Replication Data for: Advanced Experiences in Cybersecurity Policies and Practices: An Overview of Estonia, Israel, South Korea, and the United States

By Innovation in Citizen Services Division (VPS/IFD/ICS)

This dataset was created to support the discussion paper “Advanced Experiences in Cybersecurity Policies and Practices – An Overview of Estonia, Israel, South Korea and the United States.” The study was a collaboration between Dr. James A. Lewis of the Center for Strategic and International Studies (CSIS) and the Inter-American Development Bank (IDB).

The data is structured around the Cybersecurity Capability Maturity Model (CMM), jointly developed by the Organization of American States (OAS), the IDB, and the Global Cyber Security Capacity Centre (GCSCC) at the University of Oxford. Using this framework, the dataset supports a cybersecurity maturity assessment of the four countries, highlighting their experiences and lessons learned.

By examining advanced international cases, the dataset provides insights highly relevant to discussions on technology in Latin America and its role in building robust cybersecurity systems.

This dataset also complements the 2016 Cybersecurity Report Dataset published in April 2016, offering continuity for researchers and policymakers working on digital security strategies in the region.

Show more

Metadata & use

Identifier https://doi.org/10.60966/gmbqi6gu
License Creative Commons Attribution–NonCommercial–NoDerivs 3.0 IGO
Related Knowledge Product
Citation

Lewis, James Andrew (2016). Replication Data for: Advanced Experiences in Cybersecurity Policies and Practices: An Overview of Estonia, Israel, South Korea, and the United States. IDB Open Data. https://doi.org/10.60966/gmbqi6gu

Published date 2016-01-08
Modified date 2026-08-26
Tags/Keywords Caribbean · Cyber Defense · Cyber Strategy · Cybercrime · Cybersecurity · Digital Redundancy · E-Government · Incident Response · Israel · Latin America · Legal Frameworks · National Critical Infrastructure · Online Trust · Privacy · Republic Of Korea · Resilience · South Korea · United States
Language
  1. Spanish
Temporal coverage 2015-2015
Country
Estonia
Israel
South Korea
United States
Region Latin America and the Caribbean
Publisher
Inter-American Development Bank
Author
Lewis, James Andrew
Inter-American Development Bank
Data collection type Observational Data
Statistical type Cross-sectional Data
Data structure Structured Data
Data notes

What does the Cybersecurity Capability Maturity Model (CMM) measure?

The CMM evaluates national cybersecurity capacity across five dimensions: policy and strategy, culture and society, education and skills, legal frameworks, and technologies. The report notes that it “uses five levels of maturity: startup, formative, established, strategic, and dynamic.”

Which countries demonstrate the highest cybersecurity maturity?

Estonia, Israel, and the United States frequently score at the Strategic (4) or Dynamic (5) levels across multiple indicators. Examples include Estonia’s “Incident Response: Coordination” (Dynamic, 5) and Israel’s “Cybersecurity Coordinating Organizations: Command and control center” (Dynamic, 5).

What are Estonia’s main cybersecurity challenges?

Estonia faces risks linked to its proximity to Russia, exposure to Eastern European cybercrime, and reliance on cross‑border digital services. The report states that Estonia’s “strong digital economy and its proximity to cybercrime hubs in Eastern Europe make it a target for cyber theft and fraud.”

How advanced is Estonia’s national cybersecurity strategy?

Estonia is described as having one of the most dynamic approaches. Its first national strategy was shaped by the 2007 cyberattacks, and cybersecurity has become “a hallmark of Estonian foreign policy.”

How does Israel perform in cybersecurity education and workforce development?

Israel reaches Dynamic (5) in national cybersecurity education and training availability, reflecting long‑term investment in cyber talent pipelines.

Which country has the strongest legal frameworks for cybercrime?

The United States scores a Dynamic (5) in substantive and procedural cybercrime law and in legal investigation indicators. The report notes that all four countries expanded legal authorities, but the U.S. has one of the most extensive frameworks.

What does the dataset show about Critical National Infrastructure (CNI) protection?

Israel and the United States consistently reach Strategic (4) across identification, risk management, and response planning. Korea also scores Strategic (4) in several CNI protection indicators.

How do the four countries involve the private sector in cybersecurity?

The report highlights that “Estonia, Israel, and the United States made private sector participation a critical element of their cybersecurity efforts.” The dataset reflects this through high maturity scores in Cybersecurity Mindset: Private sector.

What areas remain challenging even for advanced countries?

The report notes that all four countries “struggle with workforce, cyber culture and standards despite years of effort.” This is reflected in mixed scores for cybersecurity awareness, training, and standards implementation.

What defines the highest maturity level (“Dynamic”) in the CMM?

Dynamic maturity reflects the ability to respond quickly to new requirements and maintain adaptive, coordinated cybersecurity capabilities. The report describes it as “a dynamic approach capable of responding quickly to new requirements.”

What lessons from these countries are most relevant for LAC policymakers?

The report identifies three foundational best practices:
1. Develop a national cybersecurity strategy
2. Create a central coordinating authority
3. Adopt appropriate laws and regulations
It emphasizes that “strategy, organization, and rules are the first order of business.”

What is the Cybersecurity Capability Maturity Model (CMM) explained simply?

The CMM is a framework that measures a country’s cybersecurity capacity across five dimensions: policy & strategy, culture & society, education, legal frameworks, and technologies. It uses indicators to classify maturity levels from Startup to Dynamic.

What are the 5 levels of cybersecurity maturity?

The dataset defines five levels:
- Startup: Initial, ad-hoc practices
- Formative: Basic structures emerging
- Established: Formalized and consistent practices
- Strategic: Integrated into national priorities
- Dynamic: Adaptive, continuously evolving capacity

Why do organizations use the Cybersecurity Capability Maturity Model?

Policymakers and analysts use it to benchmark national cybersecurity readiness, identify gaps (e.g., workforce training), and guide reforms. It helps compare countries and track progress over time.

What is the formal definition and primary objective of the CMM?

The CMM was developed by OAS, IDB, and Oxford’s GCSCC to provide a structured assessment of national cybersecurity capacity. Its objective is to measure strengths and weaknesses across multiple domains to inform evidence-based policy.

What are the core architecture and domains of the CMM framework?

The framework has five dimensions:
- Policy & Strategy: National strategies, defense coordination
- Culture & Society: Trust, awareness, mindset
- Education: Workforce training, corporate governance
- Legal Frameworks: Cybercrime law, privacy, investigation
- Technologies: Infrastructure resilience, redundancy, incident response, standards adherence

How has the Cybersecurity Capability Maturity Model evolved?

The dataset reflects the 2015 assessment. It shows countries moving from Formative to Strategic/Dynamic in areas like national strategies and legal frameworks, while some domains (e.g., cyber insurance in Korea) remained at lower levels.

How does a high maturity level correlate with reduced cyber risk?

While the dataset does not track insurance premiums, it shows that countries at Dynamic maturity (e.g., the U.S. in legal frameworks, Israel in education) have stronger resilience and coordination, which typically reduces risk exposure.

What are the ten domains of the CMM and their primary focus areas?

Domains include:
- National Cybersecurity Strategy
- Cyber Defense Consideration
- Cybersecurity Mindset
- Cybersecurity Awareness
- Confidence and Trust in the Internet
- National Availability of Cyber Education and Training
- Corporate Governance and Standards
- Cybercrime Legal Frameworks
- Legal Investigation and Enforcement
- Technologies (infrastructure resilience, redundancy, incident response, standards)

Dataset files

Load more