Goals GOAL 1 Develop the necessary organizational structures Policy Statement: Existing organizational structures within the country will be fostered, a National Computer Emergency Response Team (CERT) will be created and a strengthening of the cooperation with regional organizational structures like the PAC CERT will be evaluated. The objectives for Goal 1 are: Objective 1 Create a National Cybersecurity Steering Committee (NCSC) chaired by the DG responsible for ICT. The NCSC will take the overall lead in the coordination of the implementation of the Cybersecurity policy and the process of carrying out the necessary tasks. Objective 2 Identify all existing government and non-government institutions that are currently active in the field of Cybersecurity and fighting Cybercrime. Special attention should be paid to the identification of potential local points of contact in rural areas. Drafting of a report about the mandate, resources and experiences, and analysis of potential areas for synergy, overlapping and gaps. Objective 3 Identify local contact points in rural areas that can facilitate the collection of input about recent developments as well as spreading information to the communities. Within this process public private partnership approaches shall be taken into consideration. Objective 4 Establishment of a National Computer Emergency Response Team (CERT) that is capable of dealing with relevant Cybersecurity threats for citizens, tourists, businesses and government in Vanuatu. The CERT shall also provide computer forensic services within criminal investigations involving computer technology or electronic evidence. In addition the CERT shall be responsible to monitoring developments and ensuring that information about current trends and risks (such as Vanuatu specific phishing attacks or the detection of skimming devices in the country) are communicated through the different channels. Within the development of the national CERT a possible outsourcing of services to regional organizations such as PacCERT should be evaluated. National Cybersecurity Policy — English version 7

Select target paragraph3