Ambassador Gafoor
Good afternoon, everyone. The fourth meeting of the fourth substantive session of the Open-Ended Working Group on Security of and in the Use of ICT, 2021-2025, established pursuant to GA resolution 75/240 of 31 December 2020, is now called to order. The Working Group shall now continue its consideration of Agenda Item 5 to hear the remaining speakers from this morning on the issue of rules, norms, and principles of responsible behavior of states. We will continue with the speakers list. We have about 15 speakers, and after we have exhausted the list of speakers on this item, it is my intention to move on to the next item on our agenda, which is international law. And we hope to do that this afternoon. So the first speaker for this afternoon is El Salvador, to be followed by Ireland. El Salvador, you have the floor.
El Salvador
Mr. Chairman, regarding the discussion on the proposals in the Chairman’s Summary of the Working Group for 2021, El Salvador would like to highlight the following. As we have stated in previous sessions of the Working Group, the Voluntary Framework for Responsible Behavior by States in Cyberspace, in line with international law and the principles and purpose of the United Nations, is extremely important to prevent and de-escalate conflicts regarding ICTs and promotes a peaceful environment that allows for the use of these technologies to contribute to socioeconomic development. This is how my country has a draft bill on cybersecurity which takes up in general terms the norm for responsible behavior that is derived from the Group of Governmental Experts and endorsed by the Open-Ended Working Group 2021. The national guidelines highlight the need not to damage and protect critical infrastructure with the goal of enhancing capacity in cybersecurity and resilience that ensures that risks are minimized of digital services being not available. Also, there are efforts to prevent the undue use of ICTs on our territory and also to prevent and mitigate their malicious use. Due to this, we believe it is critical to further develop norms, existing norms, and rules in response to your question on actions to develop this discussion, perhaps to promote a guide or orientations on how to make these norms more operational as France suggested for specific norms. This could be through an exchange of good practices or lessons learned on implementation. We also welcome the proposal to share national definitions on the technical terms used in the ICT environment that could contribute to mutual understanding. In addition, we’d like to reiterate the need to strengthen cooperation and assistance to ensure the integrity of global supply chains because, as was stated in the previous session, in a closely interconnected world, the disruptions in one point of the global supply chain affect others in a way that cannot be predicted. With regard to the exchange of good practices, we welcome the suggestion to have these exchanges of views in the framework of managing risks in the supply chain. For example, the program of security in the supply chain of the inter-American – of the Organization of American States has good practices in risk management security in this area. In addition, partnership with various multistakeholders and the private sector is very important. Lastly, I would endorse what Argentina has said in highlighting the work of the Organization of American States. Its work at the regional level makes it possible to confront cyber threats. El Salvador encourages continuing and deepening these regional efforts that make it possible for us to further push the implementation of rules and principles. The speaker did not provide a statement.
Ambassador Gafoor
Thank you very much, El Salvador. Ireland, followed by Switzerland. Ireland, please.
Ireland
Thank you, Chair. To begin, Ireland fully aligns itself with the comments made earlier by the EU and would like to make some additional comments in our national capacity. Chair, echoing the earlier statement made by Costa Rica, we must ensure that the maintenance of international peace and security in cyberspace is rooted in human-centric and value-based principles. This is the only way of ensuring that we achieve a safe, secure, and accessible cyberspace, where human rights and fundamental freedoms apply both online and offline. At a national level, Ireland is committed to this through the development of strategies and policies for cyber and new and emerging technologies that are people-centered and promote an ethical approach to the development, adoption, and use of these technologies. Importantly, we also believe it is crucial to ensure the voices of women are fully recognized as we address the digital gender gap and implement agreed cyber norms. In particular, we wish to draw attention to the valuable work of civil society in bridging this gender divide in cybersecurity. For example, Cyber Women Ireland encourages more women to pursue careers in cybersecurity by the use of role models and providing mentorship programs. At an international level, Cyber Women Ireland welcomes partners and collaboration with cyber women groups worldwide. Chair, echoing the Netherlands’ statement, Ireland places considerable importance on the Program of Action as a means to promote capacity building in a structured and sustainable manner. As referenced by the EU, a key objective of the POA will be to assist in the implementation of agreed cyber norms and recommendations, as well as to support states in their national implementation efforts, mainly through capacity building. It is our firm view that capacity building, such as envisaged in the POA, constitutes the practical foundation to implement the UN framework for responsible state behavior in cyberspace. Chair, in response to your guiding question and facilitating deeper discussions, we wish to highlight that, as the substance of the POA is developed, it is crucial that it is done so in an inclusive manner and that there is an opportunity for relevant regional organizations, whose members are also members of the United Nations, to contribute to its consultation process. Ireland strongly supports this approach, as it provides the opportunity for detailed considerations of rules, norms, and principles in a regional setting. Such consultations will undoubtedly enrich the General Assembly’s consideration of the future of the POA through fostering a deeper understanding of regional perspectives. Thank you.
Ambassador Gafoor
Thank you, Ireland. Switzerland to be followed by India.
Switzerland
Thank you, Mr. Chair. Switzerland would like to point out that the fact that international law applies in cyberspace is part of the overall framework for responsible state behavior in cyberspace developed and reaffirmed by the GGEs and Open-Ended Working Group in 2021 and endorsed by all states in the General Assembly. This is the basis for our work in this Open-Ended Working Group. As expressed in previous sessions of this Open-Ended Working Group, it is Switzerland’s position that we currently do not see the need for a new legally binding instrument. This would be premature. At this point, as proposed in our concept paper, we should continue our work on developing common understandings on the application of existing international law in cyberspace. The process of interpreting and applying the rules of international law to a particular set of facts is a common practice and a standard procedure in international law. It is important to emphasize that it does not mean we must question the rules as such. We will say more on this as a part of the focused discussions on international law in the next agenda point. Regarding your guiding questions, Switzerland is of the opinion that at the moment we should focus on better understanding, promoting, and implementing the existing 11 norms before developing new ones. The 2021 GGE report provides a good basis for this. It lists the norms and provides further guidance on how to implement them. As in the other areas of the framework on good governance, private actors can play an important role. This does not exclude that we could develop new norms over time where useful or needed. When considering norms implementation, it is important to highlight that the norms don’t exist in a legal vacuum. In the consensus report of the previous Open-Ended Working Group, states reaffirmed that norms do not replace or alter states’ obligations or rights under international law, which are binding, but rather provide additional specific guidance on what constitutes responsible state behavior in the use of ICTs. Norms do not seek to limit or prohibit action that is otherwise consistent with international law. International law is, in this sense, our traffic law, and the voluntary norms provide guidance to help us to respect it. Switzerland supports the recommendation of the Annual Progress Report that states should survey and report their progress in norms implementation via the report of the Secretary-General on ICTs or the National Survey of Implementation. Recent cyber incidents and the actual geopolitical situation have shown that the protection of critical infrastructures becomes ever more important. Unfortunately, attacks on critical infrastructure by malicious states and non-state actors have increased excessively in recent years. Of particular concern are attacks by states and non-state actors on medical and research facilities and humanitarian actors, as well as cyber attacks in the framework of the ongoing armed conflict in Ukraine, in particular if directed against critical infrastructure. The potential for unintended or spillover effects has thus increased. Attacks of this nature can pose a serious threat to international security and peace. Regarding existing norms that could be further examined, Switzerland therefore would see merit in focusing on norms 13C, F, G, and H, calling for the protection of all critical infrastructure, supporting essential services to the public, in particular medical and healthcare facilities, as well as cooperation between states for this purpose. We thank the Netherlands as well as France for the announced working papers and will be happy to discuss these topics in more depth. Switzerland also advocates for providing explanatory guidance on attribution. More states attribute cyber incidents publicly in recent times. Attribution is a result of a process that takes into account a range of factors and information that would allow victim states to assess malicious cyber activities. These factors could include, inter alia, the larger geopolitical context, diplomatic relations between the involved states, economic and political relations, and interests. Because attribution is a complex task, taking these factors into account becomes all the more vital. Switzerland therefore proposes to further develop norm 13B. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you. Switzerland. India. To be followed by the United States. India, please.
India
Thank you, Mr. Chair. The 11 voluntary non-binding norms of responsible state behavior can reduce risks to international peace, security, and stability, and play an important role in increasing predictability and reducing risks, thus contributing to the prevention of conflict. With an increasing number of threats and potential risks to critical infrastructure emanating from the use of new and emerging technologies and associated risks, this provides a guiding roadmap in ensuring stability and security in the use of ICTs. India views the existing normative framework with broad interconnectedness with the rest of the pillars of the OEWG mandate. The norms in the existing form need a complementary framework outlining the mechanisms of cooperation, information exchange, trust-building initiatives, sharing best practices to protect critical infrastructure, and to form malicious ICT activity monitoring mechanisms. The use of ICTs, Mr. Chair, by non-state actors for terrorist and criminal purposes needs to be reported to the state that malicious activity is directed in order to take appropriate measures. OEWG may further discuss the deep interconnected nature of these norms to build a comprehensive understanding of the essential cooperation elements between member states. In this regard, Mr. Chair, during the previous substantive sessions of the Working Group, India underlined certain aspects that would take forward the discussion on the implementation of the normative framework. In the present session, we would like to put forward that developing and small countries need capacity improvement for responding to the operationalization of the existing normative framework. For instance, we would like to underline that a member state may need to have a minimum cyber preparedness level to respond to the obligations set by the normative framework. The normative framework, as the existing norms put, an obligation on the member states to respond or inform or prevent cyber incidents and threats emanating from one’s national ICT landscape. We are especially referring to Norms 13G, H, I, and J. We fully appreciate the merit and support the intention of these norms to mitigate misunderstandings and reduce unpredictability. To meet the expectations set by these norms, Mr. Chair, it is essential for a member state to have a functioning national computer emergency response team, cyber security legislation, a vibrant private sector, availability of a skilled technical cyber workforce, and academic programs on cyber to impart new skills to the available and emerging workforce to consider implementation of the normative framework. India strongly recommends that the minimum cyber preparedness aspect must be given due importance as it gets the working group to look at the working-level details that we need to focus on while discussing the normative framework, in particular on elaborating further on these individual norms. This helps in creating sustainable practices for the operationalization of the existing normative framework. In addition, CBMs and capacity building are the two key areas that encourage member states to cooperate with each other in practical ways with respect to extending further cooperation on the existing normative framework. OEWG can discuss the initiatives to enhance the capacities of the member states that enable them to prepare for taking appropriate measures whenever information of malicious activity or ICT supply chain vulnerabilities are reported. This working group must consider building an additional layer of understanding on the existing norms, rules, and principles that form the basis for responsible behavior of states and may develop additional norms, rules, and principles on a need basis. For practical adoption of a normative framework, it is necessary for OEWG to discuss the basic mechanisms of information exchange, sharing best practices, and enhancement of capacities, computer emergency response teams at the national level. Mr. Chair, in the previous GGE and OEWG final reports, it was mentioned that states were called upon to avoid and refrain from the use of ICTs not in line with the norms of responsible state behavior. While the use of ICTs by non-state actors for terrorist and criminal purposes itself is a threat, that can result in a significant risk to critical infrastructure. The state’s use of harmful ICT activities may pose a significant risk to international security. The use of cloud ICT infrastructure for such harmful practices by member states targeting other member states causes transnational conflicts, undermining international peace and security. OEWG needs to discuss the fine elements incorporated in each of these 11 voluntary non-binding norms for realizing the full potential they offer to member states through cooperation and dialogue in ensuring the stability of ICT-dependent infrastructure. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you, India, for your statement. United States, followed by Czechia. U.S., please.
