This can be difficult to achieve without the incentive of an impending crisis. However, it will be too late to start establishing those relationships during a crisis. One approach is to create a network of CERTs (Computer Emergency Response Teams, also referred to as Computer Incident Response Teams) who routinely share information, suitably anonymised where necessary. The network of CERTs forms the foundation for a crisis response capability that can then be linked to the country’s established crisis management mechanisms, which will already have the vital connections to ministers in order to secure the necessary authority to act in an emergency. The national Cybersecurity strategy will need to describe how these mechanisms will be established and how they will be exercised to test their continuing effectiveness. Appendix 2 offers an example approach. 4.6.6 Stakeholder collaboration The stakeholder section of the strategy (covered above) lists national and international stakeholders and identifies their roles and responsibilities in the delivery of the strategy. This section on collaboration should identify a focal point to provide strategic direction, coherence and consistency to inter-governmental collaboration and to facilitate relationships between non-governmental bodies. It should describe the means by which those stakeholders interact with each other without the need for explicit detailed direction from the centre. Collaboration should take place spontaneously, as needed, at all levels of implementation such as capacity building, R&D, awareness creation and in particular for operational incident response. The starting point will be informationsharing. Collaboration will develop naturally once the mutual benefit is identified, given positive encouragement from the national Cybersecurity strategy and recognition from those in authority. 4.6.7 Research and Development (R&D) Research and Development plays a critical role in developing capacity for Cybersecurity and has been identified as one of the key pillars of a number of Cybersecurity strategies. Cyberspace is developing rapidly and new tools to secure it need to be developed at a correspondingly rapid pace, creating an acute need for R&D in Cybersecurity. Ways of encouraging R&D in Cybersecurity are set out in appendix 2. 4.6.8 Monitoring and evaluation This section should set out the criteria by which progress will be measured and the method by which the data will be collected. This is a very difficult topic in any delivery activity because the simplest measurements are often about delivery activity but the act of measuring inevitably alters the deliverer’s perspective on priorities, sometimes with unintended and perverse consequences. An alternative approach is measure the outcome or end state by posing questions to those stakeholders who are intended to benefit, while accepting that such metrics will be much more subjective. Page 13 of 33 www.cto.int

Select target paragraph3