Ambassador Gafoor
Good morning, Distinguished Delegates. The third meeting of the third substantive session of the OEWG on security of and in the use of ICT 2021-2025, established pursuant to GA resolution 75-240, is now called to order. As I indicated yesterday at the closing of our meeting, we will now continue with our discussion of the revised Draft Annual Progress Report, and we will be looking at Sections A to E of the Draft Annual Progress Report, namely the Introduction, Existing and Potential Threats, Rules, Norms and Principles of Responsible State Behaviour, International Law, and Confidence Building Measures. We will begin with the speakers who remained on the list from last evening. I’d like to once again remind Delegations that it is really important that you be succinct and very focused, so that you are fair to all other Delegations who also wish to speak. And please do your best to summarize the statements that you might have prepared in advance. Where possible, please do refer to other statements already made yesterday by other Delegations to indicate your support or otherwise of proposals that might have been made or comments that might have been made, so that all of us collectively have a sense of whether there are emerging common elements or whether there are areas of divergences. This will be very useful as we embark on this process of adopting an Annual Progress Report at the end of the meeting. I had indicated yesterday evening that Indonesia would be the first speaker. I would like to give the floor to Switzerland, which is speaking on behalf of a group. So, after Switzerland, I will give the floor to Indonesia. We will start with Switzerland, to be followed by Indonesia, El Salvador, India, and Japan, and then we will go on with the rest of the speakers. So, Switzerland, speaking on behalf of a group, you have the floor, please.
Switzerland
Thank you, Mr. Chair, and good morning, dear colleagues. Thank you, Mr. Chair, for giving me the floor. Before I make my remarks on behalf of Switzerland, I am honored to read a joint statement on behalf of a group of states. My delegation is taking the floor on behalf of the delegations of Argentina, Brazil, Canada, Chile, Colombia, the Czech Republic, Estonia, Germany, Indonesia, Japan, Jordan, Mexico, the Netherlands, Senegal, Sweden, the Republic of Korea, and my own country. For our delegations, the reaffirmation that international humanitarian law applies in cyberspace and the clarification on how international humanitarian law applies regarding cyber operations in armed conflicts remain a priority. We wish to make a few comments and proposals in this regard. In an environment where we witness increasing use of ICTs by state and non-state actors in times of armed conflict, we are concerned about the effective implementation and respect of existing rules and principles of IHL. Adherence to these rules is of paramount importance. It is this branch of international law that offers fundamental protections and reduces risks and potential harm to both civilians and civilian objects – just think of the IT infrastructure of hospitals or schools – as well as combatants from cyber operations in the context of armed conflict. We therefore see a need to discuss how IHL applies to ICT operations during armed conflicts in the course of this open-ended working group. This allows us to generate common understandings on how we can best protect civilians and civilian objects, especially critical infrastructure, and attain clarity on what actions are prohibited or unacceptable during armed conflict. It can also help advance key understandings on how fundamental principles of proportionality, distinction, humanity, and necessity are to be upheld in this context. At the same time, this effort contributes to maintaining international peace and security. In our view, the open-ended working group is very well placed to take up the discussion on IHL and its principles and should do so in a timely and focused manner. Mr. Chair, we welcome the action-oriented approach of the draft Annual Progress Report and that it contains a direct reference to IHL as one of the specific topics on which the open-ended working group could convene discussions. In order to not limit the discussions on the core principles but to encompass all aspects of IHL, we propose the following wording in paragraph 9A: “And in times of armed conflict, international humanitarian law, including the principles of proportionality, distinction, humanity, and necessity.” We encourage you to organize a timely and focused discussion on IHL during the next session of the sessions of the open-ended working group, and we welcome the recommendation in the draft interim report that these discussions should include briefings from experts. Thank you. Mr. Chair, I will now speak on behalf of Switzerland and address the issues that we have been discussing yesterday. First, let me thank you and your team for all the efforts on this year’s draft you presented to us as well as the revised version. We welcome the adoption of the modalities and the program of work. And before I go into the topics, allow me to make first some general remarks. We meet here after another week that brought death and destruction to Ukraine. Since the 24th of February, the population of Ukraine has been subject to indiscriminate attacks on their lives and livelihoods. Switzerland condemns Russia’s military aggression on Ukraine in the strongest possible terms and calls on Russia to de-escalate the situation immediately, cease all hostilities, and withdraw its troops from Ukrainian territory without delay. Switzerland urges all parties to the armed conflict to respect international humanitarian law and international human rights law, and this also applies to cyberspace. Mr. Chair, Switzerland welcomes the fact that this open-ended working group has made progress on the modalities for stakeholder participation and that many non-governmental organizations and other stakeholders from different regions show interest in the open-ended working group and will be able to participate in its work. We support the statement made by the Czech Republic yesterday and thank the delegation of Ukraine for their explanation. We listened also to the statement by the Russian delegation and its readiness to give more information on its motivation for the objection to the participation of 27 non-governmental organizations upon request. Mr. Chair, we particularly welcome the action-oriented approach which is also in line with the proposal of the joint working paper on international law Canada submitted together with Switzerland. Statement 5.1 contains the important reaffirmation that the UNGGE consents the reports of 2010, 2013, 2015, and 2021, and the open-ended working group consents the report of 2021. We support the proposal made by the Netherlands for amendments in the first and second sentence inserting armed conflict and a reference to the GGE 2021 report. Mr. Chair, I would also like to echo my Canadian colleagues’ comment of yesterday. Cyberspace is not the jungle where no rule exists. Over many years, we have developed in the UN a framework of responsible state behavior in cyberspace. In particular, states agreed that existing international law applies in cyberspace. If all states would respect their obligations under international law and implement the voluntary norms as well as CBMs, we would be much closer to our goal of an open, free, and safe cyberspace. We welcome that the results reached throughout the last UNGGE and open-ended working group represent the common key and form the basis of work for this open-ended working group. This key has been endorsed by the UN General Assembly and should not be put into question again. This framework is the foundation. Therefore, we propose to replace “a foundation” in the new sentence in paragraph 1 version by “the foundation” and replace “which could” by “to be built on.” Switzerland welcomes the new paragraphs 3, 4, and 5 on multistakeholder participation, regional organizations, and gender. On threats, Switzerland agrees with others that current threats and challenges should be addressed in this section. In the following chapters, we would show how we can address these threats. We therefore could support Australia’s proposal to move the measures in paragraph 7B to the relevant sections. Threats that should be mentioned in our view are threats for critical infrastructures, ransomware, emerging technologies, threats faced by humanitarian actors, as well as the geopolitical situation. As Brazil, Costa Rica, France, and Singapore, we agree that ransomware is relevant for the work of this working group if they can pose a threat to international peace and security, in particular if critical infrastructure is targeted. We also would like to propose to delete reference in paragraph 7B, 7, to mutual legal assistance for the reasons mentioned by Brazil and Australia, and we also agree with both Australia and Brazil regarding the reference to law enforcement. Let me turn to some concrete proposals on wording. In 7A, we would like to add the following after open-ended working group in the first sentence, as I already said, and GGE 2021 reports. And then after intensify and evolve, causing increasingly physical impact due to harming digitalized production processes and unintended spillover effects due to the inherent interdependencies of the global transnational use of ICTs. States underscore, and then so on. In 7D, we would like to add at the end, as well after critical infrastructure and critical information infrastructure, as well as understanding the interdependencies of transnational critical infrastructure and critical information infrastructure. In recommendation 2, we’d like to add after experts from states, as well as business and non-governmental organizations. On the norms part, we only have a few comments on this section. We agree with Mexico and the U.S. that firstly, in paragraph 8B, we should call for the implementation of existing norms. This should be our priority. In recommendation 1, the valuable role that stakeholders can play should be mentioned here, too, in our review. And on recommendation number 2, on the common understanding on technical ICT terms, we think we should not focus on that, as other delegations, in particular those of the U.S., have said yesterday. In our view, it is more important to share understandings or definitions of ICTs so that states are aware of other states’ understandings and definitions. And here we could benefit from the valuable work that has been done in the OSCE, in particular by Serbia. I will now turn on international law, that section. In my delegation’s view, the chapter on international law is generally very welcome. It largely reflects the discussions, and we see only a few details for improvement. The comment on IHL I have made in the joint statement, it’s the same for Switzerland. And as I already said, we welcome the concrete action-oriented proposals in this part of the report. We welcome the roadmap for the focus and structured discussion on international law by suggesting convening a discussion on specific topics, a non-exhaustive list of topics, and using independent expert briefings in these discussions. Regarding the independent expert briefings, we took note of the revisions in the draft. Because of the unique importance and role of the ICRC in relation to IHL, we would like to keep the reference to the ICRC in the report. We welcome the mentioning of stakeholders other than states in paragraph 9. We propose to include the same reference to such stakeholders also in recommendations. The last sentence of recommendation 2 will then read, “Such discussions should include briefings from experts as well as interested stakeholders in an appropriate format.” In our view, it is also important that we don’t prematurely define and limit the type of suitable experts. Independent experts should be determined at a later stage based on concrete discussions and topics. We therefore propose to adapt paragraph 9A accordingly. So we propose to delete after experts from the United Nations, such as the International Law Commission, as well as, and then insert, including interested stakeholders, delete including after that, and then insert such as businesses. On the possibility of additional legally binding obligations, we think we need to work on the wording and the sequencing in the report in order to make a distinction between topics of international law that could be discussed and the conclusions that states may draw from them, in particular, whether and if so, which gaps exist on how states want to deal with them. Furthermore, we would like to state clearly that, as expressed in previous sessions of this open-ended working group, it is Switzerland’s position that we currently do not see the need for a legally binding instrument. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you, Switzerland, for the statement. Indonesia, please.
Indonesia
Thank you, Mr. Chair. Let me begin by thanking you, Ambassador Gafoor, for your commendable leadership in this process, as well as your excellent team and the Secretariat for their hard work extended towards the drafting of our first annual progress report. Rest assured of Indonesia’s constructive engagements and full cooperation. We also call on all states to extend their constructive and inclusive engagements to achieve a consensus outcome by the end of this session. Mr. Chair, we share your views on the importance of adopting the annual progress report by consensus in compliance with the mandating UNGA resolution 75-240 and without prejudice to the final report to be adopted in 2025. Successful adoption of the annual progress report during this third session holds significance in steering and marking important milestones of our work. We welcome the current structure of the report. It is action-oriented in nature, and we consider its substance as a good basis for negotiation. Mr. Chair, allow me to share Indonesia’s views regarding the substantive part of the report. We appreciate references to the previous OEWG and GGE reports in building upon our work in the current OEWG. We reiterate the need to maximize the balance of references in the report, putting on initiatives as well as positions of member states. We also underline the need to distinguish between initiatives which have gathered consensus support and those still requiring further deliberations. Regarding the threat section and the recommendation section, we would like to see the issue of capacity building related to threat perception in the ICT environment to also be highlighted. Capacities of states to identify and classify the existing and potential threats in the ICT environment are strongly influenced by different capabilities and policies in each country, and there are still gaps to be addressed. In this regard, stakeholders can contribute positively in supporting states to gather a deeper understanding of the nature of the threats from a technical standpoint. We also appreciate the addition of reference to the other relevant processes regarding the issue of mutual legal assistance in paragraph 7b. It is important for us to prevent our work from overlapping with other UN processes. Mr. Chair, I would like to move to the norms section. We appreciate references regarding the implementation of the existing norms to be done in parallel with further development of new norms. Furthermore, we would like to see the aspect of norms development to be reflected in the recommendation section and to encourage states’ contributions in enriching the list of non-exhaustive proposals annexed to the chair’s summary in the previous OEWG report. We need to also acknowledge multiple gaps and challenges faced by countries in implementing the existing norms. The report can also mention the importance of measuring the effectiveness of the implementation of the existing norms, including through developing specific indicators and parameters. On the issue of international law, we welcome the convening of discussions on specific topics related to international law as referenced in paragraph 9a. In addition, we propose to add the issue of attribution among the topics of discussion, as also recommended in the previous OEWG report, including to foster further exchange of practices between stakeholders on this issue. We also welcome recommendation number four, mandating the Secretariat to present a paper on needs, opportunities, and gaps regarding the application of international law in the ICT environment by states. We hope the paper could provide informative background on problems and challenges faced by states and identify gaps in the existing international law, if any. Furthermore, we propose an addition in the recommendation section number one to reflect focused steps for the OEWG, for example, to take stock and provide guidance on which elements of international law apply during incidents in the ICT environment, based on states’ practices and submissions. The report also needs to reflect and re-emphasize that our efforts on international law shall not be interpreted as an intention to encourage or legitimate conflicts in the ICT environment. We will share our views on the remaining issues in our next intervention. Thank you, Mr. Chair.