United States
Thank you, Chair. UN member states have made a global political commitment to the framework through their consensus endorsements of the GGE and OEWG reports, which include a robust set of peacetime norms. Since the norms were first adopted, we have sought to deepen understanding of their purpose and encourage states to adhere to them, not just by signing onto statements, but in their actions. As we confront new and emerging threats, our existing norms can provide guidance. These norms were designed to be technology-neutral, broadly applicable, and flexible, and have so far proven valuable to address emerging challenges, such as threats to election and healthcare systems and the rise of ransomware. However, there is room for the OEWG to go further on how these norms can be implemented. We remain interested in the exploration of norms implementation checklists, as raised by Singapore and others, and look forward to discussing it further. We also support the approaches proposed by Canada, France, and others, to focus the OEWG’s upcoming work on some key norms from our framework. We are particularly interested in exploring those norms addressing critical infrastructure and those covering cooperation in response to significant cyber incidents. This issue-oriented approach is practical, and a focus on critical infrastructure and cooperation in particular is very relevant, given the concerns states raised in the discussion on current and emerging cyber threats. We also recognize that some states need capacity-building to fully implement these and other norms. We welcome further discussion within this forum on how capacity-building measures can contribute to this implementation, as we recognize global adherence to these norms is in all states’ interests. In response to the comments from the delegate from Russia, UN member states have repeatedly confirmed by consensus that existing international law applies to state conduct in cyberspace. We’ve seen in recent years great development in the discourse on international law, and a lot of careful consideration from member states on how international law applies in this context. We look forward to continuing that robust discussion within the international law agenda item. We are currently discussing norms, which, as the Russian delegate pointed out, are non-binding. But their repeated endorsement as political commitments in no way undermines their usefulness in addressing the issues we face. On the contrary, the fact that they have received such strong and consistent support only underscores the unity of will among member states to act responsibly in cyberspace and highlights the need to implement these norms to fully realize their power. Of course, norms are intended to complement, not replace, the fulsome existing legal regime that governs state behavior, which is addressed in the international law sections of the OEWG and GGE reports. In addition, we fully support the comments from Sri Lanka and others that we must reach a common understanding on how existing law applies before we can consider whether any new rules are necessary. Indeed, any effort to reimagine international law and establish different rules in the cyber context risks creating destabilizing confusion and significantly delaying the goal of achieving greater common understanding. The fact that the cyber threat landscape continues to evolve is exactly the reason why a lengthy treaty process is not the right way to address these threats. Treaties take a long time to negotiate, and states cannot create new treaty provisions every time a new threat emerges. States can better address the threats we face by thinking through how the norms and existing law should be interpreted to apply to the threats as they emerge. The whole point of norms and law is that they provide a framework for responsible behavior, regardless of the specifics of the technology that is in question in any particular situation. We are particularly concerned by the Russian delegate’s suggestion that until a new legally binding document is concluded, states will be foreclosed from discussing accountability for actions that might be in violation of international law. The argument that existing international law is insufficient, and therefore cyberspace is and will remain a lawless zone until a treaty negotiation has concluded, is self-serving and risks undermining international peace and security. Thank you, Chair.
Ambassador Gafoor
Thank you, United States, for your statement. Czechia to be followed by Japan. Czechia, please.
Czech Republic
Thank you, Mr. Chair. The Czech Republic aligns itself with the EU statement delivered earlier and wishes to emphasize a couple of points in its national capacity. The Czech Republic considers rules, norms, and principles of responsible state behavior in cyberspace as a means to achieve greater stability and predictability of cyberspace. As recognized in the UN GGE reports of 2010, 2013, 2015, and 2021, and also the Consensus Report of the previous Open-Ended Working Group, they reduce risk to international peace, security, and stability. Our top priority is the implementation of the already established 11 norms of responsible state behavior unanimously endorsed by the UN General Assembly. In this context, I would like to support the intervention of Sri Lanka, Canada, Germany, Switzerland, and many other countries that there is no need to develop a new legally binding instrument, and we should rather focus on discussion on how the existing international law applies to cyberspace to target potential gaps in common understanding of its applicability. But we will discuss this issue later in the next block. As for the 11 norms of responsible state behavior, they are closely linked to capacity building because compliance in practice requires a high level of cybersecurity expertise. At the same time, we are convinced that working with the broadest possible range of state and non-state experts will enhance the implementation of the norms. In the past, we have been working intensively in cooperation with the private and non-governmental sector in the area of protection of the health sector. Today, we would like to focus on two areas. We are of the opinion that they deserve the attention of the Open-Ended Working Group. First of all, we would like to focus on supply chain security. Some countries mentioned it already yesterday during the discussion on existing and potential threats. They argued that cyber operations attacking the supply chain can cause significant damage and pose a threat. The Open-Ended Working Group has to deal with this. We fully support this argument. The issue is important also from the perspective of implementing the concrete norm of the 2015 GGE report, which recommends that states should take reasonable steps to ensure the integrity of the supply chain so that end users can have confidence in the security of its ICT products. Our lives are increasingly dependent on ICT products and services, as is our critical infrastructure. We must be able to trust the ICT we integrate into our daily lives. Highly impactful and sophisticated supply chain attacks such as SolarWinds are detrimental to attaining this trust, and we think that there is a need to address these threats appropriately through our policies and cooperation at national, regional, and most importantly, global levels with the involvement of all actors, including stakeholders. The Czech Republic is especially concerned with the risks and threats posed by emerging disruptive technologies. It is here that we see particularly great potential for further discussion on the implementation of the framework of responsible state behavior in cyberspace. It is fully consistent with the last consensually agreed annual progress report that specifies that states should continue to develop guidance and/or checklists on further implementation and elaboration of the framework. The need to ensure supply chain security is one of the pressing challenges that should inform this process. We encourage further discussion on developing these norms with a focus on the responsible behavior of suppliers and their assessment based on their respect for the rule of law, human rights, and democratic values. This, in particular, applies to the suppliers of critical infrastructure. The second area I would like to mention is the misuse of new technologies for human rights abuses explicitly. I spoke about this in a rather detailed way yesterday, also in the context of current and new threats. Today, I would like to draw our attention to the norm of the 2015 GGE report, which stipulates that states, in assuring the secure use of ICT, should respect Human Rights Council resolutions on the promotion, protection, and enjoyment of human rights on the internet, as well as General Assembly resolutions on the right of privacy in the digital age, the guarantee for respect for human rights, including the right to freedom of expression. The Czech Republic considers further discussion on the implementation of this norm as extremely important in the context of international peace and stability. We should actively promote universal human rights and fundamental freedoms, the rule of law, and democratic principles in the digital space, and advance a human-centric approach to digital technologies. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you, Czechia. Japan, to be followed by Ghana. Japan, please.
Japan
Thank you, Chair. Japan is of the view that norms of responsible state behavior are important and valuable as they contribute to reducing risks to international peace, security, and stability. Given the current state of cyberspace, we should focus our efforts on deepening the understanding and implementing the agreed 11 norms of responsible state behavior among all the member states. In this regard, we welcome the guidance on norms proposed by Canada and the checklist idea proposed by Singapore, which would facilitate member states to put the norms into practice. As Canada and others have stated, at this stage we do not believe there is a need for new additional norms. As for international law, which is the topic of the next agenda item, Japan would also like to join other delegations in stating that there is no need to develop a new legally binding instrument. We’d like to reiterate our position that existing international law, including the United Nations Charter in its entirety, is applicable to cyber operations. As Singapore, the Netherlands, India, and others have stated, capacity building efforts are important. In this regard, the Japan International Cooperation Agency (JICA) provides capacity building projects on policy formation for ensuring cyber security. As Canada, Peru, Singapore, the Netherlands, El Salvador, Switzerland, the U.S., and others stated, the protection of critical infrastructure has increased in importance, and the implementation of relevant norms is essential. The norm 13G stipulated that states should take appropriate measures to protect their critical infrastructure from ICT threats. In terms of implementation of this norm, Japan has designated 14 sectors of critical infrastructure with relevant regulatory ministries responsible for overseeing safety standards and incident reporting. I would like to note that multistakeholder collaboration is essential for protecting critical infrastructures, most of which are operated by private operators. This is an example of Japan’s efforts to put one of the norms into practice. It would be meaningful to exchange national practices and efforts of member states regarding their policies, legal frameworks, and various guidelines. Thank you, Chair.
Ambassador Gafoor
Thank you, Japan. Ghana, to be followed by Uruguay. Ghana, please.
Ghana
Mr. Chair, as highlighted by my delegation during the third substantive session, Ghana particularly supports the inclusion of recommended Next Steps 3 under the section on Rules, Norms, and Principles of Responsible States’ Behaviour on the need for states to consider surveying or reporting on their national implementation of Rules, Norms, and Principles of Responsible States’ Behaviour on a voluntary basis using existing avenues and tools like the National Way of Implementation. My delegation maintains that the exchange of information among states is crucial for maintaining stability and security in the use of information and communication technologies. To enhance this, there is a need to improve best practices and collaboration on information exchange, including the sharing of information on vulnerability disclosure, the protection of critical infrastructure, and cooperation between computer emergency response teams. Mr. Chair, Ghana believes that platforms like the OEWG session help to build on the capacities needed to bolster states’ understanding of how international law applies in the use of ICTs through the exchange of ideas and cooperation on finding solutions to divergent areas. This engagement and capacity-building effort needs to be multi-sectoral and also take place among the private sector, academia, and civil society. Furthermore, capacity-building efforts on the applicability of international law in cyberspace can be further strengthened in developing countries through workshops and training such as those offered by institutions like the GFCE and efforts like the Women in Cyber Fellowship, both of which Ghana is a part of, to enhance the understanding of the applicability of international law across member states. Regarding the Chair’s guiding questions under this section, on the proposals and next to the summary of the 2021 OEWG report, which should be further developed in order to incorporate it into further annual progress reports, Ghana supports a proposal calling for states to consider, as appropriate, sharing information on best practices for protecting CII, including baseline security requirements, incident notification procedures, incident handling tools and methodologies, emergency resilience, and lessons learned from previous incidents. Mr. Chair, Ghana is of the view that this proposal should be incorporated into the future annual progress report. Considering this, Ghana holds that the protection of CII should be urgently examined in the context of developing guidance or checklists. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you, Gana. Uruguay to be followed by Mauritius. Uruguay, please.
