CBM 7: National strategies, policies and programs
Organization for Security and Co-operation in Europe
Measure
CBM 7 (2013): Participating States will voluntarily share information on their national organization; strategies; policies and programmes – including on cooperation between the public and the private sector; relevant to the security of and in the use of ICTs; the extent to be determined by the providing parties.
Background: This CBM encourages OSCE participating states to voluntarily exchange information on how they structure and govern national cybersecurity efforts - such as through strategies, policies, public-private partnerships, and institutional frameworks. This is a quite “traditional” CBM, especially focused on building transparency, however, it also acknowledges the crucial role of the private sector to enhance cybersecurity.
Practice: This CBM, like so many others, thrives on regular exchange. There are two main options for exchanging information to implement this CBM: such documents can be exchanged via the POLIS Knowledge and Learning Platform. In 2019, already more than 200 documents from numerous OSCE participating states were available there. However, the use of the platform has declined somewhat in recent years. States also regularly use the IWG meetings to share updates on this topic. In addition, states publish such documents via channels such as their own websites or the UNIDIR Cyber Policy Portal. Furthermore, this CBM is connected to others; for example, CBM 14 also aims to facilitate the exchange of best practices regarding public-private partnerships. Overall, the CBM is widely implemented.
Key Implementation Activities and Resources
Participating states share information on national cybersecurity strategies, governance structures, public-private partnerships, and institutional arrangements.
Information exchange is facilitated through the POLIS platform, IWG meetings, and implicitly via publicly available national cybersecurity documentation.