Ambassador Gafoor
I thank the Ambassador of Indonesia for his statement. I give now the floor to El Salvador, to be followed by India. El Salvador, please.
El Salvador
Chairman, my delegation is very happy to be participating in this third working group of the Open-Ended Working Group. We will be giving a more succinct intervention today, and our complete intervention will be made available to be published on the website. With regard to current and potential threats, ransomware continues to be one of the greatest threats to information security of data in all areas of human activity. These kinds of cyber attacks, and particularly those targeted at the government, seriously harm productivity, the economy, the provision of basic services, and undermine the confidence of society in the capacity of the state to protect sensitive data. El Salvador vehemently condemns the cyber attacks against various public institutions of the Republic of Costa Rica last month. These cyber attacks are recognized as violating the sovereignty and territory of the integrity of Costa Rica. In that regard, we value the technical assistance of governments and other actors who diligently help to fight these cyber attacks. And here we reaffirm the need to increase cooperation with multiple interested actors in order to counter and prevent these global threats. This threat should be reflected in the progress report, as was mentioned by the delegations of Costa Rica, Brazil, and Switzerland. With regard to what is mentioned in the report, we continue to stress the importance of training in cyber security, and we’d like to stress two important things here: cooperation with Microsoft to train civil servants in areas such as cyber security and daily life, principal threats to internet security, and recommendations for individual and collective protection, and the national experience of passing on knowledge of the Foreign Affairs Ministry on cyber diplomacy through the repetition of a course that was organized by the Inter-American Committee Against Terrorism, part of the OAS. Still with regard to 7B and with regard to the more technical elements, we would stress the need to continue to train in cyber security with regard to CERTs and C-CERTs, the emergency response teams, and the importance of working on identifying national focal points. Chairman, my delegation reiterates our support for the steps with regard to the discussion on current and potential threats, taking into account the exponential technological advances that we’re seeing. With regard to the rules, norms, and principles of responsible behavior, El Salvador agrees with what is stated in the progress report, and our delegation shared at the last session our national cyber security policy, which contains strategic guidelines that need to – will help to make us more resilient in cyber security. This is a progress with regard to the implementation of the rules – responsible rules that states should follow in cyberspace, and that law is currently being adopted. In this context, we would highlight the creation of the El Salvador Cyber Security Office that will be responsible for national cyber security to develop critical infrastructure to improve resilience and ensure early responses to cyber attacks. We highlight the Inter-American Committee Against Terrorism. These contacts reaffirm the commitment of El Salvador to implement voluntary behavioral rules in cyberspace, and we note the progress that’s been made in increasing cyber security. As was explained at the last session, El Salvador believes that it’s important to continue discussing the development of rules, principles of responsible behavior. This is an area that is constantly developing that requires ongoing study by states and multiple interested actors, and their contributions are central in understanding new opportunities and in order to neutralize and reduce the number of threats. With regard to international law now, well, this is something that has been significantly addressed in previous sessions of the Open-Ended Working Group, and it’s also included in the progress report. El Salvador would like to take this opportunity to reaffirm that international law is applicable in cyberspace, and additionally, it is mentioned in resolutions of the General Assembly. It’s important to maintain peace, stability, and promote information technology and communications that are open, secure, and accessible and peaceful. We reiterate the practical question here, namely how international law can be applied. Well, we would look specifically at what has been happening in the digital world, and we would – in line with item C, we would say that we need to have state, regional, and international dialogues carried out so that each state can explain its interpretation of international law and how it applies in these situations. With regard to these dialogues, there needs to be a broad range of subjects at all levels. The aim is to avoid duplication of effort between actors because we know that there are entities available that have experience in terms of good practices in identifying risks and challenges, and their expertise can be benefited from at all levels. We highlight the contributions of academia, NGOs, civil society, and other interested actors who constantly are generating discussions on these very relevant subjects through generation of specialized documents. We agree with the following steps mentioned in the report, voluntary steps with regard to how states can share their national visions of international law as it applies to ICTs, particularly with regard to elements such as sovereignty, sovereign equality, noninterference, and the peaceful settlement of disputes and renunciation of the use of force in international relations. The responsibility of the state for due diligence and respect for human rights and international humanitarian law, as has been pointed out by Switzerland on behalf of a number of countries. With regard to the confidence-building measures, well, as was previously expressed, our delegation feels that these voluntary actions are basic to reduce tensions inside the space. They help to de-escalate adverse situations, promote cooperation and international assistance in order to create a peaceful, secure, and stable environment for ICTs and communication for global enjoyment. As part of these confidence-building measures, and as was expressed previously, we would highlight that El Salvador will shortly be joining the first phase of the simulation exercise for contact points that was proposed by the delegation of Singapore in coordination with UNIDIR. We believe that this initiative is an opportunity for member states of the United Nations to be made aware of this exercise that aims to demonstrate the effectiveness of a global directory of points of contact in operative and diplomatic terms that has expertise based on real situations that will make it possible to respond to challenges in cyberspace in real time. Our delegation previously spoke about the importance of creating a global directory of points of contact, not only as a tool to have updated information with regard to the first line of response or those taking decisions, but also as an exchange of information, early information, on threats, vulnerabilities, and relevant instruments that could constitute a first line of defense regionally, promoting the transference of international assistance between peers. And we applaud this initiative, which has been coordinated together with UNIDIR, which we feel could make the proposal operational in the medium term. And the progress report covers this in detail. Thank you very much.
Ambassador Gafoor
Thank you, El Salvador, for your statement. India, you have the floor, please.
India
Thank you, Mr. Chair. India sincerely appreciates your leadership and initiative in making the functioning of this working group more open, transparent, and inclusive. India would like to suggest a few edits to the section on existing and potential threats. Para 7.B3, we would like to suggest adding security and, before, integrity, thus it would read as cooperation and assistance to ensure the security and integrity of the supply chain. On point 5, that reads as cooperation and assistance for developing ICT security baseline studies and designing security as a critical requirement, we would like to suggest replacing studies with standards and best practices and replace designing security with secure by design. After point 6, we suggest adding a few more sentences. 6A, share strategies, policies, and legislation/guidelines and best practices for the protection of cyberspace. 6B, strengthen law enforcement cooperation to prevent the use of cyberspace for terrorist purposes. Point 9, measures and initiatives to strengthen data security. We would suggest deleting this line as this does not pertain to the section of existing and potential threats. Point D, we suggest inserting think tanks along with businesses, NGOs, and academia. Under recommended next steps section, we suggest adding a sentence after the end of point 2 to read as exchange of information and knowledge on these topics to facilitate building a common understanding amongst member states. For point 3, we suggest adding think tanks similar to the suggestion for point D. With respect to the suggestion to include the expression non-discriminatory business environment, my delegation does not support the inclusion of such expression into the annual progress report. Member states have the sovereign right to develop and implement policies that are of national importance, keeping in view the development goals of a member state, and such policies, as long as they are consistent with peace and security, should not be influenced with expressions that impose unnecessary obligations on the member states. Mr. Chair, under the section on rules, norms, and principles of responsible behavior, we would like to suggest changing the expression ICT terms to ICT terminology in paragraph A and paragraph 2 under recommended next steps. Under CBM section, fifth line of point A, we suggest an alternative expression to hotlines. We suggest replacing hotlines with cert to cert POCs. In the same para ending sentence that reads as a directory which would include experience at the regional level, we suggest adding national before the term regional. The sentence would then read as a directory which would include experience at the national and regional level. In point B under para 10, we suggest replacing white papers with concept papers. Mr. Chair, before suggesting edits to the capacity building section of the draft report, I would like to take this opportunity to share some thoughts on this section as it is this particular section can really help small and developing countries in developing their ICT capabilities to ensure security in their national ICT environment. During the course of the last two substantive sessions and the current one, member states are particularly interested in streamlining the capacity building area with concrete and action-oriented recommendations. We appreciate the chair and your team for your efforts in reflecting the same spirit in the draft annual progress report. We believe that capacity building area, whatever form and character this session agrees, would pave the way for future work that goes beyond the upcoming sessions of the OEWG. If we as member states take a moment to see where the work we are doing would take us down the next five or ten years, we may realize that it is time to consolidate the efforts and focus on certain priorities that are of significance to everyone. At present, we have certain measures and recommendations suggested by member states such as directory of POCs, national survey of implementation, compiling a calendar of capacity building programs, developing a list of regional and sub-regional centers of excellence, and others. What we are seeing is there are multiple portals or websites with different degrees of capacity building. Let me please stress here that India fully appreciates each of these existing and proposed mechanisms and understands the merits each one brings to the development of ICT capabilities of member states. At the same time, from the perspective of small and developing countries, it becomes excessively time-consuming and effort-seeking to continue to keep tracking different portals or calendars of capacity building. What we need now is integration of these mechanisms under the United Nations framework. The United Nations should play a lead role in capacity building and implementation of the normative framework. For this reason, we need to anchor a permanent mechanism at the UN that integrates all the existing and proposed mechanisms of cooperation under capacity building. Such a permanent portal mechanism goes beyond OEWG. It would be complementary to any future regular institutional dialogue, including the proposed Program of Action. Such an integrated and comprehensive portal would bring in trust and confidence as it is anchored at the UN. The current draft report recommends the same approach under point D of the capacity building section and reiterates it with the necessity of coordination and collaboration with the existing initiatives. In this light, we would like to propose establishing a global cybersecurity coordination portal at the UN. Mr. Chair, while deliberations on the normative framework of state behavior in cyberspace and the developments in the field of ICT in the context of international security continue in the open-ended working group on security of and in the use of ICTs 2021-2025 established pursuant to General Assembly Resolution 75/240, there is an underlying need for the OEWG to focus also on concrete ideas that can help achieve the common objective of free, open, secure, stable, accessible cyberspace and its use for peaceful purposes. During the first and second substantive sessions of the OEWG, member states have put forward such ideas, especially in the capacity building and confidence building measures, for further consideration of the group. The development of a global cybersecurity cooperation portal anchored at the UN as a global platform for cooperation and coordination by member states on cybersecurity issues is one such idea. Objectives. Currently, there are various bilateral, sub-regional, and regional mechanisms for the exchange of information and coordination among cyber agencies of member states. However, there is no global platform which enables such an exchange. Establishment of, now I use the acronym, GCSCP will overcome this lacuna. GCSCP is envisaged as a one-step platform for enabling global cooperation and coordination between member states on matters related to cybersecurity. The portal can incorporate various components, some of which are currently being discussed by the OEWG. Management. GCSCP will be a member state-driven portal with the UN Secretariat handling its overall maintenance and management. Each member state will be provided dedicated access credentials by the UN Secretariat. Member states can upload information under the various sections of the portal on a voluntary basis. UN bodies, regional organizations, and other relevant stakeholders can also share information with the UN Secretariat (UNODA) for uploading into the portal. The content. The GCSCP will provide the base platform on which various ideas to cybersecurity discussed under the OEWG can be implemented through a modular approach. GCSCP will have different modules on areas like capacity building, policy frameworks, cyber threats, etc., which can be developed independent of each other. It can also integrate best practices under existing national, regional, and plurilateral cyber cooperation platforms. Access. The portal can incorporate two kinds of content, public and restricted. While public content could be accessible to everyone to view, restricted content could be viewed only by member states. Member states can have the option to choose whether the information they upload or share would be public or restricted information. Information shared by UN bodies, regional organizations, and other relevant stakeholders can be public unless requested otherwise. How can the OEWG contribute? The OEWG can recommend the establishment of such a portal to the UN General Assembly. Subsequently, the group in its future sessions can have focused deliberations on the content/modules of the portal for further development. India is open to discuss this further with member states, and we invite all to study it and suggest what changes can be done to make it a better mechanism under the UN. Under capacity building section point B, we suggest inserting inter alia in the third line after questionnaires. We suggest a similar edit to para 5 second line. States are encouraged on a voluntary basis to survey their capacity needs, including through inter alia, the national survey of implementation, and/or the cybersecurity capacity maturity model. We would be sharing these changes with the chair in written format. Finally, India would like to assure the chair its support and flexibility in making this session productive and outcome-oriented. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, India, for the statement. I had mentioned this morning we were dealing with sections A to E. I noticed that the Indian delegation has also addressed section F, relating to capacity building, and I would also invite other delegations who wish to address this section to include it in their comments or give any reactions to comments made. I give now the floor to Japan, to be followed by South Africa. Japan, you have the floor, please. Thank you very much.