Uruguay
Thank you very much, Mr. Chairman. Technological developments must be accompanied by solid institutions, a framework recognizing human rights, and the building of secure environments as society shares obligations but also rights. The implementation of the normative framework should be conducted in a coordinated way, taking into account various opinions based on a focus on human beings. Bearing that in mind, our country has proposed a Uruguay digital agenda. Now, we cooperate with all stakeholders. For us, digital transformation goes hand-in-hand with ensuring security. This is why it’s important to put priority on administrative improvements and exchange of information. Mr. Chairman, my delegation considers that in adapting regulatory frameworks, we must put emphasis on accessibility, protection of data, security, and transparency, thus promoting adherence to international standards. Once again, the speaker did not provide a text.
Ambassador Gafoor
Uruguay, thank you very much. Once again, I’d like to encourage delegations to share your text with the interpreters. They’ve asked several times, and I hope that you can help them by sharing your statements. Mauritius, to be followed by Israel. Mauritius, please.
Mauritius
Thank you for giving me the floor, Chair. Chair, distinguished delegates, I will try to be as concise and succinct as possible in my statement. As stated by many delegations, although norms do not prevail over international law and are not aimed at prohibiting bad actors in their malicious deliberations, it is crucial to establish a commonly accepted standard of behavior in the use of ICTs. Mauritius reaffirms that regional organizations play a central role in supporting the establishment and implementation of the existing normative framework, and also in empowering countries and raising awareness in this area. Mauritius fully aligns itself with statements made by Canada and others regarding checklists and guidance to facilitate developing common understandings on rules, norms, and principles of responsible state behavior in the use of ICTs. It is equally of paramount importance to recognize the crucial role that CERT or CSIRT teams play in promoting compliance with norms of responsible state behavior and CBMs. Mauritius wishes to underscore that Africa CERT has recently established a working group with the aim of becoming a coordination point for the CERT community and developing a strategy as regards the implementation of norms and CBMs. The working group, officially known as the Working Group on Norms and Confidence Building Measures in Cyberspace, was announced in the first Africa CERT symposium held in Kigali from the 28th of February to the 3rd of March 2023. At the onset, the group aims to identify the most effective ways of promoting the adoption and integration of norms and CBMs into the practices and policies of the CERT community and establish a system for monitoring and measuring the implementation of norms within the community and evaluating its effectiveness. Before ending, let me point out that we remain open to further discussions on this topic. Thank you, Chair.
Ambassador Gafoor
Thank you, Mauritius. Israel, to be followed by Nicaragua. Israel, please.
Israel
Mr. Chair, thank you for giving us the floor to comment on the very important issue of norms, rules, and principles. I will do my best to be very concise. Answering your guiding question, at this point in time, there is no need, in our opinion, to develop or elaborate new norms, nor do we see a need for developing any legally binding instrument. Israel believes that a more cautious approach with respect to norms is required. As things currently stand, there is still a lack of certainty as to the manner in which existing norms are being implemented and interpreted by States. The 2015 GGE norms are voluntary and non-binding and do not detract from or extend beyond international law. Thus, norms are intended to signal expectations of the international community regarding appropriate State behavior, and from what we have seen thus far, their implementation has been at best uneven. Mr. Chair, before embarking on any process of updating the existing norms or developing new norms, it would be more appropriate, in Israel’s view, to focus on those norms that currently exist, assessing whether and how they are being understood and applied, ensuring that there exists a common language and understanding when referring to these norms. Once this is done, we as a community can begin to consider where the need is more actually felt, whether it is an issue with the current norm, lack of clarity, or whether the original norm itself should be reconsidered. Informed by this approach, only then, in our view, can we assess whether there exists a need for additional norms. Thank you, Chair.
Ambassador Gafoor
Thank you. Israel, Nicaragua, to be followed by Kenya.
Nicaragua
Thank you, Mr. Chairman. One of the main tasks of our working group is to formulate a normative framework that is adequate and modern to regulate challenges in the area of security and the use of information and communication technologies. It has been demonstrated throughout our discussions that voluntary and non-binding norms of behavior that exist, even though they are a positive step in effectively regulating the use of the ICTs, are not sufficient. This is why, from the very beginning of this working group, we have advocated for a legally binding instrument that regulates such behavior. This has been our ultimate goal. To achieve that goal, we should adhere to the priority mandate granted by resolution 75/240 of the General Assembly for the elaboration of rules and norms for responsible behavior by States and the elaboration of additional rules of behavior. We therefore believe that one of the main aspects that we should take into account in our work are the proposals of new norms proposed by Member States in the annex to the Chair’s report of the GTCA 2021. Our delegation endorses the proposal of a convention by the United Nations on security guarantees proposed by the Russian Federation. We agree that any draft convention should be structured, should take place under the auspices of the United Nations, and should reflect the proposals of all delegations. We would like to reaffirm that the purpose of the norms is to ensure an environment conducive to international cooperation and understanding where all can benefit in line with the purposes and principles of the Charter. It will be essential to adopt norms that prevent the militarization and politicization of cyberspace, and also prevent the imposition of unilateral coercive measures. Norms should also take into account different conditions and responsibilities in development and in the technological level of countries and between developed and developing countries. Thank you very much, Mr. Chairman.
Ambassador Gafoor
Thank you, Nicaragua. Kenya to be followed by Romania. Kenya, please.
Kenya
Thank you, Chair. Kenya continues in its efforts to domesticate the rules, norms, and principles of responsible behavior of states through the enactment of laws and regulations in alignment with our constitution. We remain focused on the protection of critical information infrastructure and have developed a critical infrastructure index for which we are in the process of developing regulations that shall guide its management, including how threats and incidents are addressed. On the Chair’s question on elaboration of the list of proposals annexed to the Chair’s summary in the 2021 OEWG report, Kenya welcomes such elaboration as a way of building a common understanding among states. In keeping with previous state initiatives of conducting norm implementation checklist workshops, we propose the setting up of work groups within the OEWG to share best practices on how existing rules, norms, and principles have been contextualized and translated to national policies. These, we believe, will enhance the implementation of the agreed normative framework. States should also be encouraged to voluntarily submit and/or report on their national efforts to implement rules, norms, and principles through the national survey of implementation and the report of the Secretary-General on developments in the field of ICTs in the context of international security. The national survey of implementation may then form a basis for discussions with the aim to create understanding and achieve consensus. On proposals requiring further elaboration, including the definition of critical infrastructure and critical information infrastructure, this should be left under the purview of states in consideration of the different contexts, capacities, and priorities each state has in the cyber domain. I thank you, Chair.
Ambassador Gafoor
Thank you very much, Kenya. Romania, please.
Romania
Thank you, Chair. My delegation is fully aligned with the EU statement. My comments in my national capacity are as follows. The 11 voluntary norms agreed by consensus within the GGE and previous Open-Ended Working Group negotiations on the topic reflect the legitimate expectations of the international community on the responsible nature of state conduct in cyberspace. Having been agreed by consensus and endorsed by member states of the United Nations, they constitute an acquis, to which the benefits of information and telecommunication technologies can be maximized without endangering international peace and security. Respecting the norms reveals the express intent of states to not endanger international peace and security, and this is what we call responsible conduct in international relations in regards to cyberspace. It is clear that by their nature, content, and role, the norms do not contradict and do not limit the obligations applicable to states under international law. They constitute particular instances of political commitment, endorsed by the entirety of the United Nations, on the type of conduct required in order not to endanger one another among states within the framework of international law, in the context of the emergence of cyberspace as a domain of interaction among states. Respecting international law is the basis of the commitment of the member states of the United Nations to avoid conflict and maintain international peace and security. The domain within which this commitment is manifested produces no effects on the nature or objectives of the commitment. This is because arbitrary behavior and the illegitimate use of force, which run contrary to international law, are triggers of conflict within any domain. Consequently, although they refer to cyberspace, norms are premised on the absence of any distinction between the legal obligations applicable to states within and outside cyberspace. Respecting the norms of responsible state conduct in cyberspace, premised on the full applicability of international law, is, as I said, the core indicator of the commitment of states to preserving international peace and security within the framework of the rule-based international order. But also, very importantly, Mr. Chair, this is also the basis of their legitimacy in their approach to shaping this order. States finding themselves in outright violation of this framework of responsible state conduct and of the basic principles of the United Nations do not carry the legitimacy of a norm or rule setter in this assembly. They have lost this right at the moment of their inexcusable and flagrant breach. This is similar to any other domain subject to law. Individuals in flagrant breach of national laws are not legitimate voices and ask for it to change in order to let them off the hook, although in practice they often are seen to claim that the law as applied to them is somehow not good. Conversations on the nature and evolution of the acquis are indeed legitimate and might be justly conducted as they have always been among equal subjects of international law, which recognize themselves as such, which respect each other as such, and which are responsible members of this system of international relations under the minimal requirement of holding an intention to preserve international peace and security, an intention which is presumed until proven otherwise. My delegation remains consistent in the trust it places upon the members of this assembly to manifest extreme caution in relation to any contrary intentions. Such intentions do nothing more than fundamentally compromise the consensual nature of evolving the acquis, which has been a feature of our work for decades, and they are completely arbitrary and serve no purposes other than those of the United Nations. We are responsible members of this international community and we must be collectively committed to safeguarding the proven nature of this responsibility. Thank you.
Ambassador Gafoor
Thank you, Romania. Mexico, followed by the UK.
Mexico
Thank you very much, Mr. Chairman. My delegation would like to express our gratitude for the efforts of you and your team throughout this process of substantive sessions. Mexico attaches significant importance to the work of the Open-Ended Working Group (OEWG) and welcomes the holding of this fourth substantive session of the group as a reaffirmation of the importance of multilateralism to address the challenges and opportunities offered by information and communication technologies and cyberspace in the framework of international security. For my country, it’s very important to include a subsection dedicated to the implementation of international law to cyberspace, as well as an appeal to states to focus discussions on the gaps in understanding of how international law is applicable to this dimension. Now, what has had great resonance in various multilateral forums is the statement that international law is applicable to cyberspace and to the use of information technologies. It is practically universal, and it is endorsed by various stakeholders such as the academic sphere, industry, and civil society. As we see it, an essential point is for the Open-Ended Working Group to serve as a catalyst for the implementation of prior agreements. For my country, the reference to international law implies not only the United Nations Charter but also points to the implementation of international human rights law and international humanitarian law. This is why we believe it would be a good idea to take as a starting point the reports of the Group of Governmental Experts (GGE) and the final report of the first Open-Ended Working Group. Therefore, Mexico would like to see reflected with specific mentions the topic of the applicability of international humanitarian law and its principles. This is why we are in favor of a more in-depth study of how international humanitarian law can be applied in cyberspace and for the use of ICTs. As has been mentioned at various opportunities during the meetings of the International Committee of the Red Cross, we agree that international humanitarian law does not authorize or acquiesce to conflicts, but rather represents a way of avoiding suffering by humans in case of conflicts. As has been mentioned by various delegations, Mexico also insists on the importance of promoting in a very concrete way the implementation of agreements that then generate reports on the advances and obstacles or challenges. This will make it possible to define new frameworks of discussion to make progress toward solutions or compilation of best practices. This will make it possible to define concrete examples of implementation that could be replicated once they are adapted to national realities. From a broader point of view, this exercise of ensuring visibility to the status of implementation will make it possible to identify specific needs of cooperation and thus generate true synergy and coherence between cooperation and capacity building. I’d like to conclude by underscoring the importance of the role that regional organizations play in implementing the commitments and developments achieved at the level of the United Nations, but also as platforms that make it possible to identify and analyze national experiences, common problems, and concerns that could and should feed back into the discussions in the framework of this working group. Thank you very much.
