5.2.1.1
Treats Cyberspace as a strategic domain
Promoters of a national cybersecurity strategy (hereafter “strategy”) should consider
highlighting the value of cyberspace to achieving strategic national objectives. One may
note that States devise strategies for land, air, sea and space domains because of their
criticality to achieving national interests. Similarly, one may point out that States require
a strategy for securing cyberspace because of its growing contribution to the delivery of
services essential to daily life, commerce, national security, innovation and the general
29
free flow of information . Therefore, strategies help mitigate the impact of cyber attacks.
5.2.1.2
Basis for a National Programme
Our work has also brought us in touch with parties sceptical of national programmes. For
example, a national leader wondered why his country required a national cybersecurity
strategy when the liberalisation of the telecommunications sector handed responsibility
over to the private sector. Readers may consider answering similar concerns as follows.
One may say that despite liberalisation, governments never cede accountability for
facilitating commerce and protecting the lives and property of their citizens. As such, one
may add that the strategy would help the Government perform its duties to citizens. To
allay Government fears, consider stressing that the Government’s primarily serves as a
facilitator rather than a doer. However, the Government has to lead efforts to define
national cybersecurity goals. The strategy helps initiate a systematic national programme
to defend cyberspace from threat whatever their origin. Critically, the strategy prioritises
cyber threats and risks as well as allocates responsibilities. The national programme
ensures that all relevant stakeholders accept responsibility for and take steps to enhance
cybersecurity. As a result, the strategy improves security as it provides all stakeholders
awareness of relevant risks, preventive measures and effective responses.
5.2.1.3
Strategy Builds Capacity
Lastly, we recommend that promoters of strategies highlight the human and institutional
capacity building impact of an inclusive national cybersecurity strategy. Our proposed
national cybersecurity strategy model is a good example. The model defines ends
(vision), ways (approaches) and means (resources). As we shall see later, cybersecurity
goals could be economic, social and national security. Based on the goals, the ways
identify priorities in terms of the five Pillars of the ITU Global Cybersecurity Agenda. For
example, our strategy model calls for legal measures and organisational structures such
as CIRT. The strategy also caters for information sharing and collaboration due to the
global nature of threats. Therefore, a strategy could yield benefits beyond security.
5.3
WHO: CYBERSECURITY STAKEHOLDERS
We recommend that States involve as many stakeholders as possible in the elaboration
of national cybersecurity strategies. This is because cyberspace increasingly touches all
forms of social, economic and national security activity. Involving a wide group of players
is important for the following practical reasons. First, it helps ensure stakeholder buy-in.
29
Refer to United Nations Resolution 64/211
27