Japan
Thank you, Chair. Thank you, Chair, for giving me the floor. Please allow me, at the outset, to express our delegation’s appreciation for the patient manner with which you continue to guide us in our effort to further advance the objectives of the OEWG. We would not have come to a consensus on the modalities for the participation of stakeholders in the OEWG process without your patient guidance. I would also like to express our appreciation for all the effort you and your team have made to come up with a zero draft and the subsequent Rev. 1 draft of the Annual Progress Report of the OEWG. It is a well-balanced effort to capture the ideas and proposals that have been expressed during the first two substantive sessions of the OEWG and to propose guidance for future work of the OEWG. Japan is generally supportive of the draft report. It is our view that memorializing our discussion during the first year of the OEWG and giving guidance to future discussions will contribute to further advancing the objectives of the OEWG in future years. I fully support the statement you made yesterday morning on the importance of adopting the Annual Report. We have no comment on the introduction and one comment on existing and potential threats. Our work cannot be separated from events in the real world. Five months have passed since Russia’s aggression in blatant violation of international law against Ukraine started. The reports of malicious use of ICTs in conjunction with military activities, including against critical infrastructure, are deeply troubling. Such actions are exactly the threat we are trying to address in our work. We support other delegations’ comments to refer to such threats in the section summarizing current threats. Under rules, norms, and principles of responsible state behavior, Japan supports paragraphs 1 and 3 of the recommended next steps as efforts to assist states to implement the norms of responsible state behavior. With regard to paragraph 2 of the recommended next steps, Japan does not believe having a common understanding of technical ICT terms is necessary to help states implement the norms of responsible behavior. We would also like to point out that efforts have been made in the past to develop a common understanding of ICT terms, but it was a very difficult process and did not lead to concrete outcomes. Japan supports the international law section of the draft report. Japan reiterates its position that existing international law, including the United Nations Charter in its entirety, applies in cyberspace. Japan is also of the view that it is important for governments to make public their basic position on how international law applies in cyberspace and encourages states to do so. Under confidence-building measures, Japan supports the sharing of regional and sub-regional organizations’ experiences. Also, UNIDIR’s cyber policy portal can play a large role in sharing the national strategies and policies of states that will lead to further confidence-building. Japan generally supports the rest of the draft report. Our delegation looks forward to working with other delegations constructively so that we will be able to adopt the report by consensus at the end of the week. Thank you very much, Chair.
Ambassador Gafoor
Thank you very much, Japan, for your statement. I give now the floor to South Africa, to be followed by Canada. South Africa, please.
South Africa
Thank you, Chair, for giving me the floor. The South African delegation welcomes the revised draft annual progress report. We join other delegations who spoke before us and applaud you, Chair, and the Secretariat for preparing a report which reflects in a fair and balanced manner views expressed by Member States during the first and second sessions of the OEWG. The revised draft report includes more of the proposals that were made in the sessions, and we welcome this. The annual progress report, as the Chair and other delegations mentioned, provides a roadmap for future work, and therefore it is very important to adopt the report by consensus at the end of this session. We stand ready, Chair, to work with you and all delegations to ensure that a report is adopted at the end of this session. We would like to make the following remarks with regards to the sections that the Chair indicated. In paragraph 1 of the introduction, like some delegations who spoke before us, we are pleased to see a reference to the foundation the previous GGEs and the first OEWG reports provide to the work of this OEWG. It is our view that the OEWG needs to progressively build on what has already been agreed to by consensus. Turning to paragraph 2, this is an important paragraph for ensuring that all six pillars of the work of the OEWG receive equal attention, and we would like to see this retained in the first annual progress report. With regards to paragraph 5, we appreciate how the report acknowledges the momentous gender parity achievements. This is a most welcome gain from the first OEWG already, and we would like to see the language retained. Turning to paragraph 6, currently, Chair, the paragraph starts by stating what the report is not intended to be and continues to state the objective of the report thereafter. We propose that the purpose or main objective of the report be the main focus of this paragraph, and the qualifying statement can then follow. On existing and potential threats, the South African delegation welcomes the Chair’s proposals contained in this section of the report, which we believe could be voluntary initiatives at this point because of the differing levels of development states are at. We are flexible on the proposal to move measures proposed in section 7b to a more appropriate section in the report. We, however, would like to make the following suggestions. With regard to paragraph 7a, we welcome the inclusion of this paragraph as it provides the threat landscape, thus giving context to the measures proposed in the report, and we hope that this paragraph will be retained in the progress report. Turning to paragraph 7b, Roman figure 2, the designation of CI and CII is a national prerogative as stated in paragraph 18 of the first OEWG report, and we view paragraph 7b Roman figure 2 as providing valuable guidance to member states to utilize on a voluntary basis. With regard to paragraph 7b Roman figure 4, South Africa proposes inclusion of “on a voluntary basis” at the end of this sentence. Sharing of information in this area will require a new level of trust between involved parties to share information which in almost all countries has restricted access due to national security considerations. Perhaps a starting point could be to strive to achieve a common understanding on emerging and potential threats to CI and CII and to share practices and measures to counter these threats. With regard to paragraph 7b Roman figure 8, we propose a slight modification to the sentence such that it reads “enhanced capacity building to be tailored to specific needs and context.” We welcome the recommended next steps section of the report, and our view is that it provides a clear roadmap for the future work of the OEWG. With regard to paragraph 1, recommended next steps, in the spirit of moving away from general statements and aiming for more concrete outcomes at the end of a five-year-long process, we propose a slight amendment to the paragraph as follows: “States should engage in focused discussions at the OEWG on existing and potential threats,” and the rest of the sentence can stay as is. On paragraph 2, we propose the following amendment in line with the comment we made in paragraph 7b Roman figure 4: “States consider utilizing the OEWG to achieve a common understanding on emerging and potential threats to CI and CII and to share practices and measures to counter these threats.” South Africa welcomes the Chair’s proposals contained in the norms section of the report, and specifically on paragraph 8b, we are pleased with the inclusion of this paragraph. Like many other delegations, we value the importance of both implementation and further development of existing norms. However, we are cognizant of the fact that parallel processes may overstretch limited capacities, particularly for developing countries. It is on this basis that the South African delegation prioritizes implementation, which in our view will contribute to a better understanding of the gaps in existing norms, if any, thus informing the need for new norms to be developed. Implementation is also an opportunity to identify effective practices and capacity building requirements. With regard to paragraph 8d, we propose that the word “voluntarily” should come before “surveying” so as to ensure that both the surveying and reporting are done on a voluntary basis. The sentence will thus read as follows: “States could consider voluntarily surveying or reporting on their national implementation of rules, norms, and principles of responsible state behavior utilizing existing avenues,” and the rest of the sentence continues. We welcome reference to the national survey of implementation as a practical tool that can assist with lessons learned to facilitate identification of capacity building requirements and an avenue to share implementation challenges and effective practices. We had views from member states on the formulation of a legally binding regime, recognizing that member states are at different stages of development in terms of capacity. South Africa’s view is that we should be cautious when introducing legally binding norms at this stage, as this may overburden states that are still building capacity to ensure compliance with agreed-upon norms on a voluntary basis. Turning to the recommended next steps section, we propose linking norms implementation to capacity building in order to empower member states to establish programs to develop the required capacity. Turning to international law, we welcome the recommended next steps reflected in this section. Similar to the comment we made in the earlier section, in paragraph 1 we prefer a more focused discussion rather than a general exchange of views. During the first and second sessions of the OEWG, some states expressed the view that existing international law, complemented by voluntary non-binding norms, is currently sufficient for addressing state use of ICTs in the context of international peace and security. South Africa shares this view. We therefore propose that in the recommended next steps section, the focused discussion proposed in paragraph 1 could be facilitated through guiding questions which seek to create a common understanding on how international law and norms sufficiently support responsible state behavior. Turning to confidence-building measures, we welcome the recommendation to create a repository of POCs to enable timely response in times of emergency. We see the value of such a repository, especially when it is kept secure and up to date. We are unable to link the operationalization of such a directory to capacity building to empower the POCs. We are particularly pleased with the time-bound operationalization of the global directory and hope that this language will be retained. South Africa also supports the use of the national survey on implementation as a tool for member states to voluntarily assess their own national processes. On capacity building, Chair, the South African delegation supports the mainstreaming of the principles of capacity building as outlined in paragraph 56 of the final report of the first OEWG. It might be useful to reflect in this section of the report that states and capacity building actors must be guided by these principles. Thank you, Chair.
Ambassador Gafoor
Thank you, South Africa, for your statement. Canada, to be followed by Jordan. Canada, please.
