Ambassador Gafoor
Good morning, Distinguished Delegates. The fifth meeting of the fourth substantive session of the Open-Ended Working Group on Security of and the Use of ICTs, established pursuant to GA Resolution 75-240 of 31 December 2020, is now called to order. Distinguished Delegates, today is a very special day. It is International Women’s Day. So let me first of all begin by wishing all our distinguished women representatives present here, but also following the meeting virtually, a very special and happy International Women’s Day. I thought that this is an occasion that should not be allowed to pass without any kind of commemoration. So it is my intention that at 11:30 this morning, we will commemorate International Women’s Day in this working group. I’ve invited Under-Secretary-General Nakamitsu to join us at 11:30 to give us some of her remarks, and I will also make my own remarks. The commemoration is fundamentally a moment of not only commemoration and celebration, but also a moment of reflection on the role of women in the area of ICT security and more broadly the role of women and how important it is in women, peace, and security. So with those comments about the commemoration that will come later, let us now continue with the consideration of Agenda Item 5, relating to the item of international law, how international law applies to the use of ICTs by states. Just to recall, I had yesterday said that we will be guided by the Annual Progress Report as well as the guiding questions that I had submitted in which I had suggested that we focus on the first cluster of issues identified in the Annual Progress Report, which is relating to how the Charter of the UN applies in the use of the ICTs, sovereignty, sovereign equality, non-intervention, the internal affairs of states, and the peaceful settlement of disputes. This is my suggestion and of course states and members are free to raise other issues that they deem important and relevant to this discussion. The idea is to have a focused discussion, so I do invite each one of you to give your response in a succinct but also focused manner, identifying the issues in the Annual Progress Report as much as possible. So with those comments, we will continue with the speaker’s list and let me see who we have now. So we’ll start with Thailand to be followed by the Netherlands. Thailand, please.
Thailand
Mr. Chair, since this is the first time Thailand is taking the floor, we would like to express our appreciation to you, Mr. Chair, and your team for your hard work and effort. We would like this meeting to be a success. Thailand would like to state the importance of a rules-based cyberspace in promoting international peace and security, as well as advancing economic progress and enhancing the living standards of the people. As highlighted in the Secretary-General’s Outcome Agenda, it is crucial to foster a culture of accountability in cyberspace. Thailand recognizes that international law, including the UN Charter, plays a crucial role in maintaining international peace and security and promoting such a culture of accountability. We reaffirm our commitment to the principles enshrined in the Charter, including state sovereignty, the peaceful settlement of international disputes, non-intervention in the internal affairs of other states, and refraining from the threat or use of force that is inconsistent with the purpose of the Charter. We believe that international law applicable to cyberspace should safeguard the sovereignty and security of states, as well as human rights and fundamental freedoms. However, there is a need to ensure that there is no gap in the implementation of international law, which is why it is crucial for states to engage in inclusive dialogue to develop a common understanding of how international law applies in cyberspace, including in the area of state responsibility. Mr. Chair, Thailand firmly believes that the law of state responsibility applies in cyberspace, and that international communities should hold accountable those states that engage in internationally wrongful acts in cyberspace. One of the critical issues related to state responsibility in cyberspace is attribution. Attributing a cyber attack to a specific state is a complex and challenging process that requires significant technical and investigative capability. States with limited resources may struggle to attribute cyber attacks and hold responsible parties accountable. Moreover, it is essential to ensure that the process of attribution is objective, transparent, and based on solid evidence to avoid false accusations and unjustified actions. It is therefore important to equip states with the capability to implement such law. Thailand believes that capacity-building efforts in attribution capability and techniques are necessary to enable states to fulfill their obligations regarding state responsibility in cyberspace. The international community should support such efforts in this regard, including through the provision of technical assistance and sharing best practices. Mr. Chair, to achieve a law-based cyberspace, we must work together, not just to bridge the gap of understanding through inclusive dialogue, but also to ensure effective implementation of international law. That is why capacity-building continues to be an essential element under this framework, and any other regular institutional dialogue on cyber security at our level. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, Thailand, for your statement. Just to remind you to send your statements to the interpreters at estatements@un.org, and while you’re doing that, please also send it to the Chair’s email, which is cyberoewgchair (in one word) at gmail.com. That way, we can keep track of all the statements that you have made, and we certainly will go through them again very carefully. The next speaker is the Netherlands, to be followed by Switzerland. Netherlands, please.
