lagen.nu
Building Effective Governance Frameworks for the Implementation of National Cybersecurity Strategies

Building Effective Governance Frameworks for the Implementation of National Cybersecurity Strategies

Utgivare
Europeiska unionens cybersäkerhetsbyrå
Antagen
2023-02-28
Språk
engelska
Ämnesord
State of cybersecurity in the EU, National Cybersecurity Strategies
Källa
www.enisa.europa.eu
Endast på engelskaEuropeiska unionens cybersäkerhetsbyrå har inte publicerat någon svensk version av detta dokument. Texten nedan återges på engelska, så som den publicerats av Europeiska unionens cybersäkerhetsbyrå.
FEBRUARY 2023 GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

ABOUT ENISA

The European Union Agency for Cybersecurity, ENISA, is the Union’s agency dedicated to achieving a high common level of cybersecurity across Europe. Established in 2004 and strengthened by the EU Cybersecurity Act, the European Union Agency for Cybersecurity contributes to EU cyber policy, enhances the trustworthiness of ICT products, services and processes with cybersecurity certification schemes cooperates with Member States and EU bodies, and helps Europe prepare for the cyber challenges of tomorrow. Through knowledge sharing, capacity building and awareness raising, the Agency works together with its key stakeholders to strengthen trust in the connected economy, boost the resilience of the Union’s infrastructure, and, ultimately, keep Europe’s society and citizens digitally secure. More information about ENISA and its work can be found here: www.enisa.europa.eu. CONTACT For contacting the authors, please use ehealthSecurity@enisa.europa.eu For media enquiries about this paper, please use press@enisa.europa.eu. AUTHORS Anna Sarri, Gema Fernández Bascuñana (ENISA) Ann-Kristin Gross, Federico Chiarelli, Marina Preasca (Wavestone) ACKNOWLEDGEMENTS ENISA would like to thank and acknowledge all the experts that took part and provided valuable input for this report and especially the following, in alphabetical order: Andrés Jesus Ruiz Vazquez (Spain); Center for Cyber Security (Denmark), Chief Advisor; Centre for Cybersecurity (Belgium); Croatian National Security Authority, Senior Advisor, Vinko Kuculo; Cyber Security Coordination and Policy Department (the Netherlands), Gijs Peeters; Cyber Security Coordination and Policy Department (the Netherlands), Pieter van den Berg; Department for Secure Communication, Senior Advisor and Sweden’s Liaison Officer to ENISA (Sweden), Peter Wallström; Department of Environment, Climate & Communications, Staff Engineer, Cyber Security & Internet Policy Division (Ireland), James Caffrey; Digital Security Authority of Cyprus, Technical Officer, Costas Efthymiou; Digital Security Authority of Cyprus, Technical Officer, Giorgos Loninos; Federal Chancellery, Department I/8 – Cyber Security, GovCERT, NIS-Office and ZAS (Austria), Deputy Head, Christian Zec; Federal Ministry of the Interior (Germany), Sascha-Alexander Lettgen; International Server Security Authority (Greece), Head of Competent Department for Cyber Security Strategic Planning, Emmanouil Patsourakis; International Server Security Authority (Greece), Head of the Directorate for Cyber Security, Ioannis Alexakis; Malta Information Technology Agency, Katia Bonello; Malta Information Technology Agency, Martin Camilleri; Ministry of Home Affairs, Security, Reforms and Equality (Malta); Ministry of Economic Affairs and Communication, Department of National Cyber Security (Estonia), Kristjan Kaskman; Ministry of Economic Affairs and Communication, Department of National Cyber Security

1

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

(Estonia), Martin Sepp; Ministry of National Defence of Lithuania; National Cybersecurity Agency (Italy); National Cyber and Information Security Agency, National Strategy and Policy Unit (Czech Republic), Tomáš Kellner; National Cyber Security Centre (Finland), Olli Lehtilä; National Security Authority (Slovakia). ENISA would also like to thank them for their valuable contribution to this study, and all the experts that provided input but preferred to stay anonymous. LEGAL NOTICE This publication represents the views and interpretations of ENISA unless stated otherwise. It does not endorse a regulatory obligation of ENISA or ENISA bodies under Regulation (EU) No 2019/881. ENISA has the right to alter, update or remove the publication or any of its contents. It is intended for information purposes only and it must be accessible free of charge. All references to it or its use as a whole or part must contain ENISA as its source. Third-party sources are quoted as appropriate. ENISA is not responsible or liable for the content of external sources including external websites referenced in this publication. Neither ENISA nor any person acting on its behalf is responsible for the use that might be made of the information contained in this publication. ENISA maintains its intellectual property rights regarding this publication. COPYRIGHT NOTICE © European Union Agency for Cybersecurity (ENISA), 2023 This publication is licenced under CC-BY 4.0 “Unless otherwise noted, the reuse of this document is authorised under the Creative Commons Attribution 4.0 International (CC BY 4.0) licence (https://creativecommons.org/licenses/by/4.0/). This means that reuse is allowed, provided that appropriate credit is given and any changes are indicated”. Cover image ©, www.shutterstock.com For any use or reproduction of photos or other material that is not under the ENISA copyright, permission must be sought directly from the copyright holders. ISBN: 978-92-9204-604-0 DOI: 10.2824/850466 Catalogue number: TP-04-22-231-EN-N

2

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

TABLE OF CONTENTS

1. EXECUTIVE SUMMARY 6 2. ABBREVIATIONS 7 3. INTRODUCTION 8 3.1 METHODOLOGICAL APPROACH 8 4. COMMON ELEMENTS OF GOVERNANCE MODELS 10 4.1 DEFINITION OF GOVERNANCE, CYBER GOVERNANCE AND GOVERNANCE MODELS 10 4.1.1 Governance 10 4.1.2 Cyber governance 11 4.1.3 Governance Models 11 4.2 THE STATE OF ART OF GOVERNANCE MODEL FOR NCSS 12 4.2.1 Political governance 13 4.2.2 Strategic governance 16 4.2.3 Operational governance 18 4.2.4 Technical governance 20 4.3 THE STATE OF THE ART: STATUS OF THE NCSS ACROSS THE EU MEMBER STATES 22 5. SETTING UP A GOVERNANCE MODEL 24 5.1 POLITICAL GOVERNANCE 27 5.1.1 Political processes 28 5.1.2 Roles and responsibilities 30 5.1.3 Legal measures 32 5.2 STRATEGIC GOVERNANCE 33 5.2.1 Elements concerning the NCSS itself 34 5.2.2 Elements related to the planning of the governance model and strategy’s implementation 34 5.2.3 Elements of the strategic aspects of risk identification and mitigation 35 5.3 OPERATIONAL GOVERNANCE 39 5.3.1 Elements about awareness raising campaigns, outreach campaigns and trainings to foster capacity-building 40 5.3.2 Elements of the incident response 41 5.3.3 Elements of the information sharing processes 42 5.4 TECHNICAL GOVERNANCE 42 5.4.1 Technological standardisation 43 5.4.2 Use of technology, tools and certification schemes 44

3

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

6. MONITORING A GOVERNANCE MODEL 45 6.1 MONITORING MECHANISMS OF GOVERNANCE MODELS DEPLOYED ACROSS THE MEMBER STATES 45 6.2 POTENTIAL RE-USE OF EXISTING KPIS 47 6.2.1 NCAF KPIs 48 6.2.2 EU Cybersecurity Index 48 6.2.3 ITU Global Cybersecurity Index indicators 49 6.2.4 Cybersecurity Capacity Maturity Model for Nations (CMM) 49 7. CONCLUSION 51 8. BIBLIOGRAPHY / REFERENCES 53 A ANNEX: ORGANISATIONAL CHARTS OF MEMBER STATES CYBERSECURITY ENTITIES 55 A.1 AUSTRIA 55 A.2 BELGIUM 56 A.3 CROATIA 56 A.4 CYPRUS 57 A.5 CZECH REPUBLIC 57 A.6 ESTONIA 58 A.7 ITALY 59 A.8 NETHERLANDS 60 A.9 SPAIN 60 B ANNEX: EXISTING SETS OF KPIS 61 B.1 NCAF INDICATORS 61 B.1.1 Cluster #1: Cybersecurity governance and standards 61 B.1.2 Cluster #2: Capacity-building and awareness 65 B.1.3 Cluster #3: Legal and regulatory 74 B.1.4 Cluster #4: Cooperation 82 B.2 ITU GLOBAL CYBERSECURITY INDEX KPIS AND SPECIFIC QUESTIONS ON NATIONAL CYBERSECUIRTY STRATEGY B.2.1 Indicators 86 B.2.2 Questions on national cybersecurity strategy 86 B.3 CYBERSECURITY CAPACITY MATURITY MODEL FOR NATIONS (CMM) 87 B.3.1 Factor - D 1.1: National Cybersecurity Strategy 87

4

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

B.3.2 Factor - D 1.2: Incident Response and Crisis Management 89 B.3.3 Factor - D 1.3: Critical Infrastructure (CI) Protection 90 B.3.4 Factor - D 1.4: Cybersecurity in Defence and National Security 91 B.3.5 Factor - D 2.1: Cybersecurity Mindset 92 B.3.6 Factor - D 2.2: Trust and Confidence in Online Services 93 B.3.7 Factor - D 2.3: User Understanding of Personal Information Protection Online 95 B.3.8 Factor - D 2.4: Reporting Mechanisms 96 B.3.9 Factor - D 2.5: Media and Online Platforms 96 B.3.10 Factor - D 3.1: Building Cybersecurity Awareness 97 B.3.11 Factor - D 3.2: Cybersecurity Education 99 B.3.12 Factor - D 3.3: Cybersecurity Professional Training 100 B.3.13 Factor - D 3.4: Cybersecurity Research and Innovation 101 B.3.14 Factor - D 4.1: Legal and Regulatory Provisions 102 B.3.15 Factor - D 4.2: Related Legislative Frameworks 103 B.3.16 Factor - D 4.3: Legal and Regulatory Capability and Capacity 105 B.3.17 Factor - D 4.4: Formal and Informal Co-operation Frameworks to Combat Cybercrime 106 B.3.18 Factor - D 5.1: Adherence to Standards 107 B.3.19 Factor - D 5.2: Security Controls 109 B.3.20 Factor – D 5.3 Software Quality 110 B.3.21 Factor - D 5.4: Communications and Internet Infrastructure Resilience 111 B.3.22 Factor - D 5.5: Cybersecurity Marketplace 112

5

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

1. EXECUTIVE SUMMARY

The importance of a sound governance model for the implementation of the National Cybersecurity Strategies (NCSSs) has been highlighted in numerous testimonies of the Member States as well as included in the NIS and NIS2 Directive. However, each country deploys its own governance model with a different level of maturity. ENISA, taking on its mandate to support and promote the development, deployment and implementation of the NCSS and accompanying governance models, produced this study on "Building Effective Governance Frameworks for The Implementation of National Cybersecurity Strategies". It analyses existing governance models to share a set of good practices when developing a governance model and putting in place the different governance elements. The proposed governance model consists of four layers with 10 sub-categories, and provides a total of 28 good practices: • Political governance o Political processes; o Roles and responsibilities; and o Legal measures. • Strategic governance o Strategy itself and its implementation; and o Risk identification and mitigation. • Technical governance o International standards and technical guidelines; and o Use of technology, tools and certification schemes. • Operational governance o Awareness raising; o Incident response; and o Information sharing. The good practices have been defined based on data collected through desk research and interviews with experts and relevant stakeholders from the Member States. The data collected has been analysed to identify trends, and effective instances across the different elements of governance. While the interviews had a European focus with 19 interviews with stakeholders from 18 EU Member States, the geographical scope of the desk research includes a global outreach. Finally, this report provides insights on KPIs and general indicators to monitor and evaluate the status of implementation of the NCSS and its governance model.

6

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

2. ABBREVIATIONS

CERT: Computer Emergency Response Team CISA: Cybersecurity and Infrastructure Security Agency CI/CII: Critical Infrastructures/ Critical Information Infrastructures CSIRT: Computer Security Incident Response Team ENISA: European Union Agency for Cybersecurity EU: European Union GCI: Global Cybersecurity Index ICT: Information and Communication Technology IMF: International Monetary Fund ITU: International Telecommunication Union KPI: Key Performance Indicator MITA: Malta Information Technology Agency MoU: Memorandum of Understanding NATO: North Atlantic Treaty Organisation NCAF: National Capabilities Assessment Framework NCSS: National Cybersecurity Strategy NGO: Non-Governmental Organisation NIST: National Institute of Standards and Technology OECD: Organisation for Economic Co-operation and Development PPP: Public-Private Partnership SMEs: Small and Medium-sized Enterprises UN: United Nations USA: United States of America

7

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

3. INTRODUCTION

With the publication of the Network and Information Security (NIS) Directive in July 2016 and issuing of the draft agreement of the NIS2 in June 2022, the EU Member States have been required to adopt a National Cybersecurity Strategy (NCSS). The NCSS should put forward strategic principles, and guidelines, objectives and priorities to improve and maintain a higher level of security in the context of network and information systems. In this relation, and as stated by the EU Cybersecurity Act , ENISA shall not only support the Member States in developing national strategies but shall also promote the effective deployment of those strategies and support the set-up of a governance model ensuring the sustainability of the NCSS. As part of its mandate, ENISA publishes a study focusing on the good practices around the setup and deployment of a governance framework to support the implementation of the NCSS in the EU. The objective of this study is to systematically review existing governance models relevant to the deployment of a NCSS and to identify and select the most relevant instances, lessons learned, and good practices from the EU Member States. This study aims to collect insights on the definition of processes, roles, and responsibilities, the subsequent deployment of monitoring measures, and to identify the main challenges and good practices that the EU Member States put in place to ensure an effective governance framework for the implementation of NCSSs. 3.1 METHODOLOGICAL APPROACH The methodological approach used to gather the best practices of governance frameworks relies on four main steps: 1. Desk Research: The first step involved conducting an extensive literature review to collect good practices and trends on governance models. The desk research has been focused on good practices adopted in the EU Member States, while insights collected from around the world complement the analysis. A systematic literature review approach has been deployed to review all documents coherently and to methodologically assess the insights of each source in terms of relevance, usefulness, and applicability. 2. Collection of experts and stakeholders’ points of view: In this context, 19 stakeholders from 18 EU Member States have been interviewed to gain first-hand insights on the status of governance models across the EU Member States, and to identify good practices, as well as challenges, needs and lessons learned. The national stakeholders have all been part of the national authority or government body in charge of the cybersecurity strategy. 3. Analysis of stocktaking input: The data collected through desk research and interviews were subsequently analysed to identify good practices in the design of a governance framework.

8

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

4. Definition of best practices for governance: Thereafter, good practices and trends in setting up governance models have been defined and validated with national experts, before publication. The target audience of this study includes policymakers, experts, and government officials responsible for or involved in designing, implementing, and monitoring the NCSS, its processes, actions, and objectives.

9

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

4. COMMON ELEMENTS OF GOVERNANCE MODELS

This section defines a common understanding of the concepts of governance, cyber governance, and governance models. Moreover, it highlights the main results and insights from the literature review conducted on the topic of governance models of NCSS. By doing so it outlines the main elements of different levels of governance and builds the framework for analysis leveraged on in chapter 5. 4.1 DEFINITION OF GOVERNANCE, CYBER GOVERNANCE AND GOVERNANCE MODELS The desk research on governance models included 49 sources, reaching from academic and scientific articles, over reports, to guides on how to develop governance models as well as governance models themselves. The main focus of the geographical scope has been the EU, nevertheless, inputs from other countries (e.g., USA) have been considered to ensure a wide array of results and to also take into account the developments in other parts of the world. 4.1.1 Governance The term governance is used in a plethora of different topics and different contexts. Following the vast amount of available literature on the topic of governance, there is not one, allencompassing definition that would hold across its different areas of application. Rather, multiple but complementary, partly overlapping definitions exist to describe and detail what ‘governance’ entails. Stemming from the original meaning of ‘governing’ in the context of individual rule it is and has been used throughout time often about institutional structures. The concept originally describes actions and processes to lead, structure, and enable institutions and organisations to exist, function, and persist. Only recently, governance has been related to international institutions and gained popularity. It has started to be used by international organisations such as the European Union, World Bank, the International Monetary Fund (IMF), and the Organisation for Economic Co-operation and Development (OECD) more frequently. Further, it has been stated that since the concept has gained more popularity, governance became one of the most controversially discussed topics when it comes to democracy theory and democratisation. Governance is predominantly seen as: • a process to coordinate a network of stakeholders with independent positions, opposing and conflicting opinions and interests; • a mechanism to steer and control society, and results from the interaction of political, economic and social actors; • a complex system including different stakeholders from the public administration, the private sector and non-governmental organizations, influenced by interactions thereof; and

10

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

• a triangle composed of participation, transparency and accountability and creates a framework “regulating socio-economic conditions, developing social and physical infrastructures, and providing social security nets”. For the remainder of this study, we will use the following definition of governance: Governance describes a complex system, defining roles, responsibilities, processes and relationships between involved actors. Governance includes stakeholders from the private sector, public administration as well as civil society and spans over different topics such as economic, social and political priorities. 4.1.2 Cyber governance The domains of cyber, cybersecurity and cyber threats experienced increasing importance, and cyber governance became a popular topic. While the field of cyber or ‘cyberspace’ describes the environment consisting of the global information systems and their connecting network, cybersecurity entails the prevention of damage and the protection against attacks on, among others, computers, information and communication systems as well as processes, data, hardand software. Threats in the cyberspace arise from attacks on the processed information or the systems themselves. Cybersecurity is also part of the cyberspace and aims at securing the confidentiality, integrity, accessibility, availability and privacy of the information processed, stored and used. Given the interconnections in the cyberspace, cybersecurity cannot be assessed, analysed or described without taking into account other aspects of cyberspace as well. The functioning of the cyberspace depends on various stakeholders, processes and elements within cyber governance. International organisations started to find solutions for challenges related to cyber governance, for example developing and signing the ‘Cyber Crime Convention’'. In addition, international standardisation has been adopted, i.e., ISO/IEC 38500:2015 providing guiding principles for governing bodies’ members on “effective, efficient and acceptable use of IT in their organizations”. Definitions of cyber governance are emerging and describe it as the “Operation of decision-making processes” which increase and ensure “participation, transparency, and accountability in taking measures related to cyberspace together with the mechanism of international agreements, strategies, laws, measures, regulations, and standards that interlock in the best way”. This definition will be used for the remainder of this study. 4.1.3 Governance Models Similar to the definition of governance, a single definition of the governance model is not agreed upon in the literature. Different types, descriptions and definitions have been developed covering different levels of granularity. This section aims to provide an overview of the current state of the art of developing governance models. To this end, structured desk research has

11

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

been conducted focusing on the development and set-up of governance models in general, and specifically, the ones related to the implementation of NCSSs. In the literature, two main patterns of defining governance models are predominant, one focusing on the different layers of governance and one targeting the stakeholders and objectives of the model. An advantage of the latter is that overarching and transversal activities can be integrated, analysed and evaluated. However, this might come at the expense of the accuracy of the definition of the roles and responsibilities of the stakeholders involved and their accountability. The Government Cyber Security Strategy of the British Government employs this path in defining its governance model and focuses on the overall objectives of the implementation of the cybersecurity strategy. Defining a governance model based on its different layers might increase the overall complexity of the framework, however, this option yields several benefits, including a more thorough description of its components (e.g., stakeholders, objectives, etc.). In addition, it is possible to provide a clear allocation of responsibilities and describe more detailed channels of communication, information exchange and collaboration. The different levels of governance include the political aspect, definition of processes, roles and responsibilities, operationalisation of actions and their technical implementation. The Global Cybersecurity Index divides governance models into legal, technical, organisational, capacity development and cooperative measures. Similarly, cybersecurity governance in some US States focuses on the following areas of governance, as identified by the Department of Homeland Security: Strategy and planning, budget and acquisition, risk identification and mitigation, incident response, information sharing, workforce and education. This report will follow the majority of sources analysed and will define governance models along different levels or layers. This allows the provision of a more granular assessment of governance models. The elements of the framework such as objectives, stakeholders and actions can be described per level, providing a holistic approach to their definition. While governance can be divided into a variety of levels, most sources assessed governance along similar layers. Based on the conducted desk research four main levels of governance have been identified as predominant, thus, these were selected to build the governance framework of this report: a) Political governance; b) Strategic governance; c) Operational governance; and d) Technical governance. The next section will provide an overview of the main elements driving each of the four levels of governance. 4.2 THE STATE OF ART OF GOVERNANCE MODEL FOR NCS In general, political governance is the most thoroughly covered level of governance in literature. Specifically, the set-up of processes and the allocation of responsibilities to ensure a successful governance framework are the most prominent elements. In addition, elements concerning incident response in the context of operational governance have been pointed out by several

12

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

sources. While their importance is highlighted and aspects are clearly defined, elements of the strategic and technical layers are less thoroughly covered. In addition to the main elements governing the different levels of governance, the literature emphasises the importance of monitoring mechanisms across all levels. Their establishment along with the ones of key performance indicators (KPIs) or other measures for coherent evaluation is important for the successful implementation of NCSSs. Chapter 6 covers the monitoring of governance models in detail. The remainder of this chapter will highlight the findings and point out the identified trends from the desk research across the four levels of governance: political, strategic, operational and technical. This provides the framework for the analysis carried out under chapter 5, which focuses on the inputs shared by the Member States. 4.2.1 Political governance Political governance provides a framework of defined processes and relationships as well as legal guidelines. It establishes the formal angle of governance and is often seen as governance itself, as it is tightly related to the execution of political actions and entails governing, leading and overseeing processes and actions implemented. The main objective of the political layer is the establishment of processes, roles and responsibilities to ensure the implementation of the NCSSs and their related policies. In turn, official processes, clearly defined roles and proper legal measures foster the creation of accountability, ensure transparency and facilitate the acceptance of the NCSSs among all the relevant stakeholders. Political bodies, such as dedicated cybersecurity agencies or departments within different ministries are leading the political level. Hence, oftentimes, decision-makers are included in some of the processes to ensure accountability and political acceptance. Other actors actively participating in building and executing political governance are academia, consultancies and other expert bodies, which provide topical expertise and support to political actors in setting up, organising and executing political governance. Public-Private Partnerships (PPPs) play an important role in the enforcement and accountability of political governance, as they help build bridges between the private and the public sector, ensuring the implementation of actions responding to industry needs. Common elements of political governance can be clustered into three main groups, as defined in Figure 1, namely: i) Political processes, ii) Roles and responsibilities, and iii) Legal measures.

13

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Figure 1: Main elements of political governance

Source: Authors’ own elaboration.

In general, political governance seems to be the most advanced of all four levels of governance, in fact, measures to define political processes, roles and responsibilities seem to be most actively discussed and analysed by the literature. Legal measures are not equally assessed, however, their importance is vital as they set the basis for the country’s legal framework and the obligations of the different stakeholders. Political Processes Among the elements of political processes, particular emphasis is put on initiating cooperative and collaborative approaches and ensuring joint dialogues. In this context, the inclusion and active participation of various stakeholder groups across different levels has been stressed , together with the creation and active integration of PPPs in the political processes given their contribution in actively shaping the implementation, monitoring and evaluation of NCSSs. Additionally, the importance of inter-sectoral cooperation has been highlighted due to the possibility of creating synergies and ensuring commitment to the implementation of actions among stakeholders. In addition, cooperation and collaboration across the different governmental institutions are essential to guarantee a coherent approach towards the implementation of the NCSSs. Intragovernmental coordination and cooperation are considered core functions and prerequisites for functioning governance mechanisms, such as the application of standards, regulations and market incentives. Hence, cooperation between government institutions is ultimately important

14

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

to ensure that the desired outcomes are met, and that the objectives of the governance model and the strategy are fulfilled. Lastly, international cooperation and collaboration have been pointed out as highly important. It has been stated that, given the international character of the cyberspace, a complete solution for cyber governance cannot be based on national understanding alone, but needs to be embedded and coordinated in the international arena. Further, international cooperation, collaboration and exchange on the set-up of a governance model will benefit all parties through the development and improvement of cyber governance. In this regard, the development of an international common language for cyber defence is considered an immediate necessity to enable international exchange among experts. Definition of roles and responsibilities After the political processes, the definition of roles and responsibilities is the most covered aspect in literature. All stakeholders must have clearly allocated roles, and responsibilities to ensure the successful implementation of the strategy and achieving its objectives. In this relation, it has been mentioned that personnel and financial resources should be clearly defined and allocated. The clear allocation of responsibilities is important to ensure accountability of the responsible actors, while the clear allocation of roles is important to set up an effective and efficient governance system and avoid overlapping of mandates. A common trend emerging from desk research is the setting-up of a lead authority or body. While different options can be deployed to do so, a central body or actor taking the main coordinating responsibilities and roles seems beneficial and is important to allocate actions and monitor the progress of implementation. There are three commonly applied options: building an entirely new body dedicated to the implementation of the NCSS; expanding the mandate and the responsibilities of an already existing central body; or extending the responsibilities of several decentralized political entities, such as ministries. In addition, working groups on different topics might be established to enable engagement across bodies and entities involved. They facilitate and develop formalized cooperation mechanisms to enable international collaboration. Finally, the establishment of an advisory council built by academic and industry experts to be consulted by responsible government officials has been pointed out as particularly beneficial. Another option refers to the partial or full outsourcing of the cybersecurity services to PPPs by establishing them as stand-alone organisations. This is particularly helpful if the government misses the expertise or capacity to react to the identified needs for action. The PPPs provide

15

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

cybersecurity services, while the national public authorities remain in an overseeing position. The different set-ups of and the collaboration with PPPs are widely discussed, and there is a common agreement on the strategic importance of including them within the NCSS and its governance model. The organisation, structure and legal basis of PPPs differentiate from country to country, however, a common factor pointed out by several sources is the relevance of including governmental and private sector representatives (e.g., SMEs) in the PPP decisionmaking process. Legal measures Regarding legal measures for governance models, it has been stressed that the establishment of a legal framework or a legal governance system is important to provide guidance and support. Additionally, the existence of legal measures provides legally binding mandates and ensures enforcement, accountability and transparency during the implementation process. On implementing legal measures, it has been specified that they should be built in a far-sighted approach to be able to accompany future changes brought by digitalisation. To support the cooperative and collaborative approach, legal measures should be inclusive and have general validity, to ensure that all institutions, organisations and related stakeholders are committed to the NCSS, its governance model and the implementing actions. Legal measures also help giving policies and actions for the implementation of a governance model a binding character and are hence essential tools of a complete governance model. In line with the importance of setting up international cooperation and collaboration, the legal framework should reflect this by international guidelines and cooperation on the definition of legal measures internationally. Lastly, it is emphasised that human rights should be tightly connected to and taken into account in all processes of setting-up a cybersecurity governance model, but specifically related to the legal framework. Of particular importance is ensuring trust, transparency, and equity through the legal framework. 4.2.2 Strategic governance Strategic governance describes the level of governance directly linked to the NCSS. It is important to tightly connect the processes of designing the strategy and designing its governance model to ensure continuity and coherence. Strategic governance targets linking and coordinating the processes of drafting the strategy and building the governance model from the outset. Additionally, strategic elements of identifying and mitigating risks necessitate strong cooperation and collaboration between actors involved in both, the governance model, as well as the strategy development. The main stakeholders involved in the strategic governance level are political actors drafting the strategy. Often, working level government officials are main actors here, while higher level government officials are involved for validation, acceptance, accountability and enforcement purposes. Political actors are often supported by working groups, consulting bodies and other

16

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

stakeholders providing expertise to draft the strategy and corresponding implementation actions. Overall, three clusters have been identified in which the main elements of strategic governance can be grouped, namely elements concerning: i) the strategy itself, ii) the implementation of the governance model, iii) strategic aspects of risk identification and mitigation. Figure 2 illustrates them. Figure 2: Main elements of strategic governance

Source: Authors’ own elaboration.

