Maybe I can elaborate.
It is indeed a team game. As Madame Xavier pointed out in her opening remarks, there's no one entity in cybersecurity. We form a tripartite in terms of protecting systems across the federal enterprise.
At Treasury Board Secretariat, we put in place rules. Indeed, we've promulgated a cybersecurity enterprise strategy for the federal government. We provide advice and guidance. Also, as Mr. Jones just alluded to, we have a Government of Canada security event management plan that is indeed followed, so that when there's a critical incident we understand roles, responsibilities, etc.
As the Auditor General pointed out, there are some shortcomings with regard to that coordination. Despite the fact that we meet regularly and we're constantly coordinating, there are certain things that we can do better. Last May, we put in place for the first time a simulation exercise at the executive level, touching several departments and agencies. Drawing from the lessons learned from that exercise, we're going to be updating our security event management plan, among other things. We also keep our policies and our strategy evergreen. We learn, as Mr. Jones just pointed out, from any critical incident.
In terms of our coordination efforts, they go from managing the policies to the direction and the guidelines. It's also a partnership with every department and agency. Each has to have a designated person responsible for cybersecurity and for making sure that they understand and interpret our rules and are putting them in place.
Mr. Jones and his organization are responsible for connections to the Internet and all of the infrastructure side of things. Then we have the special sauce, if you will, of the cybersecurity centre led by Mr. Gupta, which, above and beyond putting in place sensors, is doing all sorts of monitoring and connecting with the rest of the Communications Security Establishment to make sure we stay on top of the threat.