been a valuable tool for improving cyber security efforts that are outlined in this strategy, as well as communicating and obtaining the necessary support from upper management, boards, and Council of Ministers (COM). As part of the Vanuatu National Sustainable Development Plan (NSDP) goals and objectives which is echoed in ‘Pillar 5’ of the National Security Strategy of Vanuatu states that ‘Cyber Security’ is a priority. Thus, the maturity model helps maintain efforts in aligning and achieving the broader National Security goals. The Capability Maturity Model Integration (CMMI) framework is an example of a well-known process measuring and improvement meta-framework that helps organizations measure their processes’ effectiveness [9]. It also helps identify how to improve these processes over-time. CMMI has five maturity levels, which follow the original guidelines of Capability Maturity Model (CMM) [9]. These levels are: 1. Initial: Processes are somewhat ad hoc and undefined aside from localised documentation. 2. Managed: Processes are managed in accordance with agreed metrics, but there is no focus on assessing efficacy or gathering feedback and while processes are followed there is no notion of their success. Processes are not consistent across the business. 3. Defined: Processes are well-defined and acknowledged as standard business processes, and are broken down into more detailed procedures, work instructions and registers (artefacts) used to record process outputs. 4. Quantitatively Managed: Metrics are gathered from each process and are fed back to a process governance committee who analyze and report on process efficacy. 5. Optimizing: Process management includes a focus on disciplined optimization and continual process improvement, and a full team of business analysts who measure and assess every aspect of the business for possible issues and improvement opportunities. Based on the CMMI 5 levels of maturity, a similar approach was adopted and executed by Vanuatu in 2019. This CMM assessment was conducted by the Oceania Cyber Security Centre (OCSC) [10] and the International Telecommunication Union (ITU) [11] in partnership with the Government of Vanuatu through CERT Vanuatu and the Office of the Government Chief Information Officer (OGCIO). The maturity assessment has paved a pathway to prioritize cyber security as a national objective for Vanuatu. The CMM assessment utilized the Global Cyber Security Capacity Centre’s (GCSCC) cybersecurity Capacity Maturity Model (CMM), which defined the five (5) dimensions of cybersecurity capacity: 1. 2. 3. 4. 5. Cybersecurity Policy and Strategy; Cyber Culture and Society; Cybersecurity Education, Training and Skills; Legal and Regulatory Frameworks; and Standards, Organizations and Technologies. These maturity model dimensions are seen as reasonable essential cyber security indicators required to address Vanuatu’s current cyber security status whereby, the Vanuatu’s National Security and sovereignty is improved, strengthened, secured and protected. These indicators are the basis of the Vanuatu’s Cyber Security Strategy 2030 | 14

Select target paragraph3