Elements concerning the strategy itself and the implementation of a governance model Firstly, the literature on strategic governance emphasises that already at the set-up stage of the strategy, the development of a governance framework should be taken into account and included in the strategy. Drafting the strategy and at the same time already including possible operational, political and legal measures, which should be put in place for the strategy’s implementation, is argued to be beneficial, as processes and timelines are streamlined. Secondly, after the strategy has been drafted, the implementation should be guided by an implementation plan to point out specific actions and ensure the support of the strategy across the different governmental and civil society levels. Thirdly, thorough planning and a clear indication of the overall planned priorities, the foreseen budget and resources is important to integrate the implementation of cybersecurity in the general national planning and governance approaches. It is important to align priorities of the

17

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

cybersecurity strategy with other governmental priorities on national level. This fosters commitment and support from different bodies, and actors across the government. Risk identification and mitigation Regarding the strategic elements of risk identification and mitigation, it has been stressed that a coherent approach across all government entities and critical infrastructure operators should be aimed for. Having a sound approach for risk identification and mitigation, which is coherent across the different actors, facilitates exchange and information-sharing and fosters cooperation. In fact, the creation of specific agencies providing services of risk identification and mitigation has been pointed out, as centralizing these aspects facilitates exchanges. However, challenges related to accountability, transparency and the protection of human rights. This should be taken into account and mitigated from an early stage of the strategy. 4.2.3 Operational governance Operational governance entails the level of governance focusing on elements related with the translation of NCSSs into actions to improve cybersecurity within the country. The objective of the operational governance level is to increase cybersecurity across all sectors of a nation’s society, economy, and government. The main group of stakeholders, actively involved in the set-up and execution of this governance layer includes specialised bodies such as Computer Security Incident Response Teams (CSIRTs) and Computer Emergency Response Teams (CERTs), government officials and consulting and training bodies. Nevertheless, it is important to mention that the complete society and population is connected to this level of governance. Effectively improving cybersecurity can only be successful if the general public of a country is included and capacity and community-building efforts are undertaken across society. As pointed out, some aspects falling under the operational governance level are well covered in literature on governance models. This applies particularly to aspects in the context of incident response and capacity-building. During the desk research, three main clusters governing operational governance have been identified: i) awareness-raising campaigns, outreach campaigns and trainings to foster capacity-building, ii) incident response, iii) information sharing and channels Figure 3 illustrates them:

18

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Figure 3: Main elements of operational governance

Source: Authors’ own elaboration.

Awareness raising campaigns, outreach campaigns and trainings to foster capacity-building Awareness raising and outreach campaigns accompanying the implementation of NCSSs foster the acceptance and uptake of cybersecurity measures. It is of utmost importance to train stakeholders, which are involved either directly with the set-up or implementation of the strategy or involved in combating cybercrime. Nevertheless, there is a strong trend incentivising the creation of initiatives to raise awareness within the general population. Through explaining “why”, “how” to use certain standards, tools and technologies, or “what” to do and “why” to do so, would increase the safety of the general population. In this sense, it has been repeatedly stated that not only stakeholders and actors directly working with the NCSSs should be targeted by education campaigns and trainings, but that instead the whole population, starting from a young age, should be integrated in these activities to close the ‘cyber skill gap’. This would be important to ensure success of the NCSS, as huge cyber risks emerge from untrained persons, which are not aware of risks or how to protect against cyber threats effectively. A more holistic approach should be taken in order to build a cybersecurity culture and enhance capacity- and community-building across the population. In this way, by shifting away from pure information-sharing and problem-related approaches, cybersecurity could yield efficiency and performance gains for the private sector and the national economy. Incident response mechanisms Operational governance is also driven by formalised mechanisms for incident response. Literature suggests the creation of CSIRTs and CERTs to provide support in case of cybersecurity incidents. Specialised teams dedicated to cybersecurity mechanisms should be

19

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

implemented, driven by thorough action plans in case of incidents. CSIRTs and CERTs provide a centralised contact point on national level and enable a quick and systematic reaction during incidents. CSIRT and CERT bodies should hence take proactive as well as reactive functions and measures to not only support during incidents, but to also prevent incidents from happening and support countries in learning from experience to build resilience against cyberthreats. Information sharing Setting-up formal information-sharing programmes as well as defining possible informal information-sharing programmes through an operational framework would foster effective and consistent coordination. Trusted relationships are highly important, more specifically, the development of informal networks would be highly beneficial as information-sharing based on personal interests is most authentic. However, trusted relationships need time to develop and hence, the involvement of different stakeholders and close cooperation from the start seem to be important. Additionally, according to research, shaping information-sharing processes should be supported by CERTs and CSIRTs. For a successful incident response, it is highly important in this context to firstly define clearly what a cybersecurity incident constitutes, and how processes, roles and responsibilities are allocated and performed during an incident. 4.2.4 Technical governance The technical level of governance relates to the inclusion of technology and technical elements accompanying the implementation of the strategy. Its objective is to link the implementation of the strategy to technical and technological developments happening in parallel. This is particularly important in the cyberspace, a fast-evolving field, in which new threats and challenges arise at the same time of new technological possibilities and solutions. The main stakeholders involved in this level are technology experts from industry and academia, supporting political actors in choosing and applying technological tools as well as technical standardisation bodies on a national and international scale. Currently, the elements of technical governance are covered least in the literature and seem to not yet been heavily focussed on. Although some trends have been identified, due to the low coverage of technical aspects across literature, these trends might not be representative, given the fast technical advancements and developments. Two main clusters of elements governing technical governance have been identified during the desk research: i) definition of standards and specification, and ii) use of technology, tools and certification schemes to foster cybersecurity. They are illustrated in Figure 4.

20

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Figure 4: Main elements of technical governance

Source: Authors’ own elaboration.

Standardisation The use and definition of standards has been emphasised in order to build a technical governance framework for cybersecurity. Particularly important in this relation would be the use of international and global standards to not only provide technical guidelines but to base cybersecurity governance on existing and globally established technical standards. Use of technology, tools and certification schemes The technical layer also includes the undertaking of appropriate and proportionate technical and organisational measures to manage risks. To this end the NIS2 directive emphasises the importance of certification schemes and stresses the importance for the Member States to require essential and important entities to certify certain ICT products, ICT services and ICT processes under specific European cybersecurity certification schemes. Moreover, CSA article 58 defines mandatory obligations for the Member States to designate NCCAs (National Cybersecurity Certification Authorities) or to reuse the existing NCCA of another Member State, as to supervise certification; this entails the implementation and assessment of the technical governance activities related to such obligations (which entity has been designated, to which ministry it belongs, how it is staffed, how it interacts with other national authorities having a cybersecurity role, etc.). A second main element emerges from the use of technology and tools to support the set-up of a governance model and the implementation of the NCSSs. Updating tools and technologies used in industry, by the government or other communication systems, can support reaching the NCSS’s objectives. In addition, technology and tools such as mobile devices can not only support security but can also provide technological guidance and open possibilities to promote human rights in the sphere of cybersecurity. However, if not updated, tools and technology may pose risks to cybersecurity.

21

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

4.3 THE STATE OF THE ART: STATUS OF THE NCSS ACROSS THE EU MEMBER STATES Currently, all EU Member States have a NCSS in place. Figure 5 below showcases the status of each country of developing updated versions and new editions of their NCSS. Figure 5: State of Art: NCSSs across the EU Member States

Source: Authors’ own elaboration.

All 18 Member States interviewed for this report have currently a governance model in place to support the implementation of the NCSS. Similarly, all Member State representatives stated that having in place a governance model is highly important when implementing the NCSS. Figure 5 provides an overview of the EU Member States which have deployed their first NCSS governance model and highlights in a darker blue those countries which already employed later editions of the governance model. In general, it can be said that the NCSSs are updated every three to seven years. The governance model would need to be updated as well, taking into account recent developments in the cyberspace due to its close relationship with the NCSS.

22

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Figure 6: State of Art: Deployment of governance models for NCSS across the EU Member States

Source: Authors’ own elaboration.

From Figure 6, it can be noticed that some countries introduced an accompanying governance model over the years, and that some countries introduced it only after the first NCSS was already deployed. While this shows that the Member States used to have different approaches to implementing their NCSSs, it also indicates growing agreement of the importance of settingup a governance model. It is interesting to notice that maturity of the governance model does not necessarily depend on or correlate with the number of further editions of the NCSS.

23

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

5. SETTING UP A GOVERNANCE MODEL

Following the identification of the different levels of a governance model, this section will focus on the analysis of the different elements of each layer and will highlight the good practices shared by the Member States’ representatives during the conducted interviews. Before diving into the different governance models, it is important to have an overview of the political systems of the EU Member States to understand whether this factor influences the selection of a specific governance model. Figure 7 illustrates the model of government and selfgovernance of the Member States. Regarding the government model, out of a total of 27 Member States, 21 countries have a parliamentary political system , one has a presidential 53 54 political system and five have a semi-presidential political system . While, with regard to the self-governance model, out of a total of 27 Member States, 18 of them have unitary self- 55 56 57 governance , three of them have federal one , two a devolved self-governance and four of them have a federate one . To analyse the relation between a country’s government model, self-governance structure and the type of governance model of the NCSS currently deployed, the different governance models highlighted during the interviews have been mapped against desk research on government and self-governance types. It has been noted that there is no correlation between the type of government, self-governance, and the governance model of the NCSS. In fact, there are several additional factors that influence its definition. For instance, the size of a country, its level of maturity in the cyber domain, and the level of cooperation with the private sector, just to name a few. This finding led to the conclusion that it is not possible to have a unique governance model to be used as a reference. Therefore, in this chapter, for each element of the different levels of governance, good practices rather than a governance model will be shared.

24

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Figure 7: Member States' political system of governance Source: Authors’ own elaboration. In the preliminary phase of the interviews, the Member States shared the key elements influencing the national approach to the governance model of their NCSS, as well as the main challenges faced during its deployment. The key challenges have been assessed and grouped to provide an overview of the main challenges, experienced by several of the Member States. Table 1 presents the key challenges while Table 2 provides an overview of the related lessons learnt. It can be noticed that the most underlined difficulties are related to the definition of roles and responsibilities, the lack of coordination and cooperation as well as the challenge in reaching a common agreement between the different stakeholders. Table 1: Key challenges when deploying the governance model Key Challenges 1 Definition of roles and responsibilities Given the number of stakeholders involved, a lack of understanding of the different roles in the overall picture and duplication of efforts may happen. 2 Lack of coordination and cooperation Given the complex structure of some National Cybersecurity systems, the existence of several security authorities including regional competent authorities, coordination, and cooperation between the different actors is a challenge. 3 Reach a common agreement on the strategy Given the number of stakeholders involved, reaching an agreement on both, the main goals of the strategy and its phrasing, seems to be difficult.

25

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Key Challenges 4 Information sharing Given the number of different stakeholders involved in the implementation of the strategy, and therefore, included in the governance model, there were some difficulties in sharing information among the different actors. Considering the constantly changing field of cybersecurity, the flow of information is sometimes too slow, especially in terms of regulation and organisation. 5 Definition of the overall strategy’s budget Considering the decentralized governmental approach of some countries, significant delays may occur in receiving the budget or in obtaining a dedicated budget. 6 Achieve a higher level of national cyber security and resilience Given the increasing cyber risks and the global geopolitical situation, some Member States are struggling to cope with the new cyber challenges. 7 Timeline of the development and implementation of the NCSS In fact, it would be more beneficial to develop and approve the implementation plan and to define the governance model, at the same time as the NCSS. 8 Lack of enthusiasm Given that for some stakeholders the cybersecurity strategy is an extra workload while they are already engaged in numerous other activities, a lack of enthusiasm and motivation could be noticed, which indirectly hinders the good performance and implementation of the strategy. Source: Authors’ own elaboration. Table 2: Good practices from Member States on the deployment of the governance model Good Practices Political governance 1 Provide political support in the development and implementation of NCSS and governance models; 2 Ensure adequate coordination and cooperation among the relevant players; 3 Build trust between the different stakeholders; 4 Follow participatory approaches by putting in place platforms of exchange; 5 Involve all stakeholders in the process of developing an NCSS and a governance model (choose the right level of representation for the different stakeholders); 6 Set up a collaborative platform to monitor the progress of the action plan; 7 Ensure support from the highest political level in the creation of PPPs; 8 Mandate a single body to ensure the coordination and the implementation of the overall strategy; 9 Precisely define the roles and responsibilities of the different stakeholders involved in the governance model in one document;

26

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Good Practices 10 Create PPPs; 11 Ensure that the governance framework is supported by and defined by the legal framework. 12 Develop a section focused on the human rights in the NCSS and its governance model with explicit actions, responsibilities and roles Strategic governance Develop a dedicated budget from bottom to top; particularly, allocate a dedicated budget 1 for the cybersecurity strategy rather than allocating the budget to an overarching authority; 2 Include a paragraph on financials in the NCSS; 3 Thorough risk identification across different levels; 4 Early identification of risks and implementation of risk assessment mechanisms; 5 Follow a common methodology for risk identification; 6 Follow a common framework in case of incidents; 7 Definition of accountability and transparency rules; 8 Include legislation ensuring human rights in the NCSS. Operational governance 1 Tailored awareness-raising and training campaigns; 2 Centralise information sharing; 3 Taxonomy of best practices to ensure coherent processes of information sharing; 4 Formalise a coordinated approach between CSIRTs. Technical governance Include in the NCSS and its governance model a section focused on international standards and technical guidelines. When developing this section, refer to the technical standards that 1 should be used. The standards can be specified in another document to simplify their update. It is also important to define clear roles and responsibilities; Have in place a body that supervises the compliance of regulated entities with national, 2 European and international requirements. Put in place in the NCSS action plan a group of tasks focused on using tools and 3 technologies in respect to human rights, particularly to GDPR. Source: Authors’ own elaboration. 5.1 POLITICAL GOVERNANCE The political governance level has been proven to build a highly important part of the governance model. All Member States’ representatives indicated that political governance is

27

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

currently part of their governance model. It aims to clearly define political processes, identify and assign roles and responsibilities of different stakeholders, and put in place legal measures to support the deployment of the strategy. Overall, three clusters of elements of political governance have been identified during the desk research. These have been further detailed and validated through stakeholder consultation. Figure 8 shows the percentage of stakeholders, interviewed in the process of this study, validating the element of political governance. Figure 8: Percentage of interviewed stakeholders confirming elements of political governance

Source: Authors’ own elaboration.

5.1.1 Political processes Focus on cooperative and collaborative approaches at international, inter-sectoral and regional levels An important element of the political governance is the inclusion of cooperative and collaborative approaches at international, inter-sectoral and regional levels. All the stakeholders GOOD interviewed confirmed that this element is already part the currently deployed governance PRACTICE model in their country. An international commitment and The EU Member States follow different approaches to defining cooperative and collaborative collaboration with aspects of political processes. Some Member States define those in the NCSS itself, while international others detail them in the accompanying governance model or the legal framework. organisations and other countries is At the national level, strategies focus more on the collaboration between governmental entities mentioned as a key and across sectors. objective of the strategy.

28

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

At the international level, most Member States cooperate to varying degrees with European institutions such as ENISA, Europol, etc. However, some Member States are interested in further developing this collaboration to also promote human rights, fundamental freedoms and democratic values in the cyber domain to ensure that it remains a global, open, stable and secure space, in which international law and shared principles are respected. Main Observations Providing political support: political authorities must take the cyber security topic seriously, get involved and support the development and implementation of its NCSS and governance models together with the other stakeholders. Governments should balance between facilitating and stimulating ownership and creating responsibilities for other stakeholders. Ensure adequate coordination and cooperation among relevant players: a specific action plan for each of the relevant agencies should be developed, to define activities to be conducted about the strategic goals of the strategy. Build trust between the different stakeholders: the most inclusive approach possible should be followed to collect inputs from the different parties involved. The level of participation in the decision-making process may vary according to the political setup of the country. Follow participatory approaches by putting in place platforms of exchange where public sector entities, such as the government, its bodies and agencies are collaborating with NGOs, and stakeholders from the private sector but also from the scientific community and academia. This will facilitate cooperation across different actors from different domains to collect relevant insights. Focus on participatory approaches, including various stakeholder groups GOOD It is important to include other stakeholders such as academia, consultancies and other expert PRACTICE bodies, PPPs and representatives of critical infrastructures in the deploying of the NCSS. Participatory approaches have been identified as an important element of political governance In order to avoid and have been validated as such by most of the stakeholders interviewed. 89% of the duplications of efforts interviewed Member States confirmed that this element is part of the currently employed and overlapping governance model. mandates of the different agencies, a flexible decision -Main Observations making process that Involve all the stakeholders in the process of developing an NCSS and a governance allows for model: Every institution, private company, and individual can positively contribute to the amendments should development of cyber security. Thus, at least the following stakeholders should be involved be put in place to in the process: provide for an agile • Government bodies and agencies; process open to • Private actors such as SMEs or private industry such as internet providers or developments in the telecom operations; ecosystem. • Critical infrastructure operators; • Law enforcement agencies; • Scientific community; and • Academia. Hence, it is crucial to have an open dialogue through bilateral and multilateral discussions with all the relevant actors.

29

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Define a clear allocation of roles and responsibilities in the governance model: The definition of roles and responsibilities starts with the political decision on the level of representation for the different stakeholders, continues with the definition of allocation of roles and responsibilities and is finalised by the creation of a monitoring plan for each initiative to track the implementation of the actions. A clear allocation is fundamental to avoid the creation of overlaps of mandates among agencies and the creation of a mechanism that holds the different stakeholders accountable. Set up of a collaboration platform: following the creation of a concrete action plan to implement the objectives of the strategy, the set up a collaborative platform is a powerful tool to monitor the level of implementation of the NCSS and to engage the different stakeholders regularly. Additionally, the platform can bring together the public and private sectors and foster the exchange of information. Collaboration with PPPs PPPs play an important role in the enforcement and accountability of political governance, they help support the inclusive approach in setting up the strategy and its governance model. This GOOD has been validated by most of the stakeholders interviewed: 13 of the 19 Member States’ PRACTICE representatives interviewed confirmed that PPPs are currently employed in their actual governance model. For the 5 other Member States, PPPs are not explicitly mentioned in the Deploy a web platform strategy or governance model, but this it is highly encouraged by the country’s authorities. leveraged to collect, assess and evaluate Depending on the sector, the Member States adopt a hybrid approach. In some instances, the the inputs entered by collaboration is outsourced to independent PPPs, while in others, it takes place between the private and public government entities and PPPs. stakeholders and provide updates on the The collaboration with the PPPs takes place between the government (different ministries) and state of play of the the national bodies responsible for cybersecurity. Depending on the domain being discussed strategy. and the stakeholders involved, meetings are organised on a recurrent basis and can vary from a weekly to a monthly basis. The nature of the collaborative approach may change according to the topic being addressed. Main Observations Support from the highest political level in the creation of PPPs: Interviews with GOOD Member State representatives highlighted the importance of public sector support and PRACTICE willingness to collaborate with the private sector due to the higher reactivity of the private In the reporting phase one to the ever-changing cyber ecosystem. for the implementation of the different initiatives of the NCSS, it is important to set up 5.1.2 Roles and responsibilities a framework that Creation of specialised government authorities, bodies and agencies to ensure governance of cybersecurity supports collaboration among stakeholders The establishment of specialised government bodies to ensure the governance of cybersecurity rather than has been identified as an important element of political governance. This has been validated by competition. A good all the interviewed stakeholders, all of them have in place specialised government authorities, practice is to impose a bodies, and agencies to ensure governance of cybersecurity. simultaneal submission of the The aim of the creation of a specialized body or agency in the cyber domain is to supervise, regular reports from coordinate and monitor the deployment of the NCSS, and to ensure the coordination of the the different alignment of all the relevant stakeholders. stakeholders.

30

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Depending on the country, the central body or agency responsible for cybersecurity can have different type of mandates and varying roles on the implementation of the NCSS. If in some countries as Estonia the cybersecurity centre is the main body overseeing the activities related to cybersecurity and sharing information with state authorities and private companies, in some other instances such as Denmark, the centre plays more a supportive rather than a governing role. For those Member States that do not have a dedicated cybersecurity centre in place, an alternative committee is generally set up with the role of political coordination among parties. Main Observations Mandate a single body to ensure the coordination and the implementation of the overall strategy: this will allow to allocate specific roles, responsibilities, actions and follow the progress of the implementation. GOOD PRACTICES Creation of roles and allocation of responsibilities related to national and international International cooperation cooperation on cybersecurity can be fostered through: The definition of roles responsibilities related to international cooperation on cybersecurity has • Creation of a been identified as quite an important element of the political governance. This has been coordination group validated by almost all the interviewed stakeholders, in fact, 84% of them has defined in their to liaise for the governance model clear roles, responsibilities and task in case of incident. participation in the different international Main Observations exchanges; Define in a very precise way roles and responsibilities of the different stakeholders: In the strategy, there should a dedicated section defining the roles and responsibilities, • Definition of on the national as well as international level to avoid duplication of work and better monitor the implementation of the strategy. working groups to interact with international Define the roles and responsibilities of the different stakeholders in the same organisations; document: it will allow to have an overview of the objectives, the tasks, and the stakeholders in charge of implementing them. Thus, it will help to better monitor the implementation of the strategy. • Development of specific procedures for the allocation of responsibilities and roles related to Creation of PPPs international cooperation. Although not all the Member States interviewed (63%) currently have strong PPPs in place, it can be noticed that this aspect is very important and is increasingly encouraged by the different authorities. Main Observations Create PPPs: the creation of PPPs is a powerful tool supporting the development and deployment of the governance model. It permeates the strategy to strengthen the cyber resilience of the country and society. As cyberspace is composed of ICT products and services mainly produced or provided by private entities, the strategy should take into consideration close cooperation and continuous public-private consultation.

31

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

5.1.3 Legal measures Establishment of a legal governance/legal framework linked to specific legal measures The establishment of a legal governance/legal framework linked to specific legal measures has been identified as quite an important element of the political governance. 58% of the interviewed Member States have already in place a legal framework linked to specific legal measures. In Europe, there is a common legal ground defined by legal acts as the NIS Directive, however, it is entrusted to each country the definition of a proper legal framework that supports the implementation of the strategy and the correct allocation of roles and responsibilities, as well as resources. Based on the interviews conducted, the definition of a legal framework is a sign of the maturity of the country, and it fosters the allocation of budget to the implantation of the NCSS, as well as the clear definition of mandates for the involved bodies. All these elements provide more stability and empower the governance model related to the NCSS. Main Observations The governance framework is supported by and defined by the legal framework: the legal framework is composed of newly introduced legal measures as well as already existing legal measures whose scope has been enlarged to achieve the NCSS’s objectives as well. International cooperation about legal measures International cooperation about legal measures has been identified as quite an important element of political governance, as confirmed by 68% of the interviewed Member States. GOOD PRACTICE First of all, it can be noticed that as members of the European Union, the interviewees are involved in different European and international initiatives on cybersecurity. The same applies to Put in place a set of NATO member countries. For cooperation with non-European countries, MoUs (Memorandum guidelines, certification of Understanding) are generally used. schemes and sectorial policies addressed to public entities and private Regional coalitions such as Greece, Cyprus and Israel can also be seen joining forces to operators. enhance cooperation in the cyber security field. • the support for the development of Overall, an important part of the Member States strategies relates to the aspect that the actions European and should be mirroring general trends and activities on the EU-level in order to ensure the international alignment with the EU trends. cybersecurity certification schemes and standards; Emphasis on human rights in legal measures/legal framework: • the promotion of the inclusion of The emphasis on human rights in the digital sphere is not often covered by national legislation, cybersecurity requisites except for very specific cases as GDPR. Similarly, this aspect is not often included in the in ICT procurement Member States NCSSs. Nonetheless, many initiatives are taking place at European level (e.g., activities of Public signing of the Berlin Declaration) given its recognised importance. Administrations. Main Observations Develop a section focused on the human rights in the NCSS and its governance model with explicit actions, responsibilities and roles.

32

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

5.2 STRATEGIC GOVERNANCE Aiming at coordinating the processes of drafting the NCSS and setting up the accompanying governance model, strategic governance has been proven to build a highly important part of the governance model. All representatives indicated that strategic governance is currently part of the governance model employed in their country. Overall, three clusters of elements of strategic governance have been identified during the desk research as pointed out in chapter 4. These have been further detailed on and validated through stakeholder consultation. Figure 9 here below indicates the percentage of interviewed stakeholders confirming the existence of the identified elements of strategic governance in their country’s NCSS. a) Elements concerning the NCSS itself • Foreseeing institutional support to implement the NCSS at the time of drafting the strategy; b) Elements related to the planning of the implementation of the governance model and the strategy • Pre-defining a governance model to implement the NCSS, at the same time as drafting the NCSS; • Planning and allocation of budget and resources and integrating cybersecurity into the overall allocation thereof; c) Elements of the strategic aspects of risk identification and mitigation. • Risk identification and mitigation supported by created agencies; • Coherent approach for risk identification and mitigation across government entities and other critical infrastructure operators; • Mechanisms to ensure accountability, transparency, and human rights during risk identification and mitigation.

33

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Figure 9: Percentage of interviewed stakeholders confirming elements of strategic governance

Source: Authors’ own elaboration.

As mentioned in chapter 4, the elements of strategic governance can be divided into two main groups, elements which should be taken into account from the beginning when developing the NCSS and elements that focus on the strategic aspects of risk identification and mitigation. 5.2.1 Elements concerning the NCSS itself Foreseeing institutional support to implement the NCSS The support of governmental entities or other public sector actors in implementing the NCSS has been identified as an important element of the strategic governance layer to ensure accountability of the strategy as well as support of a wider audience, triggered by wide political and institutional support across government entities. As presented in Figure 9 this has been validated by all stakeholders interviewed: all Member States’ representatives interviewed confirmed that this element is part of the currently employed governance model. The support of different governmental actors from the outset of developing the strategy is highly important to reach consensus and to define a coherent governance model accepted throughout all levels, ministries and sectors of government. While the governance model could be broken down, as the strategy, vertically and horizontally and be focussed on by different governmental actors, the overall NCSS should be agreed upon across the whole government and all involved institutions. 5.2.2 Elements related to the planning of the governance model and strategy’s implementation

34

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Pre-defining a governance model to implement the NCSS GOOD This element of strategic governance aims to put the processes of drafting the NCSS and PRACTICE defining the governance model for the strategy’s implementation in parallel. It has been proven Including detailed most beneficial to adjust the timelines of both, the drafting of the strategy, and the planning of explanations of the the governance model or accompanying action plan to be run at the same time. By doing so, no foreseen time is lost due to time lags between the drafting of the strategy and developing corresponding implementation of the actions for its implementation. NCSS and references to the All stakeholders interviewed mentioned that this element is entailed in the current governance strategy itself in the model deployed. Additionally, it has been mentioned that while aligning the timelines was not action plan/ set-up of always ensured, it will be ensured for future strategies as well, as it has proven to be more the governance efficient for the implementation of the NCSS and to reach its objectives. model, while referencing the action Planning of allocation of budget and resources and integration of cybersecurity into the overall plan/governance allocation thereof model in the NCSS. The allocation of budget and resources to implement the NCSS is highly important, similarly is the planning of the allocation from an early stage of the development of the NCSS and its governance model. Thorough planning of the foreseen budget and resources is important to integrate the implementation of the NCSS specifically and cybersecurity in general into the overall national budget planning. Additionally, it is important to define general national priorities and to place the priorities of the NCSS within these to ensure alignment across all national priorities, budget and resource allocation and to properly integrate the NCSS and the governance model into the overall policy framework. A majority (79%) of the interviewed stakeholders stated that the allocation of resources and budget is taken into account in the context of the NCSS and the accompanying governance model. However, it has been pointed out that while this planning is taken into account, it is rarely outlined in detail and most often performed separately from the definition of the NCSS and the development of the governance model. To some extent, this is driven by the political model employed by the states, i.e., the budget is mainly dealt with on the state level in federalism, and not on a national level; alternatively, budget allocation is done per ministry and hence, in a decentralised approach, if several ministries are accountable for different parts of the implementation of the NCSS. It has been stated that specifying a dedicated budget for the NCSS is recommended rather than allocating money to an overarching authority. Main Observations Developing the budget from bottom to top: Assign coordinators to each action, create an implementation plan per action and estimate the number of resources and budget needed to reach the defined objective. Afterwards, all budget estimates are aggregated and an overall estimate for the implementation of the NCSS is drafted, which is then included in the budget of the authority in charge as well as in the national budget. Paragraph on financials in NCSS: The strategy itself includes a paragraph that identifying the country’s investments in cybersecurity and defines an overall budget for the implementation of the NCSS and its objectives. The budget is divided per stakeholder/ministry in charge, rather than per objective. 5.2.3 Elements of the strategic aspects of risk identification and mitigation

35

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Risk identification and mitigation supported by created agencies Setting up a strategy for risk identification and mitigation is highly important in order to be prepared for cyber threats and attacks, to identify and mitigate them. Desk research has shown that a common practice is to create specialised agencies to support the implementation and operationalisation of this element of governance. A small majority (58%) of the interviewed stakeholders mentioned that this element is part of the currently deployed governance model of their country. The creation of specific agencies providing services of risk identification and mitigation has been pointed out, as centralizing these aspects facilitates exchanges. It has been indicated that there seems to be a general lack of risk management if no dedicated agency is in place, but every critical infrastructure operator is responsible for risk identification and mitigation in their domain and this might create gaps or overlapping measures. Nevertheless, not creating dedicated authorities does not necessarily imply a lower level of efficiency in risk identification and mitigation, e.g., the national cybersecurity responsible agency could also be appointed the responsibility and lead the national activities. Main Observations Thorough risk identification across different levels: Agencies for identifying and mitigating risks are created at national level, these deal with the central government and critical entities. In addition, specific entities are created across the main sectors to cover risk identification and mitigation from a more domain specific angle, e.g., health, economic affairs, or climate. Lastly, leveraging on existing security and intelligence agencies, whose responsibilities have been extended to also cover cybersecurity aspects, could be a third option to build bodies responsible for risk identification. These three options could be used complementary or as stand-alone. Early on identification of risks and implementation of risk assessment: Discussions to identify risks should take place during the process of drafting the NCSS already. The process includes stakeholders from the competent authorities, agencies and private sector as well as additional experts. The discussions should support on identifying potential risks, assessing the risks and developing measures to address these. The developed measures can be included in the NCSS or an accompanying action plan, highlighting responsible actors, identifying actions, and objectives.

