Cyber Confidence-Building Measures

CBM 1: National strategies, policies and programs

Organization of American States

OASWidely implemented2018

Measure

CBM 1 (2018): Provide information on national cybersecurity policies, such as national strategies, white papers, legal frameworks and other documents that each Member State considers relevant.

Background: CBM 1 is designed to foster transparency and predictability among OAS member states in the field of cybersecurity by openly sharing strategic objectives, priorities, and governance structures related to national cybersecurity. This measure enables partners to anticipate each other's actions and policies in the cyber domain, thereby reducing the risk of misperceptions.

Practice: When this CBM was adopted in 2018, many OAS member states were still in the early stages of developing their national cybersecurity policies. Since then, progress has been steady: member states now regularly report on their developments, experiences, and challenges during the annual meetings of the CBM Working Group, in line with the CBM's transparency goals. Recognising the varying levels of capacity across the region, the CICTE Secretariat has taken a proactive role in supporting member states, for example by providing direct support to Mexico and Ecuador in formulating their national cybersecurity strategies. Overall, CICTE has supports 21 formulation processes in 16 states since 2011. These targeted efforts have helped ensure that more states are now in a position not only to develop but also to share their cybersecurity policies.

To streamline implementation, the CICTE Secretariat developed a standardised template with key fields, such as policy title, description, responsible institutions, effective date, and reference link. Member states are invited to voluntarily complete and submit this template, contributing to a centralised repository of national cybersecurity documentation. Since 2021, CBM 1 has also been supported by a secure web portal accessible to designated PoCs (see CBMs 2 and 3) from each member state. Maintained by the CICTE Secretariat and regularly updated to improve usability, the portal facilitates the exchange and retrieval of national cybersecurity policies. Since 2026, the web portal also integrates a “Cyber Threat Landscape” section, developed in coordination with the CSIRTAmericas Network. This feature enhances information exchange by providing real-time visibility into cyber incidents and threat trends across the region.

The number of states sharing documents through the portal has steadily increased, and today approximately 70% of OAS member states actively share their policies, either via the web portal or directly during CBM Working Group meetings. Therefore, this CBM is widely implemented. The Secretariat continues to encourage and support states in formulating such documents, creating clear synergies between the capacity-building dimension of CBMs 1 and 4.

Key Implementation Activities and Resources

  • The CICTE Secretariat provides capacity-building support for the development of national cybersecurity policies and strategies, (implicitly) helping states strengthen the foundations required for CBM implementation.

  • Implementation is supported by practical resources, including a standardised reporting template, a secure web portal for national PoCs, and a regional cyber threat information-sharing platform.