These include the following:
•
The development and implementation of appropriate legal framework, with
initiatives that will allow for the identification and prosecution of cybercrimes that
impact Nigeria regardless of whether they originate within Nigeria or are
launched from outside of the country. It encompasses training the judiciary,
security and law enforcement agencies, seeking international co-operation,
public and private sector co-operation and public awareness programmes. It
also introduces a special focus on data protection, privacy and lawful
interception.
•
Establishment of a National Incidents Management Strategy which outlines the
commissioning of a National Computer Emergency Response Team (CERT)
and introduces the roadmap for implementing Detective, Preventative and
Response capabilities to deal with cybercrime activities.
•
The strategy for Protecting Critical information Infrastructures including shared
responsibility between government and owner operators of critical infrastructure.
It also highlights the ways in which early warning, detection, reaction and crisis
management will be assessed, developed and implemented to provide a
proactive readiness to react to and deal with threats towards Nigeria’s Critical
Infrastructures.
•
The strategy seeks to ensure the development of information security assurance
and monitoring plan. It includes a new national mechanism on cybersecurity
assurance, adoption of fit for purpose standards for Governance, Risk and
Control,
Core
Assurance
Capabilities,
National
Enterprise
Architecture
Framework. It also endorses the adoption of application security testing as well
as the adoption of a Balanced Scorecard Framework for cybersecurity.
•
The introduction of a sustainable strategy to develop, maintain and ensure
Nigerians are informed and equipped to deal with cybersecurity events by
establishing a mechanism for Cybersecurity Skill and Manpower Development
initiatives. These initiatives will be driven through public-private partnership. It
introduces a model for certification of individuals to ensure quality of
competence in the field of cybersecurity relevant to the nation.