36

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Coherent approach for risk identification and mitigation across government entities and other critical infrastructure operators GOOD PRACTICE Applying a coherent approach for risk identification and mitigation across the involved government entities and other involved critical infrastructure operators has been identified as Daily important element of the strategic governance level. It facilitates exchange and information communication: sharing in case needed and foster cooperation between the involved entities. The majority CERT bodies which (74%) of country representatives interviewed, confirmed this and pointed out that although a are the main bodies coherent approach is difficult to implement, it is most often a clear goal of the NCSS. responsible for the risk identification and While creating dedicated agencies for risk identification and mitigation facilitates the process, it mitigation includes the risk of separating processes and actors and each body leveraging its own communication on approach. Hence, this might hamper collaboration, cooperation and communication, which are daily basis. In essentials for risk mitigation. Therefore, adopting a common and coherent approach is crucial. addition, working groups exchange opinions on an ad- Main Observations hoc basis on specific Following a common methodology for risk identification: A document defining a issues, through common methodology for identifying risks should be developed early during the process defined of drafting the NCSS or when developing the governance model. Not differentiating communication between public and private actors, the document provides a solid methodological baseline channels. for taking up a common approach for risk identification and mitigation across all involved actors. Following a common framework in case of incidents: Some countries set-up a dedicated framework, which should be followed in case of incidents. The framework includes step-by-step processes for different actors in case of specific incidents or risks identified. The framework includes measures to be taken and also outlines dedicated comprehensive requirements which need to be undertaken in case of risk identification. This facilitates the uptake of a common approach across different actors.

37

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Mechanisms to ensure accountability, transparency, and human rights during risk identification and mitigation GOOD PRACTICE During risk identification and mitigation, accountability is a particularly important element to Every institution in ensure that the objectives of a strategy will be achieved. Responsibilities are allocated and charge of people need to be accountable for the actions to be taken in order to reach the objectives set implementing actions, out by the strategy. Setting-up mechanisms to ensure accountability of all actors involved is policies, and projects hence an important element of strategic governance to already ensure accountability from the under the NCSS is set-out. Similarly, transparency is an important aspect during risk identification and mitigation, responsible to ensure which needs to be ensured throughout all processes as to increase respect and acceptance by accountability and all players but also by the society as a whole. Developing mechanisms to ensure transparency transparency. The has also been proven to be an important element of strategic governance. Last but not least, government of ensuring human rights in the digital sphere is particularly important in the context of Lithuania then cybersecurity and mechanisms need to be planned, developed and deployed to ensure human assesses from a rights in general, and personal data protection in particular, while improving cybersecurity. strategic level how the agencies and Discussing, developing and deploying these mechanisms for the NCSSs from an early point has institutions perform been proven as important and the interviewed stakeholders confirmed this finding, as more than the actions according two-thirds (67%) of the interviewees stated that these mechanisms are at least partially in place to pre-defined in their country’s governance model. measures on accountability and transparency. Main Observations Definition of accountability and transparency rules: Rules and mechanisms to ensure accountability are clearly laid down in official documents, i.e., in the NCSS itself, its implementation/ action plan, and accompanying legal documents. Clearly defining the rules and mechanisms of accountability and transparency in the documents helps to ensure these aspects throughout the implementation. Legislation ensuring human rights: Legislation on human rights is available in all Member States, nevertheless, additions and updates of existing and additional legal measures have been put in place to ensure human rights in the context of cybersecurity, in some Member States.

38

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

5.3 OPERATIONAL GOVERNANCE Operational governance aims at operationalising the policies set out in the strategy to translate these into actions and improve cybersecurity across all layers of society. Specific elements of operational governance refer to: a) Elements about awareness-raising campaigns, outreach campaigns and training to foster capacity-building; • Awareness raising, knowledge and capacity building (e.g., training, education, community building, etc.) within the complete workforce/population; • Awareness raising, knowledge and capacity building (e.g., training, education, community building, etc.) within the cybersecurity-relevant workforce; b) Elements about incident response; • Incident response mechanisms and support of CSIRTs and CERTs; c) Elements about information-sharing processes and channels; • Informal and formal processes of information sharing during incident response; All these elements have been validated by the stakeholders interviewed. 95% of the interviewed stakeholders confirmed that operational governance builds a part of their country’s governance model. Similarly, all identified elements have been validated by a majority of the interviewed stakeholders, as deployed in Figure 10. Figure 10: Percentage of interviewed stakeholders confirming elements of operational governance

Source: Authors’ own elaboration.

39

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

5.3.1 Elements about awareness raising campaigns, outreach campaigns and trainings to foster capacity-building Awareness-raising, knowledge and capacity building (e.g., training, education, community building, etc.) within the complete workforce/population GOOD PRACTICE Raising awareness for cybersecurity across the whole workforce and/or the complete population is the main aim of many of the NCSSs of the Member States. It has been confirmed that a huge In 2018, Malta risk emerges from a population being unaware of cyber risks and being untrained on how to launched the cope with these or how to safely behave in the cyberspace. Hence, training and education as nationwide well as awareness campaigns seem essential to increase the general level of knowledge and cybersecurity the general population’s capacity about cybersecurity. awareness and education campaign. As depicted in Figure 10, 89% of the consulted countries pointed out that awareness-raising It targets different campaigns as well as educational campaigns targeting the overall population are already in actors, from the place to increase the capacity of the general population and to increase their awareness of private and public cyber risks. Nevertheless, while the importance of increasing awareness has been pointed out, sectors, it has also been stated that awareness raising comes with challenges and is a difficult topic to professionals, teens, cover thoroughly. the elderly, children, educators, vulnerable groups, Main Observations public, etc. Tailored awareness raising and training campaigns: Tailoring awareness raising and training campaigns to different stakeholder groups is important in order to account for the different needs and capabilities of the groups. Possible groups reflect businesses and other private sector entities, IT staff, cybersecurity specific staff, academia, and civilians. Awareness raising, knowledge and capacity building (e.g., training, education, community building, etc.) within the cybersecurity relevant workforce. GOOD PRACTICE It has been proven beneficial, to particularly raise awareness and knowledge on cyber, cyber MITA (Malta threats and risks and cybersecurity among the people of the workforce which is most involved Information with and closely related to cybersecurity. Generally, the cybersecurity relevant workforce, most Technology Agency) often has awareness of and skills in cybersecurity. However, cybersecurity being part of the was mandated with quickly developing cyberspace necessitates constant training and education to keep up with the role of a national changes, developments and new challenges. Additionally, it has been pointed out that there is a coordination centre scarcity of skilled workforce in the cybersecurity domain, which implies that the workforce needs for training and to be enlarged through policies aiming on training and education in the field of cybersecurity. awareness-raising. Currently, MITA is Similar to raising awareness and improving skills of the whole population, 89% of the consulted collaborating with the countries mentioned that this element constitutes an important part of their governance model. University of Malta Awareness raising and training campaigns are covered to different extents by the countries’ and other governance models. Some countries simply point out the importance and the objective to stakeholders for the increase these aspects, while other countries are already more advanced, developing this creation of masters element and provide concrete mechanisms, measures and actions in their governance model. specialised in cybersecurity for example.

40

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

5.3.2 Elements of the incident response Incident response mechanisms and support of CSIRTs and CERTs GOOD Formalised processes for incident response are a main element defined in the operational governance level. Established CSIRT and CERT bodies provide support in case of PRACTICE cybersecurity incidents and provide a centralised contact point at national level to coordinate Platform to submit, and enable quick and systematic reactions to incidents. As specialised teams dedicated to share and react to developing and deploy mechanisms for cybersecurity in general and incident response in incidents: There are particular, CSIRT and CERT bodies build an incremental part of the operational governance in mechanisms for specific and the implementation and achievement of the NCSSs’ objectives in general. While sharing technical CSIRTs and CERTs provide support during incident response times, they can also play a information and for proactive role preventing incidents from happening and supporting governments in building pushing e.g., early resilience against cyber threats. warnings, news, etc. Recently, an online 89% of the interviewed countries confirmed the importance of CSIRT and CERT bodies for platform has been incident response (Figure 10). Further, they mentioned that incident response mechanisms are set-up, where it is part of their country’s governance model with CSIRTs and CERTs playing an important role in possible to receive supporting and leading these mechanisms. compliance and risk information from critical information infrastructures. Additionally, incidents can be submitted on the platform. These are synced with national CSIRT processes. If there is an incident notification, an immediate technical response can be triggered.

41

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

5.3.3 Elements of the information sharing processes Informal and formal processes of information sharing during incident response GOOD PRACTICES Establishing processes of information sharing is highly important to ensure coordinated reactions during incident response times. Formal pre-defined and transparent processes as well In Malta, a project has as informal ones should be developed and deployed. While formal processes of information been started to create a sharing often provide for and enhance accountability, informal ones might be more effective and specific team for efficient. information sharing called the “cyber threat As shown in Figure 10, 89% of the consulted countries confirmed that informal and formal intelligence team”. The processes of information sharing are important and constitute an element of the operational goal is to collect cyber governance level of their country’s governance model. threat intelligence from partners and share information. Main Observations Centralise information sharing. Activities to centralise and intensify information-sharing In the Netherlands, a have been undertaken by several Member States. survey has been started to examine the Taxonomy of best practices to ensure coherent processes of information sharing. Spain developed a taxonomy based on existing best practices and is deploying it across possibilities and modalities (legal, organisations to ensure a coherent approach towards information-sharing. financial, etc.) to develop a public-private cooperation platform to strengthen situational 5.4 TECHNICAL GOVERNANCE awareness and the timely The technical governance level has been proven to build a highly important part of the sharing of cyber threat governance model due to its role in the identification and implementation of standards at a information and national or international level, and definition of technical mechanisms. All representatives advisories. The goal is to indicated that technical governance is currently part of the governance model employed in their offer more information country. Specific elements of technical governance refer to: and a swifter perspective for action with relevant • Technical governance for cybersecurity based on international standards and organisations. When technical guidelines; and doing so, attention is also • Implemented/defined use of tools and technology. paid to cybersecurity requirements and the level of maturity of the recipients of relevant information. This survey is a follow-up of the existing cyber intel/info cell, a public cooperation platform of operational public organisations (NCSC, Police, Intelligence and Security Services and Public Prosecutor), where information on cyber threats and cyber incidents is brought together and is jointly assessed by those organisations.

42

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Figure 11: Percentage of interviewed stakeholders confirming elements of technical governance

Source: Authors’ own elaboration.

5.4.1 Technological standardisation Technical governance for cybersecurity based on international standards and technical guidelines The technical governance for cybersecurity based on international standards and technical guidelines has been identified as an important element of the technical governance. 74% of the interviewed Member States take this into account in their strategies (Figure 11). While this aspect is not addressed in all NCSS or is not very detailed, according to interviews with Member State representatives, this aspect is considered important. The use of technical standards is mentioned in the strategy; however, it is not specified which technical standards should be used. Main Observations Include in the NCSS and its governance model a section focused on the international standards and technical guidelines: this will ensure to be aligned with the other Member States. When developing this section, specify which technical standards should be used,

43

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

and define clear roles and responsibilities. To simplify the update of standards, the standards could be described in a document accompanying the NCSS and the governance model. A key enabler is the existence of a body that supervises the compliance of regulated entities with the European and international requirements. 5.4.2 Use of technology, tools and certification schemes Implemented/defined use of tools, technology and certification schemes The importance of the use of cybersecurity certification schemes as a tool to manage risk is highlighted by European agencies and will be enforced under the NIS2 directive. European cybersecurity certification schemes should apply to the majority of ICT products and services, and in particular, to all the services or activities provided by essential entities. The competent authorities should be empowered to apply sanctions consisting of the suspension of a certification or authorisation concerning part or all the services provided by an essential entity. Member States should establish a strategy to produce certificates for ICT solutions, either based on existing national schemes or next to come EU schemes, ensuring an ecosystem that can deliver certified solutions or participate to the certification of solutions through public or private conformity assessment bodies. Finally, their procurement policy or any implementation of national and/or EU laws should be based through the use of certified solutions. The use of tools and technologies was highlighted as an important element in implementing NCSSs, although this point is not developed in the strategies of some countries. Nine out of the 18 interviewed Member States take this into account in their strategies, and 53% of all interviewed stakeholders validated this element of technical governance, as shown in Figure 11. The representatives of the Member States interviewed stressed the importance of not only focusing on available standards but also taking into account improvements in technical security, based on the use of modern approaches to cybersecurity for the detection and handling of incidents. Threats and incidents are ever-evolving and hence, the instruments of cybersecurity to combat them need to quickly adapt. Main Observations Put in place in the NCSS action plan a group of tasks focused on using tools and technologies in respect to human rights, particularly to GDPR.

44

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

6. MONITORING A GOVERNANCE MODEL

Monitoring the governance model is an important factor to ensure the successful deployment of the governance model as well as for the successful implementation of the NCSS. Aiming to assess the effective implementation, monitoring mechanisms are hence highly important for the deployment of a governance model. Additionally, the use of an assessment framework can strengthen the accountability of the responsible stakeholders, foster progress in the deployment phase and provide insights for areas of improvements. Monitoring mechanisms can take different forms and levels of detail and granularity. For instance, a traffic light system could be employed to indicate whether the progress of implementation is on track (green), behind schedule (yellow) or at risk (red). Traffic light systems provide broader and more qualitative information on the progress. A more granular approach of establishing monitoring mechanisms includes the development of Key Performance Indicators (KPIs). KPIs are measurable values, in the context of governance models, they provide quantifiable information on the progress of the implementation of actions, policies, and rules. KPIs could be of both quantitative as well as qualitative nature. Another monitoring instrument used to evaluate the progress of the implementation of the governance model is reporting. This implies that accountable and responsible persons report on the progress of their specific actions to a higher-level authority. Reporting provides a more general overview of the progress and information are normally not quantifiable. It has to be mentioned that other forms of monitoring could be deployed that are completer and more fit for purpose. However, the interviews highlighted that the Member States prefer light assessment methodologies. The remainder of this section will provide an overview of the deployment of monitoring mechanisms for evaluating the progress of the implementation of the governance models accompanying the NCSSs across the EU Member States. 6.1 MONITORING MECHANISMS OF GOVERNANCE MODELS DEPLOYED ACROSS THE MEMBER STATES Figure 12 here below provides an overview of the adoption of monitoring mechanisms for the governance model across the interviewed countries. 17 out of the 18 consulted countries have some sort of monitoring mechanism in place, the majority (56%) already developed quantitative, and/or qualitative Key Performance Indicators. 17 % of the interviewed countries indicated that a traffic light system or another monitoring mechanism is in place to monitor and evaluate the progress of implementing the governance model and the NCSS. 5% of the interviewed countries mentioned that the evaluation of the progress of the implementation is based on reporting, provided by the accountable or responsible persons, per action or objective.

45

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Figure 12: Deployment of monitoring mechanisms across the interviewed EU Member States 5% KPIs 17% Traffic light system 5% Reporting 56% Other 17% not in place

Source: Authors’ own elaboration. Figure 13 provides a more granular view of the implementation of monitoring mechanisms per governance level. It emerges from the stakeholder consultation that the majority of countries has monitoring mechanisms in place for the strategic and operational governance levels. 58% of the interviewed countries have a partially or completely deployed monitoring mechanism to evaluate the progress of implementing the NCSS from a strategic governance point of view. 53% employed monitoring mechanisms on the operational governance level, while progress on deploying the technical level of governance is systematically monitored in 47% of the countries. The same percentage of countries deployed monitoring mechanisms for the political governance level. Figure 13: Monitoring mechanisms in place per level of governance

100% 90% 80% 70% 60% 50% 40% 30% 20% 10% 0% Strategic Political governance Operational Technical governance governance governance In place Partially in place Not in place No answer Source: Authors’ own elaboration. Generally, most countries monitor the progress by focusing on objectives or actions without creating a comprehensive assessment framework that could provide an overall index of progress.

46

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Good practices in the context of establishing monitoring mechanisms have been identified from the interviews with the Member States’ representatives. These are detailed here below. Good Practice – Extended set of KPIs to also monitor the state of cybersecurity across the population In Spain not only a set of KPIs has been established to monitor the progress of the implementation of the governance model, but a specific national observatory for cyber has been put in place. The observatory’s main function is to monitor the KPIs and to publish reports on the KPIs deployed to measure the progress of the implementation. In addition, the KPIs developed by Spain do not only cover the implementation of the governance model and the NCSS, but also aim at the wider objective of ensuring service and cybersecurity in the country. Therefore, additional KPIs have been introduced, which focus on the behaviour of citizens during incidents. Many of the KPIs are publicly available to also provide the population with the possibility to inform themselves about the current status of the country, the goals and the progress. Furthermore, more sensitive KPIs, focusing on more policy-specific aspects have been established. These however are not publicly available to ensure security. In Italy, it is foreseen develop specific measures and KPIs within the first twelve months after the adoption of the NCSS. The KPIs deployed will not only aim on measuring the progress of the implementation of the governance model and the NCSS, but some KPIs will aim at a more granular and more encompassing system to also measure: • Cybersecurity maturity; • Involvement of specific categories of persons (women, young, unemployed and jobseekers) in the cybersecurity training; • Involvement of specific categories of persons (women, young, unemployed and jobseekers) in the cybersecurity industry; • Cybersecurity investments; o Investments in and initiatives on cybersecurity research and development; • Number of national companies insured by cybersecurity incidents. Good Practice – Platform to enable the exchange of progress In Austria, the new NCSS is not only set up to follow a whole-of-nation/whole-of-society approach but also to allow to react to changing challenges and opportunities in the cyberspace. Accompanying the NCSS, a web platform has been developed to collect and monitor objectives, and actions and to measure progress dynamically. By using the PPPP-Model also non-governmental stakeholders are allowed to add to the platform facilitating information sharing and exchange. It provides insights into the progress of the implementation of the NCSS and its governance model. KPIs are developed to monitor the progress of reaching the strategic objectives and to implement the related measures. For every action, policy or measure of the governance model and the NCSS, a scorecard is created, each scorecard provides insights into the progress of the specific objective, action or measure. The monitoring on the scorecards is based on key project management principles in order to ensure granular and detailed monitoring of the progress. Twice a year a report based on the data on the platform is created and published on the website of the Austrian Federal Chancellery thus giving the public insights into the state of play of Austrian Cybersecurity. 6.2 POTENTIAL RE-USE OF EXISTING KPIS KPIs related to cybersecurity have been developed by different organisations already. The uptake of these indicators is encouraged, while some adjustment could be beneficial. Here

47

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

below a short explanation of three sets of KPIs related to cybersecurity is provided. The longlists of the KPIs deployed by the three sets are provided in the Annex of this report. 6.2.1 NCAF KPIs The national capabilities self-assessment framework (NCAF), developed by ENISA, aims at measuring the level of maturity of the different NCSSs. The framework specifically should empower the Member States in • Conducting the evaluation of their national cybersecurity capabilities. • Enhancing awareness of the country’s maturity level; • Identifying areas for improvement; and • Building cybersecurity capabilities. The framework provides an assessment of the NCSSs on 17 objectives, grouped into four main clusters across five levels of maturity. The four main clusters of objectives are the following: 1. Cybersecurity governance and standards; 2. Capacity-building and awareness; 3. Legal and regulatory; and 4. Cooperation. Among the different elements assessed to identify the level of maturity, there are some that refer to the governance model of an NCSS and can be extracted and reused to evaluate the governance model of a country. The specific indicators are listed in Annex B.1 of this report. 6.2.2 EU Cybersecurity Index ENISA is working since 2021 on the development of an EU Cybersecurity Index, a tool to help Member States making informed decisions by providing insights on the cybersecurity maturity and posture of the Union and MS policies, capabilities and operations. With a view to the tasks included in the latest NIS 2 Directive Proposal text , the EU Cybersecurity Index project of ENISA is expected to evolve in the direction of a biennial report on the state of cybersecurity in the Union. For this aim, a set of indicators is being defined which will provide a better understanding on which areas the EU will need to focus on to improve the overall Union cybersecurity. The development of the EU Cybersecurity Index is still work in progress and under consultation and piloting with the Member States’ National Authorities. Currently, the focus and indicators of the index will provide a better understanding on which areas the EU will need to focus on to improve the overall Union cybersecurity. As soon as the NIS2 Directive has been finalised, work will commence to evolve from the EU Cybersecurity Index project of ENISA to the new requirements defined in the NIS 2 Directive and in particular Art. 15. The main objectives of EU’s Cybersecurity Index include: • assessing the current level of maturity of cybersecurity and relevant cyber capabilities; • identifying opportunities for collaborative and local cybersecurity enhancements; and • identifying areas of network and information system security weaknesses which may provide a risk to the Union and its MS as well as its citizens, governmental structures, CI/CII and digital services, and small, medium, and large enterprises.

48

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

For the time being the EU Cybersecurity Index consists of 58 composite indicators in four areas: • Policy; • Operations; • Capacity; and • Market/industry The indicators are not yet publicly available but will be in due time. 6.2.3 ITU Global Cybersecurity Index indicators The International Telecommunication Union (ITU) is the UN agency dedicated to ICTs and launched the Global Cybersecurity Index (GCI) to measure the commitment to cybersecurity of the countries around the globe. Aiming to assist the countries to identify possible areas of improvement related to cybersecurity, the GCI’s main objective is to measure: • The type, level, and evolution over time of cybersecurity commitment within countries and relative to other countries; • The progress in cybersecurity commitment of countries from a global perspective; • The progress in cybersecurity commitment from a regional perspective; and • The cybersecurity commitment divide (i.e., the difference between countries in terms of their level of engagement in cybersecurity initiatives). The 2020 GCI consists of 82 questions feeding into 20 indicators, which are mapped across five main pillars. The main pillars of the GCI are: 1. Legal measures; 2. Technical measures; 3. Organizational measures; 4. Capacity development measures; and 5. Cooperation measures. All indicators are listed in Annex B.2 of this report. Under pillar 3, the organizational measures, the main indicator refers to the development, implementation and deployment of a national cybersecurity strategy. The specific questions feeding into this indicator are also listed in Annex B.2 of this report. 6.2.4 Cybersecurity Capacity Maturity Model for Nations (CMM) Developed by the Global Cyber Security Capacity Centre , the goal of the Cybersecurity Capacity Maturity Model for Nations (CMM) is to increase the scale and effectiveness of cybersecurity capacity-building. A first version of the model was deployed in 2014 and a revised version has been made available in 2016 and a new one in 2021. The CMM assesses cybersecurity capacity across five key dimensions, which – according to the model – represent the clusters of cybersecurity. The five dimensions are: 1. Developing cybersecurity policy and strategy; 2. Encouraging responsible cybersecurity culture within society; 3. Building cybersecurity knowledge and capabilities; 4. Creating effective legal and regulatory frameworks; and

49

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

5. Controlling risks through standards and technologies. The CMM is based on five maturity levels to evaluate a nation’s level of capacity and to measure progress in relation to specific factors and/or aspects of cybersecurity capacity: Startup; Formative; Established; Strategic; and Dynamic. The detail of each factor of the different dimensions are listed in Annex B.3 of this report. GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

7. CONCLUSION

Aimed at developing a good practice example of effective governance models for NCSSs, different governance frameworks across the EU and beyond have been analysed. Based on desk research of more than 49 sources, and 19 interviews with representatives of the EU Member States, the analysis of the Governance Framework for NCSS from March to July 2022 resulted in some conclusions that can be regarded as takeaways for the Member States. Identified through desk research, four main levels of governance frameworks have been identified as predominant. Specifically, these levels are: 1. Political governance; 2. Strategic governance; 3. Operational governance; and 4. Technical governance. This study’s research indicated that no evident correlation between the type of government, self-governance, and the governance model of the NCSS deployed exists. Rather, several additional factors such as the size of a country, its level of maturity in the cyber domain, and the level of cooperation with the private sector, influence the definition of a governance model. This finding led to the conclusion that it is not possible to have a unique governance model to be used as a reference. Therefore, good practices rather than a single best practice governance model have been identified for each layer. The four main levels of a governance framework have been further defined and sub-areas have been detailed through intensified desk research and interviews. These encompass all elements of good practice governance models.

51

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Figure 14: Good Practices of governance model elements

Source: Authors’ own elaboration.

In addition to the main elements governing the different levels of governance, the establishment of monitoring mechanisms, Key Performance Indicators (KPIs) and other measures to coherently monitor and evaluate progress, have been identified as important. KPIs and monitoring measures facilitate the finetuning of the strategy’s actions and the successful implementation of the NCSSs and the related governance model. With regard to KPIs, this study provides a list of KPIs already developed by different organisations, which could be adapted to the situation in different Member States.

52

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

8. BIBLIOGRAPHY / REFERENCES

Butcher, J., (1975). Copy-editing: The Cambridge handbook, Cambridge University Press, Cambridge. Council of Europe, (2001). Impact of the European Convention on Human Rights – Budapest Convention, Council of Europe Portal, available https://www.coe.int/en/web/impact-convention-human-rights/convention-on-cybercrime#/. Cybersecurity & Infrastructure Security Agency (CISA), (2017). Cybersecurity Governance Publications, CISA Publications, available https://www.cisa.gov/publication/cybersecurity-governance-publications. Cybersecurity foundation, (2021). The NCS Guide 2021, available https://ncsguide.org/the-guide/. European Communities, (1990). Economic transformation in Hungary and Poland, European Economy No 43, Office for Official Publications of the European Communities, Luxembourg, pp. 151-167. Efe, A. & Bensghir, K. T., (2019) cited in Savas S. & Karatas, S. (2022). Cyber governance studies in ensuring cybersecurity: an overview of cybersecurity, International Cybersecurity Law Review, 3:7, 2022, available https://link.springer.com/article/10.1365/s43439-021-00045-4. ENISA, (2020). National Capabilities Assessment Framework, ENISA Publications, available at: https://www.enisa.europa.eu/publications/national-capabilities-assessment-framework. ENISA, (2012). National Cyber Security Strategies: An Implementation Guide, ENISA Publications, available https://www.enisa.europa.eu/publications/national-cyber-security-strategies-an-implementation-guide. ENISA, (2016). NCSS Good Practice Guide, ENISA Publications, available https://www.enisa.europa.eu/publications/ncss-good-practice-guide. ENISA, (2018). Public-Private Partnerships (PPP) – Cooperative models, ENISA publications, available https://www.enisa.europa.eu/publications/public-private-partnerships-ppp-cooperative-models. ENISA, (2014). Threat Landscape report, European Union Agency for Network and Information Security. European Parliament and Council, (2016). Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union – NIS Directive, EUR-Lex, available https://eur-lex.europa.eu/eli/dir/2016/1148/oj. European Parliament and Council, (2019). Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act) – EU Cybersecurity Act, EUR-Lex, available https://eur-lex.europa.eu/eli/reg/2019/881/oj. Hamm, E., (1980). Return of the English breakfast, International Cuisine, Vol. X, No 1, Unwin, London. ISO, (2015). ISO/IEC 38599:2015 Information technology – Governance of IT for the organization, available https://www.iso.org/standard/62816.html. ITU, (2021). Global Cybersecurity Index, ITU Publications, available https://www.itu.int/pub/D-STR-GCI.01-2021.

53

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Marsh & McLennan, (2021). MMC Cyber Handbook 2021 – Cyber Resilience Perspectives: Clarity in the midst of Crisis, MarshMcLennan Publications, available https://www.marshmclennan.com/insights/publications/2020/october/mmc-cyber-handbook-2021-.html. NIST, (2022). Computer Security Resource Center, Glossary, last updated 2022, available https://csrc.nist.gov/glossary. NIST, (2020a) Success Stories – Israel National Cyber Directorate v. 1.0, available https://www.nist.gov/cyberframework/success-stories/israel-national-cyber-directorate-version-20. NIST, (2020b). Success Stories – Japanese Cross-Sector Forum, available https://www.nist.gov/cyberframework/success-stories/japanese-cross-sector-forum. NIST, (2018). Cybersecurity Framework, NIST Publications, 2018, available, https://www.nist.gov/cyberframework/resources. Savas, S. & Karatas, S., (2022). Cyber governance studies in ensuring cybersecurity: an overview of cybersecurity, International Cybersecurity Law Review, 3:7, available https://link.springer.com/article/10.1365/s43439-021-00045-4. Sutherland, E., (2018). Cybersecurity: Governance of a New Technology, in: Proceedings of the PSA18 Political Studies Association International Conference, Cardiff, 26-28 March 2018, available https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3148970. UK Cabinet Office, (2022). Government Cyber Security Strategy: 2022 to 2030, policy paper published by the UK Government, available https://www.gov.uk/government/publications/government-cyber-security-strategy-2022-to- 2030.

