10.1.2.2 Purpose of National Cybersecurity Framework Flowchart The flowchart is Figure 17 provides a high-level view of how a country may create an overall cybersecurity governance framework. The flowchart outlines minimum-security measures that all stakeholders must abide by. As we see under Means, the governance framework also serves as the basis for critical activities such as risk management. 10.1.2.3 Stage 0 – Relevant Driver A number of events may drive the formulation of national cybersecurity frameworks. The adoption of national cybersecurity legislation is a typical example. Whatever the origin, national frameworks typically define core security principles and standards that apply to a wide range of stakeholders and thus communicate the security goals. 10.1.2.4 Stage 1 – National Cybersecurity Framework Working Group We underscore the government’s accountability for cybersecurity throughout this Guide. It is no surprise then that we would expect a focal government organisation to create and orchestrate the national cybersecurity framework working Group. We further expect the participation of all organisations that handle and/or use information critical to advancing national interests. Countries may choose to limit the list to organisations responsible for local and national government data including contractors. Working groups also typically enlist the input organisations with technical and information assurance competencies. Lastly, flowchart envisages a possible role for allies and other international partners. 10.1.2.5 Stage 2 – Define Framework Integration Plan We noted in stage 1 that it might be practical to limit the working group’s membership to organisations that handle and process government information. Whatever approach a nation chooses, it is crucial to ensure that all stakeholders have a governance structure similar to the national cybersecurity framework. For example, a State would have major gaps in the implementation of its strategy if the private sector, which owns and operates the critical infrastructure, does not follow any sort of framework. Therefore, this stage ensures that all frameworks coherently support the national cybersecurity strategy goals. 10.1.2.6 Stage 3 – Communicate Cybersecurity Framework This stage calls for the creation of an efficient mechanism for ensuring all stakeholders know about the cybersecurity framework as well as any changes to it. 10.1.2.7 Stage 4 – Cybersecurity Framework Implementation At this stage, all relevant stakeholders must demonstrate compliance with the minimumsecurity requirements. The stage also requires stakeholders to demonstrate compliance with security obligations that apply to specific risk profiles as required by national bodies.

Select target paragraph3