Ambassador Gafoor
Thank you, Mexico. UK to be followed by Australia. UK, please.
United Kingdom
Chair, what we’ve heard in this session calls for new norms, rules, and principles. The United Kingdom’s priority is to support states to implement the norms currently agreed under the UN framework. As our colleague from South Africa said, there’s a lot still to do to promote awareness of the norms and to operationalize them. It is our view that this should be our priority. We have collectively agreed that international law applies in cyberspace, and the United Kingdom believes that existing international law is sufficient to maintain stability. We therefore do not believe that there is a need for a new binding instrument, and we will further outline our position on international law in the next session. Chair, regarding your guiding questions, we believe there are ample opportunities for further progress on the alignment of capacity building efforts with an understanding of existing and emerging threats and the agreed UN framework. Such an approach would tackle many of the issues described in the threat session this week. I’ll focus my intervention on two norms: the norm to prevent critical infrastructure and the norm that states should not knowingly allow their territory to be used for internationally wrongful acts using ICTs. In doing so, I build on earlier comments by colleagues from South Africa, Peru, the Netherlands, Costa Rica, and others. It’s clear from our discussions today that there is a desire to go further and deeper on issues relating to the norm to protect critical national infrastructure. We value the work led by Canada to provide greater detail on this norm and others, and we hope that the OEWG can include further such detail in its annual progress report. We raised the threat of spillover effects in the threat session, and so we also welcome work by the Netherlands to provide further guidance to protect critical infrastructure from such effects. For our own part, last May the then Attorney General of the United Kingdom described types of cyber activity against critical infrastructure that the UK believes could be unlawful. In doing so, we seek to help states avoid inadvertent or damaging escalations. In addition, our domestic National Cyber Security Centre has identified steps that can be taken by states to make themselves more resilient to the range of different cyber threats. I’ll highlight two. First, in the United Kingdom, our Cyber Aware campaign shares cyber security advice and guidance, including for critical national infrastructure organizations, so that they can better protect themselves. Second, our cyber assessment framework helps organizations assess and manage their cyber risk. We directly encourage its use by critical national infrastructure organizations and their regulators. Further details are available on the National Cyber Security Centre website. We also note interest from states in discussing the norm that states should prevent the misuse of ICTs in their territory. As with protecting critical infrastructure, states can take steps to improve their resilience and increase their ability to respond and recover from relevant incidents. Such activity can be covered by incident management processes delivered by both the government and the private sector. I’ve set out today the steps the United Kingdom has taken to clarify our understanding of international law and to share responsibility for norm implementation with additional organizations and with our private sector. We hope that over the course of this open-ended working group, we’ll see further steps to align capacity building efforts with an assessment of the threats and gaps in the implementation of the UN framework and further opportunities for private sector and multistakeholders to share their expertise in these areas too. Thank you, Chair.
Ambassador Gafoor
Thank you. UK, Australia, to be followed by Malaysia. Australia, please.
Australia
Thank you, Chair. In my intervention yesterday, I and many others spoke about the need to address threats potentially posed by new and emerging technology, and I just wanted to clarify because I think there might have been a little bit of confusion. I was proposing that we look at new technologies not in a vacuum. There are other forums more appropriate for some of those discussions, and what is relevant to our discussion here is how new technologies are being utilized by threat actors to increase the scale, scope, and effects of their malicious activity in cyberspace in a way that threatens peace and security. And yesterday, I and others spoke about the importance of understanding those threats because we consider it absolutely essential to assess those threats against our existing framework and our norms and how our norms can assist countries to address these emerging threats. Australia considers that we should not begin to develop new things if we don’t have a solid assessment and agreement about how our existing framework and our norms apply to new threats. We should not be putting the cart before the horse. Australia and many others have suggested that we include gendered impacts in our work throughout the framework. Violence against women and girls, which is increasingly prevalent online, is a significant human rights violation that causes harm by limiting women’s social, political, and economic participation. This includes behaviors such as abusers using tracking applications, monitoring internet search history, restricting access to passwords or account settings, or inflicting economic or emotional abuse. Where gender inequality and discrimination against women and girls exist, so too will inequality exist in access, use, and vulnerability to harms of cyberspace and critical technologies. We suggest that gendered impacts and proposals for implementation should be included in guidance and consideration of norm D on cooperating to address cybercrime, on norm E on ensuring respect for human rights in cyberspace, and in norm J on vulnerability reporting. Chair, you asked in your guiding questions about proposals for developing guidance and checklists to assist norm implementation. Australia can support the proposal from Canada that this group might consider developing guidance on how to implement the agreed norms and how the norms apply to particular circumstances and threats, building upon the norms guidance that has already been established and provided in the 2021 GGE report. We also note the projects by UNIDIR, ASPI (the Australian Strategic Policy Institute), and others that provide some guidance on minimum baselines for norms implementation by states. Australia is interested and potentially attracted by the proposal from South Africa for a roadmap towards implementation and the proposal and work of Singapore on a checklist of actions that states can take to implement the norms. We suggest that these proposals might be combined in our work into something that we can all work on together and that these proposals for guidance, checklists, and roadmaps provide concrete steps by which states can self-assess the implementation of the norms in accordance with the survey of national implementation, which is hosted upon the UNIDIR cyber policy portal. Chair and colleagues, this brings me to providing a few preliminary thoughts in response to some of the points that have been raised today by some delegations. First, I’m a little confused by some mentions of export control regimes in this forum. Australia supports addressing the development needs of countries and recognizes that increased access to technology can assist countries in improving their prosperity, security, and social cohesion and close the digital divide. The purpose of export controls is not to prevent states from gaining access to technology needed for sustainable development but to prevent the illegal transfer of sensitive technology which could pose a risk to international peace and stability. The agreed framework and acquis for which we base our work draw strength from its technology neutrality. We focus upon setting standards for behavior and use and not standards for technology, which is also a point I’d like to make regarding another issue. Several states have raised the use of cyber capabilities in support of military operations. Australia wants to emphasize here the importance of transparency because transparency breeds accountability, predictability, and stability. I want to emphasize that it’s not technologies themselves that are of concern; it is their misuse. Just as many states are exploring economic development opportunities of these technologies, countries are also exploring military applications of these technologies. In this regard, Australia highlights that if used responsibly, cyber capabilities can improve states’ compliance with their existing obligations and commitments. For example, military cyber tools can have highly discriminant results with limited effects on individuals and civilians. If used responsibly, they can be more discerning than kinetic weapons. This view does not disregard that there are risks. This is why we need to ensure compliance with norms and existing legal obligations to mitigate those risks because states’ activities in cyberspace are guided by the same rules as apply to military actions in the physical world. Deepening our understanding of responsible behavior is the focus of the work we have here, and the core concern which is relevant for the work of this group is the misuse of these technologies by states. It is not the technologies themselves. There was also a comment made that some countries don’t want to develop legally binding obligations in cyberspace. I think this might be a little bit misguided because we do have legally binding obligations in cyberspace. As many have already said today, we have all agreed and reaffirmed the application of existing international law, including the UN Charter, for states’ activities in cyberspace. And we’ll go further into the details of these existing legal obligations as part of our focus discussions recommended in our 2022 annual progress report under our next agenda item on international law. Australia would also like to respectfully build upon a proposition that was made by Canada that existing law and our agreed norms supported by CBMs and capacity building are sufficient to combat the threats we face to international peace and security in cyberspace. Australia agrees that this framework provides a solid foundation for all countries to counter these threats. The existing framework provides stability and independence in cyberspace for countries to determine their own future and their own economic development. However, I do want to make clear that we are not divorced from reality. We know that even while all states have agreed and committed to this framework by consensus, malicious cyber activity continues to be perpetrated against and by states. And our discussion yesterday demonstrates that we can do more work in this group on implementing that agreed framework. Because the framework, international law, norms, confidence-building measures, all supported by capacity building, is sufficient to counter the threats we face when it is implemented and when it is adhered to. Because there is no point in agreeing on rules if countries are not held accountable when those rules are intentionally broken. Chair, at the beginning of our discussions this morning, you mentioned that making updates and adding to our work is important to do without finger-pointing. And I want to build upon that theme. I found that this forum here can be inherently more sensitive than others. Because here we are talking about responsible and irresponsible behavior of states in a forum consisting of states. We’re all states here in this room, which adds a degree of immediacy and sensitivity to the discussions, which is not present in discussions on other topics, for example, cybercrime negotiations. Because in UN negotiations on combating cybercrime, we’re negotiating a way for states to work together to prevent and address cybercrime committed by individuals and criminal groups. In that forum, those whose behavior we are regulating are not in the room. And that’s not the case here in this open-ended working group. So in essence, I agree with you, Chair, that we have a difficult task before us. But I do believe we’re up to the job. And I want to emphasize that we should be focusing our work on the existing framework, its implementation, and guidance on how the framework and the norms provide a toolkit for states to address these emerging threats. Thank you, Chair.
Ambassador Gafoor
Thank you, Australia. Malaysia, to be followed by Algeria.
Malaysia
Thank you, Mr. Chair, for giving me the floor. Malaysia reaffirms that voluntary, non-binding norms can reduce risk to international peace, security, and stability. These norms add a supplementary layer of understanding with regards to the applicability of international law in cyberspace and set standards for responsible state behavior. There are significant aspects of the OEWG’s work and outcomes. Malaysia takes interest and would like to understand more on the suggestion of France on regulations of the private sector, which can help create a global risk-based approach in the development and acquisition of network-ready products and solutions. These may promote greater resiliency in the context of critical services. Malaysia shares the views of many others on the importance of protections of critical infrastructure. Malaysia supports Singapore’s statement that further attention is needed in relation to the protection of cross-border critical information infrastructure, as well as the protection of technical infrastructure essential to the general availability and integrity of the Internet. As highlighted by many Member States, capacity building is important in operationalizing the existing norms. In this regard, the development of the ASEAN Regional Action Plan on the implementation of norms serves as a link between specific norms and the capacity building needs of ASEAN Member States, as mentioned by Singapore. Malaysia supports the initiative on the norms implementation checklist, as well as the National Survey of Implementation. We also value the work by Canada on norms guidelines. For this, Malaysia supports Australia’s view to explore how to coordinate this initiative for a bigger positive impact. Finally, Malaysia appreciates the Netherlands’ elaborations on Norm 13C and supports the suggestion for the upcoming APR to recommend effective channels of communication and the POC directory as potential effective tools. Thank you, Chair. Thank you.
Ambassador Gafoor
Thank you, Mr. Chair. Algeria aligns itself with the statement delivered by the Non-Aligned Movement (NAM). We would like to emphasize the importance of capacity building and the need for a multistakeholder approach in addressing cyber security challenges. We also support the initiatives of the Global Forum on Cyber Expertise (GFCE) and the Program of Action. Thank you.