54

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

A ANNEX: ORGANISATIONAL CHARTS OF MEMBER STATES CYBERSECURITY ENTITIES

This Annex provides and overview of the different organisational charts of the Member States’ political set-up for cybersecurity. Each organisational chart indicates the different levels and stakeholders involved in cybersecurity policies of the country and particularly in setting up the governance model for the NCSS. A.1 AUSTRIA Source: Austrian Cybersecurity Strategy, 2021.

55

GOVERNANCE FRAMEWORKS FOR NCSS February 2023 A.2 BELGIUM Source: Cyber security strategy Belgium, 2021. A.3 CROATIA Source: Security Intelligence system of the Republic of Croatia, 2022. 56 GOVERNANCE FRAMEWORKS FOR NCSS February 2023 A.4 CYPRUS Source: Greek cybersecurity strategy, 2020. A.5 CZECH REPUBLIC Source: National Cyber Security Strategy of the Czech Republic 2021 – 2025. 57 GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

A.6 ESTONIA Source: Estonian Cyber Security Strategy. Source: Estonian Cyber Security Strategy.

58

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

A.7 ITALY Source: Italian Cyber Security Strategy. Source: Italian Cyber Security Strategy. Source: Italian Cyber Security Strategy. 59 GOVERNANCE FRAMEWORKS FOR NCSS February 2023 A.8 NETHERLANDS Source: The Netherlands cyber readiness glance paper. A.9 SPAIN Source: National Cybersecurity Strategy 2019. 60 GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

B ANNEX: EXISTING SETS OF KPIS

B.1 NCAF INDICATORS This section presents the ENISA National Capabilities Assessment Framework indicators. The indicators are organised by cluster. For each cluster, a table presents the comprehensive set of indicators in the form of questions representative of a given maturity level. B.1.1 Cluster #1: Cybersecurity governance and standards

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Do informal practices or activities Do you have mechanisms in place Do you cover the objective in Do you have an action plan that is Do you review your action plan exist that participate to reaching to ensure that the action plan is a your current NCSS or do you plan formally defined and regarding the objective to test its the objective in a non- dynamically adapted to to cover it in the next edition? documented? performance? coordinated manner? environmental developments?

Do you review your action plan Did you define intended results, Do you have an action plan with a regarding the objective to ensure b guiding principles or key activities clear resource allocation and that it is correctly prioritised and of your action plan? governance? optimised?

If relevant, is your action plan

c implemented and already

effective on a limited scope?

Did you start to work on building Do you have a doctrine/national Are you satisfied with the number Do you have a lesson learning national cyber contingency plans? strategy that includes Do you have a national-level or percentage of critical sectors process in place following cyber 1 – Develop national cyber 1 e.g., laying out the general goals, cybersecurity as a crisis factor cyber crisis management plan? included in the national cyber exercises or actual crises at contingency plans scope and/or principles of the (i.e., a blueprint, a policy, etc.)? contingency plan? national level? contingency plans…

Do you have a hub to acquire

information and inform decision

Is it generally understood that makers? i.e., any methods, Do you organise activities (i.e.,

cyber incidents constitute a crisis platforms or locations to ensure Do you have national-level cyber exercises) related to national Do you have a process to test the 2 factor that could threaten all crisis response actors can crisis-specific procedures? cyber contingency planning national plan regularly?

national security? access the same, real-time frequently enough?

information about the cyber-

crisis.

Have studies (technical, Are the relevant resources Do you have a communications Do you have sufficient people Do you have adequate tools and operational, political) been engaged to oversee the team specially trained to respond dedicated to crisis planning, look 3 platforms to build situational performed on the field of cyber development and execution of to cyber crises and inform the at the lessons learnt and awareness? contingency planning? national cyber contingency plans? public? implement change?

61

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Do you have a cyber threat Do you engage all relevant assessment methodology at national stakeholders (national Do you have sufficient people Do you follow a specific maturity 4 - national level that includes security, defence, civil protection, trained to respond to cyber crises model to monitor and improve procedures for impact law enforcement, ministries, at national level? the cyber contingency plan? assessment? authorities, etc.?) Do you have resources either Do you have adequate crisis specialised in threat anticipation 5 - - management facilities and - or working on prospective situation rooms? cybersecurity to address future crisis or tomorrow's challenges? Do you engage with international 6 - - stakeholders in the EU if - required? Do you engage with international 7 - - stakeholders in non-EU countries - if required?

Source: ENISA (2020), National capabilities assessment framework.

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Do informal practices or activities Do you have mechanisms in place Do you cover the objective in Do you have an action plan that is Do you review your action plan exist that participate to reaching to ensure that the action plan is a your current NCSS or do you plan formally defined and regarding the objective to test its the objective in a non- dynamically adapted to to cover it in the next edition? documented? performance? coordinated manner? environmental developments? Do you review your action plan Did you define intended results, Do you have an action plan with a regarding the objective to ensure b guiding principles or key activities clear resource allocation and that it is correctly prioritised and of your action plan? governance? optimised?

If relevant, is your action plan 2 – Establish baseline c implemented and already security measures effective on a limited scope?

Have you performed a study to identify requirements and gaps for public organisations based on internationally recognised Are the security measures drawn Is there a process to frequently Do you have a process to harden Are baseline security measures 1 standards? e.g., ISO27001, in compliance with update baseline security ICT when incidents fail to be mandatory? ISO27002, BS 15000, EN international/national standards? measures? addressed by the measures? ISO27799, PCI-DSS, CobiT, ITIL, BSI IT-Grundschutz, IETF, IEEE, NIST, FIPS, ITU, ISA, IEC, CIS...

62

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Have you performed a study to

identify requirements and gaps

for private organisations based Do you evaluate the relevance of Are private sector and other on internationally recognised Do you implement horizontal Is there a monitoring mechanism new standards that are stakeholders consulted when 2 standards? e.g., ISO27001, security measures across critical in place to examine uptake of developed in response to the defining baseline security ISO27002, BS 15000, EN sectors? baseline security measures? latest development in the threat measures? ISO27799, PCI-DSS, CobiT, ITIL, landscape?

BSI IT-Grundschutz, IETF, IEEE,

NIST, FIPS, ITU, ISA, IEC, CIS...

Is there a national authority for Do you implement sector specific Do you have or promote a checking whether baseline 3 - - security measures across critical national coordinated vulnerability security measures are enforced sectors? disclosure (CVD) process? or not?

Do you have a process in place to Are baseline security measures in identify non-compliant 4 - line with relevant certification organisations within a specific schemes? period of time?

Is there a self-risk assessment Is there an auditing process to

5 - - process in place for baseline ensure that the security measures -

security measures? are applied properly?

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Do you define or actively

encourage the adoption of secure

Do you review mandatory standards for the development of

2 – Establish baseline baseline security measures in the critical IT/OT products (medical 6 - - security measures procurement process of equipment, connected and

governmental bodies? autonomous vehicles,

professional radio, heavy industry

equipment…)?

Source: ENISA (2020), National capabilities assessment framework.

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Do informal practices or activities Do you have mechanisms in place Do you cover the objective in Do you have an action plan that is Do you review your action plan exist that participate to reaching to ensure that the action plan is a your current NCSS, or do you plan formally defined and regarding the objective to test its the objective in a non- dynamically adapted to 3 – Secure digital identity to cover it in the next edition? documented? performance? coordinated manner? environmental developments?

and build trust in digital

Do you review your action plan public services Did you define intended results, Do you have an action plan with a regarding the objective to ensure b guiding principles or key activities clear resource allocation and that it is correctly prioritised and of your action plan? governance? optimised?

63

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

If relevant, is your action plan c implemented and already effective on a limited scope?

Do you participate in European working groups to maintain Do you perform risk analyses to standards and/or design new Have you performed studies or determine the risk profile of the Do you collect indicators on requirements for electronic trust Do you promote privacy-bygap analyses to identify the needs assets or services before moving cybersecurity incidents involving services (e-signatures, e-seals, e- 1 design methodologies in all eto secure digital public services to them to the cloud or to engage the breach of digital public registered delivery services, time Government projects? citizens and businesses? any digital transformation services? stamping, website projects? authentication)? e.g., ETSI/CEN/CENELEC, ISO, IETF, NIST, ITU... Do you have a strategy to build or Do you include private Have you implemented mutual Do you actively participate in promote secure national stakeholders in designing and recognition of e-identification peer reviews as part of eID 2 electronic identification schemes delivering secure digital public means with other Member schemes notification to the (eIDs) for citizens and businesses? services? States? European Commission? Do you have a strategy to build or promote secure national electronic trust services (e- Do you implement a minimum 3 - signatures, e-seals, e-registered security baseline for all digital - delivery services, time stamping, public services? website authentication) for citizens and businesses?

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Do you have a strategy on Governmental cloud (a cloud Are any electronic identification computing strategy targeted schemes available to citizens and towards the government and businesses with a substantial or 4 - public bodies such as ministries, - high assurance level as defined in governmental agencies and the Annex of the eIDAS public administrations…) that 3 – Secure digital identity Regulation (EU) No 910/2014? takes into account the

and build trust in digital

implications for security?

public services

Do you have digital public services requiring electronic identification schemes with a 5 - - substantial or high assurance - level as defined in the Annex of the eIDAS Regulation (EU) No 910/2014?

64

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Do you have trust services

providers for citizens and

businesses (e-signatures, e-seals, 6 - - - e-registered delivery services,

time stamping, website

authentication)?

Do you foster the adoption of

baseline security measures for all

7 - - cloud deployment models (e.g., - -

Private, Public, Hybrid. IaaS, PaaS,

SaaS)?

Source: ENISA (2020), National capabilities assessment framework. B.1.2 Cluster #2: Capacity-building and awareness

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Do informal practices or activities Do you have mechanisms in place Do you cover the objective in Do you have an action plan that is Do you review your action plan exist that participate to reaching to ensure that the action plan is a your current NCSS, or do you plan formally defined and regarding the objective to test its the objective in a non- dynamically adapted to to cover it in the next edition? documented? performance? coordinated manner? environmental developments?

Do you review your action plan Did you define intended results, Do you have an action plan with a regarding the objective to ensure b guiding principles or key activities clear resource allocation and that it is correctly prioritised and of your action plan? governance? optimised?

If relevant, is your action plan

c implemented and already 4 – Establish an incident effective on a limited scope?

response capability

Do you have any mechanisms for Do you have informal incident Do you have incident response Have you defined and promoted early detection, identification, response capabilities managed Do you have at least one official capabilities for the sectors standardised practices for 1 prevention, response and within or between public and national CSIRT ? referred to in annex II of the NIS incident response procedures and mitigation of zero-day private sectors? Directive? incident classification schemes? vulnerabilities?

Do you evaluate your incident Does your national CSIRT(s) have response capability to ensure that a clearly defined scope of Is there a CSIRT cooperation you have the adequate resources 2 - intervention? e.g., depending on mechanism in your country to and skills to carry out the tasks the targeted sector, the types of respond to incidents? set out in point (2) of Annex I of incidents, the impacts the NIS Directive?

65

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Does your national CSIRT(s) have

an incident response capability in

accordance with Annex I of the Does your national CSIRT(s) have NIS Directive? i.e., availability, clearly defined relationships with physical security, business other national stakeholders continuity, international 3 - concerning national cybersecurity - cooperation, incident monitoring, landscape and incident response early warning and alerts capacity, practice (e.g., LEA, military, ISPs, incident response, risk analysis NCSC)? and situational awareness,

cooperation with private sector,

standard practices...

Is there a cooperation mechanism

4 - with other neighbouring - -

countries regarding incidents?

Have you formally defined clear

5 - - incident handling policies and - -

procedures?

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Is your national CSIRT(s)

participating in cybersecurity 6 - - - exercises both at national and

4 – Establish an incident international level?

response capability

Is your national CSIRT(s) affiliated

7 - - with FIRST (Forum of Incident - -

Response and Security Teams)?

Source: ENISA (2020), National capabilities assessment framework.

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Do informal practices or activities Do you have mechanisms in place Do you cover the objective in Do you have an action plan that is Do you review your action plan exist that participate to reaching to ensure that the action plan is a your current NCSS, or do you plan formally defined and regarding the objective to test its the objective in a non- dynamically adapted to to cover it in the next edition? documented? performance? coordinated manner? environmental developments?

5 – Raise user awareness

Do you review your action plan Did you define intended results, Do you have an action plan with a regarding the objective to ensure b guiding principles or key activities clear resource allocation and that it is correctly prioritised and of your action plan? governance? optimised?

66

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

If relevant, is your action plan c implemented and already effective on a limited scope?

Do you have mechanisms in place Have you identified a specific to ensure that awareness Is there a minimal recognition target audience for user campaigns are constantly from the government, private Have you developed Do you draw up metrics for awareness? e.g., general users, relevant regarding technological 1 sector or general users, that there communication plans/strategy for evaluating your campaign during young people, business users advancement, changes to the is a need to raise awareness on the campaigns? the planning stage? (which can be broken down threat landscape, legal cybersecurity and privacy issues? further: SMEs, OES, DSPs etc) regulations and national security directives? Are public agencies conducting Do you perform periodic cybersecurity awareness evaluation or study to measure Do you draw up a project plan to Do you have a process for campaigns within their Do you evaluate your campaigns attitude shift or behaviour 2 raise awareness on information creating content at governmental organisation on an ad-hoc basis? after execution? changes regarding cybersecurity security and privacy issues? level? e.g., in the wake of a and privacy matters across cybersecurity incident. private and public sectors? Do you have any mechanisms in Do you have resources available Do you have any mechanisms to place to identify the most Are public agencies conducting and easily identifiable (e.g., a identify target areas for raising relevant media or communication cybersecurity awareness single online portal, awareness awareness (i.e., ENISA Threat channel depending on the target Do you consult with behavioural 3 campaigns to the general public kits) for any users who seek to landscape, national landscapes, audience to maximise outreach experts to tailor your campaign on an ad-hoc basis? E.g., in the educate themselves on international landscapes, and engagement? e.g., different towards the target audience? wake of a cybersecurity incident. information on cybersecurity and feedback from national types of digital media, brochures, privacy issues? cybercrime centres, etc.) ? emails, teaching material, posters in busy areas, TV, radio… Do you bring stakeholders with experts and communications 4 - - teams together to create content?

5 – Raise user awareness

Do you involve and engage the private sector in your awareness 5 - - efforts to promote and - disseminate the messages to a wider audience? Do you prepare specific awareness initiatives for 6 - - - executives in the public, private, academic or civil society sectors?

Do you participate in ENISA 7 - - European Cybersecurity Month - - (ECSM) campaigns?

Source: ENISA (2020), National capabilities assessment framework.

67

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Do informal practices or activities Do you have mechanisms in place Do you cover the objective in Do you have an action plan that is Do you review your action plan exist that participate to reaching to ensure that the action plan is a your current NCSS or do you plan formally defined and regarding the objective to test its the objective in a non- dynamically adapted to to cover it in the next edition? documented? performance? coordinated manner? environmental developments? Do you review your action plan Did you define intended results, Do you have an action plan with a 6 – Organise cybersecurity regarding the objective to ensure b guiding principles or key activities clear resource allocation and exercises that it is correctly prioritised and of your action plan? governance? optimised?

If relevant, is your action plan c implemented and already effective on a limited scope?

Do you conduct crisis exercises in Do you involve all related Do you have a lesson learnt Do you have a cybersecurity other sectors (other than authorities of public Do you write after action analysis capacity for cyber 1 exercise program at national cybersecurity) at a national level administration? (Even if the reports/evaluation reports? (reporting processes, analysis, level? or pan-European level? scenario is sector-specific) mitigation)? Do you carry out or prioritise Do you have resources allocated cyber crisis management Do you involve the private sector Do you test national-level plans Do you have an established 2 to crisis management exercise exercises on vital societal in the planning and execution of and procedures? lessons learnt process? design and planning? functions and critical the exercises? infrastructure? Have you identified a Do you adapt the exercise coordinating body to oversee the Do you organise sector specific Do you participate in scenarios depending on the latest 3 - design and planning of exercises at national and/or cybersecurity exercises at pan- developments (technological cybersecurity exercises (public international level? European level? advancements, global conflicts, agency, consultancy...)? threat landscape…)?

6 – Organise cybersecurity

Do you align your crisis

exercises

Do you organise exercises across management procedures with 4 - - all critical sectors mentioned in - other Member States to ensure Annex II of the NIS Directive? effective pan-European crisis management? Do you have a mechanism in Do you organise inter-sectorial place to quickly adapt the 5 - - and/or cross-sectorial - strategy, plans and procedures cybersecurity exercises? from the lessons learnt during the exercises? Do you organise cybersecurity exercises specific to various 6 - - levels? (Technical and operational - level, procedure level, decisionmaking level, political level…)

Source: ENISA (2020), National capabilities assessment framework.

68

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Do informal practices or activities Do you have mechanisms in place Do you cover the objective in Do you have an action plan that is Do you review your action plan exist that participate to reaching to ensure that the action plan is a your current NCSS, or do you plan formally defined and regarding the objective to test its the objective in a non- dynamically adapted to to cover it in the next edition? documented? performance? coordinated manner? environmental developments?

Do you review your action plan Did you define intended results, Do you have an action plan with a regarding the objective to ensure b guiding principles or key activities clear resource allocation and that it is correctly prioritised and of your action plan? governance? optimised?

If relevant, is your action plan

c implemented and already

effective on a limited scope?

Do you have mechanisms in place

to ensure that trainings and Does your country encompass educational programmes are cybersecurity culture at the early Do you consider developing Do you urge personnel in the constantly relevant regarding Do you establish courses stage of students' education 1 cybersecurity training and private and public sector to be current and emerging dedicated to cybersecurity? path? For example, do you favour educational programmes? accredited or certified? technological developments, cybersecurity in middle-school changes to the threat landscape, and high-school? legal regulations and national

7 – Strengthen training and security directives?

educational programmes Do universities of your country Do you have national research Has your country developed Do you establish academic

offer PhDs in cybersecurity as an labs and educational institutions cybersecurity training or centres of excellence in 2 independent discipline and not as which are specialized in mentorship programs to support cybersecurity to act as hubs of

a computer science subject? cybersecurity? national start-ups and SMEs? research and education?

Do you actively promote the

Do you plan to train educators, addition of information security Do you encourage/fund Are academic institutions independently of their field, on courses in higher education not dedicated cybersecurity courses participating in leading information security and privacy only for computer science 3 - and training plans for employee’s discussions in the area of issues? e.g., online safety, students but also to any other member-state employment cybersecurity education and personal data protection, cyber- professional speciality? e.g., agencies? research internationally? bullying. courses tailored to the needs of

that profession.

Do you have cybersecurity Do you assess the skill gap courses and/or specialised (cybersecurity workers shortage) 4 - - curriculum for EQF (European in the area of information Qualifications Framework) level 5 security on a regular basis? to 8?

Do you encourage and/or support Do you foster networking and

initiatives to include internet information sharing between 5 - safety courses in primary and academic institutions, at both

secondary level education? national and international level?

69

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Do you involve the private sector

Do you fund or offer for free basic in any form in cybersecurity

6 - - cybersecurity trainings to education initiatives? e.g., course -

citizens? design and delivery, internships,

work placements…

7 - Strengthen training and Do you implement funding

educational programmes mechanisms to encourage the

Do you organise annual uptake of cybersecurity degrees?

7 - - information security events (e.g., e.g., scholarships, guaranteed -

hacking contests or hackathons)? apprenticeship/internship,

guaranteed jobs in specific

industry or roles in public sector

Source: ENISA (2020), National capabilities assessment framework.

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Do informal practices or activities Do you have mechanisms in place Do you cover the objective in Do you have an action plan that is Do you review your action plan exist that participate to reaching to ensure that the action plan is a your current NCSS, or do you plan formally defined and regarding the objective to test its the objective in a non- dynamically adapted to to cover it in the next edition? documented? performance? coordinated manner? environmental developments?

Do you review your action plan Did you define intended results, Do you have an action plan with a regarding the objective to ensure b guiding principles or key activities clear resource allocation and that it is correctly prioritised and of your action plan? governance? optimised?

If relevant, is your action plan

c implemented and already

8 – Foster R&D

effective on a limited scope?

Do you have a process to define Are R&D cybersecurity initiatives Do you pursue at a national level Have you performed studies or R&D priorities (e.g., emerging in line with relevant strategic Is there a plan to link R&D cooperation with any 1 analyses to identify cybersecurity topics for deterring, protecting, objectives, e.g., DSM, H2020, initiatives with real economy? international R&D initiatives R&D priorities? detecting, and adapting to new Digital Europe, EU cybersecurity related to cybersecurity? kinds of cyber-attacks)? strategy?

Are R&D priorities aligned with Is the private sector involved in Are there any national projects Is there an evaluation scheme in 2 - current or upcoming regulation setting up R&D priorities? related to cybersecurity in place? place for R&D initiatives? (national level)?

70

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Do you have local/regional start-

up ecosystems and other

networking channels (e.g., Do you participate in leading Are there any cooperation Is academia involved in setting up technological parks, innovation discussions in one or many 3 - agreements with universities and R&D priorities? clusters, networking cutting-edge R&D topics at other research facilities? events/platforms) to foster international level?

innovation (including for

cybersecurity start-ups)?

Are there any national R&D Is there investment in Is there a recognized institutional

8 – Foster R&D 4 - initiatives related to cybersecurity R&D programs in body overseeing cybersecurity -

cybersecurity? academia and the private sector? R&D activities?

Do you have industrial research

chairs in universities to bridge 5 - - - research subjects and market

needs?

Do you have dedicated R&D

6 - - funding programmes for - -

cybersecurity?

Source: ENISA (2020), National capabilities assessment framework.

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Do informal practices or activities Do you have mechanisms in place Do you cover the objective in Do you have an action plan that is Do you review your action plan exist that participate to reaching to ensure that the action plan is a your current NCSS, or do you plan formally defined and regarding the objective to test its the objective in a non- dynamically adapted to to cover it in the next edition? documented? performance? coordinated manner? environmental developments?

Do you review your action plan Did you define intended results, Do you have an action plan with a regarding the objective to ensure b guiding principles or key activities clear resource allocation and that it is correctly prioritised and of your action plan? governance? 9 – Provide incentives for the optimised?

private sector to invest in

If relevant, is your action plan

security measures

c implemented and already

effective on a limited scope?

Are there any private actors that Is there an industrial policy or Are there economic/regulatory or Do you focus incentives on react to incentives by investing in political will to encourage the Is the private sector involved in other types of incentives in place cybersecurity topics depending 1 security measures? e.g., investors development of the cybersecurity the design of incentives? to promote cybersecurity on the latest threat specialised in cybersecurity and industry? investments? developments? non-specialised investors

71

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Have you identified specific Do you provide incentives for the

cybersecurity topics to be private sector to focus on the Do you provide support (e.g., tax developed? e.g., cryptography, security of cutting-edge 2 - incentives) for cybersecurity privacy, new form of technologies? e.g., 5G, artificial start-ups and SMEs? authentication, AI for intelligence, IoT, quantum

cybersecurity… computing…

Do you provide tax incentives or

other financial motivation for 9 – Provide incentives for the 3 - - - private sector investors in private sector to invest in cybersecurity start-ups?

security measures

Do you facilitate access for

cybersecurity start-ups and SMEs 4 - - - in the public procurement

process?

Is there budget available to

5 - - provide incentives for the private - -

sector?

Source: ENISA (2020), National capabilities assessment framework.

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Do informal practices or activities Do you have mechanisms in place Do you cover the objective in Do you have an action plan that is Do you review your action plan exist that participate to reaching to ensure that the action plan is a your current NCSS, or do you plan formally defined and regarding the objective to test its the objective in a non- dynamically adapted to to cover it in the next edition? documented? performance? coordinated manner? environmental developments?

Do you review your action plan Did you define intended results, Do you have an action plan with a regarding the objective to ensure b guiding principles or key activities clear resource allocation and that it is correctly prioritised and of your action plan? governance? optimised?

10 – Improve the If relevant, is your action plan

c implemented and already

cybersecurity of the supply

effective on a limited scope?

chain

Do you use a security certification

scheme for ICT-based products Do you have a process in place to Do you have detection probes in Do you perform cybersecurity Have you performed a study on and services? e.g., SOG-IS MRA in update the cybersecurity key elements in the supply chain assessments all along the supply security good practices for supply Europe (Senior Officers Group for assessments of the supply chain to detect early sign of chain of ICT services and products 1 chain management used by Information Systems' Security, of ICT services and products in compromise? e.g., security in critical sectors (as identified in procurement in various industry Mutual Recognition Agreement), critical sectors (as identified in controls at ISP-level, security Annex II of the NIS (2016/1148) segments and/or in public sector? Common Criteria Recognition Annex II of the NIS (2016/1148) probes in major infrastructure Directive)? Arrangement (CCRA), national Directive)? components…-

initiatives, sectorial initiatives…

72

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Do you apply standards in public administrations' procurement Do you actively promote security Do you have a process in place to policies to ensure that providers and privacy by design best identify cybersecurity weak links of ICT products or services meet practices in ICT products and in the supply chain of critical 2 - baseline information security services development? e.g., sectors (as identified in Annex II requirements? e.g., ISO/IEC secure software development of the NIS (2016/1148) 27001 and 27002, ISO/IEC lifecycle, IoT lifecycle Directive)? 27036… Do you have mechanisms in place to ensure that ICT products and Do you develop and provide a services that are critical to OES centralised catalogues with are cyber-resilient (i.e., the ability extended information of existing 3 - - to maintain availability and safety information security and privacy against a cyber incident)? e.g., standards that are scalable for, through testing, regular and applicable by, SMEs? assessments, detection of compromised elements… Do you actively participate in the design of an EU certification 10 – Improve the framework for ICT digital cybersecurity of the supply products, services and processes Do you promote the chain as established in the EU development of certification cybersecurity act (Regulation (EU) 4 - schemes targeted at SMEs to - 2019/881)? e.g., participation in boost information security and the European Cybersecurity privacy standard adoption? Certification Group (ECCG), promoting technical standards and procedures for ICT products/services security Do you have any provisions in place to encourage large Do you provide any types of companies to increase the 5 - - incentives to SMEs to adopt cybersecurity of small enterprises security and privacy standards? in their supply chains? e.g., cybersecurity hub, training and awareness campaigns… Do you encourage software vendors to support SMEs by 6 - - ensuring secure default - configurations in products targeting small organizations?

Source: ENISA (2020), National capabilities assessment framework.

73

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

B.1.3 Cluster #3: Legal and regulatory

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Do informal practices or activities Do you have mechanisms in place Do you cover the objective in Do you have an action plan that is Do you review your action plan exist that participate to reaching to ensure that the action plan is a your current NCSS, or do you plan formally defined and regarding the objective to test its the objective in a non- dynamically adapted to to cover it in the next edition? documented? performance? coordinated manner? environmental developments?

Do you review your action plan Did you define intended results, Do you have an action plan with a regarding the objective to ensure b guiding principles or key activities clear resource allocation and that it is correctly prioritised and of your action plan? governance? optimised?

If relevant, is your action plan

c implemented and already

effective on a limited scope?

Is there a general understanding Do you have a methodology to Have you implemented the NIS Do you have a procedure to Do you create and update threat 1 that CII operators contribute to identify essential services ? (2016/1148) Directive? update the risk registry? landscape reports? national security?

11 – Protect critical Do you have other mechanisms in

information infrastructure, place to measure that the

OES, and DSP technical and organisational

measures implemented by OES

are appropriate to manage the Have you implemented the ECI risks posed to the security of Depending on the latest (2008/114) Directive on the network and information developments in the threat Do you have a methodology for identification and designation of 2 - systems? e.g., regular landscape, are you able to the identification of CIIs? European critical infrastructures cybersecurity audits, national onboard a new sector in your CIIP and the assessment of the need framework for the action plan? to improve their protection? implementation of standard

measures, technical tools

provided by the government such

as detection probes or system-

specific configuration review...

Depending on the latest

Do you have a national registry Do you review and consequently developments in the threat Do you have a methodology to 3 - for identified OES per critical update the list of identified OES landscape, are you able to adapt identify OES? sector? at least every two years? new requirements in your CIIP

action plan?