Canada
Thank you, Chair, for this opportunity to express Canada’s perspectives on the parts of the text dealing with norms, confidence-building measures, and international law. But first, a quick point on gender. I just wanted to respond to my esteemed Chinese colleague with regards to his comments on gender yesterday that seemed to be about having women in the room, which is a valid point, and that is one of the key things that we are trying to do here. We are doing this via the Women in Cyber Fellowship Program, and I’m pleased to say that we have four fellows funded by Canada who are from Latin America who are in the room right here. There are also 30-plus fellows that were funded by the five other donors. So that program has allowed gender parity at the previous OEWG, and it’s also promoting gender parity at this one, and I think the results in this room speak for themselves. But that said, I wanted to also make it clear that it’s not just about having women in the room. So Canada has a gender annex to our position paper, which I would recommend that my Chinese colleague and others have a look at when they have a chance. Gender is one of the top five priorities in that paper, and we have a whole annex with a bunch of ideas about how to promote this issue, including via text, including via research. This morning I ran into Alison Pitlock, who’s one of the researchers who wrote one of the papers that Canada commissioned on this. It is available on the portal of the previous OEWG. In the interest of time, I won’t get into the other ideas in our position paper and annex, but I also wanted to say that I’ve heard several countries mention this yesterday, including France, my neighbor from Cameroon, Brazil, and Spain. So I would once again encourage my Chinese and other interested colleagues to have a read of the position paper, the gender annex, and the research we funded in order to better inform themselves and potentially become allies with a capital A in helping us address this important issue. Now, moving to the report itself. On norms, Chair, we’re quite positive overall on this report. I was speaking to you privately about an hour ago, and I mentioned that Canada is mulling the possibility of tabling norms guidance text at this OEWG. For those who were part of the previous OEWG, we did so then, and we obtained the approval of about 40 states, and we also consulted stakeholders on that text. It was included in the chair summary of the previous OEWG because it did not enjoy consensus then, but we are strongly considering doing so again at this OEWG if we feel that there is an appetite from states and including from you, Chair. I have spoken to many states about this, and so far have mostly met with positive comments, but again, only want to do this work, which is significant if there’s appetite. So welcome your views, Chair, and also the views of others. I have one more comment on norms. In the text itself, there’s a sentence that we have some concerns with that reads, “states proposed that additional norms could continue to be developed over time.” So, although there is already caveating language at the beginning of that section, we would propose simply adding the word “some” before the word “states” to make it clear that while some states do indeed feel this way, other states, such as Canada, do not. For Canada, existing norms are sufficient to guide state behavior in this space, and this is why, in our view, we need to focus more on the implementation of norms rather than developing new ones, and in this, I would echo my colleague from South Africa, who just mentioned the need for some caution in this regard. Other than that small change, we are quite happy with the norms section, and likewise on CBMs. Canada has a broadly favorable view of this section, in part because many of the excellent items included in the paper of the cross-regional group on CBMs are reflected in it. For those not familiar, Canada is part of a group convened by Germany with representatives from various regions that put up a paper on the portal that has many concrete ideas, including many that were picked up in this draft annual report. One of the proposals that Canada promoted within this group, and that we were very pleased to see picked up in the report, was a transparency measure that would essentially encourage states to be transparent about their cyber capabilities and the conditions surrounding their use. This could be literally as simple as states saying, “we have an offensive cyber capability, but we will only use it in a manner consistent with international law and norms.” This is why we included also a sentence in that paragraph about how we are not seeking to obtain confidential or classified information. Canada has done this, we’ve done it in our cyber security strategy, we’ve done it in our defense policy, and we’ve done it in the act that governs our SIGINT agency. We encourage others to do it as well, and many have, and so the transparency measure would simply promote what’s already happening, and hopefully accelerate it, because this would create more transparency and therefore stability in this space. So to summarize, we are largely supportive of the part of the report on CBMs. Now moving to international law. This, in our opinion, is actually one of the strongest sections of the report in our opinion, Chair. We think it’s a very good basis for discussion this week. We support almost all of the proposed changes from the previous version and have only a few limited suggestions. I will of course provide these in writing, but the main ones are in paragraph 9A, we support a minor revision to the reference to IHL proposed in the joint statement presented by Switzerland, which Canada was happy to join, because for us the issue of IHL is very important, and we think this was a key addition compared to the last draft. Secondly, in paragraph 9B, Canada supports the mention of the previous OEWG recommendation on sharing of national views on how international law applies in the use of ICTs. We see this as a vital part of the work of this OEWG. We also noted the reference to the UNIDIR Cyber Policy Portal, which we were very glad to see retained. Chair, in that regard, I’m really pleased to announce that soon after our last OEWG session, Canada published our national statement on international law as it applies in cyberspace. This document is available on the Global Affairs Canada website, as well as on the UNIDIR Cyber Policy Portal, in both English and French. We encourage member states who have not yet had a chance to look at it to do so, because they will learn about our position, but also it may inspire them to develop their own statements. Canada and others are available to provide advice and support. I actually have two lawyers here with me today, and they’d be delighted to speak to any of you who want to learn more about this work, which I would add took a lot of time, but we’re very happy to have that out. Lastly, in paragraph 9C, Canada supports a change to the last sentence to make a clearer link to our shared efforts to build common understandings of how international law applies. We similarly support the request to delete the reference to mutual legal assistance, which we agree falls more squarely in the mandate of the Third Committee and the Ad Hoc Committee on Cybercrime. These changes will be provided by ourselves and others shortly. Chair, Canada would have liked to see further information in this report on the growing number of capacity-building activities on international law, and we will make this a priority for next year’s report. I will stop here, and my colleague will share Canada’s views on the remaining two sections of the text this afternoon. Thank you.
Ambassador Gafoor
Thank you, Canada, for your statement. I now give the floor to Jordan, to be followed by Chile. Jordan, please.
Jordan
Thank you, Mr. Chair. In addition to our statement yesterday, we would like to add a few comments. First of all, we think customer attack is an important issue, and we strongly support its inclusion in the report. We took note of some remarks by some delegations yesterday that they think it should be under the cyber crime treaty. We think actually it should be in our report and in the cyber crime treaty as well because of the importance of this issue and the threat that it poses to the international community. Also, we support the inclusion of the security of supply chains infrastructure in the report, and we think amid the disruption that we face in the supply chain infrastructure, we need to emphasize this and think of measures that can provide more protections for this critical issue. Additionally, we encourage further emphasis on cyber terrorism and the inclusion of measures that will encourage international cooperation on this issue, just to make sure that we can contain this phenomenon as it expands further and further. We also support including the paragraph on the role of regional organizations in cyber security and how they can support the role of the United Nations in this regard, as well as the role of the CSIRTs in terms of exchanging information among member states. We encourage considering establishing a network for CSIRTs or regional networks for CSIRTs to ensure that we have cohesive and solid international and regional cooperation. Finally, we also support tabletop exercises as a way to transfer knowledge, experience, and information between member states. Thank you, sir.
Ambassador Gafoor
Thank you very much, Jordan, for your statement. Chile, to be followed by Vietnam. Chile, please.
Chile
Thank you very much, Chair. Since this is the first time that we’re taking the floor, my delegation would like to extend our thanks to you, and we very much appreciate the work that you’re doing, Ambassador Burhan Gafoor, as well as your team and the Secretariat of the Disarmament Affairs Office of the UN, in preparing the revised annual progress report for this Open-Ended Working Group on progress in the area of information and telecommunications in an international context. In general terms, Chair, we think this document is a good point of departure for our discussions. We share the hope that this text can be approved by consensus. In the interests of time, and bearing in mind your appeal, we’ll be brief. As a feminist government, all actions of the state are focused on gender parity and equality, and our foreign feminist policy is therefore focused on strengthening the human rights of women and children in international fora. In this regard, Chair, we welcome the inclusion of our comments in the introduction to the document with regard to the explicit mention of the participation of women at this session. This is a measure that points towards inclusion from the point of view of gender in these negotiations. That’s why we support the revision of language that was proposed yesterday by the Distinguished Delegate of Australia, because we feel that that helps to clarify the points that have been made, and we also endorse what recently was expressed by the Delegation of Canada. We would like to express our thanks for the Women in Cyber Fellows program that we are part of, and also our sponsors, particularly Canada. This helps to include women in this process. We’d like to point out that the reference to gender issues is indispensable, and this sustains mandates that already exist within the United Nations, particularly in the area of international security. It’s not just a question of having more women here present in the room. It’s not just an issue of numbers. We have to make this process genuinely inclusive and effective in terms of gender. Chair, we’re very grateful that the introduction recognizes regional and sub-regional efforts. Regional bodies should not be more or less important than the UN level. They are necessary, particularly for the implementation of measures that have been established, and we are grateful for recognition of their work. Despite that, we recognize that not all states are part of these bodies, and that’s why we appreciate the proposal made by the distinguished Delegation of Mexico yesterday, namely to make a reference to regional organizations and other efforts and mechanisms in order to leave no one behind and to make this a genuinely inclusive process. With regard to the sections on real and potential threats and rules and principles, my country doesn’t have any great comments or suggestions to make with regard to the draft. We understand that this is a first report of the group, and it’s a first step in future negotiations. That’s why we feel it’s relevant to have an exchange of experiences that will reduce the digital divide, address real and potential threats, and make progress in cyberspace. We’re not sure whether it’s appropriate to have an exhaustive list of threats in terms of the structure of the report, because that could perhaps limit our future discussion about future threats. However, we are flexible on this. If the majority of countries feel that it’s relevant to have that list, we would support it, for example, with an explicit reference to ransomware. Chile believes that threats can affect states in different ways, depending on their level of capacity, security, and resilience in ICTs. It depends on our infrastructure as well and our development. This is a priority area. The threats can also differently affect different groups, particularly women and children. There are very many kinds of threats, and that’s why it’s important for us to increase our capacity and create coordination structures, not just at the level of government, but also effective alliances with civil society, the private sector, and academia. Also, and as was requested yesterday, we would refer to the section on international law. Chile believes that international law, and in particular the United Nations Charter, provides the applicable normative framework that should govern the behavior of states in cyberspace, including international humanitarian law, human rights, and those laws that regulate the international responsibility of states. This is essential to maintain the peace and stability that’s necessary for an open, secure, stable, accessible, and peaceful access to ICTs. We’re happy to see that this new draft has a direct reference to international humanitarian law as one of the specific aspects that this group could work on in future debates. This undoubtedly will make it possible to increase our understanding of how we can protect our civilian populations and give us greater clarity with regard to what actions are prohibited or unacceptable during a conflict situation. In this regard, we recognize that our country has joined the joint communique recently issued by the Delegation of Switzerland, reaffirming that international humanitarian law applies to cyberspace and that explaining how this applies to cyber operations in armed conflict is a priority in future debates. With regard to trust-building measures, confidence-building measures, we’re very happy to see a reference to the fact that this OEWG is in itself a measure for building confidence. This should be a forum where states are able to have an exchange of views, approaches, and express their needs, reinforce resilience, security, and the peaceful use of ICTs in general. In this regard, and with regard to a global intergovernmental directory of national contact points, my delegation feels that regional bodies can play a key role here, particularly because there are already actions that have been undertaken in this area, and it could be an opportunity to carry out comprehensive, complementary work to the work of this group with a view to not duplicating effort. One example of this could be the work that has been done in my region by the Inter-American Group Against Terrorism of the OAS. Chair, my delegation just has one suggestion to make under item six, under confidence-building measures, with regard to the next steps recommended. And in particular, with regard to the holding of an inter-sessional meeting, we’d like to suggest including regional bodies in the invitation to that meeting, given our experience on confidence-building measures and also the establishment of points of contact. In that sense, as we did previously, we’d like to stress the important work that’s been done by the OAS, particularly through the Working Group on Confidence-Building Measures in Cyberspace, which already exists within that body, Chair. Surely, I applaud the approval of the modalities for the participation of stakeholders. However, we do join in those voices that have said that effective plurality is important in this Open-Ended Working Group. We regret that vetoes have been entered because we recognize that this is joint work. We will be providing new contributions as the agenda progresses for this meeting, and we feel that the chair’s text is the first report of this group. Cyberspace, its threats, and challenges have no limits, and it’s therefore imperative that we join efforts to make progress together. We have to go beyond the agreements on paper in order to achieve concrete results in that regard. Chile is openly ready for this process to proceed, and hopefully at the end of the week we’ll be able to approve the report by consensus. Thank you.
Ambassador Gafoor
Thank you very much. Chile, Vietnam, to be followed by Nicaragua. Please.
Vietnam
Mr. Chair, on behalf of the Vietnamese delegation, I would like to thank you for giving us the floor in this first intervention. I would like to express our full support for your leadership of this working group. We now welcome the efforts of the Chair in consolidating comments and inputs from Member States to prepare the draft of the Annual Progress Report, which will be submitted to the General Assembly for consideration. These efforts will contribute to the overall objective of the working group as contained in Resolution 57-240 of the General Assembly. We now also welcome the provision of the draft report by the Chair, which has considered comments from Member States in an informal meeting on 12 July. This draft will serve as a sound basis for future discussion and deliberation on various aspects of the security and inter-use of ICTs. We also believe that such discussion will help identify confidence-building and capacity-building measures needed to counter ICT threats. Mr. Chair, like many delegations in the room, Vietnam shares the vision of a peaceful ICT environment, which is built upon several pillars. First, international and United Nations Charters, which enable States to cooperate in preventing military threats or conflict in cyberspace. Second, consensus and equal participation of States in formulating legally binding frameworks to resolve issues relating to the use, misuse, and the application of ICTs. Third, the primary roles of States in securing its national ICT environments, as well as the constructive collaboration of private and international partners. Fourth, rules, norms, and principles of responsible State behaviors and confidence-building measures in cyberspace to prevent misunderstanding, misperception, and miscalculation. In realizing that vision, we recognize the role of our OEWG processes as stepping stones, and therefore attach great importance to the efforts of all Member States in reaching agreement on the annual report, which takes note of the progress made and helps shape the future discussion of the Working Group. Mr. Chair, Vietnam is of the view that the discussion of the Working Group has made significant progress, even though major differences in national positions remain. Therefore, at this stage, the draft report should, first, focus on the core issues with vision to address common ICT concerns in the context of international securities, and avoid controversial and divisive language. Second, contain items that have reached consensus and reflect comprehensively all views that have been exchanged in previous OEWG and GGE processes, including ICT threats, application of international law in cyberspace, rules, norms, and principles of responsible State behaviors, confidence-building and capacity-building measures, as well as regular dialogue. Vietnam will participate actively in this Working Group to foster a common vision of the securities and in the use of ICTs. We have accordingly submitted to the Chair our detailed comments on the draft report during this session. I thank you for your kind attention.
Ambassador Gafoor
Thank you very much, Vietnam. I have Nicaragua to be followed by China, the Republic of Korea, the European Union, and New Zealand. So, Nicaragua, you have the floor, please.