Netherlands
Chair, distinguished delegates, the Netherlands aligns itself with the statement delivered by the European Union, and I would like to add some additional remarks in a national capacity. The Netherlands welcomes our focused discussions on international law, in accordance with the roadmap as stipulated in the Annual Progress Report of 2022, and on the basis of the guiding questions provided by the Chair. The Netherlands wishes to again express its support for the strategy paper of Canada and Switzerland on international law. We can only but reiterate the importance of these focused discussions for further development of common understandings on how international law applies in cyberspace, as part of the normative framework for responsible state behavior. That is why we believe it is important to talk about all topics of international law that have been elaborated upon in previous consensus reports. In this light, we would welcome more time to be allotted to these discussions in our next meetings. To enhance progress in our formal discussions, we would also support holding an intersessional meeting dedicated to international law in a virtual format, in order to ensure the maximum participation of delegations. Furthermore, we support having dedicated sessions, expert briefings, and capacity-building activities on international law. All of this would enrich our focused discussions, while at the same time serving as a transparency and confidence-building measure, as well as a form of capacity-building. Chair, the Netherlands would like to thank UNIDIR for organizing the Cyber Stability Conference dedicated to the UN Charter. We look forward to continuing our exchanges on the application of the UN Charter in cyberspace here today. The UN Charter is the backbone of the rules-based international order. Chair, please allow me to share some remarks with respect to sovereignty and peaceful settlement of disputes, with the aim of reflecting these principles in our next annual progress report. In these remarks, I will also refer to the Netherlands’ position on how international law applies to cyberspace, as articulated in a letter to parliament in 2019. The Netherlands considers sovereignty as one of the fundamental principles of law which is enshrined in the UN Charter. As reaffirmed in UNGGE reports, sovereignty and international norms and principles that flow from sovereignty apply to the conduct of states in cyberspace. The Netherlands holds the view that states have exclusive authority over the physical, human, and immaterial, which includes logical or software-related aspects of cyberspace within their territory. Sovereignty also implies that states may independently pursue foreign cyber policy in the area of cybersecurity. Accordingly, states have an obligation to respect the sovereignty of other states and to refrain from activities that constitute a violation of other countries’ sovereignty. Chair, another key principle of the UN Charter is the peaceful settlement of disputes. To include this language in our consensus reports was a common effort that was accomplished together with partners like Mexico. The Netherlands holds that the provisions of the UN Charter on the peaceful settlement of disputes apply equally in relation to state conduct in cyberspace. This means that, in accordance with the UN Charter, states that are party to any cyber-related dispute, the continuation of which is likely to endanger the maintenance of peace and security, must endeavor to settle such disputes by peaceful means. Nonetheless, states should also aim to peacefully settle cyber disputes that do not rise to the level of international peace and security. In terms of how this works in practice, the UN GGE 2021 report provided practical recommendations. States should avail themselves of the full range of diplomatic, legal, and other consultative options available to them, as well as voluntary mechanisms and other political commitments that allow for the settlement of disagreements and disputes through consultations and other peaceful means. We believe that, in this way, peaceful settlement of disputes is an essential tool to avoid escalation and prevent conflict. In this regard, confidence-building measures provide an essential framework for states to interact with each other. Chair, let me close by reflecting on how we, as the international community, can make collective progress in advancing a common understanding of how international law applies. States create international law. They’ve set out the rules for the maintenance of international peace and security in the UN Charter. Since then, states have had to continuously interpret and apply them to new domains. Yesterday morning, we heard Russia’s proposal regarding a new convention, and it’s not the first time they have raised this. Such initiatives seem to question the applicability of the UN Charter. The Netherlands considers these to be efforts to create ambiguity around such fundamental principles as irresponsible, in particular since we have consistently agreed by consensus that existing international law, including the UN Charter, applies to cyberspace. Instead, we have to continue our efforts to reach common understandings on the interpretation and application of international law in cyberspace. And to do so, it is essential that states articulate their position on this question. Many states have done so, and the 2021 UN GGE made significant progress in this regard by annexing national views on how international law applies. This provides us with a solid basis to reach common understandings on the normative framework, including international law, and to discover whether gaps in our common understandings exist. The Netherlands therefore encourages other states to also publish their national positions on how international law applies in cyberspace. As has been noted before, capacity building on the basis of states’ needs is key in this regard. Thank you, Chair.
