Overall, the hierarchy must be designed and developed in a thoughtful philosophical manner to cover
all levels of Cyber and Information Security (IS). It is only through such development that proper
incident response operations are able to address cyber-threats, attacks and issues. This is made
easy by establishing a clear incident response mitigation plan and an incident response recovery plan.
Furthermore it also provides the ability to further understand and identify cyber-threats that can aid
effective decisions based on the structure established through the hierarchy.
3.6 The National Cyber Security Maturity Model
A national economy values critical assessment mechanisms to stay healthy and in moving forward to
building a stronger vibrant economy as well as a strong cyber security framework. In cyber security,
maturity model assessments and certifications are a form of assessing the National Security status
of a country. An ideal cyber security maturity model offers an accelerative pathway which enables
Vanuatu to periodically assess where it is within the term of this cyber security strategy plan. The
maturity model has been a valuable tool for improving cyber security efforts that are outlined in this
strategy, as well as communicating and obtaining the necessary support from upper management,
boards, and Council of Ministers (COM). As part of the Vanuatu National Sustainable Development Plan
(NSDP) goals and objectives which is echoed in ‘Pillar 5’ of the National Security Strategy of Vanuatu
states that ‘Cyber Security’ is a priority. Thus, the maturity model helps maintain efforts in aligning and
achieving the broader National Security goals.
The Capability Maturity Model Integration (CMMI) framework is an example of a well-known process
measuring and improvement meta-framework that helps organizations measure their processes’
effectiveness [9]. It also helps identify how to improve these processes over-time.
CMMI has five maturity levels, which follow the original guidelines of Capability Maturity Model (CMM)
[9]. These levels are:
1. Initial: Processes are somewhat ad hoc and undefined aside from localised documentation.
2. Managed: Processes are managed in accordance with agreed metrics, but there is no focus on
assessing efficacy or gathering feedback and while processes are followed there is no notion of
their success. Processes are not consistent across the business.
3. Defined: Processes are well-defined and acknowledged as standard business processes, and
are broken down into more detailed procedures, work instructions and registers (artefacts) used
to record process outputs.
4. Quantitatively Managed: Metrics are gathered from each process and are fed back to a
process governance committee who analyze and report on process efficacy.
5. Optimizing: Process management includes a focus on disciplined optimization and continual
process improvement, and a full team of business analysts who measure and assess every
aspect of the business for possible issues and improvement opportunities.
Based on the CMMI 5 levels of maturity, a similar approach was adopted and executed by Vanuatu in
2019. This CMM assessment was conducted by the Oceania Cyber Security Centre (OCSC) [10] and
the International Telecommunication Union (ITU) [11] in partnership with the Government of Vanuatu
through CERT Vanuatu and the Office of the Government Chief Information Officer (OGCIO). The
maturity assessment has paved a pathway to prioritize cyber security as a national objective for
Vanuatu.
The CMM assessment utilized the Global Cyber Security Capacity Centre’s (GCSCC) cybersecurity
Capacity Maturity Model (CMM), which defined the five (5) dimensions of cybersecurity capacity:
1.
2.
3.
4.
5.
Cybersecurity Policy and Strategy;
Cyber Culture and Society;
Cybersecurity Education, Training and Skills;
Legal and Regulatory Frameworks; and
Standards, Organizations and Technologies.
These maturity model dimensions are seen as reasonable essential cyber security indicators required
to address Vanuatu’s current cyber security status whereby, the Vanuatu’s National Security and
sovereignty is improved, strengthened, secured and protected. These indicators are the basis of the
Vanuatu’s Cyber Security Strategy 2030 |
14