Nicaragua
Thank you very much, Chair. We’re very grateful for your tireless efforts and those of your team for putting forward a very relevant draft progress report as a first step in our discussions. And we’d like to reassure you of our cooperation in this effort in order to produce a first annual progress report that’s balanced and that will serve as a basis for our negotiations. With regard to Section A, we reaffirm the need to make a reference to the General Assembly resolution that contains a host of rules and established the first Open-Ended Working Group. We shouldn’t forget either the reference to resolution 75/240 that created the current Open-Ended Working Group in its introductory paragraph. The report of the Group of Governmental Experts, the GGE of 2021, we would repeat, is not acceptable to our delegation. With regard to Section B, we feel it’s important to reflect in the report the development of ICTs for military purposes that is a threat to be taken into account. And also, we believe that the exchange of technical information between states and the risk analyses should be on a voluntary basis. We support the proposal to consider a list of common terms to facilitate the process of identification and countering of existing and future threats. We also believe that we should include a reference to the initial proposal for the discussion in the Open-Ended Working Group on the need for a multilateral mechanism for attributing cyber attacks. With regard to Section C, rules, norms, and principles of responsible behavior of states, we believe it’s important to include a reference to the existing norms and the development of additional norms as proposed at previous substantive sessions of the group, Open-Ended Working Group. We don’t think there should be an excessive focus on state behavior, however, in the ICTs. We continue to support the initiative for a negotiating process within the United Nations in order to adopt an internationally legally binding instrument that will make it possible to provide an effective response that is based on multilateral cooperation, particularly that will address the legal vacuums with regard to the use of ICTs. In that regard, we believe that we should include the possibility of legally binding obligations with regard to the recommendations of the OEWG report of 2021 and that we should also refer to the recommendations for the next steps to be taken. With regard to international law, Section D, in our opinion, we need a common understanding of how international law should be applied to the ICTs. This is, however, the exclusive prerogative of states to do this. We don’t think it’s relevant either to talk about the applicability of international humanitarian law to the use of ICTs in the context of international security because this would mean that we tacitly accept the possibility of an armed conflict in this context that would contribute to militarizing cyberspace and would be a first step towards an armed cyber attack where their international humanitarian law would apply. My delegation will be making comments on the outstanding sections as we continue with our meeting. And we’d like to thank you for your attention. Thank you, Chair.
Ambassador Gafoor
Thank you very much, Nicaragua, for your statement. China, please.
China
First, a response to the comment made by Canada. He suggested putting “some” in front of States. I agree, but I think we should have uniform standards. For all of the previous parts, we should change “the States” to “some States.” We should not just add it once. About gender parity, as I said earlier, China supports gender parity. And in essence, we have no substantive difficulties in accepting gender parity in the report. The reason why I propose this issue is that lots of States who support gender parity, when they comment on other countries, believe the suggestions from other countries are not relevant to the topics discussed here. So I would like to thank our colleague from Canada for calling on China to pay more attention to gender parity. Here I would also like to make a call on Canada, as well as other countries that attach importance to gender parity, to be open to the recommendations from other States. Because when we talk about relevance, I think the recommendations from lots of other countries are at least equally relevant – as relevant as the issue of gender parity. In addition, I also heard from lots of other countries that legal assistance belongs to other committees of the General Assembly. However, the same countries also proposed that in our document there should be the addition of the content of international human rights law. So I have a question: Do we have a consistent standard or criteria for this? Third, about transparency. Transparency on the ICT capability. China believes that the security environment of countries should be considered for transparency. The transparency of capabilities for some countries – this kind of request is a signal for a military – for an arms race rather than an issue of CBM. This reminds me that in a similar situation in the nuclear arena, some States under the protection of a nuclear umbrella and while enduring the security interests of nuclear sharing call on other countries to be transparent in the nuclear area. So if we take out of the context of security, the discussion of transparency is not a constructive approach on threats. I heard lots of countries who wish to add more specific concrete recommendations. I would like to remind you that in fact, China also has its own position on this issue. For example, on the flow – cross-border flow of data and the international security issue related to it. For example, the abuse of a national – the excuse of national security to clamp down on other countries’ business. Indeed, it is the sovereign interest of States to protect their security. However, under the pretext of national security, unjustified clamping down on other countries’ businesses is not responsible behavior of a State. So on the intersection of threats and challenges, we support the current text proposed by the chair, not necessarily because this text is perfect, rather because it may be a realistic path to consensus. On 7B and 10 – item 10, I agree with Cardiff and the Netherlands for their recommendations and additional interpretation about this. On norms, on the section about norms, paragraph 8, the first sentence, it talks about concrete and action-oriented proposals. We found this formulation everywhere in this text. If we look at the OEWG document of the year 2021, only paragraph 61 mentions concrete and action-oriented. It mainly refers to capacity building or under the framework of capacity building. However, under the context of norms and international laws, these formulations have never been used. In the GGE report, additional understanding was used, not concrete or action-oriented. However, the GGE of that year was a huge success. In fact, this is a very positive formulation. But different people use it under different contexts. My understanding is that the chair chose this formulation because he wishes that our discussion will yield a concrete outcome. At the same time, the chair also has been emphasizing that we need to – that there is a need to make new rules. And therefore, in a constructive manner, China can support the use of this wording here. However, I hope that China’s position will be registered on record. We hope that in future discussions, there will not be some country that said that because we are concrete and action-oriented, we therefore should not discuss some new rules. Item B, Section B – sorry, Paragraph 8B, Item B. We hope that we want to add a BIS. Global interoperable common rules and standards for supply chain and data security. On Paragraph C, we hope to delete the phrase “potentially drawing from models of information sharing in other fields” and replace it with “well-appropriate.” We also want to add elements after the word “innovation” such as “cross-border transfer of data and timely and non-discriminatory disclosure of vulnerabilities.” On Paragraph D, we also want a new paragraph as a D BIS that reads: “Capacity-building efforts on implementation norms could be strengthened and could include workshops, training courses, as well as exchanges on best practices at international, interregional, regional, and subregional levels.” It was proposed that there should be more focused discussions on the protection of CI and CII. On the recommended next step, we want a new paragraph as 3 BIS, saying “States engage in focused discussions on the protection of CI and CII.” We also want a new paragraph as 3 TER, saying “States are on a voluntary basis invited to submit information to the secretariat on potential needs and gaps in capacity building in the area of norms. The secretariat is requested to collect the information submitted by states to prepare a background paper on needs, opportunities, and gaps in the area of capacities relating to the norms and make a presentation on topics at a fourth OEWG session.” Actually, this new proposal is almost the same expression as the relevant paragraph in the part of international law. So on the international law part, on Paragraph 9A, in the middle of the sentence, we want to delete the phrase “afterward, legally binding obligations” to delete the “state responsibility” from “state responsibility and due diligence respect for human rights and fundamental freedoms and principle international humanitarian law such as proportionality, distinction, humanity, necessity,” noting that the development of the common understanding on international law remains the exclusive prerogative of states. And the following part remains TER’s except the last phrase says “as well as interest stakeholders including business and non-governmental organizations and academias.” We want to delete this part, just a full stop afterward “International Law Commission.” On Paragraph 8C, we want a full stop in the third line afterward “of a sub-regional levels.” So from “as well as draw from experience,” we want to delete the rest part of this paragraph. On the recommended next steps, Paragraph 2, so the second line, so the state engaged in focused discussion topics on the non-exhaustive list in Paragraph 9A above and the Chairman’s summary in the 2021 OEWG report. Such – in the last sentence, such discussions could include other than should the briefings from experts in appropriate format. On the confidence-building matters, Paragraph 10A, that’s about some reference about how to use the POCs. So we want in the fourth line, we want to delete the word from the – in the use of ICT, delete that could be reached in times of urgency. For example, through hotlines. Such directory should other than would respect the state sovereignty. We believe state sovereignty should be respected. And it could be updated other than would. We also want to delete the phrase after the word “as well as capacity building such as a table top exercise where requested.” Because now we are in the early stage talking about the establishment of the POCs. So we should keep open on how to operationalize this kind of useful mechanism. In Paragraph 10B, in the fourth line, we want to delete the word “including ICT capabilities.” The reason that I explain why I respond to kind of distinguished delegates from Canada. On Paragraph 10C, we want a full stop after the word “organization and academia.” All “inter-alia,” from “all inter-alia” to the rest part of the sentence should be deleted. On Paragraph D, in the last sentence, the cooperation to mitigate attacks on CIA and other malicious IT-related activities could be enhanced. We want to delete this part. On the recommended next steps, on Paragraph 3, in the third line, we want to insert the word “effectual report” and produce “effectual report” and delete “with the options for the operationalization of such global directory.” By the end of January 2023 for reference other than consideration. So we believe the role of a secretary is to just collect information and any options and the recommendations are the member states’ responsibility. We want to make it clear in this paragraph. On Paragraph 6, the second part tries to describe, I mean, how the inter-sessional meetings will be organized and what appropriate topics should be discussed with the involvement of the multistakeholders. We want to have some amendment to the topics, saying “including inter-alia, public-private partnership, ensuring the integrity of the supply chain, disclosure of vulnerabilities, ensuring an open non-discriminatory business environment” and delete the rest part of this paragraph. On Paragraph 7, actually delete the same phrase in the second line, “including ICT capabilities.” So we will submit the amendment in written form and would be more than happy if the chair could circulate it to other interested delegations. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you, China, for your detailed statement. I look forward to receiving your contributions in writing. I now give the floor to the Republic of Korea. Please take the floor.