74

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

NCSS objective #

Do you have other mechanisms in place to measure that the technical and organisational measures implemented by digital service providers are appropriate to manage the risks posed to the Do you have a national registry security of network and Do you have a methodology to 4 - for identified digital service information systems? e.g., regular identify digital service providers? providers? cybersecurity audits, national framework for the implementation of standard measures, technical tools provided by the government such as detection probes or systemspecific configuration review... Do you have one or more national authority providing oversight on critical information Do you review and consequently Do you have a national risk infrastructure protection and the update the list of identified digital 5 - registry for identified or known security of network and service providers at least every risks? 11 – Protect critical information systems? e.g., as two years? information infrastructure, required per the NIS (2016/1148) OES, and DSP Directive Do you use a security certification scheme (national or Do you develop sector-specific international) to help OES and protection plans? e.g., including Do you have a methodology to 6 - digital service providers identify baseline cybersecurity measures map CII dependencies? secure ICT products? e.g., SOG-IS (mandatory or guidelines) MRA in Europe, national initiatives… Do you use a security certification scheme or qualification Do you deploy risk management procedure to assess service practices to identify, quantify and providers working with OES? e.g., 7 - - manage risks related to CIIs at a service providers in the field of national level? incident detection, incident response, cybersecurity audit, cloud services, smart cards… Do you have mechanisms in place Do you engage in a consultation to measure the compliance level 8 - - process to identify cross border of OES and digital service dependencies? providers with regards to baseline cybersecurity measures?

75

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Do you have any dispositions in Do you have a single point of place to ensure the continuity of contact responsible for the services provided by critical coordinating issues related to the information infrastructures? e.g., 9 security of network and crisis anticipation, procedures to information systems at national rebuild critical information level and cross-border systems, business continuity cooperation at Union level? without IT, air gap backup 11 – Protect critical procedures… information infrastructure, Do you define baseline OES, and DSP cybersecurity measures (mandatory or guidelines) for 10 digital service providers and all sectors identified in Annex II of the NIS (2016/1148) Directive?

Do you provide tools or 11 - - methodologies to detect cyber - incidents?

Source: ENISA (2020), National capabilities assessment framework.

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Do informal practices or activities Do you have mechanisms in place Do you cover the objective in Do you have an action plan that is Do you review your action plan exist that participate to reaching to ensure that the action plan is a your current NCSS, or do you plan formally defined and regarding the objective to test its the objective in a non- dynamically adapted to to cover it in the next edition? documented? performance? coordinated manner? environmental developments? Do you review your action plan Did you define intended results, Do you have an action plan with a regarding the objective to ensure b guiding principles or key activities clear resource allocation and that it is correctly prioritised and of your action plan? governance? optimised?

If relevant, is your action plan c implemented and already 12 – Address cybercrime effective on a limited scope?

Is your national legal framework fully complying with the relevant EU legal framework, including the Do you have interinstitutional Have you performed a study to Directive 2013/40/EU on attacks Do you collect statistics following training or training workshops for identify the law enforcement against information systems? e.g., Do you have units dedicated to the provisions of article 14 (1) of LEAs, Judges, prosecutors and 1 requirements (legal basis, Illegal access to information handle cybercrime in prosecution Directive 2013/40/EU (Directive national/governmental CSIRTs at resources, skills…) to effectively systems, Illegal system offices? on attacks against information a national level and/or at a address cybercrime? interference, Illegal data systems) ? multilateral level? interference, Illegal interception, Tools used for committing offences...

76

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Do you participate in coordinated

Have you performed a study to Do you collect separate statistics actions at international level to

identify the prosecutors and Do you have any legal provision on cybercrime? e.g., operational disrupt criminal activities? e.g. Do you have a dedicated budget 2 judges’ requirements (legal basis, addressing online identity theft statistics, statistics on cybercrime infiltration of criminal hacking allocated to cybercrime units? resources, skills…) to effectively and personal data theft? trends, statistics on cybercrime forums, organised cybercrime

address cybercrime? proceeds and induced damage… groups, dark web markets and

botnets takedowns…

Is there clear segregation of Do you have any legal provision Have you established a central Do you evaluate the adequacy of Has your country signed the duties across CSIRTs, LEAs and addressing online intellectual body/entity to coordinate the the training provided to LEAs, 3 Council of Europe Budapest the judiciary (prosecutors and property and copyright activities in the area of fighting judiciary and national CSIRT(s) Convention on Cybercrime? judges) when they cooperate for infringements? cybercrime? personnel to address cybercrime? addressing cybercrimes?

Have you established cooperation Do you perform regular Does your regulatory framework Do you have any legal provision mechanisms between relevant evaluations to ensure that you facilitate the cooperation 4 addressing online harassment or national institutions involved in have sufficient resources (human, between CSIRTs/LE and judiciary cyber-bullying? fighting cybercrime, including law budget and tools) dedicated to (prosecutors and judges)? enforcement national CSIRTs? cybercrime units within LEAs?

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Do you have any legal provision Do you perform regular Do you participate in building and

addressing computer-related Do you cooperate and share evaluations to ensure that you maintaining standardised tools

fraud? e.g., compliance with information with other Member have sufficient resources (human, and methodologies, forms and 5 provisions the Council of Europe States in the area of fighting budget and tools) dedicated to procedures to be shared with EU

Budapest Convention on against cybercrime? cybercrime units within stakeholders (LEAs, CSIRTs,

Cybercrime prosecution authorities? ENISA, Europol's EC3…)?

Do you have any legal provision

addressing child online Do you cooperate and share Do you have any advanced

protection? e.g., compliance with information with EU Agencies Do you have units dedicated mechanisms in place to deter

6 - provisions of Directive (e.g., Europol's EC3, Eurojust, courts or specialized judges to individuals from being attracted

2011/93/EU and the Council of ENISA) in the area of fighting handle cybercrime cases? to, or becoming involved in,

12 – Address cybercrime

Europe Budapest Convention on against cybercrime? cybercrime?

Cybercrime...

Have you identified an

operational national point of Do you have the adequate tools Does your country use EU contact to exchange information to address cybercrime? e.g., Do you have any dispositions Blueprint and/or the Law and to answer urgent information cybercrime taxonomy and dedicated to providing support Enforcement Emergency 7 - requests from other Member classification, tools to collect and assistance to victims of Response Protocol (EU LE ERP) to States relating to offences set out electronic evidence, computer cybercrimes (general users, SMEs, effectively respond to large scale in Directive 2013/40/EU forensics tools, trusted sharing large companies)? cyber incidents? (Directive on attacks against platforms...

information systems)?

77

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Have you established an interinstitutional framework and cooperation mechanisms between all relevant stakeholders Does your law enforcement Do you have standard operating (e.g., LEA, national CSIRT, 8 agency include a dedicated procedures to handle e-evidence? judiciary communities), including cybercrime unit? private sector (e.g., operators of essential services, service providers) where appropriate, to respond to cyber-attacks? Does your country participate in Have you designated, in training opportunities offered Does your regulatory framework accordance with Art. 35. 9 and/or supported by EU Agencies facilitate the cooperation - Budapest Convention, a 24/7 (e.g., Europol, Eurojust, OLAF, between CSIRTs and LE? point of contact? Cupola, ENISA)?

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Do you have mechanisms in place Have you designated an (e.g., tools, procedures) to Is your country considering operational 24/7 national point of facilitate the information adopting the 2nd additional contact for the EU Law exchange and the cooperation 10 - protocol to the Council of Europe - Enforcement Emergency between CSIRT/LE and possibly Budapest Convention on Response Protocol (EU LE ERP) to judiciary (prosecutors and judges) Cybercrime? respond to major cyber-attacks? in the area of fighting against cybercrime? Do you provide specialised training to stakeholders involved in addressing cybercrime (LEAs, 12 – Address cybercrime judiciary, CSIRTs) on a regular basis? e.g., training sessions on 11 filing/prosecuting cyber-enabled crimes, trainings on collecting electronic evidence and ensuring integrity throughout the digital chain of custody and computer forensics, among others Has your country ratified/acceded the Council of 12 - - Europe Budapest Convention on Cybercrime?

78

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Has your country signed and ratified the Additional Protocol (criminalisation of acts of a racist and xenophobic nature 13 - - - committed through computer systems) to the Council of Europe Budapest Convention on Cybercrime?

Source: ENISA (2020), National capabilities assessment framework.

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Do informal practices or activities Do you have mechanisms in place Do you cover the objective in Do you have an action plan that is Do you review your action plan exist that participate to reaching to ensure that the action plan is a your current NCSS, or do you plan formally defined and regarding the objective to test its the objective in a non- dynamically adapted to to cover it in the next edition? documented? performance? coordinated manner? environmental developments? Do you review your action plan Did you define intended results, Do you have an action plan with a regarding the objective to ensure b guiding principles or key activities clear resource allocation and that it is correctly prioritised and of your action plan? governance? optimised?

If relevant, is your action plan c implemented and already effective on a limited scope?

Do you have informal information sharing mechanisms on Do you have an incident reporting Do you have a mandatory Do you have a harmonised Do you create annual incidents 1 cybersecurity incidents between scheme for all the sectors under incident reporting scheme that is procedure for sectorial incident report? private organisations and the annex II of the NIS Directive? functioning in practice? reporting schemes? 13 – Establish incident national authorities?

reporting mechanisms

Have you implemented the notification requirements for telecommunication service providers in compliance with article 40 of the Directive (EU 2018/1972)? The Directive requires that Member States shall Is there a Are there any cybersecurity ensure that providers of public coordination/cooperation Do you have an incident reporting landscape reports in place or 2 - electronic communications mechanism for incident reporting scheme for sectors others than other kinds of analysis prepared networks or of publicly available obligations regarding GDPR, NISD, the ones under the NIS Directive? by the entity that receives the electronic communications article 40 (ex-art13a) and eIDAS? incident reports? services notify without undue delay the competent authority of a security incident that has had a significant impact on the operation of networks or services.

79

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Have you implemented the

notification requirements for

trust services providers in Do you measure the effectiveness compliance with article (19) of Do you have the adequate tools of incident reporting procedures? the eIDAS Regulation (Regulation to ensure the confidentiality and e.g., indicators on incidents that 3 - (EU) No 910/2014)? The article integrity of information shared have been reported through the (19) requires, among other via the various reporting appropriate channels, timing of requirements, that providers of channels? the incident report… trust services notify the

supervisory body about

significant incidents/breaches.

13 – Establish incident Have you implemented the

reporting mechanisms notification requirements for

digital service providers in

compliance with article (16) of

the NIS Directive? The article (16) Do you have a common requires that digital service Do you have a platform/tool to taxonomy at national level for 4 - providers notify the competent facilitate the reporting process? incident classification and root authority or national CSIRT cause categories? without undue delay of any

incident having a substantial

impact on the provision of a

service as referred to in Annex III

that they offer within the Union.

Source: ENISA (2020), National capabilities assessment framework.

80

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Do informal practices or activities Do you have mechanisms in place Do you cover the objective in Do you have an action plan that is Do you review your action plan exist that participate to reaching to ensure that the action plan is a your current NCSS, or do you plan formally defined and regarding the objective to test its the objective in a non- dynamically adapted to to cover it in the next edition? documented? performance? coordinated manner? environmental developments?

Do you review your action plan Did you define intended results, Do you have an action plan with a regarding the objective to ensure b guiding principles or key activities clear resource allocation and that it is correctly prioritised and of your action plan? governance? optimised?

If relevant, is your action plan

c implemented and already

effective on a limited scope?

Is the national data protection Do you perform regular Do you have any mechanisms in Have you performed studies or authority involved in Do you promote best practices on evaluations to ensure that you place to monitor the latest analyses to identify areas of cybersecurity related issue areas security measures and data 1 have sufficient resources (human, technological developments in improvement to better protect (e.g., drafting new cybersecurity protection by design for the budget and tools) dedicated to order to adapt relevant guidelines the rights of citizen's privacy? laws and regulations, defined public and/or private sector? the data protection authority? and legal provisions/obligations? minimum security measures)?

Have you developed a legal basis

at the national level to enforce Do you encourage organisations 14 – Reinforce privacy and the General Data Protection Do you actively Do you launch awareness raising and businesses to get certified data protection Regulation (Regulation EU No participate/promote R&D 2 - and training programs around against ISO/IEC 27701:2019 on 2016/679)? e.g., maintain or initiatives regarding privacy this topic? Privacy Information Management introduce more specific enhancing technologies (PET)? System (PIMS)? provisions or limitations to the

rules of the Regulation

Do you coordinate incident

3 - - reporting procedures with the - -

DPA?

Do you promote and support

development of technical

standards on information security 4 - - - and privacy? Are they specifically

tailored to small and medium

enterprises (SMEs)?

Do you provide practical and

scalable guidelines to support

different types of data controllers 5 - - - on meeting the privacy and data

protection legal requirements

and obligations?

Source: ENISA (2020), National capabilities assessment framework.

81

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

B.1.4 Cluster #4: Cooperation

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Do informal practices or activities Do you have mechanisms in place Do you cover the objective in Do you have an action plan that is Do you review your action plan exist that participate to reaching to ensure that the action plan is a your current NCSS, or do you plan formally defined and regarding the objective to test its the objective in a non- dynamically adapted to to cover it in the next edition? documented? performance? coordinated manner? environmental developments?

Do you review your action plan Did you define intended results, Do you have an action plan with a regarding the objective to ensure b guiding principles or key activities clear resource allocation and that it is correctly prioritised and of your action plan? governance? optimised?

If relevant, is your action plan

c implemented and already

effective on a limited scope?

Is it generally understood that

PPPs contribute to the raising of

the level of cybersecurity in the Depending on the latest country by different means? e.g., Do you have a national action Have you established national Have you established cross-sector technological and regulatory 1 sharing interests in the growth of plan for establishing PPPs? public-private partnerships? PPPs? developments, are you able to the cybersecurity industry, adapt or create PPPs? cooperation in building a relevant

cybersecurity regulatory

framework, foster R&D...

15 – Establish a public-

Do you establish a legal or private partnership (PPPs) In the established PPPs, do you contractual basis (specific laws, Have you established sector- 2 - also focus on public-public and NDAs, intellectual property) to specific PPPs? private-private cooperation? scope PPPs?

Do you promote PPPs among Do you provide funding for the 3 - - small and medium enterprises establishment of PPPs? (SMEs)?

Do public institutions lead the

PPPs overall? i.e., one single point

of contact from the public sector

governing and coordinating the

PPP, public bodies agree in Do you measure the outcomes of 4 - - advance on what they want to PPPs?

achieve, clear guidelines from

public administrations on their

needs and limitations to the

private sector…

Are you a member of the

European Cyber Security 5 - - - - Organisation (ECSO) contractual

public-private partnership (cPPP)?

82

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Do you have one or several PPPs 6 - - - working on CSIRT activities?

Do you have one or several PPPs

15 – Establish a public-

7 working on critical information

private partnership (PPPs)

infrastructure protection issues?

Do you have one or several PPPs

working on raising cybersecurity 8 - - - awareness and skills

development?

Source: ENISA (2020), National capabilities assessment framework.

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Do informal practices or activities Do you have mechanisms in place Do you cover the objective in Do you have an action plan that is Do you review your action plan exist that participate to reaching to ensure that the action plan is a your current NCSS, or do you plan formally defined and regarding the objective to test its the objective in a non- dynamically adapted to to cover it in the next edition? documented? performance? coordinated manner? environmental developments?

Do you review your action plan Did you define intended results, Do you have an action plan with a regarding the objective to ensure b guiding principles or key activities clear resource allocation and that it is correctly prioritised and of your action plan? governance? optimised?

If relevant, is your action plan

c implemented and already

effective on a limited scope?

16 – Institutionalise

cooperation between public Do you ensure cooperation

agencies channels dedicated to Do you have a national Are public agencies provided with cybersecurity exist at least cooperation scheme focused on uniform minimum information on Do you have informal between the following public cybersecurity? e.g., advisory Do public authorities participate the latest developments of the 1 cooperation channels between bodies: intelligence services, boards, steering groups, forums, in the cooperation scheme? threat landscape and public agencies? domestic law enforcement, councils, cyber centres or expert cybersecurity situational prosecution authorities, meeting groups awareness? government actors, national

CSIRT and the military?

Do you measure the successes Have you established cooperation and limits of the different 2 - - platforms to exchange cooperation scheme in fostering information? effective cooperation?

83

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Have you defined the scope of cooperation platforms (e.g., tasks 3 - - - and responsibilities, number of issue areas)?

Do you organise annual 4 - - - - 16 – Institutionalise meetings?

cooperation between public

agencies Do you have cooperation

mechanisms between competent authorities across geographical 5 - - regions? e.g., network of security - correspondents per region, cybersecurity officer in regional economic chambers…

Source: ENISA (2020), National capabilities assessment framework.

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Do informal practices or activities Do you have mechanisms in place Do you cover the objective in Do you have an action plan that is Do you review your action plan exist that participate to reaching to ensure that the action plan is a your current NCSS, or do you plan formally defined and regarding the objective to test its the objective in a non- dynamically adapted to to cover it in the next edition? documented? performance? coordinated manner? environmental developments? Do you review your action plan Did you define intended results, Do you have an action plan with a regarding the objective to ensure b guiding principles or key activities clear resource allocation and that it is correctly prioritised and of your action plan? governance? optimised?

If relevant, is your action plan c implemented and already 17 – Engage in international effective on a limited scope?

cooperation (not only with

EU MS) Do you have cooperation agreements with other countries Are national cybersecurity public Do you exchange information at Do you lead discussions on one or (bilateral, multilateral) or agencies in your country involved 1 Do you have an international strategic level? e.g., high-level many topics within multilateral engagement strategy? partners in other countries? e.g., in international cooperation policy, risk perception... agreements? information sharing, capacity- schemes? building, assistance… Do you have a single point of contact that can exercise a liaison Do you have informal Do you exchange information at Do you assess, on a regular basis, Do you lead discussions on one or function to ensure cross-border 2 cooperation channels with other tactical level? e.g., threat actors the outcomes of international many topics within international cooperation with Member State countries? bulletin, ISACs, TTPs… cooperation initiatives? treaties or conventions? authorities (cooperation group, CSIRTs network…)?

84

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

NCSS objective # Level 1 Level 2 Level 3 Level 4 Level 5

Do you lead discussions or negotiations in one or many Do you exchange information at topics within international groups Has public leadership expressed Do you have dedicated people operational level? e.g., of experts? e.g. The Global intention to engage in 3 involved in international operational coordination - Commission on the Stability of international cooperation in the cooperation? information, ongoing incidents, Cyberspace (GCSC), ENISA NIS field of cybersecurity? IOCs… cooperation group, UN Group of Governmental Experts on Information Security (GGE)...

Do you engage in international 4 - - - cybersecurity exercises?

Do you engage in international

17 – Engage in international

capacity building initiatives? e.g., cooperation (not only with 5 - - - trainings, skills development,

EU MS)

drafting standard procedures… Have you established mutual assistance agreements with other countries? e.g., LEAs activities, 6 - - - legal proceedings, mutualisation of incident response capabilities, sharing cybersecurity assets… Have you signed or ratified international treaties or conventions in the area of 7 - - cybersecurity? e.g., International - - Code of Conduct for Information Security, Convention on Cybercrime

Source: ENISA (2020), National capabilities assessment framework.

85

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

B.2 ITU GLOBAL CYBERSECURITY INDEX KPIS AND SPECIFIC QUESTIONS ON NATIONAL CYBERSECUIRTY STRATEGY B.2.1 Indicators 1. Legal Measures a. Cybercrime substantive law b. Cybersecurity regulation/legislation 2. Technical measures a. National/Government CIRT, CSIRT, CERT b. Sectoral CIRT/CSIRT/CERT c. National framework for implementation of cybersecurity standards d. Child online protection 3. Organizational measures a. National Cybersecurity strategy b. Responsible agency c. Cybersecurity metrics 4. Capacity development measures a. Public cybersecurity awareness campaigns b. Training for cybersecurity professionals c. Does your government/organization develop or support any educational programmes or academic curricula in cybersecurity d. Cybersecurity research and development programmes e. National cybersecurity industry f. Are there any government incentive mechanisms in place to develop capacity development, a cybersecurity industry? 5. Cooperative measures a. Bilateral agreements on cybersecurity cooperation with other countries b. Government participation in international mechanisms related to cybersecurity activities c. Cybersecurity multilateral agreements d. Partnerships with the private sector (PPPs) e. Inter-agency partnerships B.2.2 Questions on national cybersecurity strategy 1. Does your country have a national cybersecurity strategy/policy? i. Does it address the protection of national critical information infrastructures, including in the telecommunication sector? ii. Does it include reference to the national cybersecurity resilience? iii. Does it address the protection of national critical information infrastructures, including in the telecommunication sector? iv. Is the national cybersecurity strategy revised and updated on a continuous basis? v. Is the cybersecurity strategy open to any form of consultation with national experts in cybersecurity? 2. Is there a defined action plan/roadmap for the implementation of cybersecurity governance? 3. Is there a national strategy for Child Online Protection?

86

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

B.3 CYBERSECURITY CAPACITY MATURITY MODEL FOR NATIONS (CMM) B.3.1 Factor - D 1.1: National Cybersecurity Strategy

Aspect Start-Up Formative Established Strategic Dynamic

87

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Aspect Start-Up Formative Established Strategic Dynamic

Source: Global Cyber Security Capacity Centre (2021), Cybersecurity Capacity Model for Nations (CMM).

88

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

B.3.2 Factor - D 1.2: Incident Response and Crisis Management

Aspect Start-Up Formative Established Strategic Dynamic

89

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Aspect Start-Up Formative Established Strategic Dynamic

Cybersecurity

Source: Global Cyber Security Capacity Centre (2021), Cybersecurity Capacity Model for Nations (CMM). B.3.3 Factor - D 1.3: Critical Infrastructure (CI) Protection

Aspect Start-Up Formative Established Strategic Dynamic

90

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Aspect Start-Up Formative Established Strategic Dynamic

Source: Global Cyber Security Capacity Centre (2021), Cybersecurity Capacity Model for Nations (CMM). B.3.4 Factor - D 1.4: Cybersecurity in Defence and National Security

Aspect Start-Up Formative Established Strategic Dynamic

91

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Aspect Start-Up Formative Established Strategic Dynamic

Source: Global Cyber Security Capacity Centre (2021), Cybersecurity Capacity Model for Nations (CMM). B.3.5 Factor - D 2.1: Cybersecurity Mindset

Aspect Start-Up Formative Established Strategic Dynamic

92

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Aspect Start-Up Formative Established Strategic Dynamic

Source: Global Cyber Security Capacity Centre (2021), Cybersecurity Capacity Model for Nations (CMM). B.3.6 Factor - D 2.2: Trust and Confidence in Online Services

Aspect Start-Up Formative Established Strategic Dynamic

93

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Aspect Start-Up Formative Established Strategic Dynamic

94

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Aspect Start-Up Formative Established Strategic Dynamic

Source: Global Cyber Security Capacity Centre (2021), Cybersecurity Capacity Model for Nations (CMM). B.3.7 Factor - D 2.3: User Understanding of Personal Information Protection Online

Aspect Start-Up Formative Established Strategic Dynamic

95

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

B.3.8 Factor - D 2.4: Reporting Mechanisms

Aspect Start-Up Formative Established Strategic Dynamic

Source: Global Cyber Security Capacity Centre (2021), Cybersecurity Capacity Model for Nations (CMM). B.3.9 Factor - D 2.5: Media and Online Platforms

Aspect Start-Up Formative Established Strategic Dynamic

Source: Global Cyber Security Capacity Centre (2021), Cybersecurity Capacity Model for Nations (CMM).

96

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

B.3.10 Factor - D 3.1: Building Cybersecurity Awareness

Aspect Start-Up Formative Established Strategic Dynamic

97

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Aspect Start-Up Formative Established Strategic Dynamic

Source: Global Cyber Security Capacity Centre (2021), Cybersecurity Capacity Model for Nations (CMM).

98

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

B.3.11 Factor - D 3.2: Cybersecurity Education

Aspect Start-Up Formative Established Strategic Dynamic

99

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Aspect Start-Up Formative Established Strategic Dynamic

Source: Global Cyber Security Capacity Centre (2021), Cybersecurity Capacity Model for Nations (CMM). B.3.12 Factor - D 3.3: Cybersecurity Professional Training

Aspect Start-Up Formative Established Strategic Dynamic

100

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Aspect Start-Up Formative Established Strategic Dynamic

Source: Global Cyber Security Capacity Centre (2021), Cybersecurity Capacity Model for Nations (CMM). B.3.13 Factor - D 3.4: Cybersecurity Research and Innovation

Aspect Start-Up Formative Established Strategic Dynamic

101

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Source: Global Cyber Security Capacity Centre (2021), Cybersecurity Capacity Model for Nations (CMM). B.3.14 Factor - D 4.1: Legal and Regulatory Provisions

Aspect Start-Up Formative Established Strategic Dynamic

Substantive

Cybercrime

102

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Aspect Start-Up Formative Established Strategic Dynamic

Source: Global Cyber Security Capacity Centre (2021), Cybersecurity Capacity Model for Nations (CMM). B.3.15 Factor - D 4.2: Related Legislative Frameworks

Aspect Start-Up Formative Established Strategic Dynamic

Legislation exist.

103

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Aspect Start-Up Formative Established Strategic Dynamic

Source: Global Cyber Security Capacity Centre (2021), Cybersecurity Capacity Model for Nations (CMM).

104

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

B.3.16 Factor - D 4.3: Legal and Regulatory Capability and Capacity

Aspect Start-Up Formative Established Strategic Dynamic

105

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Aspect Start-Up Formative Established Strategic Dynamic

Source: Global Cyber Security Capacity Centre (2021), Cybersecurity Capacity Model for Nations (CMM). B.3.17 Factor - D 4.4: Formal and Informal Co-operation Frameworks to Combat Cybercrime

Aspect Start-Up Formative Established Strategic Dynamic

withForeign Law promotion and

106

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Source: Global Cyber Security Capacity Centre (2021), Cybersecurity Capacity Model for Nations (CMM). B.3.18 Factor - D 5.1: Adherence to Standards

Aspect Start-Up Formative Established Strategic Dynamic

107

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Aspect Start-Up Formative Established Strategic Dynamic

Source: Global Cyber Security Capacity Centre (2021), Cybersecurity Capacity Model for Nations (CMM).

108

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

B.3.19 Factor - D 5.2: Security Controls

Aspect Start-Up Formative Established Strategic Dynamic

109

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Aspect Start-Up Formative Established Strategic Dynamic

Cryptographic

Source: Global Cyber Security Capacity Centre (2021), Cybersecurity Capacity Model for Nations (CMM). B.3.20 Factor – D 5.3 Software Quality

Aspect Start-Up Formative Established Strategic Dynamic

Source: Global Cyber Security Capacity Centre (2021), Cybersecurity Capacity Model for Nations (CMM).

110

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

B.3.21 Factor - D 5.4: Communications and Internet Infrastructure Resilience

Aspect Start-Up Formative Established Strategic Dynamic

Source: Global Cyber Security Capacity Centre (2021), Cybersecurity Capacity Model for Nations (CMM).

111

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

B.3.22 Factor - D 5.5: Cybersecurity Marketplace

Aspect Start-Up Formative Established Strategic Dynamic

112

GOVERNANCE FRAMEWORKS FOR NCSS

February 2023

Aspect Start-Up Formative Established Strategic Dynamic

Source: Global Cyber Security Capacity Centre (2021), Cybersecurity Capacity Model for Nations (CMM).

