Figure 21 provides a high-level view of the national cybersecurity focal point roles. Let us
briefly explore the numbered processes within the flowchart.
11.2.1
Stage 0 – Relevant Driver
Focal points often grow out of national cybersecurity strategies and similar legislation.
The focal organisation may take several forms. First, the law may create a brand new
organisation to perform the role. Second, the law may designate an existing ministry as
the focal point. Third, the functions in the model may reside with different government
ministries. Lastly, an existing body such as ICT regulator may assume the role.
11.2.2
Stage 1 – Direct and Coordinate Cybersecurity
The focal point coordinates the activities of all cybersecurity stakeholders. Directing and
coordinating ensures that right actions occur at the right time on the right cybersecurity
priorities. The focal point also participates in international cybersecurity activities.
11.2.3
Stage 2 – Strategic and Tactical Cybersecurity Advice
The focal point helps with the strategic and tactical aspects of operating cybersecurity
programmes. First, the organisation explains the purpose of the national cybersecurity as
well as the obligations it places on individual stakeholders. Second, the focal point may
help shape cybersecurity programmes of major stakeholders in public and private
sectors. Third, the focal point may use its influence to promote the adoption of good
practice models. Fourth, focal point may advise on operational aspects of cybersecurity.
11.2.4
Stage 3 – Coordinate Incident Response
The focal point may not have overall technical responsibility for incident management.
However, the focal point often ensures united local and global incident response. It may
also have overall strategic ownership of major incidents. In addition, its strategic and
tactical advice role helps organisations prevent, detect and recover from incidents.
11.2.5
Stage 4 – Training and Public Awareness
The focal point ensures that all stakeholders understand the relevant cyber risks, trends
and effective countermeasures. In terms of training, the focal point could encourage the
development of cybersecurity as follows. First, the organisation may set and/or review
technical training courses for professionals. Second, the focal point may require the
inclusion of given technical security features for example, parent controls. In terms of
public awareness, focal points often lead campaigns to build a culture of cybersecurity.
The campaigns take the form of television, radio and internet advertisements. In addition,
the focal point may evaluate training programmes, prepare materials and train trainers.