South Korea
Mr. Chair, let me begin by thanking you and the Secretariat for organizing this session and for the effort in drafting the Annual Progress Report that reflects our lengthy discussions during the last two sessions. We believe the revised draft serves as a good basis for our deliberations during this week. We welcome the introductory paragraphs 1 to 6 of the draft, in particular, their mentioning of the anarchy of cyberspace, including the 11 norms of responsible state behavior, OEWG’s commitment to meaningful stakeholder engagement, and recognition of the role of regional organizations, as well as participation of women delegates in its discussions. My delegation would like to extend a warm welcome to the multistakeholders present at this session. We note the efforts made by the OEWG to provide greater opportunities for their participation and look forward to further engaging them in a more meaningful and substantial manner, so that we can incorporate in our discussions the valuable and varied expertise of the stakeholders. Mr. Chair, with regard to threats, the last two sessions were a valuable opportunity for all member states to understand how each of us perceives threats in the ICT environment. We believe paragraph 7 reflects the concerns raised by states regarding the growing and evolving nature of threats in cyberspace in an appropriate manner, as well as the importance of fostering stronger cooperation between CSIRTs. We also support some member states’ proposal to include examples of threat elements, such as ransomware and critical infrastructure attacks, as there is value in raising awareness on technical aspects of the threats. Turning to norms, rules, and principles, Mr. Chair, as my delegation highlighted in previous sessions, it has been well established through discussions at various international fora that there is no vacuum of legalities in cyberspace, as the international law, including the UN Charter in its entirety, applies to cyberspace. This does not rule out the possibility of additional norms developing over time, as paragraph 8b duly elaborates. Regarding this, my delegation would like to stress it is important these additional norms develop in a way that will complement, not challenge or substitute, existing laws and norms in cyberspace. Moreover, we believe discussions to develop additional norms must focus on providing concrete protection to states affected by cyberattacks and ways to promote implementation of existing norms in that regard. We support the Voluntary National Survey of Implementation of Norms, mentioned in paragraph 8d, as a useful mechanism for stocktaking the current state of norms implementation in the international community. The Republic of Korea has submitted the national survey in March 2020, which we will update and share with the OEWG in due course. Moving on to international law, Mr. Chair, let me begin by welcoming the draft report includes due diligence in the list of specific topics of international law to be discussed in future sessions in paragraph 9a. Due diligence is becoming increasingly important in both preventing and responding to cyber incidents. Promoting deeper understanding of this principle will also go a long way in enhancing the implementation of the agreed norms, as many of them are pertinent to the principle of due diligence. Equally welcomed in the same list is the explicit mentioning of international humanitarian law, the importance of which has been echoed by many states during our discussions. Regarding this, we would like to suggest reinstating the deleted clause in paragraph 9a, mentioning briefings from ICRC, as we believe it will greatly help enhance member states’ understanding of the IHL in the context of ICT security. We hope to see these elements retained in the final outcome. On the other hand, we suggest deleting the phrase, development of common understanding remains the exclusive prerogative of states in paragraph 9a, since such understanding can also be further developed by other entities, such as academia, through legal interpretation of the international law. A useful way of developing such a common understanding is through voluntary sharing of national views on how international law applies in the use of ICTs, as mentioned in paragraph 9b. We appreciate that many states have submitted their national views, and we plan to submit our own in the second half of this year. The Republic of Korea also strongly supports the importance of capacity building on international law, and therefore welcomes the expression in paragraph 9c. We are committed to promoting better understanding of how international law applies to cyberspace through such efforts as the ROK-Netherlands joint webinar on the application of international law in cyberspace. We also take interest in improving mechanisms for mutual legal assistance regarding malicious use of ICTs, mentioned in the same paragraph, and look forward to further discussions in this area. Mr. Chair, regarding CBMs, the Republic of Korea is committed to developing and operationalizing CBMs in UN and regional fora. We believe a functioning and effective POC network at the UN level can be a useful starting point for global confidence-building. To this end, we are participating in the joint effort to establish a UN cyber POC network and believe it is important to foster greater coordination between such efforts at the UN and those at regional levels such as ARF and OSCE. We welcome paragraph 10a and recommended next steps, too, in this regard. We also believe in the utility of UNIDIR’s cyber policy portal as a means to promote confidence-building and therefore support its mentioning in paragraph 10b. We would like to share that ROK is engaged in efforts to enhance the CBMs in regional and cross-regional fora, including through co-chairing the ARF ISM on ICT security and participation in the cross-regional CBM group. We hope these regional and cross-regional efforts for CBMs yield concrete results that build and reinforce mutual confidence in cyberspace. Mr. Chair, I will move on to capacity building. The importance of narrowing the digital divide in making of a safer cyberspace has been echoed by delegations across the board during our previous sessions, and the role of capacity building in this regard has gained unequivocal support. However, a significant gap still exists between the international community’s will for capacity building and concrete mechanisms on which it can rely to that end. A permanent mechanism dedicated to capacity building efforts to be potentially established within the UN, as mentioned in paragraph 10d, and recommended next steps 2, is a welcome step in the right direction. In these paragraphs, we would like to suggest adding POA as a concrete example of such mechanisms, considering many member states, co-sponsors, and others have recognized its potential role in enhancing capacity building. We suggest adding to the end of paragraph 10d the phrase states noted that POA, among other proposals, could be a possible example of such a mechanism. The ROK is also actively engaged in capacity building efforts in regional fora, such as the ARF and ASEAN, including through proposing workshops on fostering cybersecurity professionals. We are committed to continuing these efforts in and outside of the UN. Lastly, regarding regular institutional dialogue, Mr. Chair, as a co-sponsor of the POA, the Republic of Korea shares the same position with other co-sponsors. We believe that POA as a permanent organized mechanism can serve as a practical way for operationalizing the various proposals put forward at the OEWG. We welcome mentioning of POA in paragraph 12c and look forward to further discussions and development of the proposal. Thank you very much.
Ambassador Gafoor
Thank you, ROK. I give the floor now to the European Union.
EU
Thank you, Chair. I have the honour to speak on behalf of the European Union and its Member States. The candidate countries, North Macedonia, Montenegro, Ukraine, and the Republic of Moldova, the country of the stabilization and association process and potential candidate Bosnia-Herzegovina, as well as Georgia and Monaco, align themselves with this statement on the norms section. I will also deliver our views on the international law and confidence-building measures section, and alignment will be appropriately reflected in the written version of the EU statement for these sections. Being respectful of and guided by international law, rules, norms, and principles of responsible state behaviour are key to maintaining international peace, security, and stability. Consequently, enhancing our common understanding about these rules, norms, and principles and advancing their concrete implementation should be at the core of our common efforts. We shall make a common effort to implement all 11 norms and work together to provide additional guidance to advance their implementation, as well as elaborating on the conclusions and recommendations agreed in prior OEWG and UNGGE reports. In this regard, paragraph 8 should include a clear reference to the existing 11 norms of responsible state behaviour, as agreed by all UN member states. There should be no confusion about the repeated consensus support for the UN framework of responsible state behaviour. As indicated by the Chair, there is a varying level of support from states to proposals made and outlined under this section. This means that the introduction of proposals should be consistent. For instance, proposal A should be “states could consider.” We also believe that there is more support for the use of national survey implementation, which was agreed by consensus in 2021, than for developing a common understanding of ICT terms, which is a recent divisive proposal by some states. The current wording and ordering are unbalanced and do not do justice to the work of the international community thus far. Regarding the recommendation suggested by the Chair, indeed the OEWG should continue engaging, exchanging views with the aim of developing a common understanding of rules, norms, and principles of responsible state behaviour and the use of ICTs. But the recommendation should, however, clarify that this common understanding will facilitate the implementation rather than the OEWG itself. We also recall the working paper on the establishment of the Program of Action that has already been submitted to the first and second OEWG and the UNGGE, which contain concrete proposals for activities and funding facilitating the implementation of the rules, norms, and principles. Furthermore, we should focus first on our common work as regards our understanding of the implementation of the existing norms and the necessary steps to do so before we start developing new norms. Some of the proposals of the 21st list that are referred to in the text are not considered as new norms, but rather further guidance to the existing norms. So, rather than focusing on a list of proposals submitted at the last OEWG, we suggest recommending organizing focused discussions on existing norms to discuss guidance for the implementation and invite participants to make in-depth proposals in that regard. We should also focus on enhancing a common understanding of what activities are needed to implement norms and providing guidance to capacity-building efforts globally. Initiating discussion on terminology would not only divert us but would also be time-consuming at the expense of concrete discussion on the implementation of norms. The EU requests to delete the common understanding of ICT terms. In addition, we see duplication between the National Survey of Implementation, as contained in the recommendation of the 2021 OEWG report, which feeds the discussions on norms implementation and identifies the opportunities to better support states in their endeavours, and duplication with submitting new working papers on the development of guidance and checklists. The EU recommends using work done to date rather than creating duplicating initiatives and efforts. The EU supports exploring merging the two recommendations, 2 and 3, in order to combine providing norms guidance and implementation. In the OEWG’s efforts to share best practices as regards norms implementation, regional organizations could be encouraged to participate in view of their efforts, such as the developed roadmap for the implementation of norms. We also see the need to share best practices with the regional organizations in order to better support the implementation of norms. In the OEWG’s efforts to share best practices as regards norms implementation, regional organizations could be encouraged to participate in view of their efforts, such as the developed roadmap by ASEAN member states. Chair, we welcome the international law section, noting at the same time, it is important to underline that we are not starting from scratch, and the international community has achieved much. This is the paper presented by Switzerland and Canada, which outlines a proper agenda for our discussion on international law. In this light, we welcome the revised draft report to take forward the discussion on the application of international humanitarian law, including but not limited to its main principles. However, the draft report fails to reflect appropriately a crucial element that we are now taking forward in our discussion, which is on how international law applies. We, therefore, support reflecting it, notably under Recommendation 3. We also welcome the opportunities to be briefed by relevant experts in an OEWG session. The International Committee of the Red Cross should also be clearly included. In addition, we do not see the added value of limiting the participation of regional organizations in paragraph 9C. For instance, the Organization of American States has been very active in developing a questionnaire on the application of international law to gather their member state views. We are the ones that will benefit from such efforts. We strongly caution against putting premature and difficult discussions on our agenda. In particular, the proposal to discuss additional legally binding obligations is premature, even not realistic in light of the repeated condemnation of some states breaching international law and not adhering to the norms of responsible state behaviour, and so certainly in 2023. Moreover, the discussion on additional binding obligations should not precede the conclusion on discussion and implementation of international law and potential gaps in this regard. Finally, as regards the section on confidence-building measures, we can express our support to the Chair and congratulate the Chair and his team on the good reflection of discussion and solid recommendation on the way forward. We welcome the efforts by other states, notably Australia, Brazil, Canada, Germany, Israel, Republic of Korea, Mexico, Netherlands, and Singapore, in putting forward concrete proposals as regards CBMs, including awareness-raising as well as the points of contact. We also welcome the proposed recommendation, notably to establish a global point of contact directory among states and relevant international and regional organizations, which will allow us to reduce risk stemming from the use of ICTs and to make concrete progress on advancing international security and stability in cyberspace. We also welcome the inclusion of other stakeholders as a crucial element, noting the responsibility of all stakeholders to reduce misinterpretation and contribute to confidence-building in cyberspace. However, we do not see a need to limit this inclusion to topics to foster confidence-building measures, which is rather vague and does not capture the role of stakeholders in the implementation of CBMs. We suggest going back to the previous wording. We also encourage the Chair to start in-depth discussion and note that such discussion on recommendation could be taken in conjunction with the ones that focus more on norms implementation, notably those related to ensuring the integrity of the supply chain, preventing the malicious use of ICT tools and techniques, preventing the use of harmful identity functions, and the sharing of current threat information, including because of the pertinent interlink. The EU, being part of multiple regional discussions on CBM, is happy to exchange upon its experience and we welcome the concrete recommendation on the role of regional and sub-regional organizations in this context, as well as will continue to engage to share best practices in our discussion. However, we do not support the addition of “where appropriate” in this recommendation. Regional organizations have been at the forefront of developing and implementing confidence-building measures. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you, European Union. I now give the floor to New Zealand, to be followed by Mauritius. New Zealand, please.
New Zealand
Thank you very much, Chair, and let me start by thanking you for your stewardship of this process. REV1 demonstrates that this is truly an inclusive process, with comments reflected from the informal last week included throughout, so thank you. We welcome in the introduction the reference to the challenging geopolitical context, and we note this context was set out very clearly yesterday by Her Excellency Nakamitsu. Over the period of this OEWG, we have seen cyberspace used in conflict, and so we see value in the inclusion of a reference to armed conflict at the end of the first sentence, as proposed by the Netherlands. We support and align with the intervention on stakeholder modalities made by the Czech Republic yesterday, and we thank Ukraine for its explanation. And while we welcome Russia’s offer to provide an explanation on its decision, we encourage Russia to provide its explanation to the Chair so that it can be considered by all states. We welcome the reference in paragraph 3 and throughout the report, given the importance of stakeholders, who are very well placed to speak to the impact of the eventuality of the threats that we are discussing, including on the human rights of individual citizens, as well as share knowledge on best practice. We are very pleased to see the inclusion of gender in paragraph 5, noting UNSC Resolution 1325, which recognizes the importance of considering gender in achieving long-standing peace and security. Finally, my last general comment is that we would propose the inclusion of the words security of, or some alternative formulation, as appropriate to accompany the phrase in the use of ICTs throughout the report, to reflect our clear mandate here at the OEWG. Regarding the threat section, we agree with many of our colleagues who have noted the cyber threats faced by states was a clear theme across many interventions during the first two sessions. A shared understanding of the threats faced, built on consensus language of the previous OEWG, will be useful for states to agree on approaches to combating these threats, and so we would like to see a clearer articulation of exactly what these threats are. In this vein, we condemn the campaign of destructive cyber activity that has disrupted Ukrainian government and private sector networks and systems over 2022, which have been attributed to Russia. This has increased the threat to cyberspace globally since the 2021 report, and we consider therefore that this context should be reflected in the annual report. Like Costa Rica, El Salvador, and many of our colleagues, we would welcome a specific reference to ransomware. In May last year, New Zealand experienced a ransomware attack against one of our health authorities. This attack caused disruption and difficulty and deep anxiety for thousands of people, including as their access to healthcare was delayed. This is not ordinary cybercrime. These ransomware attacks can represent national emergencies, which is exactly what we should be working to prevent today. For these reasons, we thank Australia for its offer and efforts to develop consensus language, and we strongly support their proposals. Finally, as China proposed regarding 7b, we welcome the shifting of these items under the section to later sections of the report where they are relevant, because they are actions to reduce threats. We support the suggestion of Indonesia and others to remove the reference to mutual legal assistance from this report, given the work in the third committee. On norms, we agree with others who have confirmed that our focus should be on the implementation of existing norms. And we support South Africa’s cautioning of the burden on smaller states. We agree with the proposals of Switzerland to include language regarding stakeholders. On international law, we confirm that we are comfortable with the language proposed, and thank the Chair for the inclusion of international humanitarian law, noting that we are already in the situation where cyber is being used in armed conflict. We would support the further amendments outlined by Switzerland. Finally, on confidence-building measures, we confirm that we are comfortable with this section, and we note that the broad comfort of many states in this area reflects the work of many states over a long period, and we thank states for their efforts in this area. Thank you, Chair.
