10.1.2.8 Stage 5 – Periodic Compliance Reporting
The cybersecurity focal organisation is accountable for monitoring the effectiveness of
the national cybersecurity framework. Focal organisations often take three approaches to
gathering compliance data. First, the organisation may rely on self-assessment reports
from the relevant stakeholders. Second, the focal organisation may undertake the audits
itself. Lastly, the organisation may require reporting as part of external audits. As ever all
States should choose the approaches that fits local circumstances. The compliance data
may form the basis for an annual national cybersecurity report.
10.2
TECHNICAL MEASURES
We advise States to pursue a united approach to tackling vulnerabilities in hardware and
software products. The ever-increasing sophistication of malware requires that nations
devise coherent strategies for sourcing trusted software and hardware tools to prevent,
detect, deter and recover from cyber attacks. The measures satisfy these GCA Goals:
GCA PILLAR: TECHNICAL AND PROCEDURAL MEASURES
Corresponding
GCA Goal –
Technical
Measures
Goal 5
Goal 7
Development of global strategies for the creation and
endorsement of a generic and universal digital identity
system and the necessary organisational structures to
ensure the recognition of digital credentials across
geographical boundaries.
Proposals on a framework for a global multistakeholder strategy for international cooperation,
dialogue and coordination in all the above-mentioned
areas.
Figure 18 – Technical Measures and related GCA goals
10.2.1
Network Protection Strategy Principles
The technical solutions required depend on the application of cyberspace and the threats
and risks to those activities. Therefore, it is unhelpful to require nations to acquire given
solutions without knowing the local confidentiality, integrity and availability requirements.
Requirements emanate from the system’s operational environment and user needs.
Therefore, we feel providing technology-neutral principles would be more beneficial. The
principles would guide stakeholders in their formulation of technology strategies as well
as during the selection of technical solutions. The principles are as follows:
55