Algeria
Thank you, Mr. President. I’d also like to express my appreciation of the manner in which you are conducting our efforts to take our work forward. The principles regarding rules, norms, and policies according to what was adopted by the UN General Assembly for the course of 2010, 2013, 2015, and 2021, of the GGE, and in addition to the report 2021 of the OEWG, constitute a certain basis for multilateral efforts regarding information technology, information, and information technology. Regarding the recommendations of the OEWG, including the summary of the Chair, in addition to the implementation of the agreed norms, I believe that it is important to develop more rules and norms. This is because of the developing and increasing nature of the challenges and taking into consideration disputed issues that have not been settled yet in the relevant working groups. In this respect, developing new norms should not stop us from adopting new rules which will only complement the current rules in addition to more explanations about these new norms and rules or will develop additional norms and rules. These new norms and rules could deal with the emerging threats and challenges which we dealt with in the previous sessions of the OEWG. For example, the effects of AI (artificial intelligence), security, and information, in addition to developing needs of international cooperation and implementing them. We support what was expressed about the uses of negotiating an international legally binding instrument for cyber security which was adopted by the United Nations General Assembly and through which we can lay the international legal basis for the work agreed upon during the works of the previous sessions and to create an international instruction to face challenges to cyber security in addition to other matters including building capacities in a sustainable and effective manner. Thank you for the floor.
Ambassador Gafoor
Thank you very much, Algeria. Colombia, to be followed by Botswana, please.
Colombia
Mr. Chairman, with regard to the rules, norms, and principles of responsible behavior of states, which are the agreed existing basis at the international level, my delegation would like to share the following considerations. As we have agreed in the past, voluntary norms, non-binding norms of behavior can reduce risks to peace, security, and stability, and they play an important role in terms of predictability and reducing the risks of wrong interpretations. My delegation considers that before moving forward with proposals on new norms, we should consolidate understanding and implementation of existing frameworks. In monitoring the implementation, as well as the development of future normative frameworks, given the evolving character of cyberspace, with regard to any future proposals, it has to be consistent with the law and the purposes and principles of the UN Charter, including maintaining internet security, international humanitarian law, and human rights. Now, to the premise that we must advance in the development of common understandings in the implementation of rules, norms, and principles that are agreed, it is important to understand how they have been implemented at the national level, and to exchange experiences and practices, for example, through the peer review process. Also, it is important to understand regional efforts in the area, and the experience of partnerships with other stakeholders, such as the private sector and the technological community. We have heard valuable contributions by various delegations today, and on this, we consider that the updated document presented by Canada could be a good guide in implementation. Also, we greatly value the proposal of Singapore in elaborating a list of actions on capacity building for each one of the norms. We also agree with Switzerland on FGHA&E norms regarding critical infrastructure. These are the most important. Mr. Chairman, regarding monitoring the implementation of rules, norms, and principles, it is important to have a standing institutional mechanism that is inclusive and oriented towards action that makes it possible to ensure monitoring at the national, regional, and global levels. As we have stated previously, my delegation considers that the Program of Action could be an adequate mechanism for regular institutional dialogue regarding promoting a framework for responsible behavior, as well as to ensure cooperation for their collective implementation and to promote and discuss new developments. Obviously, this would include a section on the rules, norms, and principles. Lastly, I would like to reiterate that capacity building and cooperation on this point are essential for the implementation of the normative framework. We also agree with Australia on the importance of both incorporating a gender perspective as well as in its implementation. Thank you.
Ambassador Gafoor
Thank you, Colombia. Botswana, to be followed by Bangladesh, please.
Botswana
Thank you, Chair. Chair, we wish to express our gratitude for the impeccable work that you and the Secretariat are doing in an effort to meet the objectives of the OEWG, and Botswana offers its total support in furtherance of these efforts. Chair, the understanding of and the facilitation of the implementation of rules, norms, and principles of responsible state behavior in the use of ICTs, including on best practices, remains key and critical to the exchange of views on this platform. It goes without saying that states are expected, under international law, to adhere to the rules, norms, and principles of state behavior in their use of ICTs. As much as all states are vulnerable to malicious cyber attacks, all have the equal duty and responsibility to uphold the rules, norms, and principles of responsible state behavior in the use of ICTs. Chair, I would like to join many before us in highlighting the importance of having a common understanding of these rules and, similarly, a common minimum cyber preparedness, especially for small states, as was stated by India. This would assist member states in need to further their capabilities towards the normative framework implementation. A common understanding calls on member states to work with each other, to share information, and have regular dialogue, to develop a common understanding of the norms and the relevant actions to be undertaken, to make them a part of our legal systems. We believe the global points of contact will be instrumental in the exchange of information, and Botswana looks forward to its implementation. The Botswana delegation believes that the implementation of all the existing 11 norms should be at the forefront of our discussions, and ensuring that member states know and understand the modalities of implementation is to be done, as was highlighted by France. Out of the awareness of the varying degrees of capabilities of member states, the need for capacity building in this regard is required. Botswana agrees that states may continue to share national views on additional norms that could continue to be well-developed over time in the consideration of the evolving cyber landscape and ICT security environment. But this should not overtake the dialogue on the implementation of existing norms, and also that the additional norms should be a refinement of the existing ones, as was highlighted by South Africa. The basic capacities that Botswana believes are required to implement the normative framework for stability in cyberspace, as well as to strengthen cyber security, include financial support for extensive awareness-raising initiatives, targeted training for policymakers and legislators, enhancement of technical expertise on legal drafting, planning, and adoption of the necessary implementation actions. We align with Costa Rica that the implementation process should be inclusive of all stakeholders. Botswana knows that non-governmental stakeholders, such as the private sector, are critical because not only are they responsible for the implementation of these norms, but they are also owners of critical infrastructure. This should also address the gender dimension. States can be supported through a UN-based framework that facilitates the capacity building between member states and ensures focused and necessary capacity building. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you, Botswana. Bangladesh, to be followed by the Republic of Korea.
Bangladesh
Thank you, Mr. Chair. Bangladesh believes that maintaining international peace and security in cyberspace is a collective responsibility for all states. As the use of new and emerging technologies continues to increase, so do the vulnerabilities to malicious exploitation. In this context, norms would serve as a guiding framework for ensuring stability and security in the use of ICTs. By establishing clear standards and expectations, these norms can help mitigate the risk associated with emerging technologies and support a safe and more secure digital environment. We believe that states should start implementing the existing 11 rules, norms, and principles as the basis for responsible state behavior in cyberspace. The best way to put these norms into practice is through collective efforts by states to provide guidance on their interpretation and implementation. Therefore, like many other delegations, Bangladesh emphasizes that all states should have a common and comprehensive understanding of these norms. We support the proposal from Canada in this regard. Capacity building is of paramount importance in this regard. Developing countries are in critical need of support in order to develop the knowledge, skills, and resources necessary to effectively implement the normative framework in cyberspace. Bangladesh reaffirms the importance of regular information sharing between states on their experiences in implementing the rules, norms, and principles of responsible state behavior. In this regard, the global Program of Action (POA) would be an excellent step to start with. The group should discuss possible ways to enhance member states’ capacities to respond effectively with regard to the norms and basic mechanisms for information exchange. Bangladesh stresses the importance of implementing existing norms while additional norms may be developed on a needs basis. It should be seen as a continuous process of evaluating, updating, and recalibrating the norms rather than a one-time exercise. I thank you, Chair.
Ambassador Gafoor
Thank you, Bangladesh. Republic of Korea, please.
Republic of Korea
Thank you, Mr. Chair. My delegation is of the view that the key principles of the existing international law, including the UN Charter, International Humanitarian Law, and International Human Rights Law, can be applied to cyberspace. At the same time, we recognize that the constantly evolving nature of cyberspace sometimes may pose a challenge to the application of the existing international law in the exact same way as it applies to other traditional security areas. In such a circumstance, my delegation is of the view that a voluntary and non-binding set of norms indeed can play important roles in promoting responsible behavior and fostering confidence among state parties and therefore reducing risks of conflict. In this respect, we think that the set of norms produced through the GGE process is a solid achievement to build upon, and we need to continue to focus on elaboration and update of these norms to increase their utility and adaptability. My delegation supports in that regard your efforts to identify norms and to further elaborate them for their operationalization. Having said that, Mr. Chair, we would like to offer the following comments on how to make progress going forward, bearing in mind the guidance you provided. First, we believe that all 11 norms from the GGE process deserve our efforts for further elaboration. However, we may at this stage focus on some key components that many member states have already shown their attention to, namely norms around the protection of critical infrastructure, information sharing, response to cyber incidents, and cooperation between countries in case of incidents. We also believe that norms with respect to due diligence can be further developed. Second, with respect to the operationalization, my delegation believes that norms are voluntary. So basically, we believe that their operationalization should also be at the discretion of each member state. But we have the view that norms can be operationalized in various forms, such as legislation, strategy or policy documents, SOPs, or CSIRTs at the national level. Political documents or regional bodies reflecting normative elements can be a very useful way of operationalizing the norms. And OEWG could facilitate the operationalization of norms by compiling and sharing experiences and best practices of member states. Third, OEWG may consider another round of collecting contributions from member states on the elaboration and operationalization of norms to update previous ones and gather broader views from more member states. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, Republic of Korea, for your comments as well as your suggestions. Distinguished delegates, I don’t have any more speakers on this agenda item, so we might be able to make the transition to the next agenda item, which is international law. But before we do that, I wanted to say that it has been a very useful discussion, and thank you also for responding to the guiding questions. That too was very useful for me, and I hope also useful for you to listen to each other. It’s quite clear that the implementation of the norms that we already have is the starting point. It’s important. And therefore, whatever we can do in terms of capacity building to have the agreed norms implemented is going to be very important. That, I thought, was a theme that came across many interventions. Second, a discussion on norms inevitably brings us to different parts of our mandate, which is in many ways so tightly interconnected. So the norms discussion also had a discussion on international law and the need for a legally binding agreement, the relationship with the confidence-building measure, and also how some of the norms, or at least one of the norms, relates to the POC directory. So the interrelationship between the norms, rules, and principles, and the rest of the issues under the agenda item was also very, very clear. So we’ll need to look carefully at what additional elements we can capture for our annual progress report. The point was also made, and this was agreed in our last annual progress report, that additional norms could continue to be developed even as we look at the implementation of existing norms. Even as we discuss additional norms, from the annex to the chair summary from the previous OEWG report, we also need to look at guidance on the implementation of existing norms. And here, there is a lot of guidance on the implementation of existing norms. And here, there were some ideas that came up in the discussion, and some proposals as well. So I look at them carefully. For example, critical infrastructure and critical information structure was something that came up quite frequently. So this is not a summary at all, just some quick reflections. At the end of a very useful exchange of views. So we’ll make the transition to the next agenda item. But before that, I propose that we take a 10-minute pause for humanitarian reasons. Or coffee, if you like. That too is humanitarian. So let’s come back in 10 minutes, and we will start with the item on international law. Meeting is adjourned for 10 minutes.