Ambassador Gafoor
Thank you very much, Netherlands. As I said yesterday, this is a very important and necessary discussion in the Working Group, and I really don’t want to come in and give any comments at this stage, but I thought I should at least share one reflection before we continue with the speaker’s list. In the Annual Progress Report, we did agree, as part of the carefully crafted, balanced document, that part of the value of the exchange in the OEWG is the exchange of diverse perspectives, new ideas, and important proposals that were put forward, even though they were not necessarily agreed by all States, including the possibility of additional legally binding obligations. So the fact that there has been a proposal put forward by a delegation on additional legally binding obligations is in itself not an irresponsible act. But whether that proposal receives support is another matter, and if it does not receive support, I think it’s good to discuss what is missing and why support is not possible. So I would encourage delegations to have that difficult discussion. I think in the context of a UN process, every delegation has the sovereign right to put forward proposals. I think we have to respect that. And as Chair, I will do my best to facilitate that difficult conversation that you need to have among yourselves. So let’s not, at this point, reach conclusions about what would constitute a responsible proposal as opposed to an irresponsible proposal. I think what we need to do is look at all the proposals, put forward the arguments and the reasons as to why certain proposals will need additional work, or need to be considered further, or why they may not be able to command consensus. But in any case, this is the place for all proposals to be put on the table. And as Chair, I’ll be looking to each one of you to see where the middle ground will lie. So with those comments, we’ll continue with the speakers list. And I have Switzerland to be followed by Czechia. Switzerland, please.
Switzerland
Mr. Chair, distinguished delegates, as we have already dealt with the question of possible gaps and the need for new binding rules under the previous agenda item, we will not repeat our position here, but Canada’s example of the canoe very much reflects our position. We were surprised by some delegations’ remarks made yesterday that they oppose the automatic application of IHL, International Humanitarian Law. In our view, the answer regarding the application of International Humanitarian Law in cyberspace is to be found in the UNGGE Report 2021, which clearly states International Humanitarian Law applies only in situations of armed conflict. And this was reaffirmed in the Annual Progress Report 2022, endorsed by all states in the General Assembly. We thank you for the timely opportunity to launch the beginning of focused discussions on international law at today’s formal session of the OEWG, and for the provision of the guiding questions. We found them a very helpful tool for preparation and for moving from general statements to focused discussions. The acquis that international law applies in cyberspace is part of the overall framework for responsible state behavior in cyberspace, developed and reaffirmed by the GGEs and the OEWG, and endorsed by the General Assembly. As we have outlined in December in our concept paper, we believe it is key to continue the work done on international law since 2013 in previous GGEs and the OEWG. The deliverable of these focused discussions should be to move forward constructively and to continue to build in common understandings on the application of international law in cyberspace over the life of this OEWG. And this meeting today is a starting point for the implementation of the roadmap agreed in the first Annual Progress Report of 2022, and it is a first non-exhaustive exchange of topics, and that should be continued over the life of this OEWG. The UN Charter is a key legal framework applicable in cyberspace, and it has received explicit reference in all GGE and OEWG reports since 2013. As part of the acquis, states have repeatedly reaffirmed that the United Nations Charter is applicable and essential to maintaining peace and stability and for promoting an open, secure, peaceful, and accessible ICT environment. And it is Switzerland’s position that the UN Charter applies in its entirety to cyberspace. The application of the rules of the UN Charter to a particular cyber incident, however, requires a case-by-case assessment. Let me now turn to sovereignty. UN GGE reports 2013 and 2015 have confirmed that state sovereignty and international norms and principles that flow from it apply to the conduct by states of ICT-related activities and to their jurisdiction over ICT infrastructure within their territory. Sovereignty refers to a state’s right to define, apply, and enforce its own legal order, which in principle is limited to its territory. At the interstate level, however, sovereignty implies an independent and equal coexistence among states. Respect for and protection from interference with territorial integrity is a product of state sovereignty. The UN Charter is a key framework; accordingly, each state is obliged to respect the sovereignty of other states and the sovereign equality between states. In interstate relations and cyberspace, the principle of sovereignty provides wide scope for protection against cyber operations. For example, state sovereignty protects information and communication technologies infrastructure on a state’s territory against unauthorized intrusion or material damage. The UN GGE reports 2015, 2021, and the OEWG report 2021 all confirm peaceful settlement of disputes as one of the UN Charter’s central principles, which also applies to cyberspace. And as a country with long-standing experience and engagement in the provision of good offices, Switzerland