In Poland, every couple months I see news that our government/military is supposedly creating some sort of "cyber force". If one day they actually create it, I hope this kind of stuff will be its focus.
They can (and have) act in an advisory capacity but they have no regularity authority to force companies to secure their shit.
Now whether such an organisation should exist that’s an interesting question I guess.
Over here in the UK we have a similar body.
https://en.m.wikipedia.org/wiki/National_Cyber_Security_Cent...
As someone in the UK tech industry I’m not sure what they actually do on the ground.
https://news.ycombinator.com/item?id=17216853
Their main requirement was and is SIGINT. That drives about all their budget and power. Their secondary requirement was to protect the government and/or military (not sure) with communications security (COMSEC). They may have expanded that to computer security. They were also supposed to protect defense contractors since they were an extension of the military. That's why their most secure stuff is unavailable to average American but defense companies can buy it. Also, the penalties for failing to stop the next 9/11 are astounding compared to failing to prevent... (checks today's articles)... a Fortune 500 company from leaking 264GB in client, payment data.
So, they deny us good stuff and weaken what we have wherever possible in general case. Some tiny number of them in Information Assurance give us tools and guides to help us. NSA can't be trusted to protect us. I do think the people in IA who gave us the best tools should be hired by the organization that will protect us. :)
If China wants a model, the TCSEC is a decent start at one. It was made for military requirements, though. Like MLS. The next approach should focus on commercial needs. Also, both TCSEC and Common Criteria were paper heavy with long evaluations after product development was done. The next should focus on actual code with reviewers getting into the process early on, reviewing deliverable by deliverable, so they have better insight into what's going on with faster time to market. Lots of room for improvement over the current model.
TCSEC
https://en.wikipedia.org/wiki/Trusted_Computer_System_Evalua...
Example of what industry was doing under TCSEC
https://csrc.nist.gov/csrc/media/publications/conference-pap...
Modern example from that lineage:
All talk, nothing's done.