🇨🇴⚖️ La Rama Judicial valida a Ariel en prueba de concepto de IA. Conoce los resultados aquí

OEA - Guide to Developing a National Cybersecurity Strategy

OEA - Organización de Estados Americanos

Icono de documento PDF

Descargar PDF

Disponible

Detalles

Título
OEA - Guide to Developing a National Cybersecurity Strategy
Autor
OEA - Organización de Estados Americanos
Categoría
Doctrina
Área del derecho
Internacional_Publico
Año

i

GUIDE TO DEVELOPING A NATIONAL CYBERSECURITY STRATEGY 3RD EDITION

STRATEGIC ENGAGEMENT IN CYBERSECURITY

Guide to Developing a National Cybersecurity Strategy

THIRD EDITION 2025ii

GUIDE TO DEVELOPING A NATIONAL CYBERSECURITY STRATEGY 3RD EDITION

SOME RIGHTS RESERVED

ISBN 978-92-61-42081-9 (PDF English Edition) © 2025 International Telecommunication Union (ITU) and The World Bank (WB). This Guide was developed by thirty-seven Contributors from Intergovernmental and International Organizations, private sector, as well as academia and civil society and included the following organizations: Accenture, African Union (AU), Arab League, Axon Partners Group, Commonwealth Telecommunications Organisation (CTO), Council of Europe (CoE), Cybercrime Research Institute (CRI), Cybersecurity Capacity Centre for Southern Africa (C3SA), Deloitte, DiploFoundation (Diplo), European Bank for Reconstruction and Development (EBRD), e-Governance Academy (eGA), European Union CyberNet (EU CyberNet), Experirē Strategy & Advisory, Forum of Incident Response and Security Teams (FIRST), Geneva Centre for Security Sector Governance (DCAF), Global Cyber Security Capacity Centre (GCSCC), Global Forum on Cyber Expertise (GFCE), Global Partners Digital (GPD), Hathaway Global Strategies LLC, Inter-American Development Bank (IADB), International Criminal Police Organization (INTERPOL), International Monetary Fund (IMF), International Telecommunication Union (ITU), KPMG, Microsoft, NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE), NRD Cyber Security, Organization of American States (OAS), United Nations Development Programme (UNDP), United Nations Interregional Crime and Justice Research Institute (UNICRI), United Nations Institute for Disarmament Research (UNIDIR), United Nations Office of Counter-Terrorism (UNOCT), United Nations Office for Disarmament Affairs (UNODA), United Nations Office on Drugs and Crime (UNODC), United Nations University (UNU), World Bank (WB), World Economic Forum (WEF), and the European Union

work by the International Telecommunication Union, the World Bank and Contributors. Views and opinions expressed in the adaptation are the sole responsibility of the author or authors of the adaptation and are not endorsed by the International Telecommunication Union, the World Bank or by any of the Contributors.” Any mediation relating to disputes arising under the licence shall be conducted in accordance with the mediation rules of the World Intellectual Property Organization ( http://www.wipo.int/amc/en/mediation/rules ). Third-party materials. If you wish to reuse material from this work that is attributed to a third party, such as tables, figures or images, it is your responsibility to determine whether permission is needed for that reuse and to obtain permission from the copyright holder. The risk of claims resulting from infringement of any third party-owned component in the work rests solely with the user. Attribution - Please cite the work as follows: International Telecommunication Union (ITU), The World Bank, et Al., 2025. Guide to Developing a National Cybersecurity Strategy, 3rd Edition – Strategic Engagement in Cybersecurity. Creative Commons Attribution-NonCommercial 3.0 IGO licence (CC BY-NC 3.0 IGO). GENERAL DISCLAIMERS The designations employed and the presentation of the material in this publication do not imply the expression of any opinion whatsoever on the part of the International Telecommunication Union, the World Bank or any of the Contributors concerning the legal status of any country, territory, city or area or of its authorities, or concerning the delimitation of its frontiers or boundaries. The ideas and opinions expressed in this publication are those of the authors; they do not necessarily reflect the views of the International Telecommunication Union, the World Bank, its Board of Executive Directors, or the governments they represent, or those of the Contributors. The mention of specific companies, products or services does not imply that they are endorsed or recommended in preference to others of a similar nature that are not mentioned. Errors and omissions excepted; the names of proprietary products are distinguished by initial capital letters. All reasonable precautions have been taken by the International Telecommunication Union, the World Bank and Contributors to verify the information contained in this publication. However, the published material is being