is committed to upholding the peaceful settlement of disputes in cyberspace, emphasizing the overriding aim of ensuring that cyberspace is used for peaceful purposes. Disputes which may endanger international peace and security must be settled by peaceful means, and the legal obligations regarding the peaceful settlement of disputes are stipulated in Articles 2, 3, and Article 33 of the UN Charter. The International Court of Justice has generally recognized this as customary international law, and this includes diplomatic proceedings, arbitration, including recourse to the Permanent Court of Arbitration, or recourse to the International Court of Justice. And future focused discussions in this OEWG could address both the legal obligation to settle international disputes endangering peace and security, but also the added value of the expectation for peaceful settlement of international disputes in cyberspace, which applies to disputes that do not reach the level of endangering peace and security. Concrete measures, such as the ongoing OEWG’s work on the Points of Contact Directory, strengthen our overall goal of settling disputes in a peaceful way. Let me conclude by once again commending the Chair for starting focused discussions on international law at this formal session. We must continue implementing this part of the roadmap of the Annual Progress Report 2022, and we should tailor capacity-building efforts according to the demands of states. But this requires adequate time for preparation and foresighted planning of concrete topics for the remaining sessions in 2023 and beyond. Focused discussions should be supported by briefings from states and independent experts as part of the capacity-building activities in international law, and the UNIDIR conference and the IHL side event of this last week were a highly valuable starting point for this. Another topic dear to Switzerland is the application of international humanitarian law in cyberspace, and we welcome that at yesterday’s side event states and other stakeholders have started this conversation on how the principles of IHL apply in cyberspace. We would also like to recall the joint statement submitted by the cross-regional group on IHL to this OEWG, and discussing this issue in the near future in this OEWG is timely and it answers a call from states and other stakeholders. We support proposals made yesterday and today by several states to have an interstitial meeting or a dedicated session on international law, and such sessions could be held in a hybrid or virtual format in May or June, and time should also be dedicated at the formal session in July. This would provide an excellent opportunity to continue this important conversation and to address other important topics such as international humanitarian law. Finally, this year’s annual progress report should reflect the start of focused discussions on international law, and it should lay out concrete next steps and topics to be discussed in 2024 and 2025. I thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, Switzerland, for your focused statement. I would also encourage delegations which wish to put their statements on the OEWG website to send them to the Secretariat, because I am hearing a lot of very thoughtful interventions. So if you want to share your views with everyone, send them to the Secretariat and they will put them on the OEWG website, so that everyone can look at your statements. That is needed to have that conversation here and reach some understandings, common understandings, and convergence, hopefully. Thank you, Switzerland. Czechia to be followed by Estonia, please.
Czech
Thank you, Mr. Chair. The Czech Republic aligns itself with the EU statement and wishes to highlight the following in its national capacity. Mr. Chair, distinguished colleagues, for more than a year now we have been witnessing Russia’s flagrant violation of fundamental principles of international law through its continued unjustified and unprovoked act of aggression against Ukraine, undermining international security and stability. As we have emphasized in our previous statements, the Czech Republic strongly condemns these actions. It has been previously consensually confirmed by the GGE and OEWG report 2021, as well as in the first annual progress report of 2022 of the current OEWG, and also approved unanimously by the UN General Assembly that international law, and in particular the UN Charter, are applicable to cyberspace. It is indeed timely to start focusing on the application of existing rules and principles of international law, in particular the UN Charter, to cyberspace, and I would therefore like to thank you, Mr. Chair, for proposing a focused discussion. Mr. Chair, let us stress that what we are trying to do here is to develop a common understanding of how existing international law applies to cyberspace, and only then target potential gaps in that understanding, because we already have an existing legal framework. We believe that it would be appropriate for the states to put on record their understanding of how international law applies to cyberspace before they put on the table proposals for a new legally binding instrument. The Czech Republic finds it premature to ask for a treaty at this moment. Mr. Chair, a number of states have already publicly shared their views on the applicability of international law to cyberspace. The Czech Republic is currently in the process of finalizing its own national position and is fully aware of the challenges that this entails. We believe that the publication of national positions is one of the key steps toward developing a common understanding. We are aware that developing such a position requires certain capacities and that not all states may have the capacity to do so. We therefore consider it important that states that may need to do so express what