Ambassador Gafoor
Thank you, distinguished delegates. Welcome back. We’ll now proceed to consider the item of international law on the agenda item five, and I wish to draw the attention of delegations to the annual progress report where, in the recommended next steps, we agreed that we will continue exchanging views on how international law applies in the use of ICTs. We agreed in the annual progress report that we will engage in focused discussions on the topics from the non-exhaustive list in paragraph 15, which is the section on international law in the annual progress report, as well as the 2021 OEWG report. Now, if we look at the section on international law under the annual progress report, paragraph 15A is a listing, non-exhaustive as it is, of proposals with varying levels of support, which we agreed may be further elaborated and supplemented at subsequent meetings of the OEWG. Now, I would suggest that when we look at the international law aspect of our mandate, there’s a whole series of issues that we need to discuss, and it’s not my intention to exclude any particular issue or prevent any delegation from raising any issue you consider important. You are free to do that, because that is how we work in the open-ended group. But I would invite delegations, as a starting point, to look at the issue of how international law applies, in particular the Charter of the UN, how the Charter of the UN applies in the use of ICTs, and related to that is the question of sovereignty, sovereign equality, non-intervention in the internal affairs of other states, and the peaceful settlement of disputes. So we’ll need to start somewhere. All issues are related and deeply interrelated, but I would also invite you to look as a starting point on the question of the Charter, and I hope that I can get your views on that matter. And I would also finally draw your attention to the guiding questions that I had submitted as well. So please do your best to respond to those questions. If you don’t agree with them, say so. I won’t read out the questions. It’s there before you. But if you disagree with the questions and you wish to address another question, feel free to do so, too. At this session in March, for each of the topics, we try not to repeat a general discussion, but to be focused as possible. So that’s what I’m looking for at this session in general, and also in particular for this section on international law. So with those opening remarks, I will now give the floor to the delegation. We do have a list of delegations. We’ll start with the European Union, to be followed by Sweden. EU, you have the floor, please.
EU
Thank you, Mr. Chairman. I have the honor to speak on behalf of the EU and its Member States. North Macedonia, Montenegro, Albania, the Republic of Moldova, Bosnia and Herzegovina, Iceland, Norway, Monaco, and San Marino align themselves with this statement. States’ efforts to determine how international law applies in cyberspace are today concentrated on two sets of activities. First, considerations on the issue at the multilateral level, but States are also considering the matter by developing national positions on how they interpret existing legal rules and principles in the cyber context, and exchanging upon this in various settings, including in the EU, but also in bilateral dialogues and broader events. An increasing number of States have publicly shared their views, whether by reporting on the issue to the UN Secretary-General as part of their national cybersecurity strategies, as standalone oral or written statements, or in other formats. When made publicly available, the statements contribute to common understandings on how international law applies to the use of ICTs by States, increase transparency, and reaffirm commitments to adhere to the framework of international law in the cyber context. The multilateral and national processes should be viewed as complementary, with the latter being a prerequisite to success in the former. Indeed, it is only when States have considered the matter internally and determined how the law can best achieve its objective and purpose in the cyber context and protect the value it was created to safeguard that States can meaningfully engage with other States and stakeholders on the multilateral level. Both processes are essential for finding common understandings on how international law applies to the use of ICTs by States. From the perspective of international peace and security, continuing the discussions on the multilateral level is necessary. International law is designed to regulate relations between States, including in cyberspace, and finding a common understanding on how the existing international legal framework applies can only be the result of the joint multilateral effort of States. It is both the privilege and responsibility of every single State to take ownership of this process with a view to clarifying definitions and thresholds for State conduct in the cyber domain. That said, we recognize that only a small number of countries have been involved in these discussions from the outset, and numerous States are joining them only now. This reality emphasizes the need for capacity building in the field, including through trainings and exercises, to improve our understanding of the application of international law in the cyber domain. Capacity building, if delivered in a neutral and objective manner, can make a tangible difference in States’ ability to develop their own positions and defend the national interest in the Open-Ended Working Group, as well as to ensure we do not further the digital divide by having only a small number of States meaningfully participate in the discussions. It is crucial that the Open-Ended Working Group continues to study how international law applies to States’ use of information and communication technologies. International law is the foundation of a rules-based international order. For cyberspace to fall within that order, international law must be upheld and enforced also in this domain. We call upon all States to avoid and refrain from taking any measures not in accordance with international law. That said, the Open-Ended Working Group should, as a next step, focus on those branches, rules, and principles of international law that are of most relevance from the perspective of safeguarding international peace and security, and seek to minimize human suffering as a result of hostile cyber activities. The EU and its Member States support the paper by Canada and Switzerland, and the proposal that international law discussions should start with addressing how international humanitarian law, the UN Charter, the obligation to peacefully settle disputes, and the law of States’ responsibility apply in the cyber context. Preferably, other international law topics agreed as applicable to the use of ICTs by States identified in our consensus report should also be discussed. As recapped by the UN Member States before, and most recently, in the Open-Ended Working Group Annual Progress Report in 2022, international humanitarian law applies in situations of armed conflict. There is a need to further study how and what the principles of humanity, necessity, proportionality, and distinction apply to the use of ICTs by States. Importantly, the EU underlines that recalling these principles by no means legitimizes or encourages conflict, but aims to prevent harm to civilians. We also propose to have a dedicated session on international law in the near future. A dedicated session would give us an opportunity to get our international law advisors involved, and therefore have more in-depth discussion on this important topic. Thank you.
Ambassador Gafoor
Thank you, EU. Sweden to be followed by the UK. Sweden, please.
Sweden
Thank you, Chair. Thank you for giving me the floor. I speak on behalf of Denmark, Finland, Iceland, Norway, and Sweden in our national capacities. The Nordic countries fully align themselves with the EU statements just delivered now by a colleague from the European External Action Service. In the humanitarian interest of saving time, I will be shortening our statement and submit it in full to you in writing. The Nordic countries welcome this focused discussion on the application of international law to the use of information and communications technologies by states. We believe that beginning with preliminary discussions on the application of the Charter of the United Nations is a good starting point for finding common ground. Considering that we have limited time at our disposal today, and not all states have a legal advisor from capital’s presence, we hope that today’s discussions will be continued. Like many others have already mentioned, both during this and previous sessions, international law, including the UN Charter, applies in cyberspace. This has been affirmed by the previous Open-Ended Working Group and endorsed by the international community on multiple occasions. International law is the foundation of a rules-based international order, and the applicability of international law does not depend on the technological means employed but applies across domains. Mr. Chair, the Nordic countries are all of the view that the rule of state sovereignty is applicable in cyberspace, a breach of which may amount to an internationally wrongful act. If it is attributable to a state, it may also give rise to state responsibility. Assessments need to be made on a case-by-case basis, as they would in the physical world. The commitment made by states in the UNGGE report from 2021 regarding the peaceful settlement of conflicts is still valid. The states party to any international disputes, including those involving the use of ICTs, the continuance of which is likely to endanger the maintenance of international peace and security, shall, first of all, seek a solution by such means as described in Article 33 of the Charter, namely negotiation, inquiry, mediation, conciliation, arbitration, judicial settlement, resort to regional agencies or arrangements, or other peaceful means of their own choice. Mr. Chair, the Nordic countries are of the view that our efforts should be directed towards finding common interpretations of existing law. The increasing number of national positions on international law and cyber contribute not only to this common understanding but also to capacity building. Neutral and objective capacity building on international law related to cyberspace must be tailored to the needs identified by beneficiary states. Such measures would then not only assist states in their effort to develop their own national positions but ultimately also improve our common understanding of the application of international law in cyberspace. In addition to capacity building, further detailed discussions on how to assess different kinds of threats and acts are also necessary. Today’s discussion must therefore be regarded primarily as a starting point for further in-depth exchanges on the application of international law. The Nordic countries would, in this regard, welcome a dedicated session on international law during the June interim sessions ahead of the July session. The goals for such a dedicated session would be threefold. First, to find common ground on key issues. Second, to pan out what can be added to the annual progress report negotiations in July, and third, to identify specific needs and capacity building measures to address these. We suggest that an international law session be held in hybrid formats to allow maximum participation of states’ legal advisors from capital. We also believe that the four topics identified in the Canadian-Swiss paper presented ahead of the informal OEWG in February constitute a good starting point for such discussions. Two of them, the Charter of the United Nations and peaceful settlements of disputes, are already introduced here today. In addition, we believe it would be useful to also discuss state responsibility and international humanitarian law, the latter, in our view, being applicable to cyber operations conducted in the context of armed conflict. Cyber operations are subject to the same restrictions and regulations as conventional attacks, including the principles of humanity, military necessity, proportionality, and distinction. Thank you, Chair.
Ambassador Gafoor
Thank you, Sweden. UK to be followed by Austria. UK, please.
UK
Chair, the UK welcomes this session of focused discussions on how international law applies to the use of ICTs. Such focused discussions are essential to deepen common understandings, avoid misunderstandings, and increase predictability and stability in cyberspace. Turning to the Chair’s guiding questions, the existing legal frameworks that are relevant to the regulation of state conduct in cyberspace include the UN Charter and international law, including international humanitarian law and international human rights law. As to whether there are gaps in existing legal frameworks, it is important to emphasize that cyberspace is not a lawless domain. Multiple processes, including the final reports of the previous OEWG and GGE, have affirmed the applicability of existing international law, including the UN Charter, to state activities in cyberspace. In this regard, it is the view of the United Kingdom that a process for a new legally binding instrument, as proposed by the Russian Federation, is not necessary. What is needed is to continue exchanges of views between states, including in particular in this forum, to clarify and deepen understandings of how existing international law applies. It would be a mistake to ignore and undermine the protection provided to all states by the UN Charter and existing international law in a rush to write new rules. The process of interpretation and clarification of existing international law does not mean that the applicability of the rules themselves must be called into question or discarded. Chair, given the limited time constraints in this afternoon’s session, the UK will focus on two issues identified by the program of work. Both of these topics merit detailed further consideration, as do the other topics in the cluster of issues suggested for discussion. First, the UN Charter is applicable in its entirety to state activities in cyberspace, just as it applies to state activities in the offline world. The continued application of the Charter is essential to maintaining peace and stability and for promoting an open, secure, stable, accessible, and peaceful ICT environment. To call into question the sufficiency of the Charter, or indeed the sufficiency of existing rules of international law, risks undermining international peace and security. Second, it is the UK’s view that Article 2.3 and the provisions of Chapter 6 of the UN Charter on the peaceful settlement of disputes apply equally in relation to state activities in cyberspace, as they do in relation to any other state activity. This means that, in accordance with Article 33.1 of the Charter, states that are party to any cyber-related international dispute, the continuation of which is likely to endanger the maintenance of international peace and security, must endeavor to settle such disputes by peaceful means, such as negotiation, inquiry, mediation, conciliation, arbitration, judicial settlement, recourse to regional agencies or arrangements, and other peaceful means of their own choice. In this regard, the UK endorses the practical guidance suggested by the GGE in its 2021 report that, quote, “an effective state’s response to malicious cyber activity attributable to another state should be in accordance with its obligations under the Charter of the United Nations and other international law, including those relating to the settlement of disputes by peaceful means and internationally wrongful acts.” States could also avail themselves of the full range of diplomatic, legal, and other consultative options available to them, as well as voluntary mechanisms and other political commitments that allow for the settlement of disagreements and disputes through consultation and other peaceful means. We also welcome the Chair’s non-paper for the development and operationalization of a points of contact directory. Such confidence-building measures reduce the risk of misunderstandings and escalation and are practical deliverables that support and complement the peaceful settlement of disputes. On capacity building, we think it is important to hear from those states who seek to benefit from capacity building to understand what they require in terms of resources and institutional support in order to enhance and deepen states’ common understandings of how international law applies in cyberspace. Finally, the UK underlines the need to identify a roadmap for consideration of specific issues of international law in future meetings of the Working Group. We echo the request of Sweden on behalf of the Nordic countries that the Chair schedule an international meeting this coming May or June dedicated to focused discussions on international law with briefings by recognized experts identified in advance in a virtual or hybrid format to facilitate attendance by as many states as possible. The UK endorses the proposals contained in the concept paper on international law proposed by Canada and Switzerland, including the proposals to consider international humanitarian law and state responsibility as topics of focus. We also ask that provision for discussions on international law should be included in the July session with a roadmap for discussions set out in the 2023 Annual Progress Report. Thank you, Chair.