113

-N -EN -231 -22 -04 TP ABOUT ENISA The European Union Agency for Cybersecurity, ENISA, is the Union’s agency dedicated to achieving a high common level of cybersecurity across Europe. Established in 2004 and strengthened by the EU Cybersecurity Act, the European Union Agency for Cybersecurity contributes to EU cyber policy, enhances the trustworthiness of ICT products, services and processes with cybersecurity certification schemes, cooperates with Member States and EU bodies, and helps Europe prepare for the cyber challenges of tomorrow. Through knowledge sharing, capacity building and awareness raising, the Agency works together with its key stakeholders to strengthen trust in the connected economy, to boost resilience of the Union’s infrastructure, and, ultimately, to keep Europe’s society and citizens digitally secure. More information about ENISA and its work can be found here: www.enisa.europa.eu. ISBN: 978-92-9204-604-0 DOI: 10.2824/850466

Fotnoter

  1. 1 European Parliament and Council, (2016). Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union – NIS Directive, EUR-Lex, available https://eur-lex.europa.eu/eli/dir/2016/1148/oj. 2 European Parliament and Council, (2019). Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act) – EU Cybersecurity Act, EUR- Lex, available https://eur-lex.europa.eu/eli/reg/2019/881/oj.
  2. 3 Savas S. & Karatas, S. Cyber governance studies in ensuring cybersecurity: an overview of cybersecurity, International Cybersecurity Law Review, 3:7, 2022, available https://link.springer.com/article/10.1365/s43439-021-00045-4.
  3. 4 Savas S. & Karatas, S. Cyber governance studies in ensuring cybersecurity: an overview of cybersecurity, International Cybersecurity Law Review, 3:7, 2022, available https://link.springer.com/article/10.1365/s43439-021-00045-4. 5 NIST Computer Security Resource Center, Glossary, last updated 2022, available https://csrc.nist.gov/glossary. 6 NIST Computer Security Resource Center, Glossary, last updated 2022, available https://csrc.nist.gov/glossary. 7 Council of Europe, Impact of the European Convention on Human Rights – Budapest Convention, Council of Europe Portal, 2001, available https://www.coe.int/en/web/impact-convention-human-rights/convention-on-cybercrime#/. 8 Savas S. & Karatas, S. Cyber governance studies in ensuring cybersecurity: an overview of cybersecurity, International Cybersecurity Law Review, 3:7, 2022, available https://link.springer.com/article/10.1365/s43439-021-00045-4. 9 ISO, ISO/IEC 38599:2015 Information technology – Governance of IT for the organization, 2015, available https://www.iso.org/standard/62816.html. 10 Efe, A. & Bensghir, K. T., cited in Savas S. & Karatas, S. Cyber governance studies in ensuring cybersecurity: an overview of cybersecurity, International Cybersecurity Law Review, 3:7, 2022, available https://link.springer.com/article/10.1365/s43439-021-00045-4.
  4. 11 UK Cabinet Office, Government Cyber Security Strategy: 2022 to 2030, policy paper published by the UK Government, 2022, available https://www.gov.uk/government/publications/government-cyber-security-strategy-2022-to-2030. 12 ITU, Global Cybersecurity Index, ITU Publications, 2021, available at https://www.itu.int/pub/D-STR-GCI.01-2021. Cybersecurity & Infrastructure Security Agency, Cybersecurity Governance Publications, CISA Publications, 2017, available https://www.cisa.gov/publication/cybersecurity-governance-publications. 14 Among others: ITU, Global Cybersecurity Index, ITU Publications, 2021, available at https://www.itu.int/pub/D-STR- GCI.01-2021; Savas S. & Karatas, S. Cyber governance studies in ensuring cybersecurity: an overview of cybersecurity, International Cybersecurity Law Review, 3:7, 2022, available https://link.springer.com/article/10.1365/s43439-021-00045-4; Sutherland,
  5. 15 Among others: Cybersecurity & Infrastructure Security Agency, Cybersecurity Governance Publications, CISA Publications, 2017, available https://www.cisa.gov/publication/cybersecurity-governance-publications; ITU, Global Cybersecurity Index, ITU Publications, 2021, available at https://www.itu.int/pub/D-STR-GCI.01-2021; Cybersecurity foundation, The NCS Guide 2021, 2021, available https://ncsguide.org/the-guide/; ENISA, NCSS Good Practice Guide, ENISA Publications, 2016, available https://www.enisa.europa.eu/publications/ncss-good-practice-guide. 16 ENISA, Public Private Partnerships (PPP) – Cooperative models, ENISA publications, 2018, available https://www.enisa.europa.eu/publications/public-private-partnerships-ppp-cooperative-models.
  6. 17 Savas S. & Karatas, S. Cyber governance studies in ensuring cybersecurity: an overview of cybersecurity, International Cybersecurity Law Review, 3:7, 2022, available https://link.springer.com/article/10.1365/s43439-021-00045-4; NIST Success Stories – Japanese Cross-Sector Forum, 2020, available https://www.nist.gov/cyberframework/success-stories/japanesecross-sector-forum. 18 ITU, Global Cybersecurity Index, ITU Publications, 2021, available at https://www.itu.int/pub/D-STR-GCI.01-2021. 19 Cybersecurity foundation, The NCS Guide 2021, 2021, available https://ncsguide.org/the-guide/.
  7. 20 Sutherland, E. Cybersecurity: Governance of a New Technology, in: Proceedings of the PSA18 Political Studies Association International Conference, Cardiff, 26-28 March 2018, SSRN, 2018, available https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3148970; Cybersecurity foundation, The NCS Guide 2021, 2021, available https://ncsguide.org/the-guide/ 21 Savas S. & Karatas, S. Cyber governance studies in ensuring cybersecurity: an overview of cybersecurity, International Cybersecurity Law Review, 3:7, 2022, available https://link.springer.com/article/10.1365/s43439-021-00045-4. 22 NIST Computer Security Resource Center, Glossary, last updated 2022, available https://csrc.nist.gov/glossary. 23 Cybersecurity foundation, The NCS Guide 2021, 2021, available https://ncsguide.org/the-guide/; Savas S. & Karatas, S. Cyber governance studies in ensuring cybersecurity: an overview of cybersecurity, International Cybersecurity Law Review, 3:7, 2022, available https://link.springer.com/article/10.1365/s43439-021-00045-4. 24 Cybersecurity foundation, The NCS Guide 2021, 2021, available https://ncsguide.org/the-guide/; Sutherland, E. Cybersecurity: Governance of a New Technology, in: Proceedings of the PSA18 Political Studies Association International Conference, Cardiff, 26-28 March 2018, SSRN, 2018, available https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3148970; NIST Computer Security Resource Center, Glossary, last updated 2022, available https://csrc.nist.gov/glossary. 25 ENISA, National Cyber Security Strategies: An Implementation Guide, ENISA Publications, 2012, available https://www.enisa.europa.eu/publications/national-cyber-security-strategies-an-implementation-guide. 26 Savas S. & Karatas, S. Cyber governance studies in ensuring cybersecurity: an overview of cybersecurity, International Cybersecurity Law Review, 3:7, 2022, available https://link.springer.com/article/10.1365/s43439-021-00045-4. 27 Marsh & McLennan, MMC Cyber Handbook 2021 – Cyber Resilience Perspectives: Clarity in the midst of Crisis, MarshMcLennan Publications, 2021, available https://www.marshmclennan.com/insights/publications/2020/october/mmccyber-handbook-2021-.html.
  8. 28 Marsh & McLennan, MMC Cyber Handbook 2021 – Cyber Resilience Perspectives: Clarity in the midst of Crisis, MarshMcLennan Publications, 2021, available https://www.marshmclennan.com/insights/publications/2020/october/mmccyber-handbook-2021-.html. 29 ENISA, Public-Private Partnerships (PPP) – Cooperative models, ENISA publications, 2018, available https://www.enisa.europa.eu/publications/public-private-partnerships-ppp-cooperative-models.. 30 Cybersecurity foundation, The NCS Guide 2021, 2021, available https://ncsguide.org/the-guide/. 31 Savas S. & Karatas, S. Cyber governance studies in ensuring cybersecurity: an overview of cybersecurity, International Cybersecurity Law Review, 3:7, 2022, available https://link.springer.com/article/10.1365/s43439-021-00045-4. 32 Savas S. & Karatas, S. Cyber governance studies in ensuring cybersecurity: an overview of cybersecurity, International Cybersecurity Law Review, 3:7, 2022, available https://link.springer.com/article/10.1365/s43439-021-00045-4. 33 Savas S. & Karatas, S. Cyber governance studies in ensuring cybersecurity: an overview of cybersecurity, International Cybersecurity Law Review, 3:7, 2022, available https://link.springer.com/article/10.1365/s43439-021-00045-4; Cybersecurity foundation, The NCS Guide 2021, 2021, available https://ncsguide.org/the-guide/.
  9. 34 Cybersecurity foundation, The NCS Guide 2021, 2021, available https://ncsguide.org/the-guide/. 35 Cybersecurity foundation, The NCS Guide 2021, 2021, available https://ncsguide.org/the-guide/; ITU, Global Cybersecurity Index, ITU Publications, 2021, available at https://www.itu.int/pub/D-STR-GCI.01-2021; Marsh & McLennan, MMC Cyber Handbook 2021 – Cyber Resilience Perspectives: Clarity in the midst of Crisis, Marsh McLennan Publications, 2021, available https://www.marshmclennan.com/insights/publications/2020/october/mmc-cyber-handbook-2021-.html.
  10. 36 Cybersecurity foundation, The NCS Guide 2021, 2021, available https://ncsguide.org/the-guide/; Marsh & McLennan, MMC Cyber Handbook 2021 – Cyber Resilience Perspectives: Clarity in the midst of Crisis, Marsh McLennan Publications, 2021, available https://www.marshmclennan.com/insights/publications/2020/october/mmc-cyber-handbook-2021-.html. 37 Cybersecurity foundation, The NCS Guide 2021, 2021, available https://ncsguide.org/the-guide/. 38 Sutherland, E. Cybersecurity: Governance of a New Technology, in: Proceedings of the PSA18 Political Studies Association International Conference, Cardiff, 26-28 March 2018, SSRN, 2018, available https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3148970; Cybersecurity & Infrastructure Security Agency, Cybersecurity Governance Publications, CISA Publications, 2017, available https://www.cisa.gov/publication/cybersecuritygovernance-publications. 39 ENISA, NCSS Good Practice Guide, ENISA Publications, 2016, available https://www.enisa.europa.eu/publications/ncssgood-practice-guide; Savas S. & Karatas, S. Cyber governance studies in ensuring cybersecurity: an overview of cybersecurity, International Cybersecurity Law Review, 3:7, 2022, available https://link.springer.com/article/10.1365/s43439- 021-00045-4; Cybersecurity foundation, The NCS Guide 2021, 2021, available https://ncsguide.org/the-guide/; ITU, Global Cybersecurity Index, ITU Publications, 2021, available at https://www.itu.int/pub/D-STR-GCI.01-2021; Cybersecurity & Infrastructure Security Agency, Cybersecurity Governance Publications, CISA Publications, 2017, available https://www.cisa.gov/publication/cybersecurity-governance-publications.
  11. 40 Cybersecurity foundation, The NCS Guide 2021, 2021, available https://ncsguide.org/the-guide/. 41 Savas S. & Karatas, S. Cyber governance studies in ensuring cybersecurity: an overview of cybersecurity, International Cybersecurity Law Review, 3:7, 2022, available https://link.springer.com/article/10.1365/s43439-021-00045-4; Cybersecurity & Infrastructure Security Agency, Cybersecurity Governance Publications, CISA Publications, 2017, available https://www.cisa.gov/publication/cybersecurity-governance-publications; NIST Computer Security Resource Center, Glossary, last updated 2022, available https://csrc.nist.gov/glossary. 42 ITU, Global Cybersecurity Index, ITU Publications, 2021, available at https://www.itu.int/pub/D-STR-GCI.01-2021.
  12. 43 Cybersecurity foundation, The NCS Guide 2021, 2021, available https://ncsguide.org/the-guide/. 44 ITU, Global Cybersecurity Index, ITU Publications, 2021, available at https://www.itu.int/pub/D-STR-GCI.01-2021. 45 Cybersecurity foundation, The NCS Guide 2021, 2021, available https://ncsguide.org/the-guide/ 46 Cybersecurity & Infrastructure Security Agency, Cybersecurity Governance Publications, CISA Publications, 2017, available https://www.cisa.gov/publication/cybersecurity-governance-publications. 47 Cybersecurity & Infrastructure Security Agency, Cybersecurity Governance Publications, CISA Publications, 2017, available https://www.cisa.gov/publication/cybersecurity-governance-publications. 48 Savas S. & Karatas, S. Cyber governance studies in ensuring cybersecurity: an overview of cybersecurity, International Cybersecurity Law Review, 3:7, 2022, available https://link.springer.com/article/10.1365/s43439-021-00045-4.
  13. 49 NIST, Cybersecurity Framework, NIST Publications, 2018, available, https://www.nist.gov/cyberframework/resources; NIST, Success Stories – Israel National Cyber Directorate v. 1.0, 2020, available https://www.nist.gov/cyberframework/success-stories/israel-national-cyber-directorate-version-20; Savas S. & Karatas, S. Cyber governance studies in ensuring cybersecurity: an overview of cybersecurity, International Cybersecurity Law Review, 3:7, 2022, available https://link.springer.com/article/10.1365/s43439-021-00045-4. 50 Savas S. & Karatas, S. Cyber governance studies in ensuring cybersecurity: an overview of cybersecurity, International Cybersecurity Law Review, 3:7, 2022, available https://link.springer.com/article/10.1365/s43439-021-00045-4.
  14. 51 The following Member States have been interviewed during this study: Austria, Belgium, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, Germany, Greece, Ireland, Italy, Lithuania, Malta, the Netherlands, Slovakia, Spain, Sweden.
  15. 52 A parliamentary political system is a democratic form of government in which the party (or a coalition of parties) with the greatest representation in the parliament (legislature) forms the government, its leader becoming prime minister or chancellor. 53 A presidential political system is a form of government in which a head of government, typically with the title of president, leads an executive branch that is separate from the legislative branch in systems that use separation of powers. 54 A semi-presidential political system is a system of government in which a president exists alongside a prime minister and a cabinet, with the latter two responding to the legislature of the state. 55 A unitary state is a system of political organization in which most or all the governing power resides in a centralized government. 56 A federal self-governance is characterized by a union of partially self-governing provinces, states, or other regions under a central federal government (federalism). 57 A devolved self-governance is a statutory delegation of powers from the central government of a sovereign state to govern at a subnational level, such as a regional or local level. It is a form of administrative decentralization. 58 A federated state is a territorial and constitutional community forming part of a federation. Such states differ from fully sovereign states, in that they do not have full sovereign powers, as the sovereign powers have been divided between the federated states and the central or federal government.
  16. 59 Proposal for a DIRECTIVE OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on measures for a high common level of cybersecurity across the Union, repealing Directive (EU) 2016/1148
  17. 60 Subject to review. The number of indicators might change based on consultations with cybersecurity experts coming from national authorities, EU Agencies, and the industry. 61 The Global Cyber Security Capacity Centre is part of the Oxford Martin School within the University of Oxford.
  18. 62 ENISA, National Capabilities Assessment Framework, 2020 ; Available at: https://www.enisa.europa.eu/publications/national-capabilities-assessment-framework. 50
  19. A national cybersecurity strategy has The national cybersecurity strategy
  20. been published.An assessment of and implementation plan are both
  21. country-specific national cybersecurity proactively reviewed to take account of Strategy review and renewal Processes for strategy risk has been conducted.The strategy broader strategic developments within processes are in place.Emerging development have been initiated.An reflects the needs and roles of relevant the country (political, economic, social, No national cybersecurity strategy cybersecurity risks are regularly outline/draft national cybersecurity stakeholders across government technical, legal and environmental).The exists, although planning processes assessed and used to update the Strategy strategy has been (national and sub-national), business country is an acknowledged authority for strategy development may have strategy and implementation Development articulated.Consultation processes and civil society.An implementation within the international community and begun.Advice may have been sought plan.The impact of the strategy on have been agreed for key stakeholder programme is in place which covers is supportingthe development of from international partners. risk and harm reduction groups, including private sector, civil the scope of the strategy.Mechanisms national and global cybersecurity isunderstood and is used to inform society and international partners. are in place to enable strategy ‘owners’ strategies.Cybersecurity considerations funding and priority decisions. to monitor achievement of outcomes, are embedded within other relevant
  22. address implementation issues and national-level strategies and
  23. maintain strategy alignment. implementation programmes.
  24. The content of the national
  25. cybersecurity strategy is based on a The content takes account of the comprehensive risk assessment that impact on cybersecurity risk of includes explicit links to wider national emerging technologies and their level economic and political policies Content exists that reflects country- use within critical infrastructure, the and strategies.The content includes The content takes account of the specific priorities and wider economy and society.The actions to raise public and impact of broader developments on circumstances.Links exist between outcomes defined in the strategy Various national policies and businessawareness, mitigate cybersecurity risk (political, economic, the strategy (or draft strategy) and are specific and measurable. strategies may exist that refer to cybercrime, establish incident response social, technical, legal and priorities such as national Metrics have been defined which cybersecurity, but these are not capability, promote public-private environmental).The content of the Content security,digital strategy and economic enable stakeholders to evaluate comprehensive and there is little partnership and protect critical national cybersecurity strategy development, but these are generally theeffectiveness of the strategy in evidence that these reflect specific infrastructure and the wider promotes and encourages bilateral and ad hoc and lack detail.The strategy reducing harm.Consideration has national priorities and circumstances. economy.Consideration has been multilateral co-operation between (or draft strategy) defines the key been given to how the beneficial given to how the national cybersecurity countries to ensurea secure, resilient outcomes against which success can outcomes of the strategy can be strategy might incorporate or support and trusted cyberspace. be evaluated. sustained beyond the strategy’s wider online policy objectives such as: lifetime, including how the child protection; the promotion of maintenance of new capabilities Human Rights; the promotion of will be financed. Equality, Diversity and Inclusion; and
  26. managing disinformation.
  27. A detailed implementation plan has
  28. been published including actions,
  29. responsible entities and resource
  30. budgets. The implementation plan Outcome-oriented metrics are involves relevant stakeholders across being used to monitor the impact government and other sectors.A co- A co-ordinated cybersecurity that the programme is having on ordinating body has been assigned. Mechanisms are in place to make implementation programme is being risk reduction (and other relevant The body has sufficient authority to more far-reachingchanges to the developed with relevant stakeholders strategy goals).There is evidence ensure that action ‘owners’ are held to programme in the event of significant involved, including the private sector of these metrics being used to No overarching national account.The resources required to changes in circumstance (political, Implementation and civil society.Actions within the refine action plans.Metrics (both cybersecurityimplementation deliver the actions of the programme economic, social, technical, legal and and Review programme have been assigned to progress and outcome-oriented programme has been developed. have been identified and are in place. environmental).The programme specific ‘owners’ but the availability of metrics) are drawn from a wide Budget shortfalls are identified and contributes to the global development adequate resources has not yet been variety of governmental, nonescalated to the relevant of outcome-oriented metrics and their confirmed.Mechanisms to review governmental and international authority.Programme review processes application. processes are limited or ad hoc. sources.There is independent and metrics are in place that allow oversight and/or assurance of the progress to be measured and risks, programme. issues and dependencies to be
  31. escalated to the relevant authority.
  32. These processes are adequately
  33. funded.
  34. An assessment has been made of how
  35. the international debates on The country is aware of the cybersecurity policy and related issues existence of international discussions The country is a leading actor in affect the country’s interests and There is limited awareness of the on cybersecurity policy and related building consensus, fostering inclusivity international standing. Specific The country is actively building principal international debates relating issues.The country may, on occasion, and shaping the international debates engagement objectives have been international communitiesof interest to cybersecurity policy (suchas participate in regional or international on key cybersecurity policy issues.The defined accordingly. Multiple around specific cybersecurity policy cybersecurity norms, mutual legal discussions on matters related to country is focused on the future, seeing stakeholders have been involved in this goals and promoting their International assistance, Internet Governance, data cybersecurity issues, but does not emerging issues (around new process.The country is actively adoption.The country makes a Engagement sovereignty, data protection).The generally play an active role.The technology or new types of threat), and participating in relevant international major contribution to regional/ country may benefit from regional/ country may participate in relevant is initiating new international debates bodies and forums, either directly or international operational bodies international operational collaboration operationalcollaboration and policy around the key issues.The country is through relevant representative and is actively involved in building networks but does not actively bodies (such as FIRST, regional actively involved in creating new bodies.Their voices are being heard and capacity in third-party countries. engage. CERT bodies, the IGF, or the UN regional/ international collaboration are having an impact.The country GGE), but takes mainly a passive mechanisms. actively contributes to regional/ role. international operational collaboration
  36. and policy bodies.
  37. Most major organisations have internal Some organisations and sectors have The criteria for categorising mechanisms for identifying and internal mechanisms for identifying and incidents are sufficiently flexible to categorising incidents.A central registry of categorising incidents within their cater for rapidly emerging Identification national- level cybersecurity incidents Insights arising from national level
  38. No process for identifying and purview.A process for identifying changes in the underlying and exists and a process for timely escalation incidents are routinely analysed in order categorising national-level national-level incidents is under technological or threat Categorisation of incidents, from the organisational to the to establish lessons and inform broader incidents exists. development.There is no central registry environment.The country is national level, is in place.Individual national cybersecurity policy and strategy. of Incidents in place but ad-hoc arrangements exist contributing to international best
  39. incidents are categorised according to for dealing with the most significant practice in incident identification severity and resources are allocated events. and categorisation. accordingly.
  40. A national body for incident response
  41. has been established. It has the resources,
  42. skills, documented processes and legal The national body undertakes a wide authorities required to address the range of range of engagement activities such as cyber incidentscenarios that the country is conveningcommunities of interest, A national CERT might exist but lacks likely to face (including out-of-hours running cross-sector exercises and sufficient resources and skills.Processes capability, if appropriate).Relationships and The government’s overall promoting best cybersecurity for managing incidents are still in protocols are in place to enable incident operational response is adaptive No organisation for national- practices.The national body innovates development.Some organisations from management co-ordinationbetween the to changes in the underlying level cyber incident response to provide a range of additional services public and private sectors have internal national body and other elements of the technical and threat exists.A few organisations may that improve the country’s ability to Organisation cybersecurity response mechanisms in public and private sectors.The role of sub- environment.The country is have internal cybersecurity prevent, detect, respond and recover place but co- ordination with the national national bodies in incident response is contributing to international best response mechanisms in place from threats.The national body is widely CERT is ad hoc.The role of sub-national clear and mechanisms are in place practice on how to organise but co- ordination is minimal. recognised as an authoritative voice on bodies is unclear.Bilateral co-operation toenable co-ordination between the operational responses to cybersecurity within the country.The with international partners is limited or ad national and sub-national levels.There is cybersecurity threats. effectiveness of the national body in hoc. regular sharing of threat and vulnerability reducing cyber risk and harm is information, and operational good practices regularly evaluatedand benchmarked between the national body and a wide against international good practice. range of public and private sector
  43. organisations, as well as international
  44. partners.
  45. Cybersecurity is fully integrated into the A national crisis management national crisis management framework and framework is in development and a the organisation responsible for crisis Lessons learnt from cyber crisis specific organisation has been allocated management is equipped to deal with a exercises are used to inform both The country is contributing to No framework exists for responsibility for leading national-level range of cybersecurity- related national crisis management policy and the debate on the integration of Integration of national- level crisis crisis response.Cybersecurity has been scenarios.The role of a cyber incident the national cybersecurity strategy and cyber into national management.Cybersecurity has recognised as relevant to national crisis management authority within the crisis implementation plan.International crisis andinternational crisis
  46. not been considered as a management, both as a factor in its own management process is well defined and planning and exercising with partners management.Emergency into National potential national-level crisis right and as an element of other crisis established, and escalation thresholds are exists and routinely includes communications capabilities are Crisis scenario.Emergency scenarios.An exercise programme is in fully understood.National crisis cybersecurity as an element.The capable of operating beyond the Management communication capabilities are development and includes cybersecurity- management scenarios with cybersecurity resilience of emergency country’s border in order to limited. based scenarios.Emergency components are regularly communications has been stress- support third- party countries and communication capabilities are in place exercised.Emergency communication tested against a wide range of potential global crisis responses. but may not be well integrated or lack systems are regularly tested for cyber scenarios. resilience to cyber disruption. resilience against a range of cybersecurityrelated scenarios.
  47. There is flexibility in the process for identifying CI assets to cater for There may be some The list of CI assets has been formalised and rapidly emerging changes in the appreciation of what incorporates a range of appropriate public and private The list of CI assets is adaptive to strategic underlying technological or threat constitutes a CI asset, A list of general CI assets, sector organisations.Specific operators have been shifts in the underlying technical, social and environment.The country is Identification but no formal sectors and operators has identified and are aware of their status.The list is kept economic environment.Interdependencies actively involved in the categorisation of CI been created. up to date to reflect changes in the country’s between sectors are managed.Cross-border identification and prioritisation of assets has been circumstances.Cross-border dependencies have been dependencies are managed. global CI assets.Cross-sector and produced. identified. cross-border dependencies are mitigated.
  48. The need for baseline CI operators are mandated by regulation to meet Regulatory frameworks are standards to govern CI appropriate cybersecurity standards (either in the form Novel approaches to regulatory supervision are sufficiently flexible to cater for There are no existing assets isacknowledged but of specific cyber regulation or as part of broader being developed to improve CI cybersecurity rapidly emerging changes in the Regulatory regulatory requirements these are not explicitly regulatory requirements).Mandatory breach reporting while also facilitating effective and efficient CI underlying technological or threat Requirements specific to the mandated in and vulnerability disclosure requirements are in place. service delivery.The country is promoting best environment.The country is cybersecurity of CI. regulation.Sector regulators Formal processes are in place to evaluate CI operator practice regulatory approaches at an international actively involved in establishing do not routinely assess CI compliance with regulatory standards and incident and level. regulatory approaches to assuring operators for compliance. vulnerability disclosure. global CI.
  49. CI operators are consistently implementing Many CI operators are recognised industry standards and the effectivenessof The country and its CI operators There is extensive collaboration among CI implementing good their cybersecurity controls are regularly are contributing to the international operators and with public authorities to develop A few CI operators cybersecurity practice.There assessed.Mechanisms are in place for operators to debate on global critical strategies that enhance collective may be implementing is some self-assessment share threat and vulnerability information, best infrastructure resilience.Experts Operational cybersecurity.The resilience of the critical goodcybersecurity against recognised industry practices and lessons learned from incidents and near from the regulators and CI Practice infrastructure ecosystem as a whole has been practices, but this is standards.Some informal misses.CI operators participate fully in national operators are recognised assessedagainst a range of scenarios, and inconsistent. arrangements exist for incident response and crisis management planning internationally for their contribution measures are in place to address systemic risks collaboration across and and exercising. Mechanisms are in place for public to addressing global infrastructure to the economy and society. within sectors. authorities to provide information and other practical protection challenges. support to CI operators, both pre- and post- incident.
  50. A strategy for cybersecurity for national security and defence has been formally adopted (stand-alone Strategy and doctrine are not The potential impact of or as part of a wider document).The strategy is Defence strategy includes appropriate static but are adaptive tochanging The potential impact cybersecurity on national security supported by appropriate legal authorities and considerations of deterrence.The country’s capabilities and to the geo-political of cybersecurity on and defence has been assessed and relevant operational doctrine and rules of defence and national security establishment and technical threat Defence Force national security and a strategy for addressing these risks engagement. These are consistent with international (alongside other stakeholders) is actively environment.The strategy is Cybersecurity defence may have is under development.This analysis humanitarian law.The dependence of national engaged in the global debate on designed to promote stability in Strategy been considered but includes risks to the ability of the security and military entities on the cybersecurity of international humanitarian law and norms of cyberspace. This includes has not been formally country’s military and other national other parts of the critical national infrastructure is behaviour as they relateto conflict in measures to predict and influence articulated. security assets to operate in a understood and is addressedin the defence cyberspace. Declaratory strategy and the strategies and actions and contested cyber environment. cybersecurity strategy.Cybersecurity considerations published doctrine may be part of this. reactions of potential allies and inform other elements of national security and adversaries. defence strategy, where relevant.
  51. Capabilities and organisational structures are in
  52. place and have been tested. Resourcing is provided Relevant deterrence and Specialist Specialist cybersecurity capability through the national military estimate or equivalent defence/resilience capabilities are in place, cybersecurity Defence cybersecurity Defence Force requirements are understood, and process.Operational doctrine and rules of forming part of the country’s defence capability within the capabilities are able to support Cybersecurity relevant organisational structures engagement are fully embedded in training.Specialist cybersecurity strategy.Cybersecurity is national security multilateral responses to shared Capability have been defined.Initial steps have intelligence resources are being applied to provide embedded in wider operational and establishment is national security challenges. been taken to establish these. support and are appropriately resourced.Mechanisms command training within the country’s limited. to facilitate collaboration with allies are in place and military forces.
  53. have been tested.
  54. Collaboration on cybersecurity between civil and
  55. defence entities exists and has been Civil defence collaboration on
  56. formalised.Respective roles have been defined within cybersecurity is built into the strategic
  57. Informal collaboration on the country’s crisis management procedures.The planning of both sectors and designed to The country is leading the Collaboration on cybersecurity between civil and resources required within the defence and national address a range of future crisis international debate on best Civil Defence cybersecurity between defence entities may exist but has security community, to support civil and CI scenarios.Mechanisms are in place that practice in cross-governmental, Co-ordination civil and defence not been formalised.Defence entities authorities, have been formally assessed and enable defence and the national security civil-defence cybersecurity entities is limited. have not been formally resourced to assigned.Formal mechanisms are in place to community to draw on the skills and collaboration. undertake this work. determine military/ national security cybersecurity capabilities of the broader economy and
  58. dependencies on civil and CI infrastructure. The society. (For example, via a formal cyber
  59. ability of civiland CI infrastructure operators to provide reserve force)
  60. these services has been assured.
  61. There is widespread Government agencies at all levels are
  62. Leading government agencies have awareness of cybersecurity fully aware of cybersecurity risks and The government has minimal or no Government agencies across all levels are a minimal level of awareness of risks within most government use them to update cybersecurity level of awareness of cybersecurity aware of cybersecurity risks and proactively cybersecurity risks.Leading private agencies.There is widespread policies and operational practices.Most risks.The private sector has minimal anticipating new risks.Private sector actors at Awareness firms have a minimal level of awareness of cybersecurity private sector actors across all levels or no level of awareness of all levels are fully aware of cybersecurity risks of Risks awareness of cybersecurity risks.A risks within most private firms.A mitigate cybersecurity risks and use cybersecurity risks.Users have and are anticipating new risks.Users are fully limited proportion of Internet users growing number of Internet them to update cybersecurity policies minimal or no level of awareness of aware of cybersecurity risks and try to have awareness of cybersecurity users within society have and operational practices.Most users cybersecurity risks. anticipate new risks. risks. awareness of cybersecurity identify and anticipate cybersecurity
  63. risks. risks and try to adapt their behaviour.
  64. Government agencies across all levels Most government agencies at routinely prioritise and reassess cybersecurity Government agencies at all levels The government has minimal or no Leading government agencies and all levels are making priorities in response to changing threats to the habitually, as a matter of course, recognition of the need to prioritise private firms recognise the need to cybersecurity a priority.Most population.Most private sector actors across all prioritise cybersecurity.Private sector cybersecurity.Private sector actors prioritise cybersecurity.Private firms private firms at all levels are levels routinely prioritise and reassess actors at all levels habitually prioritise have minimal or no recognition of the recognise the need to prioritise making cybersecurity a cybersecurity priorities in response to changing cybersecurity, as a matter of Priority of need to prioritise cybersecurity.Users cybersecurity.A limited proportion of priority.A growing number of threats to the population.Most users routinely course.Users habitually prioritise Security have minimal or no recognition of the Internet users recognise the need to Internet users within society prioritise cybersecurity and seek to take cybersecurity and take steps to improve need to prioritise cybersecurity.No prioritise cybersecurity.Surveys and make cybersecurity a proactive steps to improve their security online.Survey results and surveys or metrics exist to document metrics to assess knowledge of priority.Surveys and metrics to cybersecurity.Surveys and metrics are metrics are used to refine cybersecurity cybersecurity ingovernment, private cybersecurity within the nation are evaluate knowledge of routinely conducted and publicised in fields of policies, inform operational practices and sector, or across users. limited or ad hoc. cybersecurity within the nation government, business and industry, and IT-related initiatives within the nation. are available. among users.
