A/RES/64/211
Stakeholder roles and responsibilities
5.
Determine key stakeholders with a role in cybersecurity and critical
information infrastructure protection and describe the role of each in the
development of relevant policies and operations, including:
•
National Government ministries or agencies, noting primary points of contact
and responsibilities of each;
•
Other government (local and regional) participants;
•
Non-governmental actors, including industry, civil society and academia;
•
Individual citizens, noting whether average users of the Internet have access to
basic training in avoiding threats online and whether there is a national
awareness-raising campaign regarding cybersecurity.
Policy processes and participation
6.
Identify formal and informal venues that currently exist for Governmentindustry collaboration in the development of cybersecurity and critical information
infrastructure protection policy and operations; determine participants, role(s) and
objectives, methods for obtaining and addressing input, and adequacy in achieving
relevant cybersecurity and critical information infrastructure protection goals.
7.
Identify other forums or structures that may be needed to integrate the
government and non-government perspectives and knowledge necessary to realize
national cybersecurity and critical information infrastructure protection goals.
Public-private cooperation
8.
Collect all actions taken and plans to develop collaboration between
government and the private sector, including any arrangements for informationsharing and incident management.
9.
Collect all current and planned initiatives to promote shared interests and
address common challenges among both critical infrastructure participants and
private-sector actors mutually dependent on the same interconnected critical
infrastructure.
Incident management and recovery
10. Identify the Government agency that serves as the coordinator for incident
management, including capability for watch, warning, response and recovery
functions; the cooperating Government agencies; non-governmental cooperating
participants, including industry and other partners; and any arrangements in place
for cooperation and trusted information-sharing.
11. Separately, identify national-level computer incident response capacity,
including any computer incident response team with national responsibilities and its
roles and responsibilities, including existing tools and procedures for the protection
of Government computer networks, and existing tools and procedures for the
dissemination of incident-management information.
12. Identify networks and processes of international cooperation that may enhance
incident response and contingency planning, identifying partners and arrangements
for bilateral and multilateral cooperation, where appropriate.
4