Page 39
1) Each Member State shall make it a point to inculcate a culture of security in all
stakeholders, namely: Governments, enterprises and the civil society, which
develop, possess, manage, operationalize and use information systems and
networks. The culture of security shall place premium on security in information
systems and networks development and on the adoption of new ways of thinking
and behaving during the use of information systems as well as during
communication or transaction across networks.
2) As part of the promotion of a culture of security, Member States may adopt the
following measures: devise a cyber security plan for the systems run by
Government; conduct research and devise security awareness-building
programmes and initiatives for the systems and networks users; encourage the
development of a culture of security in enterprises; foster the engagement of the
civil society; launch a comprehensive and detailed national awareness-raising
programme; strengthen scientific and technological as well as research and
development activities, and raise awareness on cyber threats and available
solutions.
Article III – 1 – 9: Role of Government
Each Member State shall take the lead in the development of a culture of security within
its borders. Member States shall to this end enhance awareness-building, provide
education and training and disseminate information to the public.
Article III – 1 – 10: Public-private partnership
Each Member State shall adopt public-private partnership as a model to engage
industry, civil society and the academia in the promotion and enhancement of a culture
of cyber security.
Article III – 1 – 11: Education and training
Each Member State shall develop capacity building measures with a view to offering
training that covers all areas of cyber security in appropriate government institutions,
and set standards for the private sector. Such training should help to promote
information exchange among experts and security vendors, ICT owners, managers and
users. Member States shall promote technical education for ICT professionals in and
outside government structures through certification and standardization of training;
categorization of professional qualifications as well as development and needs-based
distribution of educational materials.
AU Draft0 010111