16
PRIORITY 2 – TECHNICAL AND
PROCEDURAL MEASURES
Actions under this priority address help create a generic and universal digital identity
system and the necessary organisational structures to recognise digital credentials
across jurisdictions through the following actions:
16.1
PROCEDURAL MEASURES
Countries should consider the following actions under this priority/pillar:
16.1.1
Action 1: National Cybersecurity Framework
A Cybersecurity Framework implements the vision outlined in the Cybersecurity strategy.
The Framework is a standards-based but flexible model for establishing, implementing,
operating, monitoring, reviewing, maintaining and improving Cybersecurity Programmes.
The Framework outlines minimum-security measures that stakeholders must abide by to
claim compliance with national cybersecurity requirements. Cognisant that cybersecurity
is a global issue, this Guide defines a Framework modelled on ISO/IEC 27000 Series,
the most widely recognised Information Security Management System (ISMS).
16.1.2
Cybersecurity Goals
The eleven ISO/IEC 27002 security control clauses are a natural model for security goals
because organisations that implement these clauses are on the way to meeting ISO/IEC
27001 requirements. This Guide adapts the control clauses to define four model security
goals for the consideration of national administrations. The goals are not security policies
for direct application by departments and agencies. Instead, the security goals define the
minimum or mandatory security requirements. We provide an example below:
16.1.2.1 Goal 1: Governance and Risk Management
Objective: Effective security results from a good governance structure as well as the
selection of security controls based on sound risk management principles.
16.1.2.1.1 Governance
This sub-goal coincides with the ISO/IEC 27002 “Organising Information Security”
security control clause. The clause calls for the creation of a management framework to
initiate and control the implementation of security within an organisation. This Guide
recommends that the organisation serves as the focal point for all activities dealing with
75