Ambassador Gafoor
Thank you, New Zealand. I give the floor to Mauritius, to be followed by Ireland. Mauritius, please.
EU
Good afternoon, Chair, Excellencies, and distinguished colleagues. Thank you for giving me the floor and allowing me to express our appreciation to you, Chair, for the efforts you and your team have put forward for the concise draft report that served as a guidance for many of us in the room. Mauritius is of the opinion that annual progress reports will keep on serving as vital instruments to capture significant inputs and progress made at the end of each substantive session. They pave the way for delegations to keep their discussions on specific topics of the OEWG within a defined framework. Section B of the updated draft emphasizes that global inter-regional cooperative measures will be effective in addressing existing and potential threats and that there is a necessity for cooperation and assistance to establish and strengthen CSIRTs. Mauritius aligns itself with this statement and strongly considers that the involvement of relevant stakeholders and a coordinated approach are beneficial to resolve cybersecurity incidents occurring both within and beyond borders. When it comes to incident reporting, most states consider stored and shared information as private or otherwise sensitive. Thus, an adequate level of trust between sharing parties is of paramount importance. Many states will agree that the most straightforward way to establish trust between parties is through the signature of a legally binding document that defines the scope of cooperation and information sharing. Mauritius affirms that the network of CSIRT relationships could also be expanded with the signature of MOUs with other CSIRTs. This will essentially enhance cyber incident reporting and response linkages and promote exchanges on current and emerging cyber threats. With regards to cooperation and assistance, developing states could seek the assistance of established CSIRTs for the setting up of their incident response teams, be it at national or organizational level. In its quest to boost cooperation at the regional and sub-regional levels, Mauritius has been actively collaborating with regional countries and is committed to providing assistance to countries to set up their CSIRTs and acting as a sponsor in their affiliation to the Global Forum of Incident Response and Security Teams. At this stage, Mauritius is looking forward to further strengthening its regional and international linkages and welcomes any requests for assistance as well as exchanges with the international community and cybersecurity partners. I thank you very much, Chair. Thank you.
Ambassador Gafoor
Thank you very much, Mauritius. I give the floor to Ireland, to be followed by Uruguay.
Ireland
Ireland, please. Mr. Chair, as it is Ireland’s first intervention, we wish to thank Under-Secretary-General Nakamitsu for her opening remarks yesterday, and to you and the Secretariat for organizing this meeting. Ireland aligns itself with the statement made by the EU colleague. I wish to make brief summarized remarks in a national capacity on both the rules, norms, and principles and international law sections of the report. Mr. Chair, our discussions this week take place within the context of a global upsurge in the malicious use of cyber by both state and non-state actors who target our citizens, our public institutions, and critical infrastructure. Echoing comments by the EU, Russia’s aggressive actions against Ukraine and the Ukrainian people, including from a cyber perspective, have made the work of this OEWG more difficult but all the more necessary. Ireland fully supports the EU27 declaration last week condemning malicious cyber activities conducted by hacker groups in the context of Russia’s aggression against Ukraine. More broadly, Ireland acknowledges the damage suffered by states globally from malicious cyber activity. In this regard, developing states suffer disproportionately. Ireland will continue to call out malicious cyber activity while at the same time working constructively with states and stakeholders to develop solutions grounded in the acquis. In this regard, Ireland aligns itself with the statement delivered by the Czech Republic and welcomes the many stakeholders who are able to join us here this week. We would like to add our profound disappointment that the only Irish-based stakeholder to apply was blocked from participating. Inclusive and transparent engagement from a broad range of multistakeholders is indispensable when exploring norms, as full implementation can only be fulfilled with their expertise. In this regard, we are pleased to support open dialogue and discussion at this OEWG by providing funds to you in order to support and facilitate the participation of a number of non-state stakeholders at this meeting. Mr. Chair, Ireland welcomes the draft annual report, noting its action-oriented structure and usefulness as a roadmap for our future discussions. Ireland welcomes the language on the voluntary norms of responsible state behavior, which have been endorsed by the UN General Assembly and past OEWG and GGE reports. Adherence to the 11 voluntary norms of responsible state behavior is of the utmost importance to maintain international peace and security. As we have previously stated here at the OEWG, we must now build upon our common understanding and focus on implementation rather than attempting to introduce new norms. In this regard, we would welcome further language on practical initiatives to enhance implementation, particularly in reference to the vital role of multistakeholders and regional organizations. Ireland welcomes the survey of national implementation and notes its potential in allowing Member States to make concrete progress in norm implementation over the coming years. Further thought could be given here so that we are not duplicating efforts. Ireland also wishes to support textual suggestions by Canada on the addition of “some” before “states” to make it explicit that most Member States now wish to focus on the urgent implementation of existing norms rather than develop additional norms. We believe that these 11 voluntary norms are sufficient to guide states in responsible state behavior in cyberspace and that more clarity is needed to ensure that non-consensus views are not presented as universal. In this light, paragraph 8 would benefit from a clear reference to these existing voluntary norms. Now, very briefly on international law, Ireland supports the UN consensus that existing international law, notably the UN Charter in its entirety and international humanitarian law and human rights law, apply to states’ actions in cyberspace, as reflected in past GGE, OEWG reports, and UN General Assembly resolutions. Ireland welcomes the insertion of language into the draft report on international humanitarian law and notes the importance of developing a common understanding amongst all Member States in this regard. We echo comments made by the EU and many other states here that the applicability of international humanitarian law in no circumstances legitimizes the use of force and instead is a protection which underpins international peace and security. In this regard, Ireland supports constructive initiatives such as the paper presented by Switzerland and Canada. Mr. Chair, as we have consistently highlighted on previous occasions in this forum, we do not see the need for a new legally binding instrument that does not enjoy broad support and the divisive and time-consuming negotiations that this would require. Ireland further welcomes language in the draft report on the UNIDIR Cyber Policy Portal, which allows Member States to share national position papers, which can promote confidence and mutual understanding. We also strongly welcome the inclusion of language on capacity building and note the importance of the Program of Action on Cyber, which Ireland is pleased to co-sponsor alongside 60 other Member States in delivering in this regard. We conclude by reiterating our support for your work and the work of this OEWG and thanking your team for your engagement.
Ambassador Gafoor
And in recent months, thank you. Thank you, Ireland, for your statement. I give now the floor to Uruguay, to be followed by Croatia. Uruguay, please.
Uruguay
Good morning, good afternoon, Chair. We hope that this session will be very successful. We’d like to greet the Secretariat and thank you for your valuable contributions. We also appreciate the work that is being done for the mandate of this group, and you can count on the support of my delegation. As has been said at previous sessions, my delegation attaches particular importance to the subject being dealt with in this group. Currently, we are working at different levels nationally as well as regionally on these issues. And in parallel, we’re actively participating in the ad hoc committee to establish an international commission to counter the illicit use of ICTs for the purposes of cybercrime. We feel that this tool will help to build a safer internet and provide greater guarantees to the membership. With regard to the document presented at the previous session, my delegation asked, when we took the floor before, that we have a more focused agenda, and I think that what we have now reflects this. And we have a good method for collecting contributions of member states. We need to have a general report that will cover the previous reports and will be very valuable for this group and institution that we’re working with. An institutional memory, as it were, for the group, particularly on such a sensitive issue as ICTs. We think, therefore, that this report is very valuable, and, as I said, you can count on the support of my delegation. The annual progress reports are important in order to inform the group, particularly of the reports of experts in civil society. In terms of a general comment, the text – the introduction, we agree with the current drafting of paragraph 2, namely that the 2022 report should capture the specific progress made in the previous groups to date as well as upcoming action. And then in chapter C, the rules for responsible behavior of states, that’s very important for Uruguay and that we continue to cover these aspects, building greater understanding based on the conclusions and recommendations of the reports of the previous working group and also the GGE. We need to build on all of the consensual elements in the past and build agreements on them, based on them. With regard to international law, paragraph 5A, we feel that we should talk about how international law will be applied and refer to international law. We can look at that more in detail later with regard to the drafting of that text. Also, the principles of international law should be included, but with sufficient flexibility. In the recommendations for paragraph F, we should include 2A, references to cooperation, south and triangular cooperation. And as the meeting proceeds, we will make further comments on this. Then, paragraph F, capacity, we agree with the proposals there. We feel that the group could create greater understanding with regard to the needs of developing countries when it comes to capacity building. And also, we agree with what’s said in paragraph 7 with regard to innovative technologies. And finally, in G, we’d like to support greater understanding of the cyberspace and ICTs. With regard to the various initiatives presented that we’ve received throughout this process, we are very grateful to all delegations for those contributions. They are a way of making the contributions of this group operational. And perhaps this should have been reflected on the website overall. We’d also like to say something with regard to the other meetings organized this week. They’re very useful for delegations as well as accredited experts here in New York, as well as for the capital. However, it might be very useful as well in order to participate in those meetings to coordinate with the membership so that there’s no overlapping of work, so that all delegations will be able to participate in those meetings and make them a success. There’s also the political aspect to all of this. We can’t ignore that, but these sense that political sensitivities shouldn’t affect the technical work being done in this group so that we can complete our mandate and make our task easier. We will continue to make contributions, and we feel that it would also be good to know how the chair in detail feels that the group should continue its work throughout the week with regard to the document and also the holding of the informal meetings so that we can adjust the agenda to take into account all of these aspects that I’ve mentioned. With regard to the other meetings, I’d like to take into account all of these aspects that I’ve mentioned. With regard to the initiatives that were presented, we will be including some of those that are of particular interest. Thank you very much to the members of the group.
Ambassador Gafoor
Thank you very much, Uruguay. Croatia to be followed by Italy. Croatia, please.
