• • Practicable. Optimise for adoption by the largest possible group of critical assets and realistic implementation across the broadest range of critical sectors. Globally relevant. Integrate international standards to the maximum extent possible, keeping the goal of harmonization in mind wherever possible. In particular, in order to focus its investment effectively, the strategy must be informed by the prevailing risks, which will likely change during the period of the strategy’s delivery. It is important that the strategy can be reprioritised as circumstances change. 4.3 Vision and strategic goals section Framed by the principles set out above, the national Cybersecurity strategy should set a clear direction to establish and improve Cybersecurity for government, academia, consumers and service-providers who serve those communities. This will be expressed as a set of strategic goals. Examples, from a range of sources in appendix 3, include: • • • • • • • • Promote economic development. Providing a safe environment for users of Cyberspace engenders a level of trust among international business community to develop, with confidence, trade relations with such countries. In the long run, this contributes towards the economic development of the country; Provide national leadership. This demonstrates a strong commitment of government to work with and bring cohesion to the necessary stakeholders in addressing Cybersecurity; Tackle Cybercrime. For many countries, this is a priority, to reduce the corrosive and pernicious effects of on-line crime; Strengthen the critical infrastructure. Identifying the scale, scope and approach to securing the country’s critical national infrastructure; Raise and maintain awareness. One major challenge facing national economies in addressing the subject of Cybersecurity is the low knowledge levels of users in Cyberspace. With improved awareness, Cyberhygiene improves; Achieve shared responsibility. Citizens and Austria has declared a goal of using businesses have a responsibility, with their “self-regulation” to encourage the service providers, for their own security. The private sector to set its own detailed owners of ICT networks bear the standards on Cybersecurity whilst the responsibility, with their suppliers, of putting state creates the necessary overarching the necessary measures in place to secure regulatory framework. their own systems; Defend the value of Human Rights. It is important to achieve the right balance between national security objectives and citizens’ right to freedom of expression, to privacy and access to information. Countries that want to address concerns about inappropriate use of social media will want to avoid introducing disproportionate internet censorship; Develop national and international partnerships. A key component in delivering security in Cyberspace is the collaboration within and beyond national boundaries. This covers national and international initiatives; Page 8 of 33 www.cto.int

Select target paragraph3