capacity amongst researchers and information security professionals The medium term will focus on following policy thrust: Culture of Cyber Security & Capacity Building - Implement Action 1 Research & Development towards Self–Reliance - Implement Actions 1 - 2 and accompanying infrastructure Compliance and enforcement - Implement Action 1 and accompanying infrastructure Legislative and Regulatory Framework Long Term Year 5+ Implement Action 1 Developing selfself-reliance - in terms of technology as well as professionals, monitoring the mechanisms for compliance, evaluating and improving the mechanisms and creating the culture of cyber security The long term strategy will focus on following policy thrust: Cyber Security Technology Framework - Continuous review and improvement Compliance & Enforcement - Enforcing adopted Risk Management framework within CNII for compliance Culture of cyber security - ii. Continuous awareness creation Specific Initiatives Details of Specific initiatives including strategic objectives, estimated cost and drivers are attached in the appendix. 36 | P a g e National Cyber Security Policy & Strategy

Select target paragraph3