This can be difficult to achieve without the incentive of an impending crisis. However, it
will be too late to start establishing those relationships during a crisis. One approach is
to create a network of CERTs (Computer Emergency Response Teams, also referred to as
Computer Incident Response Teams) who routinely share information, suitably
anonymised where necessary. The network of CERTs forms the foundation for a crisis
response capability that can then be linked to the country’s established crisis
management mechanisms, which will already have the vital connections to ministers in
order to secure the necessary authority to act in an emergency.
The national Cybersecurity strategy will need to describe how these mechanisms will be
established and how they will be exercised to test their continuing effectiveness.
Appendix 2 offers an example approach.
4.6.6 Stakeholder collaboration
The stakeholder section of the strategy (covered above) lists national and international
stakeholders and identifies their roles and responsibilities in the delivery of the strategy.
This section on collaboration should identify a focal point to provide strategic direction,
coherence and consistency to inter-governmental collaboration and to facilitate
relationships between non-governmental bodies. It should describe the means by which
those stakeholders interact with each other without the need for explicit detailed
direction from the centre. Collaboration should take place spontaneously, as needed, at
all levels of implementation such as capacity building, R&D, awareness creation and in
particular for operational incident response. The starting point will be informationsharing. Collaboration will develop naturally once the mutual benefit is identified, given
positive encouragement from the national Cybersecurity strategy and recognition from
those in authority.
4.6.7 Research and Development (R&D)
Research and Development plays a critical role in developing capacity for Cybersecurity
and has been identified as one of the key pillars of a number of Cybersecurity strategies.
Cyberspace is developing rapidly and new tools to secure it need to be developed at a
correspondingly rapid pace, creating an acute need for R&D in Cybersecurity. Ways of
encouraging R&D in Cybersecurity are set out in appendix 2.
4.6.8 Monitoring and evaluation
This section should set out the criteria by which progress will be measured and the
method by which the data will be collected. This is a very difficult topic in any delivery
activity because the simplest measurements are often about delivery activity but the act
of measuring inevitably alters the deliverer’s perspective on priorities, sometimes with
unintended and perverse consequences. An alternative approach is measure the outcome
or end state by posing questions to those stakeholders who are intended to benefit, while
accepting that such metrics will be much more subjective.
Page 13 of 33
www.cto.int