Part Two Focus Areas and Strategies 2.1. Policy Issues It is becoming a challenging issue to maintain the sovereignty of states in the cyber world. Especially, in cyberspace that has a global nature, the cyber sovereignty of a state which has not built a competent capability will be under question in one way or another. This happens because of the reason that the leading states in cyber technology do not easily transfer the technology to other states and for the reason that the technology creates a convenient environment to put other states under their influence. As a result of this, those states which are lagging in technology will highly be vulnerable. On the other hand, as avoiding the cyber world is not an option, countries have become part of this globalization. Thus, in addition to building the technological capability in the area, countries strive to ensure cyber security through establishing a regulatory mechanism. The fact that Ethiopia is a developing country cannot immune it from the vulnerability that comes with cyber and cyber technology. Hence, it needs to set in place a regulatory mechanism in addition to advancing its cyber defense capability by arming itself with cyber security technology internally through research and development schemes or procurement. In this process, it needs to build a knowledge-based system by understanding the paradoxes in the cyber world. Therefore, considering the global and national cyber security reality on the ground, major policy issues have been identified. Accordingly, the NCSPS comprises seven major policy focus areas. These are Legal and Regulatory Framework, Awareness, Capacity Building, Research and Development, Digital Identity and Personal Data Protection, Key Information Infrastructure Protection, and International and National Cooperation. 2.2. Legal and Regulatory Framework 2.1.1. Policy Statement It is important to develop and implement up-to-date legal and regulatory frameworks that are consistent with the reality on the ground to reduce the progressively increasing cyber security vulnerability and threat, defend against attacks, and hold perpetrators accountable. 7

Select target paragraph3