Ambassador Gafoor
Thank you. UK, Austria, to be followed by Canada. Austria, please.
Austria
Mr. Chair, thank you for giving me the floor. Austria fully aligns itself with a statement by the European Union, and we would like to add some further remarks in our national capacity. Mr. Chair, the international community has now repeatedly affirmed that international law applies to state cyber operations, and yet we repeatedly find ourselves in the same position of reaffirming the so-called acquis, not reaching any more detailed conclusions as to how international law applies to cyber operations. The proposal made by Canada and Switzerland on a practical approach to international law in this OEWG seeks to move our discussion forward by suggesting to focus on a limited set of topics to be discussed in dedicated sessions on international law. While we are still of the opinion that a dedicated four-week session would be the best practical solution, as was also just mentioned by the UK and Sweden, we nevertheless appreciate your suggestion to focus our discussions today on a first cluster of issues, namely how international law, in particular the Charter of the United Nations, applies to the use of ICTs, as well as the concepts of sovereignty, sovereign equality, non-intervention, and peaceful settlement of disputes. As a starting point, and as we’ve mentioned in previous statements, Austria holds that international law as a whole, meaning customary international law, general principles of law, and international treaty law, is the framework that is and should be applicable to state cyber conduct. In particular, this includes, of course, the UN Charter in its entirety. It has been repeatedly affirmed, both in this working group as well as in the GGE, that the UN Charter is applicable to cyber operations. This includes upholding the sovereign equality of all member states, as well as the peremptory norm enshrined in Article 2, Paragraph 4, to refrain from the threat or use of force against the territorial integrity or political independence of any state, or in any other manner inconsistent with the purposes of the United Nations. It also includes the obligation on states to settle international disputes by peaceful means, as enshrined in Article 2, Paragraph 3 of the UN Charter. Lastly, it also includes the inherent right of self-defense against an armed attack, a customary international law principle enshrined in Article 51 of the UN Charter. On this last point, let me stress, as we’ve done previously several times, that the right of self-defense does not legitimize the use of armed force by any means, but merely serves as a safeguard against unlawful armed attacks and is subject to certain conditions, such as necessity and proportionality. Austria also aligns itself with the positions of an ever-increasing number of states which affirm the rule of sovereignty with regard to cyber activities. While not all cyber operations may automatically constitute a violation of sovereignty, certainly some operations, especially those that are particularly intrusive or disruptive in nature, but do not reach the threshold of coercive interference under the principle of non-intervention, may also be considered a violation of sovereignty. However, we reiterate our view that further discussions on this topic, including on clear definitions of the terms used, would be beneficial to find common understanding. Regarding the principle of non-intervention, we’ve heard different views from various states on when cyber operations constitute a coercive interference in the domaine réservé of another state. In this context, it is worth recalling the 1986 judgment of the International Court of Justice in the Nicaragua case, which, on the question of coercion, the ICJ stated the following, and I might quote, “The element of coercion which defines and indeed forms the very essence of prohibited intervention is particularly obvious in the case of an intervention which uses force, either in the direct form of military action or in the indirect form of support for subversive or terrorist armed activities within another state,” unquote. However, with regard to cyber operations, the element of coercion may be less obvious than in the case of an intervention which uses force. We therefore believe that this aspect deserves more in-depth discussion in a dedicated session within this working group or elsewhere. Lastly, as to peaceful settlement of disputes, we hardly think that there is any debate whatsoever that disputes arising out of state cyber operations are to be settled by peaceful means. International law and the UN Charter offer an array of means in this regard, as was elaborated by the United Kingdom, including through negotiation, arbitration, or litigation at an international court or tribunal, including the International Court of Justice. With regard to the guiding question on gaps in existing legal frameworks, Austria is of the view that due to the applicability of international law as a whole to cyber activities, there is no need for the development of new binding legal instruments, but rather for clarification regarding the application of the existing rules. Mr. Chair, let me reiterate our wish to have more time in the OEWG for in-depth discussions on international law by devoting several days within one of the OEWG meetings in 2023 solely to the topics of international law. This would allow legal advisors also from capitals to participate in the meeting and thus contribute to advancing the common understanding on this important topic. In that context, we reaffirm our support to the updated concept paper by Switzerland and Canada and the procedure and topics proposed therein, which largely coincide with our priorities. Regarding your question on capacity building measures, we would suggest that these could be included in future arrangements, such as, for example, the Program of Action, and are of the view that additional workshops with leading academics in the field and cross-regional cooperation would be beneficial in this regard. And I think this was voiced also by Ghana in the previous session. Austria remains dedicated to this issue, and thanks again, Mr. Chair, for giving us the opportunity to share our views on these important matters. Thank you.
Ambassador Gafoor
Thank you. Austria. Floor now to Canada, to be followed by South Africa. Canada, please.
Canada
Chair, Canada is pleased to be able to contribute today to our focused discussions on international law in line with the roadmap agreed in our annual progress report last July. Such discussions will surely help us continue to build common understandings and consensus. Chair, Canada would first like to thank you for the guiding questions you have circulated for our consideration. We found these very useful and will address these today. That the first cluster of topics you have identified starts with the Charter of the United Nations is timely and most welcome, especially given the state of our world today. It was timely as well that the Charter was the focus of UNIDIR’s excellent Cyber Stability Conference Friday. UNIDIR is to be commended for helping prepare for this week’s discussions, both in terms of the topic and also in supporting our OEWG’s mandate and commitment to capacity building on international law as it applies to cyberspace. Chair, your first guiding question invites us to consider existing legal frameworks, whether there are any gaps, and if so, how they should be addressed. For Canada, our short answers are as follows. On existing legal frameworks, as agreed in the GGE reports since 2013, 10 years ago, it is above all the UN Charter and customary international law that are relevant. Plus, in certain circumstances, specialized bodies of law such as IHL and international human rights law. Chair, on whether there are gaps, our sincere answer after years of analysis and reflection, we think not. This view was affirmed for Canada through the process of developing our national statement published in April last year. The process of analyzing many aspects of international law in relation to cyberspace in our national interdepartmental process also affirmed Canada’s view that existing international law, together with the 11 non-binding norms, provides a very solid, sufficient, and workable framework for responsible state behavior. But we are open to considering all of this further with other member states through dialogue and focused discussions here in this open-ended working group. Chair, to answer your question, the best way to identify and address any potential gaps is through focused discussion, dialogue, and capacity building. In this spirit, Canada would focus on two topics in the first cluster, especially the UN Charter and peaceful settlement of disputes. On the Charter, Canada would like to make four points. First, we affirm that international law applies to the activities of every state in cyberspace, and this includes the UN Charter in its entirety and customary law. Secondly, I want to underline Canada’s position clearly identifying that the Charter in its entirety applies, not parts but all, that apply to all of us. Third, it goes without saying that the prohibition on the threat or use of force extends to cyberspace. This prohibition in Article 2.4 of the Charter is well known. In Canada’s view, cyber activities may amount to such a threat or use of force where the scale and effects are comparable to those from other operations that we would all agree constitute the use of force in international law. Canada will assess cyber activities that may amount to a threat or use of force on a case-by-case basis with a focus on the scale and effects, and Canada spoke about this in more detail at the UNIDIR workshop Friday morning. We’d be happy to share our remarks in that regard. And fourthly, Chair, on the Charter, we in all candor remain puzzled by the assertion of a few states that there is no discernible law applicable in cyberspace and we urgently need a new treaty. We find this a premature conclusion which would be better made after more focused discussion and consolidation of our common understandings. In December, I spoke of the tradition of some First Nations in Canada that have continued passing down through the generations the expertise of building birchbark canoes. That was in our informal discussions, and what I explained was that a lot of care goes into building birchbark canoes. It takes a lot of effort and patience, but in the end, once the canoe is put in the water, it becomes quickly clear whether there are gaps. The canoe floats or it doesn’t, and here we need to build together our canoe in the form of our common understandings, and at that point, together, we can put the canoe in the water, and at that point, together, we will see if the boat floats or if there are gaps. Until then, it would be premature. On peaceful settlement of disputes, Chair, let us just briefly say that this is a central and at times overlooked rule of international law, and it’s the obligation of every state. The prohibition in the Charter relates to both the threat or the use of force, and that prohibition applies in cyberspace as it does elsewhere. The obligation to seek the settlement of disputes by peaceful means is not unlimited, nor does it diminish other international legal obligations or rights, but it is undoubtedly an obligation on all states in cyberspace. Chair, sovereignty is a fundamental element of international law and international relations. It is axiomatic that the principle of sovereignty applies in cyberspace just as it does elsewhere. It animates a number of obligations for all states, and it’s inseparable from the sovereign equality of all states, which is equally and undeniably applicable in cyberspace. Chair, I would like now to address your second and third guiding questions, both related to capacity building. Chair, all member states need to boost their capacities in this important and complex field. For Canada, we have benefited greatly from UN processes, such as this open-ended working group, and from courses and workshops and tools offered by various organizations, including UNIDIR, the Organization of American States, the ICRC, the Oxford Process, the toolkit of the CCDCOE, and the Talon manuals. And based on our own experiences, Canada has supported capacity building courses for officials from dozens of member states. Their feedback to us has been very positive, telling us that the training courses that Canada has organized have been well-tailored to their specific requirements. That said, it remains member states, each member state, which can best determine what their capacity building needs are in relation to international law. For example, this year, some states may wish to seek advice on the process of developing a national statement, or perhaps a regional or sub-regional statement. In this regard, Canada, having built our canoe, is ready to give some canoe building workshops for other states that want, or regions that want to build their canoes. But Canada is listening intently in our session here today, and in informal and bilateral discussions, and we will do our best to respond accordingly to the needs of other states. In conclusion, Chair, let me give Canada’s suggestions for our continued progress on international law beyond this week. We have momentum now. Let us build on it. First, we would propose that intersessional discussions on international law be scheduled for May on selected topics that we can identify in advance. These could be virtual or, if administratively feasible, hybrid. We could select topics through consultation or simply continue to work on the basis of clusters of topics included in our first annual progress report. We recall the Swiss-Canadian concept note, updated and circulated last November. It includes topics and modalities to optimize our work on international law, and we would invite member states to refresh their reading of this or to speak to Canada and Switzerland about it. We would propose that further focused discussions on international law be included in the agenda for our July session. Some concentrated sessions in international law, as others have suggested, would be very beneficial. Again here, identifying topics in advance will allow member states to propose recognized experts for briefings and to prepare their positions and their questions. Member states would be in a position to plan to have relevant officials available on the dates in question. But this will also allow member states to cooperate in advance to structure capacity building activities that relate to the topics that we have agreed to work on together, thus enabling more member states to participate meaningfully in our OEWG’s vital work on international law. Finally, we suggest that our annual progress report further develop the roadmap on international law, building on our work last year, setting out topics that we will address in 2023 through to 2025 with provisional timings on these so that all member states and relevant stakeholders will be able to prepare accordingly. Chair, I thank you for your time and attention.