that are not mentioned. Errors and omissions excepted; the names of proprietary products are distinguished by initial capital letters. All reasonable precautions have been taken by the International Telecommunication Union, the World Bank and Contributors to verify the information contained in this publication. However, the published material is being distributed without warranty of any kind, either expressed or implied. The responsibility for the interpretation and use of the material lies with the reader. In no event shall the International Telecommunication Union, the World Bank or any of the Contributors be liable for damages arising from its use.iv

GUIDE TO DEVELOPING A NATIONAL CYBERSECURITY STRATEGY 3RD EDITION

CONTRIBUTORS

CONTRIBUTORSv

GUIDE TO DEVELOPING A NATIONAL CYBERSECURITY STRATEGY 3RD EDITION

OBSERVER

OBSERVERvi

GUIDE TO DEVELOPING A NATIONAL CYBERSECURITY STRATEGY 3RD EDITION Technology and connectivity are powerful enablers of inclusive and sustainable development. Technological growth, however, brings persistent and evolving cybersecurity challenges. Experience shows that the full potential of digitalization remains out of reach unless its underlying infrastructure and services are secure, resilient, and reliable. One of the most important steps governments can take as they seek to promote digital transformation while addressing cybersecurity risks is to invest in long-term strategic planning to guide resource allocation, set priorities, and build capacities. Cybersecurity should be integrated into a country’s broader vision and approached strategically and systemically, through iterative cycles of implementation, monitoring, and evaluation. To this end, many countries have gained valuable experience through the development and successive revisions of their national cybersecurity strategies. This accumulated knowledge provides a solid foundation for drawing conclusions and formulating recommendations that can guide countries with less experience or resources in navigating this ever-evolving domain. In 2018, to empower and equip national leaders and policymakers with the analytical and conceptual tools needed to craft national cybersecurity strategies, a group of Contributors co-authored the Guide to Developing a National Cybersecurity Strategy (the “Guide”). Building on the positive reception of the first edition, a broader coalition convened to update the Guide and publish its second edition in 2021.

Crime and Justice Research Institute Dr. Jingbo Huang Director, United Nations University Institute in Macau Ms. Izumi Nakamitsu Under-Secretary-General and High Representative for Disarmament Affairs, UNODA Ms. Brigitte Strobel-Shaw Officer in Charge of the Division of Treaty Affairs, UNODC Ms. Christine Zhenwei Qiang Global Director, Digital Transformation, World Bank Mr. Tal Goldstein Head of Strategy and Growth, Centre for Cybersecurity, World Economic Forumix