Croatia
It’s not working. It’s not working. Is it? It’s OK, now it’s fine, thank you. Thank you, Chair, and also many thanks to the whole team for the zero-draft report, and even more for the revised version, which very well reflects our previous discussions. Different arguments were presented during last year, and this draft report has taken most of them into account. Let me begin by stating that Croatia aligns itself with all interventions of the European Union. Croatia would also like to stress the importance of acknowledging previous UNGGE reports and last year’s OEWG report, which were endorsed by UNGA, as a good framework and baseline for our discussion so that we can continue to build upon it. Dear Ambassador Gafoor, we would also like to compliment your commitment to the process, as well as openness and readiness to hear every single voice. We strongly believe that our joint goal is to show that the needs and interests of our citizens come first, and that our work today is to ensure open, free, secure, and stable cyberspace, not just for now, but also for the future. So with that in mind, we stand ready to actively and constructively work on finalizing this annual progress report. Croatia strongly condemns Russian military aggression against Ukraine, which is clearly a breach of the UN Charter and violates international law. And when it comes to cyberspace, it is damaging all our work and efforts we all have invested in the last several years to achieve a security of the ICT domain. Using ICT in a proper manner can have a positive impact on effective implementation of the UN 2030 Agenda and economic and social development well beyond 2030. Reducing the digital divide, especially the gender digital divide, is another aspect that needs to be recognized. Therefore, we would like to warmly welcome these acknowledgments in the revised draft and urge delegations not to bring in question the obvious fact that in the ICT sphere we still have a gender divide. Outside of this room, we don’t have the same gender parity and same opportunities for all genders, so therefore we would like to keep this reference in the text. Croatia would also like to support the Czech Republic, Canada, and others on the participation of the multistakeholder and their important role in the whole process. And we regret that many of the well-known and active stakeholders have been denied the participation at the meeting. When it comes to existing and potential threats, we support the listing of technical and cooperative measures, although some of them could be placed in other chapters like confidence-building measures. States have a responsibility to respect already agreed norms and principles of responsible behavior in cyberspace, which will then contribute to lowering the risk of cyber incidents. What we find is still missing in this chapter are real threats such as ransomware and DDoS attacks, which continue to cause significant damage and shake our societies. We strongly condemn recent attacks on critical infrastructure and governmental institutions and call upon states to restrain from conducting such attacks. Croatia would like to support countries who believe that the chapter on threats could be enforced and we should also mention real everyday threats states are faced with. Distinguished colleagues, we should work jointly to ensure that existing international law, international humanitarian law, and the entire global legal system built around the UN Charter are fully respected and implemented in the cyberspace. Implementation is the key and therefore we welcome mentioning the importance of the capacity building in this area. Sharing views and best practices on the implementation of international law in the use of ICTs is of utmost importance and will contribute to better understanding how international law applies in cyberspace. In this regard, we would also welcome more exchanges among law enforcement communities, but also with experts from non-governmental sector, academia, as well as private sector. We support intervention of Switzerland and group of countries regarding the implementation of the international law, humanitarian law, and Netherlands proposals for changes in chapters on international law. Croatia would like to reaffirm its support to the National Survey of Implementation since it can contribute to better understanding on how international law applies on national level and where states need help to improve their capacities and performances. To build trust and confidence among us at the diplomatic level, but also among our colleagues at the policy and technical level, personal contact is very important and how to get in touch with someone in the case of emergency if you don’t have her or his number. Therefore, we would like to support the establishment of point of contact directory while using already existing structures and avoiding duplication of efforts. Experiences of regional and sub-regional organizations in this regard should be better utilized, especially when it comes to lessons learned. Furthermore, availability of national practices and other relevant information could be improved, so we would like to encourage states to publish and update them online and in this way share them with other countries. Learning from each other’s experiences, but also from mistakes, could improve our own capabilities and capacities and contribute to confidence building. We would also encourage cooperation and exchanges among CSIRTs, especially sharing best practices for raising resilience and mitigating consequences of cyber incidents. In upcoming meetings, we should also discuss how to mainstream agreed recommendations into already existing programs and ensure adequate financial assistance and transfer of the know-how. The EU and its member states are already integrating cyber into our development assistance and we are supporting countries around the world in their cyber capacity building. Dear colleagues, we should focus on deliverables that have broad support and could be achieved quickly. We believe CBMs and capacity building are low-hanging fruits that we can pick up and make a good smoothie. As a co-sponsor, Croatia supports the French proposals regarding the Program of Action as well as the intervention of Republic of Korea. Furthermore, Indian proposal on global cooperation portal deserves to be discussed more during our next meetings. And finally, Croatia reaffirms its commitment to chair prudent leadership and may the force and wisdom be with all of us in following days and let’s try to reach an agreement on the annual progress report. Thank you, Chair.
Ambassador Gafoor
Thank you very much, Croatia, for your statement and also for the smoothie. It is getting close to lunchtime, and I think we will get to that soon, but we can still take, hopefully, a few more speakers, one or two. I give the floor now to Italy, to be followed by Estonia. Italy, please.
Italy
Thank you, Chair, and good morning, colleagues. Good afternoon, actually, talking about smoothies and lunchtime. Chair, I wanted to thank you and your team for the revised zero draft, and we’re looking forward to providing our support in reaching the goal of adopting a consensus report by the end of this week. I’ll try and be telegraphic in my remarks, in the interest of time. We agree on the value of the report as a roadmap for our future work, whilst at the same time we do not consider it as a straitjacket. For example, should additional threats present themselves in the months to come? We therefore support the Austrian inquiry made yesterday on the value of the report going forward. Italy supports all EU interventions. Obviously, we’re talking about 27 member states, and I think I counted seven non-EU states. We support the Czech comments from yesterday morning regarding the multistakeholder participation. We’re also supportive of your comments, Chair, and efforts to make the OEWG as inclusive as possible by organizing specific, also informal, consultations. We support such an approach also during the intersessional period. And additional language proposed by Australia in paragraph 3 would actually be very welcome in this regard. In the revision of the current draft, preservation of the acquis should remain the guiding principle. We’re obviously flexible on how you wish to achieve this. Regarding section A, as mentioned by other colleagues, we support both the reference to the role of regional organizations in paragraph 4 and to gender in paragraph 5. Always in this context, we support the suggestion of Costa Rica to insert a reference also in paragraph 4 to IHL. In the same vein, we support and share her comments on references to critical infrastructure, including the health sector. As Nakamitsu said yesterday, the pandemic, and as my face mask witnesses, the pandemic is not over yet. We agree with all colleagues who suggested the need of making section B more specific and complete, and we’re looking forward to language suggestions. Again, the Australian colleague mentioned this yesterday. It is the core business of the OEWG. We need to see greater recognition of current challenges, notably in the context of the Russian aggression of Ukraine. Therefore, we support insertion of language suggested by the Netherlands in paragraph 1 as a bare minimum. We support language on the need to refrain from military use of ICTs, as well as hacktivism, as underlined by Germany and others yesterday. We also agree on the need to ensure that we leave for ourselves the possibility to discuss future threats, as mentioned by the U.S. yesterday morning. Italy also supports all delegations which have advocated for reference to ransomware, taking into account that the threshold of such criminal activities could well constitute a threat to states. Let me end on the issue of IHL. We support the reference made in paragraph 9a to ICRC in the zero draft and wish to see it reinstated, as suggested by Switzerland and the Republic of Korea, noticing that such references were also supported by Under-Secretary-General Nakamitsu in her welcoming address yesterday. Should this still be problematic, we’re available, obviously, to look at other language which might be proposed by colleagues later today, notably referring to entities having received a standing invitation to participate as observers in the work of the General Assembly. Finally, and in a similar vein to statements by Japan and Canada, we also wish to encourage states to develop national positions on international law in cyberspace, as done by Italy at the end of last year, and we welcome the reference to the UNIDIR cyber portal, which we wish to see still in the next version of the report. Thank you, Chair.
Ambassador Gafoor
Thank you. Italy, Estonia, please.
Estonia
Thank you, Mr. Chair, and I hope there are not too many mentions of smoothies; I’m getting hungry also. Mr. Chair, thank you for giving me the floor. Estonia aligns itself with the statements delivered by the European Union. We also support the statement by the Czech Republic yesterday on stakeholder participation. We would also like to use this opportunity to add some points on national capacity. On the existing and potential threats section of the revised draft report, Estonia joins those delegations in support of outlining the list of threats that we are facing to set the context for the rest of the reports and the work of this OEWG. Regarding the section on rules, norms, and principles on responsible state behavior, Estonia regards the agreed normative framework as a crucial footing for everything we do in the field of cybersecurity, and the OEWG can play a crucial role in strengthening the 11 norms by further clarifying the expectations that the norms reflect and exploring further opportunities to support states in this implementation. With this said, we welcome the action-oriented approach of the revised draft progress report and support the recommendation to develop additional guidance or checklists on norms implementations. A better overview of how the norms are being implemented will help create more targeted and needs-based capacity building measures. The threats in cyberspace are evolving fast, and to keep up with the pace, the matter of priority should be on a concerted effort to implement existing norms. We therefore also support the several proposals voiced yesterday to reference explicitly the existing 11 norms in this annual progress report. We are also of a strong view that the temptation to develop additional norms should be resisted at this point in time. With that said, and especially with an understanding that the draft revised report at hand sets out the priorities for the OEWG for the coming year only, we would support the deletion of paragraph 8b. We would also like to see this OEWG concentrating its full focus on the implementation of existing norms with a focus on behavior rather than the terminology of the technology in itself and would therefore support the deletion of developing common understandings on technical ICT terms at the end of paragraph 8a. Estonia has always been convinced and advocated for the existing international law to be applicable also in cyberspace. Despite today’s geopolitical situation where the Russian Federation is blatantly violating international law by its military aggression against Ukraine, we continue to believe that all states benefit from rights stipulated by international law provided that states also follow obligations deriving from it. While we call on Russia to stop immediately its military aggression against Ukraine and to fulfill its obligations under international law, including the UN Charter, the international community needs now more than ever to join forces to strengthen the international rules-based order, also through adhering to it in cyberspace. We therefore welcome the substantive section on international law in the revised draft report. The introduction section of the draft progress report notes well that the states reaffirm the previous consensus outcomes of the GGEs and OEWG. We believe that it would merit to set this as a starting point also in the international law section of the progress report and to state explicitly that the further work of this OEWG will build on the agreed understanding that international law, including international humanitarian law and human rights law, apply in cyberspace. As there have been no substantial discussions yet on the international forum on how the existing international law provisions apply in practice, in order to advance common understandings, we need to make the best use of the opportunity provided by this OEWG. Therefore, paragraph 9a could be strengthened by saying that the OEWG should, instead of could, convene discussions on specific topics of international law. These discussions should approach international law holistically and include different branches of international law, including international humanitarian law. These discussions should also be advised by different experts that are not only limited to the UN or the businesses and non-governmental organizations but also include entities having received a standing invitation to participate as observers in the work of the General Assembly. We would appreciate it if the end of paragraph 9a could be reworded accordingly. The use of ICTs by state and non-state actors in the context of armed conflicts is a fact. This has clearly been evidenced by Russia’s unprovoked and unjustified military aggression against Ukraine, which has been accompanied by a significant increase in malicious cyber activities, including by a striking and concerning number of hackers and hacker groups indiscriminately targeting essential entities globally. While strongly condemning all cyber attacks against Ukraine, Estonia stresses that the use of cyber capabilities in armed conflicts must be subject to obligations deriving from international humanitarian law and its principles of proportionality, distinction, humanity, and necessity. Leaving cyberspace outside the scope of IHL rules would leave civilians, infrastructure, and combatants without an additional layer of protection. Given the protective nature of IHL, we see it as misleading to assume that applying IHL would legitimize cyberspace as a battleground in the country. This is why we joined the statement delivered by Switzerland this morning. Mr. Chair, as we continue working under your able leadership on creating common understandings on existing international law provisions, it is premature to be already talking about possible new legally binding instruments. We see that first it is important to see whether gaps in the existing provisions exist at all, and only then can we start discussing what would be the best way to address these potential gaps, if any. With that said, we fully support paragraph 9c on capacity building on international law. In line with that, Estonia is, for example, organizing a series of teleworkshops on international law and cyber operations, with the main objective to create a forum for informal discussions between partners, as well as offer the opportunity to examine the most pertinent international law issues related to state conduct in cyberspace. We have found these workshops to be very useful, and we hope that these inspire also others to take up similar initiatives. In regard to capacity building activities, it is clear that the current demand for further projects and initiatives exceeds the supply. Estonia has always been open to sharing our knowledge and experiences, and we remain committed to it. Capacity building is a key part of our national cyber diplomacy policy. For us, it is very important to make sure that we take full advantage of the existing capacity building formats and platforms, like the Global Forum on Cyber Expertise, in a coordinated and collaborative manner. As a principle, we need to make sure that we do everything to avoid duplication and inefficiency in our efforts. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, Estonia, for your statement. It’s exactly one o’clock, and I think we need to break now. I wanted to share with you that I have a speakers list with requests from more than 30 delegations. I welcome certainly the interest of delegations to take the floor. We will continue with the speakers list this afternoon, but I wanted to point out that most of the delegations that have asked for the floor are also delegations that have already spoken once or at least once, and so it’s possible that we might be able to complete the speakers list this afternoon. This afternoon we will start with the UK, to be followed by Peru, the United States, Israel, and Romania as the first five speakers. UK, Peru, USA, Israel, and Romania as the first five speakers. And I also wanted to say that this afternoon we will also begin, in accordance with our program of work, the discussions on sections relating to regular institutional dialogue as well as capacity building. Some of you have already addressed the sections relating to capacity building this morning. We will continue with that this afternoon. So, in other words, this afternoon we will cover the entirety of the draft document before us, and delegations which are intervening are invited to comment on any aspect of the draft, but keeping in mind the need to be succinct and where your views have already been expressed to focus on issues which are not yet addressed. So, I look forward to hearing your views this afternoon. The meeting is now adjourned. Thank you.
Leave a Reply