ENISA issued the Evaluation Framework on National Cyber Security Strategies (NCSS)

ENISA has presented at the workshop on National Cyber Security Strategies in Brussels the Evaluation Framework on National Cyber Security Strategies (NCSS).

ENISA issued the Evaluation Framework on National Cyber Security Strategies (NCSS), an important work that addressed to policy experts and government officials that are in charge for the implementation and evaluation of an NCSS policy. The work was presented on the 27th November 2014 at the first workshop on National Cyber Security Strategies in Brussels.

The work resumes a framework on NCSS elaborated by the ENISA in 2012, when the Agency defined a collection of best practices for the implementation of an NCSS through “a well-defined lifecycle.” The previous work also included an analysis on how to align policy and how to involve the private entities. Previous work also includes operational and regulatory objectives.

The framework results from the contribution of the leading experts on NCSS that have shared best practices on the above activities.  The work considers the eighteen EU National Cyber Security Strategies and eight non-EU strategies and was issued  to assist Member States in developing capabilities in the area of NCSS in compliance with Cyber Security Strategy (EU CSS).

The proposed Evaluation Framework on National Cyber Security Strategies (NCSS) consists of the following elements and includes recommendations for proper implementation of the framework itself.

  • A blueprint logic model presenting conceptual building blocks and a structure. The Logic modelling is an evaluation tool which is suggested to deploy in order to understand the logic of the
    NCSS and its implementation;
  • A list of possible key performance indicators (KPIs);

Within the primary goals of the framework there are the achievement of the cyber resilience and the development of cyber capabilities through the improvement of cooperation within public and private sector. The list of elements in the Logic modelling includes:

  • Developing cyber defence policies and capabilities
  • Achieving cyber resilience: developing capabilities and cooperating efficiently within public and private sector
  • Reducing cyber crime
  • Develop the industrial and technological resources for cybersecurity
  • Secure critical information infrastructure

The Key performance indicators (KPIs) are an essential component for the evaluation of an NCSS and allow actors to measure performance or progress of the implementation of an NCSS. Key performance indicators are crucial in both phases of NCSS implementation and evaluation, from their analysis, it is possible to review objectives during the lifecycle of the program.

The KPIs are categorized per objective:

  • Key objective 1: Developing cyberdefence policy and capabilities
  • Key objective 2: Achieving cyber resilience: develop capabilities and efficient cooperation within public and private sector
  • Key objective 3: Reduce cybercrime
  • Key Objective 4: Develop the industrial and technological resources for cybersecurity
  • Key objective 5: Secure critical information infrastructure

“A National Cyber Security Strategy is an important step that allows Member States to address cyber security risks and challenges. This is a continuous process that requires proper evaluation, in order to adjust to the emerging needs of society, technology and the economy. With this work ENISA provides a systematic and practical evaluation framework that allows EU Member States to improve their capabilities when designing NCSS”. Commented Udo Helmbrecht, the Executive Director of ENISA. 

As highlighted in the work, the NCSS has to be adjusted to the needs of different Member States depending on the level of maturity reached in the lifecycle of an NCSS.

Let me suggest you the reading of this excellent work.

Pierluigi Paganini

(Security Affairs –  ENISA, NCSS)

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Meta stopped covert operations from Iran, China, and Romania spreading propaganda

Meta stopped three covert operations from Iran, China, and Romania using fake accounts to spread…

19 hours ago

US Treasury sanctioned the firm Funnull Technology as major cyber scam facilitator

The U.S. sanctioned Funnull Technology and Liu Lizhi for aiding romance scams that caused major…

1 day ago

ConnectWise suffered a cyberattack carried out by a sophisticated nation state actor<gwmw style="display:none;"></gwmw><gwmw style="display:none;"></gwmw>

ConnectWise detected suspicious activity linked to a nation-state actor, impacting a small number of its…

1 day ago

Victoria’s Secret ‘s website offline following a cyberattack

Victoria’s Secret took its website offline after a cyberattack, with experts warning of rising threats…

2 days ago

China-linked APT41 used Google Calendar as C2 to control its TOUGHPROGRESS malware

Google says China-linked group APT41 controlled malware via Google Calendar to target governments through a…

2 days ago

New AyySSHush botnet compromised over 9,000 ASUS routers, adding a persistent SSH backdoor.

GreyNoise researchers warn of a new AyySSHush botnet compromised over 9,000 ASUS routers, adding a…

2 days ago