GUIDE TO DEVELOPING A NATIONAL CYBERSECURITY STRATEGY 3RD EDITIONx

GUIDE TO DEVELOPING A NATIONAL CYBERSECURITY STRATEGY 3RD EDITION 1 DOCUMENT OVERVIEW .......................................................................................................................2 1.1 Purpose .......................................................................................................................................................3 1.2 Scope ..........................................................................................................................................................3 1.3 Overall structure and usage of the Guide ..................................................................................................4 1.4 Target audience .........................................................................................................................................4 2 INTRODUCTION ....................................................................................................................................6 2.1 What is cybersecurity .................................................................................................................................7 2.2 Benefits of a National Cybersecurity Strategy and Strategy Development Process ...............................7 3 LIFECYCLE ..........................................................................................................................................10 3.1 Phase I – Initiation ......................................................................................................................................11 3.2 Phase II – Stocktaking and Analysis......................................................................................................... 15 3.3 Phase III – Sustainable Funding and Resource Planning ......................................................................... 16 3.4 Phase IV – Production of the National Cybersecurity Strategy .............................................................. 19 3.5 Phase V – Implementation ........................................................................................................................ 21 3.6 Phase VI – Monitoring and Evaluation......................................................................................................22 4 OVERARCHING PRINCIPLES ........................................................................................................26 4.1 Vision ........................................................................................................................................................27 4.2 Comprehensive approach and tailored priorities ....................................................................................27 4.3 Inclusiveness ........................................................................................................................................... 28 4.4 Economic and Social Prosperity ............................................................................................................. 28 4.5 Fundamental human rights ...................................................................................................................... 29 4.6 Risk management and resilience ............................................................................................................ 29 4.7 Appropriate set of policy instruments .................................................................................................... 29

4.3 Inclusiveness ........................................................................................................................................... 28 4.4 Economic and Social Prosperity ............................................................................................................. 28 4.5 Fundamental human rights ...................................................................................................................... 29 4.6 Risk management and resilience ............................................................................................................ 29 4.7 Appropriate set of policy instruments .................................................................................................... 29 4.8 Clear leadership, roles, and resource allocation .................................................................................... 30 4.9 Trust environment ................................................................................................................................... 30 4.10 Technological foresight and adaptability ............................................................................................... 30 Contentsxi

GUIDE TO DEVELOPING A NATIONAL CYBERSECURITY STRATEGY 3RD EDITION 5 NATIONAL CYBERSECURITY STRATEGY GOOD PRACTICE ............................................32 5.1 Focus Area 1 – Governance..................................................................................................................... 34 5.2 Focus Area 2 – Critical Infrastructure, Critical Information Infrastructure, and Essential Services .......37 5.3 Focus Area 3 – Risk Management in National Cybersecurity ................................................................ 40 5.4 Focus Area 4 – Incident Response ......................................................................................................... 42 5.5 Focus Area 5 – Capability and Capacity-Building, and Awareness Raising .......................................... 45 5.6 Focus Area 6 – Legislation and Regulation ............................................................................................. 49 5.7 Focus Area 7 – International Cooperation ...............................................................................................52 6 REFERENCE MATERIALS .......................................................................................................................56 7 ACRONYMS....................................................................................................................................................58xii

GUIDE TO DEVELOPING A NATIONAL CYBERSECURITY STRATEGY 3RD EDITION PREFACE The Guide to Developing a National Cybersecurity Strategy is one of the most comprehensive overviews of what constitutes a successful cybersecurity strategy. It is the result of a unique, collaborative, and equitable multistakeholder effort. The Contributors came together with an appreciation of the need to strengthen cooperation and coordination across the international community on cyber capacity-building. The objective of this effort is to support national leaders and policymakers in the development of defensive and proactive responses to cybersecurity risks, in the form of a National Cybersecurity Strategy (NCS), and in thinking strategically about cybersecurity, cyber preparedness, response, and resilience, while building confidence and security in the use of digital technologies.

