It is equally important that the application and enforcement of Cyber Security Standards and Legal frameworks provide guidelines, remove barriers and offer opportunities with a Cyber-boundary to secure and protect Vanuatu’s cyberspace, industries, technologies, processes and people (citizens). It also helps build trust and confidence for consumers and businesses when using digital services. For example, applying Standards can help keep user private data and information secure and protected. The CSP-6 priority will be achieved through the following national goals and action plans shown below: Implement and enforce Cyber Security Standards, and relevant standards and regulations. » Create an avenue for suitable Security, ICT and Trade standards, regulations and legislation. » CSP-6 Goal Vanuatu will: Create relevant national policies, strategies, & procedures to accomodate and guide national standards. » Implement & enforce Cyber Standards and Legal Frameworks. e.g. Data Protection & Online Privacy Act. » Collaborate with stakeholders on adopting, & enforcing sectorial Standards, regulations and compliance to various standards and Legal acts » Cyber Standards and Legal Frameworks Vanuatu’s Action Plan: Vanuatu’s Standards and Legal Frameworks Priority Goals:  Develop and implement national policies and strategies to accommodate Cyber Security Standards, regulatory frameworks and other relevant non-Cyber Standards.  Stimulate avenues to encourage the adoption of international Standards, and regulations such as the 27000 Family Series of Standards and specifically the ISO 27001 Information Security Management Systems, ISO 31000 Risk Management Standards,7 and ISO 9001 – Quality Management Systems (QMS) Standards8 .  Encourage dialogues on the need to develop appropriate laws aimed at the cyberspace and relevant areas.  Encourage development of new national Standards, Regulations, and laws in Cyber Security, ICT and the trade and commerce environment. To achieve this goal Vanuatu is empowered to:  Collaborate with stakeholders on adopting, and enforcing sectorial Standards, regulations and compliance to various standards and Legal acts.  Develop and upskill national and regional Cyber Security Capability within Standards and Legal frameworks.  Promote Cyber Security Standards and Regulations Awareness Raising programs and campaigns.  Encourage an increased and improved Quality and Risks Management frameworks to comply with various national and international Standards enforced.  Implement and enforce the Cybercrime Act of Vanuatu.  Develop and implement a Harmful Digital Communications Act of Vanuatu.  Develop and implement a Data Privacy and Protection Act of Vanuatu. 7 ISO 31000 Risk Management Standards provides principles, a framework and a process for managing risk. It can be used by any organization regardless of its size, activity or sector. Using ISO 31000 can help organizations increase the likelihood of achieving objectives, improve the identification of opportunities and threats and effectively allocate and use resources for risk treatment. 8 ISO 9001 Quality Management Systems Standards is the international standard that specifies requirements for a quality management system (QMS). Organizations use the standard to demonstrate the ability to consistently provide products and services that meet customer and regulatory requirements. Vanuatu’s Cyber Security Strategy 2030 | 42

Select target paragraph3