The recent Vanuatu Independence Anniversary ‘YUMI40’ theme of ‘Prosperity for Self-Reliance and a Resilient Future,’ allowed the Vanuatu Bureau of Standards (VBS) to introduce the theme of “Tingting Kwaliti, Tingting Standad”. This has enabled Vanuatu to also prioritize the development and adoption of Standards. Such theme displayed the need to drive the usage, application and enforcement of Standards in Vanuatu purposely to improve and contribute to economic benefits. The Vanuatu Bureau of Standards is mandated to promote standardization in industry and commerce; act as a depository for all Standards; prepare draft Standards and to declare them as Vanuatu Standards. Similarly, the Office of the Government Chief Information Officer (OGCIO) and the Telecommunications Radiocommunications Broadcasting Regulators (TRBR) office are also responsible for the development of ICT and Cyber Security Policies, Standards and Regulations. These responsibility places the lead agencies to continually work on developing national standards and regulations that will contribute to the improvement of Telecommunications and ICT services in Vanuatu. Other developments include the recent membership of Vanuatu to the International Organization for Standards (ISO). The Office of the Government Chief Information Officer (OGCIO) and its Cyber Security arm (CERT Vanuatu) in collaboration with the Vanuatu Bureau of Standards have taken the necessary preparatory steps to adopt the ISO 27000 Standards series and precisely the ISO 27001 Standard – Information Security Management Systems (ISMS) Standard. The adoption ISO 27001 Standard will enable OGCIO, CERT Vanuatu and the Vanuatu Bureau of Standards (VBS) to implement measures of the Standard in order to ensure Vanuatu’s Information Security framework are certified and have met an adequate compliance. Implementing a national Cyber Security Standard is crucial to establish a common avenue for all national and international sectors to effectively collaborate with the intention of improving business continuity and effectively sharing information. For example, the current work towards adopting the ISO 27001 Information Security Management System (ISO 27001 ISMS) which will keep information assets secure and protected. The ISO 27001 Information Security Management System Standard permit organizations to manage the security of assets such as financial information, intellectual property, employee details or information entrusted by third parties. Moreover, Cyber Security legal frameworks comprising legislations and regulations are important and compliment Standards. The Strategy aims to allow our Cyber Security lead agencies to work with multiple stakeholders to develop appropriate Cyber Security and ICT regulations. These regulations will ensure the usage of technologies, online platforms, applications, and processes that exist over the Internet are used accordingly and legally and not for a malicious intent. An example is the newly developed ‘Type-Approval’ regulation that require all types of electronic hardware imported into Vanuatu must meet certain requirements. It has allowed better screening of hardware products imported into Vanuatu and it is a step forward to safeguard products imported into Vanuatu. The development and enforcement of necessary legislation, regulations, policies and contracts are important as they provide guiding principles and controls to govern the actions of people and organizations in both the private and public sectors. The proposed Cybercrime Act No. of 2020 and other relevant laws and regulations will help address issues that affect order and good governance. Thus, through the implementation of proper Cybercrime, Data Privacy and Protection laws, and Harmful Digital Communications legislation that allows Vanuatu to:  understand and manage geographical borders and cyber sovereignty, i.e. the issue of no geographical borders in the digital world;  understand and manage the bond that the Internet and connected devices bring to users;  enable the transnational world and realm; and  manage, guide and understand issues and the reach which devices enable communication capabilities. Therefore, in the National Cyber Security Strategy, various legal and policy institutions such as the Ministry of Justice, the office of the State Law (SLO), Prosecution agencies and OGCIO play a vital role in ensuring our laws uphold National Security and ensure offenders or culprits are held accountable for their crimes committed. 41 | Vanuatu’s Cyber Security Strategy 2030

Select target paragraph3