A brief examination of Jamaica\u2019s new National Cyber Security Strategy.<\/em><\/p>\n
Over the past 3 years or so, the Government of Jamaica has been embarrassed by a number of cybersecurity breaches that have occurred across its ministries, departments and agencies, which ranged from simple website defacement, to the theft of data from key institutions. Though there had been some discussion about cybercrime\/cybersecurity and the need for improved systems, those incidents were likely to have the effect of galvanising the Government to move from idle talk to action.<\/p>\n
Two weeks ago, one of those outputs, a National Cyber Security Strategy, was made publicly available. The strategy is the culmination of a number of activities that were charged by the National Cyber Security Task Force established by the Ministry of Science, Technology, Energy and Mining. The launch of a Cyber Incident Response Team is being eagerly awaited, and (hopefully) should be realised soon.<\/p>\n
However, Jamaica\u2019s new cyber security strategy does signal a new and important development in efforts to address and better manage Jamaica\u2019s cyber landscape. Below is a synopsis of the strategy, and some early thoughts on its contents.<\/p>\n
Cybercrimes and cyber incidents in Jamaica have been increasing. In 2011, there were 19 reported cybercrimes and 1,432 cyber incidents, whilst in 2012, those figures jumped to 43 and 2,438, respectively (Source: Government of Jamaica<\/a>).<\/p>\n
To that end, the Government\u2019s cybersecurity framework<\/a> comprises the following four key areas and the accompanying strategic objectives<\/p>\n
1. Technical measures<\/strong>, such as ensuring that<\/p>\n
2.\u00a0 Human resource and capacity building<\/strong>, which includes ensuring that<\/p>\n
3.\u00a0 Legal and regulatory<\/strong>, which includes ensuring that<\/p>\n
4.\u00a0 Public education and awareness<\/strong>, to ensure that<\/p>\n
The strategy will be valid for a period of three years, and within the next three months an implementation plan must be developed.<\/p>\n
Jamaica\u2019s National Cyber Security Strategy is a glossy and beautifully laid out document. The strategy is relatively straightforward and has been distilled to cover the four areas outlined above. Also annexed to the document is a list of proposed activities that could satisfy the strategic objectives, which are likely to be used to prepare the anticipated implementation plan.<\/p>\n
However, when the document is examined in its totality, it still appears somewhat superficial, in that it has little depth: a general course has been plotted, but much still needs to be fleshed out. To some degree, this approach could be attributed to the fact that cybersecurity is a new area, and the since most of players would have little experience in that space, the strategy has been designed to given them, and the entire process, some latitude to adjust as needed.<\/p>\n
Further, when the list of proposed activities is considered, the fact that international donors will be needed to provide assistance for some activities, and there might not be a dedicated unit charged with managing and implementing the strategy, from the outset, the strategy seems to be an ambitious undertaking. It will therefore be interesting to see how Jamaica navigates and implements it, going forward.<\/p>\n
<\/p>\n
Image credit: Andriyko_UA<\/a>, Wikimedia Commons<\/em><\/p>\n
___________<\/p>\n","protected":false},"excerpt":{"rendered":"