  65. The government agencies do not Most government agencies at Government agencies at all levels follow safe cybersecurity Leading government agencies all levels follow safe Government agencies across all levels habitually follow and also develop safe practices.Private sector companies follow safe cybersecurity cybersecurity practices.Most routinely follow safe cybersecurity cybersecurity practices.Private sector do not follow safe cybersecurity practices.Leading private firms follow private firms at all levels follow practices.Most private sector actors, (including actors at all levels habitually follow and Practices practices.In this country, very few safe cybersecurity practices.A limited safe cybersecurity SMEs) across all levels routinely follow safe develop safe cybersecurity Internet users follow safe but growing proportion of Internet practices.Most Internet users cybersecurity practices.Most users know and practices.Nearly all users know and cybersecurity practices or take users know or follow safe within this country know and routinely follow safe cybersecurity practices. habitually follow safecybersecurity protective measures to ensure their cybersecurity practices. follow safe cybersecurity practices as a matter of course. security. practices
  66. Nearly all Internet users habitually
  67. Most Internet users critically assess assess the risk in using online services, Very few Internet users in this A limited but growing proportion Most Internet users critically assess what they see or receive online, based on including changes in the technical and country critically assess what they of Internet users critically assess what they see or receive online, based on identifying possible risks.Most Internet cybersecurity environment.Internet users see or receive online.Internet users what they see or receive online.A identifying possible risks.Most Internet users recognise questionable information continuously adjust their behaviour generally do not believe or even limited proportion believe that Digital Literacy users understand how and act to protect online and take steps to ignore it or check based on their assessments of the consider that they have the ability they have the ability to use the and Skills themselves from misinformation online, its validity.Efforts are under way to co- quality of information they to use the Internet and protect Internet and protect themselves such as performing a search.Programmes ordinate programmes that support receive.Internet platform providers, themselves online.No programmes online.One or more programmes have been developed to support digital Internet, digital, and media literacy skills regulators and civil society are are available to support digital and are being developed to support and media literacy skills. between Internet platform providers, collaboratively developingprogrammes to media literacy skills. digital and media literacy skills. regulators and civil society. support Internet, digital, and media
  68. literacy skills.
  69. Most users have a learned level of trust
  70. in using the Internet safely and recognise Nearly all users trust that they can Only a limited proportion of A growing proportion of users have indicators of legitimate sites and Most Internet users have no trust or safely use of the Internet for a variety of users have sufficient trust in their sufficient trust in using the Internet safely information sources.Most Internet users have a blind trust in websites and purposes and can help others to use it User Trust and use of the Internet.A limited and recognise indicators of legitimate sites feel confident using the Internet, believe
  71. what they see or receive online.Very safely.Nearly all Internet users feel Confidencein proportion of Internet users feel and information sources.A growing they can recognise problematic or nonfew Internet users feel confident in confident using the Internet and sourcing Online Search and confident using it.Surveys and number of users feel confident using the legitimate websites (including mimicry using the Internet.Surveys or other valid content.Surveys and metrics have a Information metrics to assess users’ trust and Internet.Surveys and metrics to assess attempts), and check information using metrics to assess users’ trust and strong reputation in the region or globally confidence online are limited or users’ trust and confidence online are in tools such as search options. confidence online are not available. and are shaping the development of ad hoc. place and adequately funded. Surveys and metrics to assess users’ metrics in other nations. trust and confidence online are routinely
  72. conducted.
  73. Internet platform providers have Internet platform providers have Internet platform providers are instituted policies and practices to Internet platform providers are Internet platform providers have a instituted policies and practices to developing approaches toaddress address disinformation in some not addressing issues of number of approaches in place to address address disinformation; these respect issues of disinformation in this innovative ways that respect freedom of disinformation such disinformation; theserespect freedom of freedom of expression and other human nation.The development of tools expression and other human rights asmisinformation, in this expression and other human rights rights online.The joint efforts of civil and resources to address online.The joint efforts of civil society nation.Civil society and other non- online.Civil society stakeholders have society stakeholders are in place and are disinformation have beeninitiated stakeholders are proactively reviewed to government actors lack the tools developed tools and resources to address regularly used to address online Disinformation by leading civil society and non- take account of broader strategic and resources to address online online disinformation.Government disinformation in ways that respect governmental actors.Government developments related to disinformation disinformation, suchas exposing programmes and initiatives to strengthen freedom of expression and other human programmes and initiatives to and awareness raising.The country is misinformation the public’s preparedness against online rights online.Outcome-oriented surveys address disinformation are supporting the development of national/ campaigns.Government agencies disinformation are restricted to awareness are used to refine programmes and beingdeveloped but entail filtering regional/ international action plans and and actors have not addressed raising, but avoid censorship or filtering of initiatives aimed at empowering users and limited efforts to inform guidelines to address disinformation in online disinformation online. information. and building the public’s understanding of Internet users. ways that protect an open Internet and possible online disinformation. empower users.
  74. Government has begun to build E-government services in this country a core set of e-services, for which E-government services have become Government offers a very limited Key e-government services have been are recognised regionally or they recognise the need to apply the dominant (default) mode of number of e-services, if any, and developed and have generated a large internationally.Internet users trust thatesecurity measures in order to government information service has not publicly promoted their number of users.A sizeable and growing government services are proactively establish trust in their use.A delivery.The majority of Internet users in security.Generally, the public does number of Internet users trust in the use of reviewed, improved and expanded to limited number of early adopters this country trust in the secure use of e- User Trust inE- not use any significante- e-government services.Surveys and enhance their security.Outcome-oriented trust in the secure use of e- government services and make use of government government services.No surveys or metrics to assess users’ trust in e- surveys are used to review egovernment services.Metrics to them.Surveys and metrics to assess Services metrics exist to show how Internet government services are in place and government services and evaluate the assess users’ trust in e- users’ trust in e-government services are users trust e-government adequately funded.Public authorities are management of online content.The government services is limited or routinely conducted.Public authorities are services.There is a lack of publishing information and updates of their country is a leader in informing users ad hoc.Public authorities are co- ordinating, publishing and informing information about e-government privacy and security breaches and about current and developing privacy developing information on privacy users about privacy and security security and security breaches. initiatives such as privacy by default. and security breaches, initiatives and and security initiatives and initiatives and breaches. other issues. breaches in an ad-hoc manner.
  75. E-commerce services in this country E-commerce services are being E-commerce services are fully E-commerce services have become are recognised regionally or provided to a limited extent.A established by multiple stakeholders in a widely accepted as a safe practice for E-commerce services are not internationally.Internet users trust that elimited number of early adopters secure environment.A sizeable and consumers.The majority of users trust in offered.Internet users lack the trust commerce services areproactively trust in the secure use of e- growing number of Internet users trust in the secure use of e-commerce services to use any available e-commerce reviewed, improved and expanded to commerce services.Metrics to the secure use of e-commerce and make use of them.Surveys and User Trust in E- services.No surveys or metrics enhance their security.Outcome-oriented assess users’ trust in e- services.Surveys and metrics to assess metrics to assess users’ trust in ecommerce exist to show how Internet users surveys are used to review and commerce services is limited or users’ trust in e-commerce services are in commerce services are routinely Services trust e-commerce services.There is improvee-commerce services in order to ad hoc.The private sector place and adequately funded.Reliable conducted.Stakeholders are investing in little or no recognition of the need promote transparent,trustworthy and recognises the need for the security solutions are up to date and enhanced service functionality of efor security initiatives for e- secure systems.Terms and conditions application of security measures available, such as for payment systems. commerce services, protection of commerce services. provided by e-commerce services are to establish trust in e-commerce Certification schemes and trust marks personal information andthe provision of clear and easily comprehensible to all services. fore-commerce services are in place. user feedback mechanisms. users.
  76. Users and stakeholders within A growing proportion of users All stakeholders have the information, Users and stakeholders within the the public and private sectors have have the skills to manage their confidence and the ability to take steps to Users have the knowledge and skills public and private sectors may have no or minimal knowledge about privacy online, and protect protect their personal information online and necessary to protect their personal general knowledge about how personal how personal information is themselves from intrusion, to maintain control of the distribution of this information online, adapting their abilities to information is handled online; and may handled online, nor do they believe interference, or unwanted access of information.Users and stakeholders within the changing risk environment.Policies in Personal employ good (proactive) cybersecurity
  77. that adequate measures are in information by others.There is the public and private sectors widely private and public sectors are proactively Information practices to protect their personal place to protect their personal considerable public debate regarding recognise the importance of protection of reviewed to ensure privacy and security do Protection information online.Discussions have information online.There is no or the protection of personal personal information online and are aware of not compete in a changing environment Online begun regarding the protection of limited discussion regarding the information and about the balance their privacy rights.Mechanisms are in place and are informed by user feedback and personal information and about the protection of personal information between security and in private and public sectors to shape public debate.New mechanisms are in balance between security and online.Privacy standards are not in privacy.Privacy policies have been Internet and social media practices and place, such as privacy by default, as tools privacy.Concrete actions or privacy place to shape Internet and social developed within the public and ensure that privacy and security do not for transparency and are promoted. policies are being developed. media practices. private sectors. compete.
  78. The public and/or private sectors are providing There are no official reporting Co-ordinated reporting mechanisms Mechanisms have been developed to cosome channelsfor reporting cyber harms (such as Reporting mechanisms have mechanisms available, but are widely used and promoted within ordinate response to reported incidents online fraud, cyber-bullying, child abuse online, been established, promoted and discussions might have public and private sectors.Internet between law enforcement and the national identity theft, privacy and security breaches, and are regularly used.Internet users Reporting begun.Users do not use social users routinely use social media incident response capability.Internet users other incidents), but these channels are not co- widely use social media channels Mechanisms media channels to raise channels to inform other users.Cyber habitually use social media channels to ordinated and are used in an ad-hoc to inform other users.There are concerns over any cyber harms harm metrics have been used to inform inform other users and share good manner.Internet users use social media channels to good metrics of reported and problems.No metrics of the revision and promotion of new practice.Metrics are routinely used to inform inform other users in an ad-hoc manner.Metrics of incidents. reported incidents exist. policies and practices. policy and decision- makers. reported incidents is being developed.
  79. Mass media rarely, if ever, cover It is perceived that there is ad-hoc mass It is perceived that the broad discussion It is perceived that cybersecurity is a It is perceived that mass media coverage information about cybersecurity or media coverage of cybersecurity, with of personal experiences and common subject across mainstream extends beyond threat reporting and can inform report on issues such as security limited information provided andreporting on personalattitudes of individuals across media, and information and reports on the public about proactiveand actionable Media breaches or cybercrime.There is specific issues that individuals face online, mainstream and social media inform policy
  80. a wide range of issues, including cybersecurity measures, as well economic and and no, or rarely any discussion on such as protection for children online, or making and facilitate societal security breaches and cybercrime, are social impacts.There is frequent discussion on Social social media about cyber-bullying.It is perceived that there is change.Social media has become a major widely disseminated.There is broad social media about cybersecurity and individuals Media cybersecurity.Any portrayal of limited discussion on social media about component in tracking and addressing discussion on social media about regularly use social media to share online whistleblowers is negative, and cybersecurity.There have been positive cyber harms.Whistleblowing has been cybersecurity.There is acceptance that experiences.Transparency is encouraged as are based on criminal or other negative examples of cases where whistleblowers encouraged and protected as a means of whistleblowers can play a positive role. whistleblowers. stereotypes. have had a constructive impact. social accountability.
  81. A co-ordinated cybersecurity awareness The national cybersecurity awareness- A co-ordinated national cybersecurity raising programme with the involvement ofthe raising programme with private and civil awareness- raising programme with detailed The national awareness-raising government is under development, with society stakeholders is proactively implementation plan is published. The programme is fully integrated with sector- No overarching national relevant stakeholders involved, including the reviewed to take account of broader contentincludes explicit links to national specific, tailored awareness-raising cybersecurity awareness- private sector and civil society.Awareness- strategic developments within the country cybersecurity strategy.A co-ordinating body programmes, such as those focusing on raising programme has been raising programmes, courses, seminars and (political, economic, social, technical, has been assigned with sufficient authority industry, academia, civil society, and/or developed by the online resources initiated by the government legal and environmental).The country is Initiatives and resources required to deliver the actions women and children.Emerging government.The need for are available but not sufficiently reflected in actively involved in creating new regional/ by of the national programme.A national cybersecurity risks are regularly assessed awareness of cybersecurity thenational cybersecurity strategy or is in international cybersecurity awareness- Government cybersecurity awareness portal exists to and used to update the threats and vulnerabilities in development.The actions within the raising programmes that contribute improve the skills and knowledge of the nationalcybersecurity awareness-raising the government is not programmes are led by different ‘owners’ but toward expanding and enhancing societyand is disseminated via that programme.There is evidence of these recognised or is only at initial they are not yet co- ordinated.The availability international awareness-raising good programme.Programme review processes metrics being used to refine actions within stages of discussion. of adequate resources has not yet been practices.The national cybersecurity and outcome-oriented metrics are in place, the national awareness-raising programme confirmed.Initial system of mechanisms and awareness-raising programme has a are adequately funded and allow and national cybersecurity strategy. metrics to review processes are limited or ad measurable impact on the reduction of effectiveness to be measured. hoc. the overall threat landscape.
  82. Collaborative awareness-raising efforts
  83. (e.g.: joint policy and/or advocacy work) with The joint awareness-raising efforts with
  84. government and civil society stakeholdersare government and civil society The effectiveness of joint awarenessmade in order to pool resources, information stakeholders are proactively reviewed to Awareness-raising programmes, courses, raising efforts with government and civil The need for awareness of and identify solutions for cyber safety take account of broader strategic seminars and online resources initiated by the society stakeholders is regularly assessed cybersecurity threats and practices.The role of specific ‘owners’ developments within the country Initiatives private sector are available but no co- and used to enhance collaborative vulnerabilities in the private assigned to actions within private sector (political, economic, social, technical, by Private ordination or scaling efforts have been processes.Private sector initiatives are fully sector is not recognised or is initiatives are clear and mechanisms are in legal and environmental).The joint Sector conducted.Initial system of mechanisms and integrated into the national awarenessonly at initial stages of place to enable co-ordination between the awareness-raising efforts with metrics to review processes are limited or ad raising programme.Evidence from the discussion. levels of government, private sector and civil government and civil society hoc. lessons learnt is fed into the development society.Programme review processes and stakeholders have a measurable impact of future programmes. outcome-oriented metrics are in place, well- on reduction of the overall threat
  85. funded and shared with government and civil landscape.
  86. society stakeholders.
  87. Collaborative awareness-raising efforts
  88. (e.g.: joint policy and/or advocacy work) with The joint awareness-raising efforts with government and private sector stakeholders The effectiveness of joint awarenessgovernment and private sector are taking place in order to pool resources raising efforts with government and stakeholders are proactively reviewed to and information and identify solutions for privatesector stakeholders is regularly The need for awareness of There are indications that civil society take account of broader strategic cyber safety practices.The role of specific assessed and used to enhance Initiatives cybersecurity threats and realises that it can play a role in awareness- developments within the country ‘owners’ assigned to actions within civil collaborative processes.Civil society by Civil vulnerabilities in civil society raising programmes, courses, seminarsand (political, economic, social, technical, society initiatives are clear and mechanisms initiatives are fully integrated into the Society is not recognised or is only at online resources, but no real deliverables are legal and environmental).The joint are in place to enable co-ordination between national awareness-raising initial stages of discussion. yet evident.Initial system of metrics may exist. awareness-raising efforts with the levels of government, private sector and programme.Evidence from the lessons government and private sector have a civil society.Programme review processes learnt is fed into the development of future measurable impact on reduction of the and outcome-oriented metrics are in place, programmes. overall threat landscape. well-funded and shared with government and
  89. private sector stakeholders.
  90. Executive awareness-raising efforts in Awareness raising of executives in the nearly all sectors include the identificationof public, private, academic and civil society strategic assets, specific measures in place sectors address cybersecurity risks in Awareness raising on Executives are made aware of general to protect them, and the mechanism by Cybersecurity risks are considered as general, some of the primary methods of cybersecurity issues for cybersecurity issues, but not how these issues which they are protected.Executives are an agenda item at every executive attack, and how the organisation deals with executives is limited or non- and threats might affect their able to alter strategic decision making and meeting, and funding and attention is cyber issues (usually abdicated to the Executive existent.Executives are not organisations.Executives of particular sectors, allocate specific funding and people to the reallocated to address those CIO).Select executive members are made Awareness yet aware of their such as finance andtelecommunications, have various elements of cyber risk, contingent risks.Executives at regional and aware of how cybersecurity risks affect the Raising responsibilities been made aware of cybersecurity risks in on their company’s prevailing international level are regarded as a strategic decision making of the organisation, toshareholders, clients, general, and howthe organisation deals with situation.Executives are made aware of source of good practice in responsible particularly those in the financial and customers, and employees in cybersecurity issues, but not of strategic what contingency plans arein place to and accountable corporate cybersecurity telecommunications sectors.Awarenessrelation to cybersecurity. implications. address various cyber-based attacks and governance. raising efforts of cybersecurity crisis their aftermath.Executive awareness management at the executive level is still courses in cybersecurity are mandatory for reactive in focus. nearly all sectors.
  91. Cybersecurity educators are not only Qualifications for and supply of drawn from the academic environment, but educators are readily available in incentives are in place so that industry cybersecurity.Specialised courses in and/or government experts take these cybersecurity are offered and accredited at positions as well.Accredited cybersecurity university level.Cybersecurity riskcourses are embedded in all computer awareness modules are offered as part of science degrees.Degrees are specifically many university courses.Degrees in National courses, degrees, and Qualification programmes for offered in cybersecurity, and encompass cybersecurity-related fields are offered by research are at the forefront of Few or no cybersecurity cybersecurity educators are being courses and models in various other universities or equivalent educational cybersecurity education.Cybersecurity educators are available, and there explored, with a small cadre of existing cybersecurity-related fields, including institutions.Universities and other bodies education programmes maintain a are no qualification programmes for qualified educators.Some educational technical and non-technical elements such hold seminars/lectures on cybersecurity balance between preserving core educators.Computer science courses exist in cybersecurity-related as policy implications, and multiissues, aimed at non-specialists.Research components of the curriculum and Provision courses are offered that may have a fields, such as information security, disciplinary education.Cybersecurity and development are leading promoting adaptive processes that security component, but network security and cryptography, but educational offerings are weighted and considerations in cybersecurity respond to rapid changes in the nocybersecurity-related courses are cybersecurity-specific courses are not focused on an understanding of current education.Cybersecurity education is not cybersecurity environment.Prevailing offered.No accreditation in yet offered.A demand for cybersecurity risks and skills requirements. The content limited to universities or equivalent cybersecurity requirements are cybersecurity education exists. education is evidenced through course of cybersecurity courses covers topics on educationalinstitutions, but ranges from considered in the redevelopment of all enrolment and feedback. emerging threats in cybersecurity.National primary, secondary and tertiary to post- general curricula. or international cybersecurity frameworks graduate levels, including vocational and/ or curricular guidelines are taken into education.Steps might have been taken to consideration by academic institutions incorporate STEM orequivalent education when designing cybersecurity framework with a focus on cybersecurity courses.Apprenticeship programmes in throughout primary and secondary different industry sectors are offered to curricula. combine knowledge and practical skills.
  92. Broad consultation across government,
  93. The need to enhance cybersecurity private sector, academia and civil society
  94. education in schools and universities or stakeholders informs cybersecurity The need to enhance national Metrics are being used to refine actions International cybersecurity centres of equivalent educationalinstitutions has education priorities and is reflected in cybersecurity education is not yet within educational investment to create a excellence are established through been identified by leading government, national cybersecurity strategy.National considered.A network of national cadreof cybersecurity experts in the country twinning programmes led by worldindustry, and academic budget is dedicated to national contact points for governmental, across, all sectors.Management of the class institutions.Co-operation between stakeholders.Schools, government and cybersecurity research and laboratories at regulatory bodies, critical industries government budget and spending on all stakeholders in cybersecurity industry collaborate in anad-hoc manner universities or equivalent educational and education institutions is not yet cybersecurity education is based on education is routine and can be Administration to supply the resources necessary for institutions.Competitions, initiatives and established.Discussion of how co- national demand.Leading national proven.Content in cybersecurity providing cybersecurity education.A funding schemes for students and ordinated management of cybersecurity academic institutions share education programmes is aligned with national budget focused on employees are promoted by government cybersecurity education and lessons learnt with other national and practical cybersecurity problems and cybersecurity education is not yet and/or industry in order to increase the research enhances national international counterparts.Government has business challenges and provides a established.Initial system of attractiveness of cybersecurity knowledge development has not or established academic centres of excellence mechanism for enhancing curricula mechanisms and metrics to review the careers.Programme review processes and has only just begun. in cybersecurity. based on the evolving landscape. supply and demand for cybersecurity outcome-oriented metrics to review the
  95. courses are limited or ad hoc. supply and demand for cybersecurity
  96. courses are in place and well-funded.
  97. The need for training professionals in Structured cybersecurity training programmes A range of cybersecurity training courses is cybersecurity has been documented at the exist to develop skills towards building a cadre of tailored towards meeting national strategic national level.Training for general IT staff is cybersecurity- specific professionals.National or demand and aligns with international good The public and private sector collaborate provided on cybersecurity issues so that they international cybersecurity vocational-based practice.The training programmes outline the to offer training, and constantly adapt and can react to incidents as they occur, but no frameworks and international best practices are priorities in the national cybersecurity seek to build skillsets drawn from both training for dedicated security professionals taken into consideration when designing strategy.Training programmes are offered to sectors.Training offerings and education exists.ICT professional certification is professional training courses.Security professional Few or no training cybersecurity professionals and focus on the programmes are co-ordinated so that the offered, with some security modules or certification is offered across sectors within the Provision programmes in skills necessary to communicate technically foundation established in schools can components.Best practice training and country.The needs of society are well understood, cybersecurity exist. complex challenges to non- technical enable training programmes to build a certifications might be accessible via and a list of training requirements is audiences, such as management and general highly skilled workforce.Programmes and international online sources (e.g.: documented.Training programmes for nonemployees.Outcome-oriented metrics drawn incentive structures are in place to ensure CISSP).Ad-hoc training courses, seminars cybersecurity professionals are recognised and from comprehensive supply-and- demand the retention of the trained workforce within and online resources are available for offered.Government initiatives to stay in the data for cybersecurity professionals are being the country. cybersecurity professionals through public or country after the successful completion of used to inform the modes, sustainability and private sources, with limited evidence of cybersecurity training programmes might be in procedures of future training programmes. take-up. place.
  98. There is an established cadre of certified
  99. employees trained in cybersecurity issues,
  100. processes, planning and analytics.A national
  101. register of successful and certified students and Training uptake by IT professionals might exist.The transfer of personnel designated to Metrics that evaluate the take- up of ad-hoc knowledge from employees trained in respond to training courses, seminars, online resources, cybersecurity to untrained employees in both The uptake of cybersecurity training is used cybersecurity incidents Cybersecurity professionals not only fulfil and certification offerings are limited in scope public and private sectors is established.Job to inform future training programmes.Cois limited or non- national requirements, but domestic Uptake or ad hoc.The transfer of knowledge from creation initiatives for cybersecurity within ordination of training across all sectors existent.There is no professionals overseas are consulted to employees trained in cybersecurity to organisations are established and encourage ensures the national demand for professionals transfer of knowledge share lessons learnt and best practice. untrainedemployees in both the public and employers to train staff to become cybersecurity is met. from employees trained private sectors is ad hoc. professionals.Programme review processes and in cybersecurity to metrics are in place to allow progress to be untrained employees. measured and assess the supply and demand for
  102. cybersecurity-skilled workers in both public and
  103. private environments. These processes are
  104. adequately funded.
  105. The country is a leading actor in There are limited or no Some integration of cybersecurity R&D Cybersecurity R&D activities have been The country is actively building cybersecurity research and innovation cybersecurity research and activities occurs within the country, or with a established and are indicated in the national communities of interest around R&D and is shaping international debates development (R&D) partner country that understands how cybersecurity strategy. R&D strategy may be in priorities in cybersecurity.R&D strategy is in on the development of R&D strategic activities occurring in the cyberactivity R&D applies to the local development.The resources and processes place and fully implemented.The country plans.The country is forward looking, country.There is no access context of the country.The country may required to deliver the actions of cybersecurity makes a major contribution to cybersecurity seeing emerging issues (around new to R&D activities in participate in relevant regional/ international R&D activities have been identified and are in R&D and is actively involved in building technology or new types of threat), cybersecurity from other cybersecurity-related research collaboration place. Funding is adequate to deliver these innovation capacity through international and uses R&D to prepare a future countries. networks. actions. R&D consortia and investment. threat environment.
  106. There is active regional/international Emerging cybersecurity risks are collaboration with leading practice and regularly assessed and used to update the developments.The country is actively participating national cybersecurity strategy and the Research and contributing to regional/ international The country is contributing to Cybersecurity R&D performancemetrics development of future programmes of the and cybersecurity-related research collaboration international best practices in are limited in scope, orad hoc. R&D strategy.Synergy between academic Development networks.Metrics for measuring R&D performance cybersecurity R&D. institutions and industry supports R&D are in place and allow progress to be measured activities and is used to design cyber and to improve the cybersecurity R&D capability of curricula that cover industry needs. the country.
  107. Substantive cybercrime law is
  108. Specific substantive Substantive cybercrime legal provisions are Measures are in place to exceed minimal constructed so that it can cater for
  109. criminal law on Partial legislation exists that contained in specific legislation or a general baselines specified in international treaties, dynamic changes inthe underlying
  110. cybercrime does not exist. addresses some aspects of cybercrime, criminal law.The country may have ratified regional where appropriate.The country seeks to technology and threat environment,
  111. General criminal law may or cybercrime legal provisions are in or international instruments on cybercrime. The adapt its substantive cybercrime legislation without the need for substantial and Legislation exist, but its application to development. country consistently seeks to implement these to take account ofemerging technologies lengthy revision.The country is actively
  112. cybercrime is unclear. measures into domestic law. and their use. contributing to the international promotion
  113. of effective cybercrime legislation.
  114. Regulatory frameworks are sufficiently There are limited Comprehensive cybersecurity requirements are flexible to cater for rapidly emerging cybersecurity set out in relevant regulation and law (including Stakeholders from relevant sectors changes in the underlying technological Legal and requirements set out in sector-specific requirements, where have been consulted to support the The effectiveness of law and regulation in or threat environment.The country is regulation or law.The relevant).These requirements may include Regulatory establishment of legal and regulatory improvingcybersecurity practice is regularly promoting best practice legal and need to create legal and mandatory standards, or breach notification Requirements frameworks.Draft legislation and assessed and used to inform their future regulatory approaches internationally.The regulatory frameworks on requirementsand vulnerability disclosure for regulation may be in place, but this has development.Regulations are updated to country is actively involved in the cybersecurity may have requirements.Relevant civil and criminal liabilities yet to be adopted and may not cover all take account of emerging technologies. development of international agreements Cybersecurity been recognised and may are clearly articulated and understood by regulated
  115. relevant sectors. to promote harmonisation and mutual have resulted in a gap entities.Relevant legal and regulatory bodies have recognition of cybersecurity laws and analysis. the powers needed to enforce these requirements. regulations.
  116. Comprehensive criminal procedural law Procedural cybercrime law is Specific procedural containing provisions on the investigation of constructed in a way that it can cater for criminal law for cybercrime and evidentiary requirements has been Measures are in place to exceed minimal dynamic changes in the underlying cybercrime does not exist. adopted and is applied.The country may have Development of specific procedural baselines specified in international treaties, technology andthreat environment, Procedural It is not clear how general ratified regional or international instruments on cybercrime legislation, or amendment of where appropriate.The country seeks to without the need for substantial and Cybercrime criminal procedural law cybercrime. The country consistently seeks to general procedural criminal law to adapt adapt procedural cybercrime legislations to lengthy revision.The country is actively Legislation applies to cybercrime implement these measures into domestic to cybercrime cases, has begun. take account of emerging technologies and contributing to the promotion of effective investigations, law.Procedural laws relating to cybercrime permit their use. procedural cybercrime legislation and prosecutions, and the exchange of information (and other actions instruments to improve international electronic evidence. required) to support successful cross-border cybercrime investigations. investigation of cybercrime.