Ambassador Gafoor
Thank you, Canada, for your statement. South Africa, to be followed by the Russian Federation. South Africa, please.
South Africa
Chairperson, we welcome the opportunity to elaborate our views on how international law applies to the use of information and communications technologies by States. South Africa has consistently expressed its commitment to promoting a peaceful and stable cyberspace underpinned by international law, including human rights law, and consistent with the 11 norms of responsible State behaviour. We maintain our belief that the United Nations Charter applies in its entirety to cyberspace, and that the principles of the UN Charter apply to cyberspace, such as sovereign equality, the settlement of international disputes by peaceful means, respect for human rights and fundamental freedoms, and non-intervention in the internal affairs of other States. Chairperson, when discussing this matter, we should consider that a cyber operation may, depending on its scale and effects, violate the prohibition on the threat or use of force in Article 2.4 of the UN Charter. When a cyber operation constitutes an armed attack under Article 51 of the UN Charter, States may exercise the inherent right of individual or collective self-defense recognized in the Charter, while customary international law principles of necessity and proportionality remain applicable. It is South Africa’s view that a cyber operation could be deemed an internationally wrongful act when it is attributable to a State under international law and involves a breach of an international obligation of the State. Therefore, States should not knowingly allow their territory to be used for internationally wrongful acts using ICTs. If a State is notified of harmful activity emanating from its territory, it must take reasonable steps to address such activity. If a situation amounts to an armed conflict and cyber operations are carried out during that conflict, international humanitarian law applies to these cyber operations, as it does to all operations with a nexus to an armed conflict in general. It is our understanding that IHL prohibits the use of cyberspace to attack civilian infrastructure, for example. During war and peacetime, States are required to take all feasible precautions to protect civilians and civilian objects. Chairperson, with this understanding in mind, we should encourage States to forge closer cooperation in developing and applying measures to increase security in the use of ICTs and to avoid ICT practices that could endanger the maintenance of international peace and security. South Africa believes that we should develop a common understanding of the applicability of international law, including international humanitarian law in cyberspace based on existing legal frameworks. In this regard, the working group would also benefit from briefings from international legal experts, and we have proposed garnering the views of bodies such as the International Law Commission to this end. Chairperson, we are closely following the discussion on this matter, and we agree with our Nordic colleagues that we should have more time to discuss it, perhaps during the intersessional period. I thank you.
Ambassador Gafoor
Thank you very much. South Africa, Russian Federation, please, to be followed by Kenya.
Russia
Chairman, distinguished colleagues, discussions in the group have demonstrated that the majority of states do not share the opinion on the automatic applicability of existing international legal norms to the use of ICTs without taking into account the specifics of ICTs. The majority of states advocate for the use of ICTs for development and to prevent related conflicts. In these conditions, any attempts at the international level to legitimize the use of ICTs for military and political purposes against other states, as well as to impose the rules of so-called cyber warfare, are unacceptable. There is an urgent need to adapt and progressively develop international law with due regard for the specifics of these technologies. The priority is to create a universal and fair international legal regime for regulating cyberspace based on a legally binding UN convention on international information security. We have described Russia’s relevant initiatives in depth, in particular the concept of a convention, during the discussion on the norms, rules, and principles of responsible state behavior. This document has been published on the OEWG webpage. We assume that there is consensus in the international community regarding the applicability of generally recognized principles of international law to the field of ICTs, meaning sovereign equality, the non-use of force and threat of force, respect for the territorial integrity of states, the settlement of international disputes by peaceful means, non-interference into internal affairs, the fulfillment of international obligations in good faith, and cooperation between states. We deem it important to focus the work on two issues. One, on how specific principles of international law apply to the use of ICTs, and two, what gaps there are in existing international law and what legal relations among states in this area remain unregulated. In particular, the practical application of the legal principle of cooperation between states in the use of ICTs could be discussed. As far as the applicability of international humanitarian law to cyberspace is concerned, the 2021 GGE report clearly states that international humanitarian law applies only during armed conflicts. The legal norms of IHL cannot be used to assess the legality or illegality of the malicious use of ICTs in peacetime. This is because it applies only during an armed conflict. At the same time, there is no consensus in the international community on the issue of qualifying the malicious use of ICTs as an armed attack in the sense of Article 51 of the UN Charter. Therefore, there are no grounds for assessing the legality of the use of ICTs from the perspective of international humanitarian law. Under these circumstances, it is inadmissible to speak about the automatic applicability of the existing norms of international humanitarian law to the field of information security without taking into account its specifics. We deem it necessary to focus on elaborating criteria for qualifying instances of the use of ICTs for purposes that are inconsistent with the objectives of maintaining peace and security. Further study is needed on how and when international humanitarian law can be applied to the use of ICTs by states and on codifying such an understanding in a legally binding instrument. We presume that the exchange of national positions and approaches to the international legal regulation of the use of ICTs can and should be organized within the Open-Ended Working Group itself. In the context of the issue of attribution touched upon by Sweden, we wish to note that this topic is indeed complicated. However, a discussion on this issue is made more difficult by the issue of the trustworthy identification of the source. The current level of organization of the global internet does not allow such facts to be confirmed. We need to observe the principle that is enshrined in UNGA resolution 73/27 and the GGE reports from 2015 and 2021. And this principle is that all accusations of organizing or committing wrongful acts brought against states should be substantiated. Paradoxically, this principle is being forgotten by those states who are requiring the norms of the GGE from 2015 and are advancing baseless accusations that run counter to these norms. We believe that public attribution of responsibilities for incidents in cyberspace on a specific state should not be carried out without any technical evidence. Thank you.
Ambassador Gafoor
Thank you, Russian Federation, for your statement. Kenya, please.
Kenya
Thank you, Chair. Kenya reaffirms the importance of having an appreciation of both the possibilities and existing challenges when it comes to the applicability of international law in the use of information communication technologies by states. Existing legal frameworks seeking to harmonize national or regional laws, increase cooperation amongst nations, and regulate the conduct of states in cyberspace, such as the Budapest Convention on Cybercrime and the African Union Convention on Cybersecurity and Personal Data Protection, have been met with hesitancy and delayed implementation. It is our view that part of our discussions within the OEWG should include identification of such challenges and possible contextualized solutions when it comes to the applicability of international law in the cyber domain. An approach that allows member states to develop domestic laws regulating behavior in cyberspace, modeled around the 11 non-binding norms of responsible state behavior, may be considered as an important first step to address such gaps. Sharing of good practices on how the provisions of international law apply in the use of ICT, in complementarity with the state’s national legal framework, would also contribute to enhancing a shared understanding on this issue. The publication of national position papers on the interpretation of international law and its applicability to the use of ICTs not only raises awareness but is also a confidence-building measure that would guide nations in their interactions with one another. Mr. Chair, we also urge for recognition of state efforts to establish national legal mechanisms in the area of cybersecurity in alignment with the United Nations Charter and other agreed mechanisms. Kenya, for example, has enacted the Computer Misuse and Cybercrime Act to facilitate international cooperation in dealing with computer and cybercrime matters. More effort should be put into identifying the types of training and capacities that are needed to bolster ICTs’ legal and policymakers’ appreciation of how international laws apply in the use of ICTs. Such capacity building should seek to guide and not influence the national position of the recipient state and be relevant to the needs of the recipient state. The capacity building effort should be progressive and measurable to ensure that the purpose for which it is intended is actually achieved. As I conclude, Mr. Chair, Kenya notes the usefulness of a repository where states can deposit their published positions on the application of international law. This will go a long way in identifying points of divergence and establishing points of convergence in the interpretation of the application of international law. I thank you.
Ambassador Gafoor
Thank you very much, Kenya. I give the floor now to Singapore.
Singapore
Thank you, Mr. Chair. As a small state, Singapore has always been strongly supportive of the rules-based multilateral system, including in relation to states’ conduct in cyberspace. The adherence to international law is essential to support and promote an open, secure, stable, accessible, peaceful, and interoperable ICT environment. We support the Chair’s approach to focus on the first cluster of issues identified in the inaugural Annual Progress Report, which we will address in turn. Singapore affirms the UN Charter and its key underpinning principles, which apply in cyberspace as they do in the physical world. This includes the principle of state sovereignty, the sovereign equality of all states, and non-intervention. On the application of sovereignty, Singapore’s position is that the territorial sovereignty of a state extends over cyber infrastructure located in its territory and over activities associated with such infrastructure. We are also of the view that a cyber operation could, in certain circumstances, amount to a breach of sovereignty. The principle of non-intervention requires that a state refrain from intervening in another state’s domaine réservé in a manner that is coercive in nature. A prohibited intervention must have a bearing on matters in which the victim state is permitted by the principle of state sovereignty to decide freely, including its choice of a political, economic, social, and cultural system and the formulation of its foreign policy. For instance, interference with the electoral processes of another state through cyber means would, in certain circumstances, constitute a prohibited intervention. Another key element of the UN Charter relates to the peaceful settlement of disputes. Singapore shares the concerns of other states on the escalation of conflicts in the cybersphere against the backdrop of continuing fast-paced developments in technology. In line with the previous OEWG and GGE reports, Singapore affirms the obligation on all states to settle their international disputes by peaceful means in such a manner that international peace and security are not endangered, in accordance with Article 2, Paragraph 3, and Article 33 of the UN Charter. These obligations, which serve the maintenance of international security, apply in cyberspace as in the physical world. Singapore also affirms the obligation of all states to refrain from the threat or use of force against the territorial integrity or political independence of other states. This prohibition applies equally to cyber operations, just as how they would apply to… [Ed: Audio cut out in recording at 02:41:48]
Ambassador Gafoor
[Ed: Ambassador Gafoor speaks from 02:43:12 to 02:47:48 in the video recording, but the audio is missing]
Leave a Reply