is to support national leaders and policymakers in the development of defensive and proactive responses to cybersecurity risks, in the form of a National Cybersecurity Strategy (NCS), and in thinking strategically about cybersecurity, cyber preparedness, response, and resilience, while building confidence and security in the use of digital technologies. The Guide was developed through an iterative approach that sought to reach agreement through consensusbuilding. It is based on existing authoritative resources and aims to facilitate their use by national stakeholders. Wherever possible, the relevant sources and tools used in developing each section of this Guide are listed in the Reference section (available on www.ncsguide.org ) to encourage their broader use. Cybersecurity is a foundational element underpinning the achievement of socio-economic objectives of modern economies. The hope is that this third edition of the Guide to Developing a National Cybersecurity Strategy can continue to serve as a useful tool for all stakeholders involved in the development, implementation, and revision of this type of official document, including national leaders, policymakers, legislators, and regulators with cybersecurity responsibilities. In addition, it might have broader applicability, as the concepts introduced can be applied at the regional or municipal levels, and can also be adapted for industry or used for academic research. NOTE TO READERS ON THE UPDATE Version 3 of the Guide to Developing a National Cybersecurity Strategy (NCS) updates, refines, and expands upon Version 2, which was published in 2021. Since then, the cybersecurity risk environment, technologies, and policy practices have continued to evolve and grow in complexity. This edition captures key developments in cybersecurity as well as emerging and disruptive technologies that governments should consider in their national strategic planning, while preserving compatibility with prior versions and the Guide’s process-pluscontent approach. This new Version focuses on practical recommendations and ease of use, and includes new material where practice has advanced. However, Version 3 remains fully compatible with Version 2 and preserves the Guide’s balance between process (Lifecycle) and content (Overarching Principles and Focus Areas). Countries that adopted earlier versions can use Version 3 to review and update their national cybersecurity strategies or make incremental improvements, particularly in financing, governance, requirements for critical infrastructure, critical

(CSIRTs), Computer Incident Response Teams (CIRTs)) with sectoral counterparts, Security Operations Centers (SOCs), and Product Security Incident Response Teams (PSIRTs) in national cybersecurity architectures. It also reinforces contingency planning, information-sharing mechanisms (including ISACs/ISAOs), national and international exercises, and severity/impact assessments. • Capability, capacity, and awareness : Deeper guidance is provided on national cybersecurity workforce frameworks, education-to-workforce pathways (from early education to advanced programs and apprenticeships), and inclusive strategies to attract and retain talent, including women and underrepresented groups. The Guide also highlights executive and operational training, certification, dedicated career pipelines, and coordinated national awareness campaigns tailored to diverse audiences. • Legislation and regulation : The updated Guide presents a holistic approach by mapping policy goals to legal and regulatory instruments. It clarifies mandates and oversight, embeds safeguards in cybercrime and electronic-evidence provisions, and emphasizes proportionality, human rights, due process, and data protection. It also supports legal harmonization and cross-border cooperation. • International cooperation : This version strengthens links between domestic priorities and foreign policy. It encourages participation in international law and norms processes, confidence-building measures (CBMs), and standards bodies; promotes practical cooperation through formal and informal networks (including CERT/CSIRT/CIRT communities, law enforcement channels, and multistakeholder platforms); and expands on capacity-building for cyber diplomacy and international engagement. • Reference section (available at www.ncsguide.org ): This version of the Guide will provide a dynamic Reference Section on its website, enabling simplified access and maintenance to keep references up to date. This updated Guide is designed as a practical reference for national leaders, policymakers, regulators, industry representatives, civil society, and other parties involved in the development of an NCS. Recognizing the importance of multistakeholder engagement, the Guide’s emphasis on government entities in some sections seeks to highlight where a government entity’s leadership is pivotal to the sustainability of the process. It aims to help countries develop, implement, and sustain an effective NCS in alignment with

United Nations Office for Disarmament Affairs (UNODA), United Nations Office on Drugs and Crime (UNODC), United Nations University (UNU), World Bank (WB), World Economic Forum (WEF), and the European Union Agency for Cybersecurity (ENISA) contributed to the Guide as observer. All the above-mentioned entities are hereinafter collectively referred to as “Contributors”. RIGHTS & PERMISSION This work is available under the Creative Commons Attribution-NonCommercial 3.0 IGO licence (CC BY-NC 3.0 IGO; https://creativecommons.org/licenses/by-nc/3.0/igo/deed.en ), unless otherwise indicated in the work. For any uses of this work that are not included in this licence, please seek permission from ITU at cybersecurity@itu.int. Within the scope and under the terms of this licence, you may copy, redistribute and adapt the work for non-commercial purposes, provided the work is appropriately cited, as indicated below. In any use of this work, there should be no suggestion that the International Telecommunication Union, the World Bank or any of the Contributors endorse any specific organization, products or services. The unauthorized use of the International Telecommunication Union, The World Bank or any of the Contributors’ names or logos is notiii

