4.5 Stakeholder section The delivery of these objectives will involve a wide range of stakeholders, who should be identified in this section of the national Cybersecurity strategy. The majority of the technical infrastructure that comprises Cyberspace is designed, built, owned and operated by the private sector. These companies are often multi-national with complex international supply chains. The threats posed by Cybersecurity transcend national borders and call for strong coordination mechanisms nationally, regionally and internationally and across “The Government of the sectors. In constructing the list of stakeholders, a wide Republic of Trinidad and Tobago (GoRTT) will partner with the range of constituencies should be considered, private sector and civil society in including policy makers, officials from across most the implementation of its cyber government departments, specific agencies, private security strategy” sector representatives from many industries, civil society, academics, international bodies and possibly other countries. Appendix 2 offers a list of potential stakeholders to consider. 4.6 Strategy implementation section Having set out the high-level objectives and identified the stakeholders, this section should describe how the work is divided into manageable components. The following headings are illustrative and the structure of each country’s strategy must reflect the country’s needs, existing structures and immediate risk-based priorities for action. 4.6.1 Governance and management structure Implementation requires a governance and management structure that brings together all stakeholders and harnesses each stakeholder’s strengths and competencies. An effective strategy will most likely depend on innovative and spontaneous collaboration between stakeholders, without calling for the direct involvement of the management structure. Nevertheless lines of authority and reporting should be clear and unambiguous. To achieve both outcomes, it may be helpful to construct a table of stakeholders that records the individuals who are responsible, accountable, consulted and informed about the major topics of the strategy 2. It may require some debate to determine this structure. Once finalised, it should be recorded in the strategy document. Appendix 5 offers an example of a RACI table. 4.6.2 Legal and regulatory framework The legal and regulatory framework is a foundation to any national strategy, particularly for law enforcement activities, and must remain under continuous review in order to be effective and to reflect the contemporary risks and opportunities of the rapid evolution of Cyberspace. In this section, the national Cybersecurity strategy should describe how this will be achieved and set targets to: • Review existing frameworks and develop new ones to remain up-to-date with current technological developments; 2 Responsible, Accountable, Consulted and Informed: the so-called RACI table. For more on this approach, see http://en.wikipedia.org/wiki/Responsibility_assignment_matrix Page 11 of 33 www.cto.int

Select target paragraph3