4 implementation with regards to the compliance framework of Cyber Security policy needs to be constantly monitored, assessed, and improved. For that matter, a holistic approach and appropriate legal and technical structures could help to identify the potential threats and consequences attached thereto, and properly it could investigate and no weak area be left to be exploited by the wrongdoers. 1.3.3 Enforcement of Required Structures and Processes The assurance of Cyber Security requires proper structures and processes for governance, regulation, implementation, and enforcement. Any absence or weakness of the regulation structures poses a threat to Cyber Security. i. Inadequate and Poor Quality of Resources Cyber Security is a rapidly growing field that requires a continually updated set of relevant skills and resources as the inadequacy of the required skills shall lead to weaknesses in Cyber Security. Moreover, bridging the demand and supply gap in the digital workforce is an emerging challenge. The absence of a mechanism for ensuring the quantity and quality of these skills and resources is a threat to the Cyber Security of the country. ii. Lack of Data Governance Countries face the threat of data colonization whereby data is managed, controlled, and processed out of the legal jurisdiction of the country and there is limited or no bilateral agreement among the stakeholders in this regard. Threat actors are liable to pollute the information domain and citizen data may be sold to third parties without due consent or validation. Such proliferation and abuse of data lead to the exploitation of selected segments of society. Weak governance of data, poor data quality, and absence of data stewardship generate unreliable information resources and poses a threat to Cyber Security. iii. Reliance on External Resources With the increasing use of information technology in all domains including operations technology, critical information assets are likely to be exposed to cyber-attacks. In absence of adequate local resources, reliance on external National Cyber Security Policy 2021

Select target paragraph3