international cooperation and collaboration plays a central role in the National
Cybersecurity Strategy (NCS). An open and free internet, the protection of personal
data as well as the integrity of interconnected networks are critical for overall
prosperity, security and the promotion of human rights in Botswana. This strategy
provides a multi-stakeholder framework for ensuring the safety, security and
reliability of Botswana’s cyberspace.
1.2 Situational Analysis
In 2012 the country carried out cyber security assessment assisted by the
International Telecommunication Union (ITU) and International Multilateral
Partnership Against Cyber Threats (IMPACT) to assess the country’s readiness for
establishing a National Computer Incident Response Team (CIRT), which will assist
in responding to the cyber security threats1. The study found that Botswana has a
well-developed ICT infrastructure with fibre-optic cables linking the major population
centres. In addition the country has international connectivity through WACS,
SEACOM and EASSY undersea cables. The community is well connected with mobile
network covering more than 90% of the population. Internet usage is increasing
throughout the country with many people using the mobile services to access the
Internet, more especially the social media; the country’s mobile broadband
subscription was 1 409,274 as of Dec 2016.
1.2.1
Summary of the Key Findings of the Assessment
i)
Cyber security is not allocated sufficient priority in policy making and on the ongoing ICT projects. Also, Cyber security principles are not adopted by
government in all the projects related to ICT.
ii)
Critical National Information Infrastructure (CNII) has not been identified and
there is no defined cyber security strategy in place to manage and mitigate
cyber security incidents in case of a coordinated cyber-attack on the critical
national information infrastructure. It was recommended that the Country should
develop a National Cyber Security Strategy that will clearly define roles of the
various stakeholders and develop measures and procedures for the protection of
CNII
iii) Appropriate legislation, policies and regulations on cyber security are inadequate
to address the current cyber security challenges.
iv) Training, specifically in the area of cyber security needs to be improved; all
stakeholders such as regulators, Law Enforcement Agencies, Judiciary,
Prosecutors, Service providers, Financial Institutions, service providers need to
have adequate capacity and capability to handle matters related to cyber
security.
1
The Full report of ITU/Impact CIRT Readiness assessment Report can be assessed at
www.bocra.org.bw
9 | Page
National Cybersecurity Strategy