personnel (e.g., best practices) safeguards. For example measures may include promoting government and private sector to adopt international standards related to cyber security (e.g., ISO 27001 on Information Security Management System). 4.3.10 Academia Academic institutions will play an important role in the implementation of the national cybersecurity strategy. Academic institutions educate the technical, management and information assurance experts required to execute cyber security strategies. In addition, research and development (R&D) activities, need to be carried out on cybersecurity and the protection of information infrastructures. Through partnerships with the private sector and governments the Academia can assist in the development of cybersecurity related technologies, techniques, standards and processes that further the national cybersecurity agenda. The Academia institutions may also have cybersecurity forensics laboratories which may assist on the investigation and enforcement of cybersecurity legislations 4.3.11 Civil Society Civil society will play an important role in ensuring that there is a right balance in terms of protection civil liberties, privacy and human rights etc. as we implement the national cyber security strategy. The civil society needs to form part of the stakeholders in order to provide confidence and integrity that the national cybersecurity strategy implementation does not tramp on civil liberties. For example monitoring cyberspace has to be done in a manner which does not invade personal privacy. Internationally a number of civil society not-for profit organisations have also been established around the issue of cybersecurity and cybercrime for example those dealing with child online protection (COP). Therefore it is very important that collaboration is established with international civic society to assist also on the consumer education. 4.3.12 Private Sector (Industry) Businesses are expected to implement an adequate level of cyber security safeguards into their business operation and practices. Such safeguards typically involve the installation of technical solutions and the adoption of best practice secure business processes. For example, the financial and banking sector, with its dependency on international clearing and central banking, and its links to international financial market systems, cyber security concerns should be accorded high priority. On a collective level, the private sector has an important role to play in its own right and in cooperation with government in developing cyber security business norms, standards and codes of conduct, as well as in identifying and encouraging the adoption of good practices. By taking part in relevant forums or standards-development 35 | P a g e National Cybersecurity Strategy

Select target paragraph3