5.2 The Strategy Consultation Execution Methodology Phase 2 Phase 1 Cyber Security Assessment CMM Review Report NCSS Concept Alignment to NSDP, NSS & other National Frameworks NCSS 1-to-1 Consultations Design Review Development Assessment: Past ICT / Cyber Security Reports Tangible Outputs Cyber Security Priorities NCSS Translations & Printing NCSS 2030 Strategy Framework Launching NCSS Overview National-wide Consultations with Stakeholders NCSS Drafting: Draft-1 Information Gathering Key Ideas Phase 3 NCSS Document Approval and Signing Cyber Security Strategy Response Information Processing National Cyber Security Execution Plan and Procedures Information Reporting Objective Figure 7: Cyber Security Development Timeline with critical phases The development of the Strategy required numerous methodologies to ensure all cyber security components are captured. This meant that a careful assessment on existing cyber security infrastructure, capacity capability, the cyber-threat landscape and the broader government policies and strategies are carried out. It also meant that including crucial security components for this strategy will cater for, and provide top-level priority needs that will go in line with both the National Security Strategy and the National Sustainable Development Plan of 2030. As a result, it will achieve various important national goals and objectives in the cyberspace and Information and Communications Technology (ICT) realm. The strategy pathway requires that all cyber security and critical infrastructure stakeholders were consulted to capture and determine current cyber security needs, risks, issues and challenges that hinder business continuity and processes. Addressing the challenges and issues aids the implementation of this strategy in achieving and maximising economic benefits. The National Cyber Security Strategy is designed to enable all government agencies, statutory bodies, non-government organizations (NGOs), private sector and the civil society to execute various plans as well as identify and follow a relevant effective strategical cyber security framework for Vanuatu. Hence, the strategy consultation outcomes are aimed at achieving the following:  Provide primary guidelines for all cyber security infrastructure implementation in Vanuatu;  Build on the National Cybersecurity Policy and the National Security strategy to formulate key government policies and essential services with cyber security requirements – i.e., build government or business operations around cyber security and by developing a cyber-security culture;  Implement proper cyber security frameworks to secure and protect all citizens and international visitors accessing Internet, technology services and other essential services in Vanuatu; and  Provide for, and guide the sharing, access and dissemination of information in Vanuatu and across international borders. This requires the adoption and enforcement of various information security best practises such as the ‘Information Sharing’ and ‘Traffic Light Protocol (TLP)2.’ 5.3 The Strategy Consultation Coverage and Demography The National Cyber Security Strategy consultation procedure has utilized two primary methods and covers in total an approximately 10,946 attendees who are from all sectors. These 3 consultation methods are: 2 The Traffic Light Protocol (TLP) is a set of designations used to ensure that sensitive information is shared with the appropriate audience. Vanuatu’s Cyber Security Strategy 2030 | 26

Select target paragraph3