GUIDE TO DEVELOPING A NATIONAL CYBERSECURITY STRATEGY 3RD EDITION permitted. If you create a translation of this work, you should add the following disclaimer along with the suggested citation: “This translation was not created by the International Telecommunication Union, the World Bank or any of the Contributors, which are not responsible for the content or accuracy of this translation. The original English edition shall be the binding and authentic edition”. If you create an adaptation of this work, please add the following disclaimer along with the attribution: “This is an adaptation of an original work by the International Telecommunication Union, the World Bank and Contributors. Views and opinions expressed in the adaptation are the sole responsibility of the author or authors of the adaptation and are not endorsed by the International Telecommunication Union, the World Bank or by any of the Contributors.” Any

balance between process (Lifecycle) and content (Overarching Principles and Focus Areas). Countries that adopted earlier versions can use Version 3 to review and update their national cybersecurity strategies or make incremental improvements, particularly in financing, governance, requirements for critical infrastructure, critical information infrastructure, and essential services (CI/CII/ES), risk management, incident response, legislation, and international engagement.xiii

GUIDE TO DEVELOPING A NATIONAL CYBERSECURITY STRATEGY 3RD EDITION Major updates and additions include: • Lifecycle financing and long-term sustainment : More detailed language emphasizes strategic resource planning and sustainable funding across the full NCS lifecycle (development, implementation, monitoring, review, and renewal). This includes alignment with national budget and public investment cycles, the use of dedicated funding lines, optimization of existing government resources, and external financing (e.g., multilateral development banks (MDBs), international financial institutions (IFIs), donors, technical assistance). Multi-year sustainment, attention to out-year costs and forward-looking budget projections, and fully funded initiatives are stressed. Resources should be defined in terms of money, people, and material. • Monitoring, evaluation, and cyclical reviews : Governments are encouraged to incorporate SMART KPIs (Specific, Measurable, Achievable, Relevant, Time-related) into their strategies and action plans, establish clear governance of monitoring and evaluation, and define baseline metrics with scheduled reviews (e.g., mid-term check-ins, 3–5-year renewals) to ensure the strategy remains current with threats, technologies, and national priorities. • Technological foresight and adaptability (new principle) : This principle underscores horizon scanning and policy agility to anticipate evolving digital risks and adapt to emerging technologies (artificial intelligence (AI), automation, quantum computing, Internet of Things (IoT), 5G/6G, distributed ledger technologies), with mechanisms to translate foresight into strategy and regulation.

and policy agility to anticipate evolving digital risks and adapt to emerging technologies (artificial intelligence (AI), automation, quantum computing, Internet of Things (IoT), 5G/6G, distributed ledger technologies), with mechanisms to translate foresight into strategy and regulation. • Governance and accountability : G u i d a n c e i s s t r e n g t h e n e d o n l e a d a u t h o r i t y r o l e s , w h o l e - o fgovernment and whole-of-society coordination, stakeholder engagement, and advisory mechanisms. It emphasizes intra-governmental and cross-sector coordination, clear assignment of responsibilities and mandates, and integration of governance into action plans. • Critical infrastructure, critical information infrastructure, and essential services (CI/CII/ES) : Expanded guidance addresses identification, designation, governance, and risk-based requirements for operators. It introduces outcome-focused baselines, tiered expectations, oversight mechanisms, and considerations for cross-border interdependencies and systemic cybersecurity risks (e.g., an incident involving a widely used software provider that leads to the disruption of thousands of its customers, or a failure of a critical financial institution that disrupts an entire financial system, causing broader economic impact). • Risk management framework : The updated Guide stresses the importance of having a national approach to assessing and managing cybersecurity risk, including dynamic national and sectoral assessments; a continuously updated national risk register covering critical sectors, services, functions, operators, and assets; adoption of common methodologies aligned with international standards; and feedback loops linking risk insights to policy, investment, and crisis management. • Incident response and resilience : This version expands guidance on the role of national response teams (Computer Emergency Response Teams (CERTs), Computer Security Incident Response Teamsxiv

