14 MEANS – ACTIONS The Means flow from the Ways. The means describe the resources available to achieve the stated ends. The actions we present are not prescriptive. Local conditions should determine the type and order of actions you choose from this list. One should feel free to create new actions. The only condition, of course, is that one does not lose track of the GCA association. National administrations may also use the section to review or improve existing institutions, policies, and relationships addressing cybersecurity issues. 15 PRIORITY 1 – LEGAL MEASURES Actions under this priority focus on the establishment and modernisation of criminal law, procedures, and policy to prevent, deter, respond to, and prosecute cybercrime. 15.1 ACTION 1: LEGAL MEASURES STRATEGY We advise that nations adopt a legal measures strategy to provide common direction and obtain the commitment of all stakeholders. The strategy would allocate resources, coordinate and control all activities aimed at enacting and enforcing a comprehensive set of laws relating to cybersecurity. The strategy also identifies the roles and responsibilities in the creation and modernisation of criminal law, procedures, and policy to prevent, deter, respond to, and prosecute cybercrime. 15.2 ACTION 2: REVIEW ADEQUACY OF LEGISLATION Statutes define roles of parties that fight cybercrime. Thus, countries should establish whether national statutes related to cybercrime, privacy, data protection, commercial law, digital signatures and encryption are adequate. The review should involve as many stakeholders as possible. Typical participants include government departments, intelligence and law enforcement, private firms, civil society, academics and citizens. We recommend that you involve regional and international partners, where practical, because international cooperation is pivotal to confronting the global issue: 15.2.1 Model Cybercrime Legislation If relevant experts and stakeholders determine no sufficient legislation exists, then the country should draft and/or adopt cybercrime legislation. We recommend that you adopt harmonised legislation that is compatible with regional and cybercrime legislation. For example, the ITU Toolkit for Cybercrime Legislation contains sample language that 72

Select target paragraph3