  117. Human rights impact assessments of
  118. substantive and procedural cybercrime Human rights impact assessments are Substantive and legislation and cybersecurity regulations Full human rights impact assessments of regularly reviewed to ensure that practice procedural cybercrime may have been conducted, including substantive and procedural cybercrime legislation remains compatible with human rights legislation and The country is actively contributing to Human Rights consideration of privacy and freedom of and cybersecurity regulations have been requirements, and that the effect of cybersecurity regulations the development and promotion of Impact expression implications. Some issues, completed and international standards are emerging technologies is may be in development, human rights impact assessments as Assessment however, have yet to be met.Implementation of this legislation is monitored considered.Consideration has also been but no human rights they relate to cybersecurity. resolved.Relevant human rights experts on a regular basis for human rights compliance, given to how cybersecurity can enhance impact assessments have have been consulted in the and this is independently verified. human rights protection within the country been carried out. development of the legislation and and internationally.
  119. regulation.
  120. Data protection legislation is constructed so that it
  121. Comprehensive data protection The effectiveness of data protection cancater for dynamic changes in the underlying technology
  122. Data protection legislation is in legislation in line with international legislation is regularly assessed and andthreat environment, without the need for substantial and Data Data protection development.Stakeholders from relevant standards and best practice has used to inform its development.The lengthy revision.The country is developing and promoting Protection legislation does not sectors have been consulted to support the been adopted and is enforced.A country seeks to adapt data protection international standards for data protection legislation.The
  123. development of this legislation. lead agency responsible for data laws to take account of emerging country is actively involved in the development of legal
  124. protection has been designated. technologies and their use. instruments to enable improved international collaboration
  125. in this area.
  126. Online child protection law is constructed so that it can The application of child protection The effectiveness of online child Legislation relating to Legislation related to child protection is in cater for dynamic changes inthe underlying technology and in the online environment is protection law is regularly assessed child protection is place and is being adapted to reflect its threat environment, without the need for substantial and Child understood and reflected in and used to inform its limited and its application in the online lengthy revision.The country is developing and promoting Protection relevant legislation. Legislation is development.The country seeks to application in the online environment.Stakeholders from relevant international standards for online child protection law.The Online implemented in line with adapt child protection law to take environment is yet to be sectors have been consulted to support the country is actively involved in the development of legal international standards and best account of emerging technologies and considered. development and adaptation of this legislation. instruments to enable improved international collaboration practice. their use. in this area.
  127. Consumer protection legislation is constructed so that it The application of consumer The effectiveness of online Legislation related to Legislation related to consumer protection is can cater for dynamic changes in the underlying technology protection in the online environment consumer protection law is regularly consumer protection is in place and is being adapted to reflect its andthreat environment, without the need for substantial and Consumer is understood and reflected in assessed and used to inform its limited andits application in the online lengthy revision.The country is developing and promoting Protection relevant legislation. Legislation is development.The country seeks to application in the online environment.Stakeholders from relevant internationalstandards for online consumer protection Legislation implemented in line with adapt consumer protection legislation environment is yet to be sectors have been consulted to support the law.The country is actively involved in the development of international standards and best to take account of emerging considered. development of this legislation. legal instruments to enable improved international practice. technologies and their use. collaboration in this area.
  128. Intellectual property legislation is constructed so that it The application of intellectual The effectiveness of online Legislation related to Legislation related to intellectual property can cater for dynamic changes in the underlying technology property protection in the online intellectual property protection law is intellectual property protection is in place and is being adapted to andthreat environment, without the need for substantial and Intellectual environment is understood and regularly assessed and used to inform protection is limited and reflect its application in the online lengthy revision.The country is developing and promoting Property reflected in relevant legislation. its development.The country seeks to its application in environment.Stakeholders from relevant internationalstandards for online intellectual protection Legislation Legislation is implemented in line adapt intellectual property protection theonline environment sectors have been consulted to support the law.The country is actively involved in the development of with international standards and legislation to take account of emerging is yet to be considered. development of this legislation. legal instruments to enable improved international best practice. technologies and their use. collaboration in this area.
  129. Quantified risk assessments are used to allocate
  130. A comprehensive institutional capacity with resources to operational cybercrime units (at The country is actively
  131. sufficient human, procedural and technological national and state/local levels).Trends and involved in the development of
  132. resources to investigate cybercrime cases has been statistics on cybercrime, law enforcement collaborative platforms between Traditional investigative Law enforcement officers/ established.Digital chain of custody and evidence interventions and their impact on harm reduction national law enforcement measures are applied to cybercrime agencies do not have sufficient integrity is established, including formal processes, are collected, analysed and used to inform strategy authorities.The law enforcement investigations, but digital Law capacity to prevent and combat roles and responsibilities.Standards for the training and long-term resource allocation decision.Law agencies within the country are investigation capacity is limited.Law Enforcement cybercrime and do not receive of law enforcement officers on cybercrime and enforcement strategies include crime prevention at the forefront of developing enforcement officers may receive specialised training on cybercrime digital evidence exist and are implemented.The measures alongside enforcement measures. new capabilities and training on cybercrime and digital investigations. respective roles of national and state/local law Intelligence is used to support proactive approaches for the prevention evidence, but it is ad hoc. enforcement agencies are understood and state- investigation.Law enforcement agencies have the and disruption of cybercrime
  133. /local-level forces are equipped to undertake their capabilities to maintainthe integrity of data to meet and promoting their use
  134. role. international evidential standards in cross-border internationally.
  135. investigation.
  136. Prosecutors do not receive A limited number of prosecutors Institutional structures are in place, with a clear adequate training and resources have the capacity to conduct A comprehensive institutional capacity, including distribution of tasks and obligations within the to review electronic evidence or cybercrime cases and to handle sufficient human and technological resources, to There is national capacity to prosecution services at all levels of the state.A prosecute electronic evidence, but this prosecute cybercrime cases and cases involving prosecute complex domestic Prosecution mechanism exists that enables the exchange of cybercrime.Consultation may capacity is largely ad hoc and is not electronic evidence is established.A specialist cadre and cross-border cybercrime informationand good practices between have begun to consider this institutionalised.If prosecutors of cybercrime prosecutors may have been cases. prosecutors and judges to ensure efficient and capacity in the prosecutor receive training on cybercrime and established. effective prosecution of cybercrime cases. community. digital evidence, it is ad hoc.
  137. Sufficient human and technological resources are
  138. There is no process to equip available to ensure effective and efficient legal A limited number of judges have judges so they can preside over proceedings regarding cybercrime cases and cases the capacity to preside over a The institutional capacity of the court system to The country is actively cybercrime cases or cases involving electronic evidence.Judges receive cybercrime case, but this capacity conduct cybercrime cases is frequently reviewed involved in developing and Courts involving electronic specialised training about cybercrime and electronic is largely ad hoc.If judges receive and revised based on an assessment of promoting best practices in the evidence.Consultation may have evidence.States/local courts are equipped to deal training on cybercrime and digital effectiveness. conduct of cybercrime cases. begun to consider this capacity in with cybercrime cases, appropriate to their evidence, it is ad hoc. the judicial community. level.Relevant courts are equipped to process civil
  139. litigation relating to cybersecurity liability.
  140. Sector-specific regulators have The impact of regulatory actions on started to establish their Sector-specific regulators (e.g.: finance, energy, Sector-specific regulators have organisations’ cybersecurity practices are regularly cybersecurity roles.A requirement transport) are equipped with the capability and limited understanding of the assessed and used to inform supervisory activity Regulatory bodies are for the establishment of cross- resources required to oversee compliance with potential impact of cyber on their and regulation development.Regulatory bodies actively involved in the Regulatory sector regulatory bodies to oversee cybersecurity requirements within their regulated entities.There is no regularly assess emerging technologies and their development and promotion of Bodies compliance with specific sector.Where cross-sector regulatory bodies have cross-sector regulatory body to potential impact on the cybersecurity of regulated regulatory best practice cybersecurity regulations may have been established to oversee cybersecurity, they supervise specific cybersecurity entities.Regulatory interventions and investigations internationally. been considered.Relevant have the necessary capability and resources to requirements. are informed by, and prioritised on the basis of, stakeholders have been consulted undertake their role. national assessments of cyber risk. in this process.
  141. Exchange of information on cybercrime The country is actively Co-operation between domestic Information is regularly exchanged between The effectiveness of public and private between domestic public and private contributing to the public and private sectors on domestic public and private sectors and is supported co-operation is regularly assessed and Law sectors is ad hoc and promotion of public– cybercrime is limited.Specifically, by appropriate legislation.Effective co-operation used to enhance collaborative Enforcement Co- unregulated.Specifically, ad-hoc co- private partnership and co-operation between Internet mechanisms between Internet service and other processes.Collaboration frameworks are operation with operation between Internet service and the development of service and other technology technology providers and law enforcement have regularly adapted to takeaccount of new other technology providers and law international public– Private Sector providers and law enforcement has been established aspart of these broader public– technologies and emerging forms of
  142. enforcement exists but is not always private partnership not been established. private sector collaboration arrangements. cybercrime. effective. platforms.
  143. Formal mechanisms of international law
  144. Formal mechanisms of international law enforcement co-operation have been established to The country actively enforcement co-operation may exist, but facilitate the detection, investigation, and Law enforcement agencies work jointly Co-operation contributes to the
  145. There are minimal or no forms of their application to cybercrime is ad hoc or prosecution of cybercrime.Mutual legal assistance, with foreign counterparts, potentially
  146. international co-operation to only possible in some cases.Law extradition agreements and mechanisms have been through joint task forces, resulting in Enforcement development of prevent and combat cybercrime. enforcement is not formally integrated into established and are applied to cybercrime successful cross-border cybercrime Counterparts international co-operation regional and international cybercrime cases.Domestic law enforcement agencies are investigations and prosecutions. mechanisms. networks. integrated with regional and international networks,
  147. such as Interpol or 24/7 networks.
  148. The country actively
  149. The relationship between government contributes to the Government- Formal relationships between government and
  150. There is minimal interaction Exchange of information between actors, prosecutors, judges and law international promotion of Criminal Justice criminal justice actors have been established, between government and criminal government and criminal justice actors is enforcement agencies is regularly efficient and timely Sector resulting in the regular exchange of information on justice actors. limited and ad hoc. assessed and used to enhance their exchange of information Collaboration cybercrime issues. effectiveness. between government and
  151. criminal justice actors.
  152. Government and organisations promote
  153. use of standards and best practices
  154. Either no standards or good A nationally-agreed baseline of according to assessment of national risks
  155. practices have been identified cybersecurity-related standards and good and budgetary choices.The choice of The country is actively involved in the for use in securing data, practices have been identified and standards and best practices and their development and promotion of defined technology or infrastructure, by Information risk management implemented widely across public and implementation is continuously standards internationally.Implementation of the public and private standards have been identified for use private sectors.An entity within government revised.Emerging cybersecurity risks are standards and non-compliance decisions are sectors.Or initial identification and there have been some initial signs of exists to assess the use of standards across regularly assessed and used to remade in response to changing threat ICT Security of some appropriate standards promotion and take-up within public and public and private sectors.Government evaluate the need for additional ICT environments and resource drivers across Standards and good practices has been private sectors.There is some evidence of schemes exist to promote continued security standards.There is evidence of sectors and CI, through collaborative risk made by the public and private measurable implementation and use of enhancements, and metrics are being debate between government and other management.Evidence exists of debate sectors, and possibly some ad- international standards and good applied to monitor compliance.Consideration stakeholders as to how national and within all sectors on compliance to standards hoc implementation, but no practices. is being given as to how standards and best organisational resource decisions should and best practices, based on continuous concerted endeavour to practices can be used to address risk within align and drive implementation of needs assessments. implement or change existing supply chains within the CI, by both standards.Evidence of contribution to
  156. practice in a measurable way. government and CI. international standards’ bodies exists and
  157. contributes to thought leadership and
  158. sharing of experience by organisations.
  159. Organisations have the ability to monitor
  160. and change use of standards and best
  161. practices in procurement processes,
  162. support deviations and non-compliance
  163. decisions as the need arises through risk-
  164. based decision- making.Emerging Cybersecurity standards and best Cybersecurity standards and best cybersecurity risks are regularly assessed practices guiding procurement practices in guidingprocurement processes and used tore-evaluate the need for No standards or best processes(including risk management, (including risk management, lifecycle additional standards in The country is actively involved in the practices have been identified lifecycle management, software and management, software and hardware procurement.Critical aspects of development and promotion of these Standards foruse in guiding procurement hardware assurance, outsourcing, and assurance, outsourcing, and use of cloud procurement and supply, such as total standards internationally.Implementation of in processes by the public and use of cloud services) have been services) are being adhered to widely within lifecycle cost, quality, inter- standards in procurement processes and Procurement private sectors. If they are identified for use.Evidence of promotion public and private sectors.Implementation operability,maintenance, support and other non- compliance decisions are made in recognised, implementationis and implementation ofcybersecurity and compliance of standards in procurement value- adding activities, are continuously response to changing threat environments. ad hoc and un-co-ordinated. standards and best practices in defining practices within the public and private improved, and procurement process procurement practices exists within public sectors is evidenced through measurement improvements are made in the context of and private sectors. and assessments of process effectiveness. wider resource planning.Organisations are
  165. able to benchmark the skills of their
  166. procurement professionals against the
  167. competencies outlined in procurement
  168. standards and identify any skills and
  169. capability gaps.
  170. Security considerations are incorporated There is evidence of widespread in all stages of the development of Core activities and methodologies for implementation of standardsin the software software, hardware and provision of Either no standards or best secure development and lifecycle development processes, hardware quality managed services and cloud practices have beenidentified management for software, hardware and assurance, provision of managed services services.Core development activities, for use in securing the products provision of managed services and cloud and cloud servicesby public and private including configuration and documentation The country is actively involved in the and services (in particular, services are being identified and sector organisations.Government has an Standards management, security development and development and promotion of these
  171. software, hardware, managed discussed within professional established programme for promoting and for Provision lifecycle planning have been adopted into standards internationally.Implementation of servicesand cloud services) communities.Government promotes monitoring standard adoption in software of Products the practices of product and service these standards and non-compliance developed or offered by relevant standards in software development, hardware quality assurance and Services providersProjects on software decisions are made in response to changing providers in the country.Or development, hardware quality and cloud security, for public and development, hardware quality assurance, threat environments. there is some identification, but assurance, provision of managed commercial systems.Evidence that high managed service and cloud security only limited evidence of take- services and cloud security but there isno integrity systems and software development continuously assess the value of up. evidence of widespread adoption of these techniques are present within the standards and reduce or enhance levels of standards yet. educational and training offerings in the compliance according to risk-based country. decisions.
  172. Widespread adoption of technological security
  173. controls leads to effective upstream protection of
  174. users and public and private sectors.All sectors
  175. have the capacity to continuously assess the Technological security controls are Up-to-date technological security security controls deployed, for their deployed by users and public and private controls, including patching and backups, effectiveness and suitability according to their sectors, but possibly not consistently across There is minimal or no are deployed in all sectors.Physical changing needs.The understanding of the all sectors.The deployment of up-to-date understanding or security controls are used to prevent technological security controls being deployed technological security controls is promoted deployment of the unauthorised personnel from entering extends to their impact on The application of advanced in an ad-hocmanner and all sectors are technological security computing facilities in all sectors.Internet organisationaloperations and budget technological controls within the being incentivised to make use of controls available in service and other technology providers allocation.The public and private sectors have country is a leading influence Technological them.Internet service and other technology themarketplace, by users establish internal policies for the the capacity to critically assess and upgrade internationally.Implementation of Security ontrols providers may be offering security services and public and private deployment of technical security controls, cybersecurity controls according to their advanced technological security as part of their services but possibly in an sectors.Internet service and to manage identified risks in the products appropriateness and suitability for use, and controls are made in response to ad-hoc manner.Internet service and other other technology providers and services they are offering.The considering emerging risks.There is widespread changing threat environments. technology providers recognise a need to may not offer any upstream technological cybersecurity control set adoption of multi-factor authentication for online establish internal policies for the deployment controls to their customers. reflects internationally-established services and privileged accounts. Certificate of technical security controls, to manage cybersecurity frameworks, standards and Authorities are available and digital certificates identified risks in the products and services good practice. are widely used.Internet service and other they are offering. technology providers have the ability to prevent
  176. access to non-trusted sites or webaddresses in
  177. accordance with the requirements of the
  178. appropriate regulator.
  179. The public and private sectors critically
  180. Cryptographic techniques are available assess the deployment of cryptographic
  181. for all sectors and users for the controls, according to their objectives and
  182. Cryptographic techniques protection of data at rest or in priorities.The public and private sectors adapt
  183. (e.g.: encryption and digital Cryptographic controls for protecting data transit.There is a broad understanding of encryption and cryptographic control policies The country is contributing to the
  184. signatures) for protection of at rest and in transit are recognised and secure communication services, such as based on the evolution oftechnological international debate around best
  185. data at rest and data in deployed ad hoc by multiplestakeholders encrypted or signed email.The advancement and changing threat practice on cryptographic
  186. transit may be a concern but and within various sectors.Tools, such as cryptographic controls deployed meet environment.The public and private sectors controls.Implementation of Controls are not yet deployed within TLS, are deployedad hoc by service international standards and guidelines for have developed encryption and cryptographic cryptographic controls are made in
  187. the government or private providers to secure all communications each sector and are kept up to control policies based on the response to changing threat
  188. sector, or by the general between servers and users. date.Tools, such as TLS are routinely previousassessment, and regularly review the environments.
  189. public. deployed by service providers to secure policies for effectiveness.The country has
  190. all communications between servers and considered implementing digital-identity
  191. users. management.The country has considered
  192. whether it requires a national PKI.
  193. Quality and performance of Software quality and functional Quality of software used in public and software used in the country is a Software quality and functional requirements requirements in public and private sectors are private sectors is monitored and concern, but functional in public and private sectors are recognised and recognised and established.Reliable software assessed.Policies and processes on Software applications of high- level requirements are not yet fully identified, but not necessarily in a strategic applications that adhere to international software updates andmaintenance performance, reliability and usability monitored.A catalogue of manner.A catalogue for assured software standards and good practices are being used (including patch management) are being are available, with service continuity assured software platforms and platforms and applications within the public and Software widely in the public and private improved, based on risk assessments and processes fully applications within the public and private sectors is in development.Policies and Quality and sectors.Policies on and processes for the critical nature of services in all automated.Requirements of software private sectors does not processes on software updates Assurance software updates andmaintenance (including sectors.Benefits to businesses from quality are being systematically exist.Policies and processes andmaintenance (including patch management) patch management) are established in all additional investment in ensuring software reviewed, updated, and adapted to regarding updates and are now in development.Evidence of software sectors.Software applications are quality and maintenance are measured and the changing cybersecurity maintenance (including patch quality deficiencies is being gathered and characterised as to their reliability, usability assessed.Software defects are environment. management) of software assessed regarding its impact on usability and and performance in adherence to manageable in a timely manner and applications have not yet been performance. international standards and good practices. service continuity is ensured. formulated.
  194. Regular assessments are Affordable and reliable Internet Reliable Internet services are widely Acquisition of infrastructure technologies Limited Internet services and made of technology, of processes services and infrastructure in the country available and used.Internet services are is effectively controlled, with flexibility infrastructure are available, but with low for compliance with international may not have been established; if they trusted widely for conductinge-commerce and incorporated according to changing market levels of adoption and issues of standards, and of guidelines that have been, adoption rates of those electronic business transactions; appropriate dynamics.Costs for infrastructure unreliability.The ability of Internet address the national need inthe services are a concern.There is little or authentication processes are technologies are continually assessed and Internet infrastructure in public and private sectors face of emerging risks, and no national oversight of network established.Technology deployed and optimised.Scientific, technical, industrial Infrastructure to withstand incidents with minimum changes are made as infrastructure.If networks and systems processes used for managing Internet and human capabilities are being Reliability disruption has been discussed by multiple required.There is effective and are outsourced, the reliability of third- infrastructure meet international standards systematically maintained, enhanced, and stakeholders but may not have been fully controlled acquisition of critical party providers may not have been and follow good practices.National perpetuated in order to maintain the addressed.Support for securing Internet technologies, and there are considered.Network redundancy infrastructure is formally managed, with country’s independent infrastructure may rely on regional managed strategic planning and measures may be considered, but not in documented processes, roles and resilience.Optimised efficiency is in place assistance. service continuity processes in a systematic, comprehensive fashion. responsibilities, and limited redundancy. to mediate extended outages of systems. place.
  195. Risks related to emerging and
  196. Mechanisms are in place in both public and converging technologies are National-level assets can act to work
  197. private sectors to conduct risk assessments, regularly assessed by Internet with the international community in the No risk assessments are conducted by Processes on developing risk monitor and test network resilience, and to Infrastructure owners.Risks event of a trans-jurisdictional crisis or Internet infrastructure owners to identify assessments for Internet infrastructure respond to incidents.Incident response plans related to emerging and incident.Lessons learnt from international vulnerable assets and prioritise owners have been initiated.There is ad- Monitoring are in place in both public and private sectors converging technologies are collaborations are used toevolve protective actions.There is no monitoring hoc monitoring of parts of the and Response and are regularly tested and kept under regularly assessed by regulatory monitoring and response in place to detect that incidents have Internetinfrastructure, but it may not be review.Appropriate resources are allocated to agencies responsible for capabilities.Evidence exists that sovereign occurred.No incident response plans are comprehensive.Incident response plans hardwareintegration, technology stress electronic communications novel monitoring and response capabilities in place. are in development in some sectors. testing, personnel training, monitoring, networks and this is used to are being developed in anticipation of
  198. response, and drills to test response plans. inform funding and priority emerging threats.
  199. decisions.
  200. If there is local development of Security functions in software and cybersecurity technology, it abides by computer system configurations are secure codingguidelines, good automated in the development and If domestic production of practices and adheres to deployment of technologies.Domestic cybersecurity technologies If there is domestic production, the If there is domestic production, secure internationally- accepted cybersecurity products are exported to exists, it does not follow secure need for secure processes is processes are in place.If there is reliance on standards.Risk assessments and Cybersecurity other nations and are considered processes.The country has not recognised.If there is reliance on foreign foreign technologies, the security implications market incentives inform the Technologies superior products.The country has considered the security technologies, the security implications are identified and mitigated in the context of an prioritisation of productdevelopment established a body to assure the implications of using foreign are considered. international supply chain. and mitigation of identified risks.The security of foreign technologies cybersecurity technologies. security implications of using foreign (devices and software) and supply technologies are routinely analysed chains, or to certify entities which can and revised based on the assessment do this. of emerging cybersecurity risks.
  201. There are a growing number of
  202. cybersecurity consultancyservices There are widespread cybersecurity consultancy Private and public organisations
  203. Cybersecurity consultancy available for private and public services available for private and public routinely seek advice from Cybersecurity services are not widely on offer organisations.A growing number of organisations.All service providers provide details cybersecurity consultancy services, The cybersecurity service sector in
  204. Services and in the country.Few if any service service providers provide detail of the of the professional certifications they possess.A including advice about emerging the country helps shape the
  205. Expertise providers have professional professional certifications they national body accredits service providers, to risks.There is an adequate supply of international market.
  206. certification. possess.There may be limited or no assist organisations in selecting service cybersecurity professionals in the
  207. guidance to assist organisations with the providers. country.
  208. selection of service providers.
  209. Some organisations and sectors Most major organisations from the public and
  210. No risk assessments are conduct risk assessments to determine private sectors conduct risk assessments to Insights arising from risk
  211. conducted to determine how to how to mitigate the risks of outsourcing determine how to mitigate the risks of assessments are routinely analysed in
  212. mitigate the risks of outsourcing IT to a third party or cloud services.At outsourcing IT to a third party or cloud order to establish and promote Security The country is contributing to IT to a third party or cloud least some organisations and sectors services.There is widespread understanding of cybersecurity best practices to Implications of international best practice on how to services.There is a lack of understand the security measures that the security guarantees provided by the mitigate the risk of outsourcing Outsourcing mitigate the risk of outsourcing IT. understanding of the security the outsourced IT service provider outsourced IT service providers.Most IT.Different risk scenarios with the IT
  213. measures that the outsourced applies.At least some organisations have organisations have developed and tested service provider are explored and
  214. IT service provider applies. developed business continuity and processes to support business continuity and tested, including emerging risks.
  215. disaster recovery processes. disaster recovery.
  216. Cyber-insurance market offers a
  217. variety of covers to mitigate
  218. consequential losses.Cover is
  219. The need for a cyber- The need for a market in cyber- selected by organisations based on A market for cyber-insurance is established insurance market may have insurance has been identified through strategic planning needs and identified and encourages the sharing of threat- Cyber-insurance practices in the been identified, but no products the assessment of financial risks for the risk.The cyber-insurance market is Cyber Insurance information among participants of the country help to shape the international and servicesare widely public and private sectors, and the innovative and adapts to emerging market.Products suitable for small and medium- market. available, either domestically or appropriateness of availableofferings is risks, standards andpractices, while sized enterprises (SMEs) are also on offer. from external providers. now being discussed. addressing the full scope of cyber
  220. harm.Insurance premium reductions
  221. are offered for consistent cyber-
  222. secure behaviour.
  223. Vulnerability information-sharing
  224. There is no informal way of There are formal information- sharing mechanisms are continuously Technical details of vulnerabilities are sharing information among the mechanisms or channels in place to share the reviewed and updated basedon the shared informally with other stakeholders stakeholders about the technical technical details of vulnerabilities with other needs of all affected stakeholders, and The country is contributing to the Sharing which can distribute the information more details of stakeholders, which can distribute the in the light of emerging risks.All debate and international best practice Vulnerability broadly.Software and service providers vulnerabilities.Software and information more broadly.A substantial affected products and services are on the sharing of vulnerability Information are able to address bug and vulnerability service providers generally lack proportion of vulnerabilities in products and routinely updated within defined information. reports but there may not be formal the ability to address bug and services are remedied within defined deadlines deadline.Processes are in place to protocols for doing so. vulnerability reports. after their discovery. review and reduce deadlines where
  225. possible.
  226. The need for a responsible- disclosure
  227. policy in public and private sector A responsible-disclosure policy or framework Responsible-disclosure policies and organisationsis recognised but policies or is in place in public and private sector Policies, processes are continuously reviewed The need for a responsible- processes may not be in place, or may organisations, and includes a disclosure and updated based on the needs of all Processes and disclosure policy in public and only be in development.The right to legal deadline, scheduled resolution, and the need for The country is contributing to the debate
  228. affected stakeholders and in the light Legislation for private sector organisations, protections for those disclosing security acknowledgement.Organisations have on responsible-disclosure frameworks of emerging risks.An analysis of the Responsible and the right to legal protections flaws is recognised but legislation may established processes to receive and and legal protections for those technical details of vulnerabilitiesis for those disclosing security not be in place; or may only be in disseminate vulnerability information disclosing security flaws responsibly. Disclosure of published and advisory information is
  229. flaws are not yet acknowledged. development.Software and service responsibly.The right to legal protections for Security Flaws disseminated according to individual providers commit to refraining from those disclosing security flaws responsibly is in roles and responsibilities. taking legal action against a party place.
  230. disclosing information responsibly.