GUIDE TO DEVELOPING A NATIONAL CYBERSECURITY STRATEGY 3RD EDITION

(CSIRTs), Computer Incident Response Teams (CIRTs)) with sectoral counterparts, Security Operations Centers (SOCs), and Product Security Incident Response Teams (PSIRTs) in national cybersecurity architectures. It also reinforces contingency planning, information-sharing mechanisms (including

the importance of multistakeholder engagement, the Guide’s emphasis on government entities in some sections seeks to highlight where a government entity’s leadership is pivotal to the sustainability of the process. It aims to help countries develop, implement, and sustain an effective NCS in alignment with evolving risks, emerging technologies, and international good practices.GUIDE TO DEVELOPING A NATIONAL CYBERSECURITY STRATEGY 3RD EDITION2 1 – DOCUMENT OVERVIEW

GUIDE TO DEVELOPING A NATIONAL CYBERSECURITY STRATEGY 3RD EDITION

Document

Overview SECTION 13 1 – DOCUMENT OVERVIEW

GUIDE TO DEVELOPING A NATIONAL CYBERSECURITY STRATEGY 3RD EDITION 1.1 PURPOSE The purpose of this document is to guide national leaders and policymakers in the development, implementation, and revision of a National Cybersecurity Strategy (NCS), and in thinking strategically about cybersecurity, cyber preparedness, and resilience. This Guide aims to provide a useful, flexible, and user-friendly framework to set the context of a country’s socio-economic vision and current national cybersecurity posture and to assist national leaders and policymakers in the development or revision of a Strategy that takes into consideration a country’s specific situation, cultural norms, and societal values, while encouraging the pursuit of secure, resilient, digitally empowered, and connected societies. The Guide is a unique resource, as it provides a framework developed and endorsed by organizations with demonstrated and diverse experience in this topic area and builds on their prior work in this space. As such, it offers the most comprehensive overview to date of what constitutes a successful National Cybersecurity Strategy. 1.2 SCOPE Cybersecurity is a complex challenge that encompasses multiple governance, policy, operational, technical, and legal aspects. This Guide addresses, organizes, and prioritizes many of these areas based on existing and well-recognized models, frameworks, and references. The Guide focuses on protecting civilian aspects of cyberspace and, as such, highlights overarching principles and good practices that need to be considered in the drafting, development, implementation, and revision of a National Cybersecurity Strategy. To this end, the Guide makes a clear distinction between the “process” adopted by countries during

of cyberspace and, as such, highlights overarching principles and good practices that need to be considered in the drafting, development, implementation, and revision of a National Cybersecurity Strategy. To this end, the Guide makes a clear distinction between the “process” adopted by countries during the lifecycle of a National Cybersecurity Strategy (initiation, stocktaking and analysis, production, implementation, reviews) and the “content” (i.e., the actual text that would appear in a National Cybersecurity Strategy document). The Guide does not cover aspects such as the development of defensive or offensive cybersecurity capabilities by a country’s military, defense forces, or intelligence agencies, even though a number of countries have been developing such capabilities. This Guide addresses (i) “what” should be included in a National Cybersecurity Strategy, and (ii) “how” to build, implement, and review it. The Guide also provides an overview of the core components of what it takes for a country to become cyber-prepared, highlighting the critical aspects that governments should consider when developing their national strategies and action plans. Finally, this Guide offers national leaders and policymakers a holistic, high-level overview of existing approaches and applications, as well as an online Reference Section with additional and complementary resources that can inform specific national cybersecurity effo

Consultar sobre este documento ...