challenges could be targeted through capacity building in order to receive tailored assistance in developing their own national position and to reflect on what might be relevant in order to meaningfully engage in substantive discussions in the near future. An inclusive participation of the broadest range of states is essential in order to reach a common understanding. In this connection, it is important to acknowledge the meaningful and broad engagement of the multistakeholder community in cyberspace. In the field of international law in particular, we can benefit from the expert briefings or exchange of views as we can see in the side events that take place throughout this week. Mr. Chair, regarding the future discussion on the applicability of international law to cyberspace, the Czech Republic would like to reiterate its strong support for the working paper submitted by Canada and Switzerland last year, which outlines an appropriate agenda for future discussions on international law. At the same time, not only in light of Russia’s ongoing aggression in Ukraine, we would like to reiterate the need to include international humanitarian law in the list of topics for a focused discussion. This discussion is not limited to basic principles but encompasses all aspects of IHL. Such a discussion will allow us to develop a common understanding on how to best protect civilians and civilian objects, especially critical infrastructure, and to reach a better understanding of what activities are prohibited or unacceptable during an armed conflict. We would also like to support the idea of an inter-sessional meeting dedicated to a focused discussion on international law, including expert briefings held either hybrid or virtual to ensure broad participation. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you, Czechia, for your statement. Estonia, to be followed by Australia, please. Estonia.
Estonia
Thank you, Mr. Chair, for giving me the floor. Estonia aligns itself with the statement by the European Union and adds the following in its national capacity. Firstly, we would like to thank you, Chair, for the guiding questions put forward for this session that will definitely help to start more focused discussions on concrete topics on international law. Our remarks today are complementing our domestic views on the interpretation of international law, which we have published previously. Estonia is a strong supporter of the application of international law to state behavior in cyberspace. We reiterate that the existing international law, including the UN Charter, international humanitarian law, and international human rights law, is applicable also in cyberspace. The applicability of international law in its entirety in cyberspace has by now been affirmed several times by the UN General Assembly and the OEWG consensus reports. We agree with Sri Lanka, Canada, Switzerland, and many other countries that before we develop new rules, we must have a better understanding of how international rules apply. The discussions we are having here today are very useful for developing such an understanding. Estonia underlines that states are called upon to avoid and refrain from taking any measures not in accordance with international law. In this light, we underline again our condemnation of Russia’s unjustified military aggression against Ukraine, which has been accompanied by a significant increase in malicious cyber activities, including targeting critical infrastructure and conducting information campaigns. The international community needs now more than ever to join forces to strengthen the international rules-based order and adhere to it also in cyberspace. The UN Charter is undoubtedly one important centerpiece in international law. It includes some of the most important rights and obligations for relations between states, among them also the topics raised by the Chair as a starting point for our focused discussions. Allow me to reiterate the Estonian position on these selected topics. The UNGGE reports have underscored that sovereignty and the international norms and principles that flow from it apply to state conduct of ICT-related activities. States have territorial sovereignty over the ICT infrastructure and persons engaged in cyber activities on their territory. However, states’ right to exercise sovereignty on their territory is not unlimited. States also bear the responsibility to comply with legal obligations flowing from sovereignty. For example, the responsibility not to breach the sovereignty of other states and to take reasonable efforts to ensure that their territory is not used to adversely affect the rights of other states. The principle of sovereignty is also closely linked with the principle of non-intervention. When assessing whether a cyber operation constitutes an unlawful intervention into the external or internal affairs of the other state, the element of coercion is a key factor. Cyber operations that aim to force another nation to act in an involuntary manner or to refrain from acting in a certain manner and target, for example, the other nation’s national democratic processes, such as elections or military security or critical infrastructure systems, could constitute an unlawful intervention. The UN Charter also obliges all states in the name of peace and security to seek to settle possible disputes between states through negotiation, inquiry, mediation, conciliation, arbitration, judicial settlement, resort to regional agencies, arrangements, and other internationally lawful peaceful means. Following the framework of peaceful settlement of disputes would help to peacefully solve conflicts, avoid escalation, and essentially strive for stability in cyberspace. Estonia also stresses that the use of cyber operations during armed conflict is subject to the rules and principles of IHL, just like the use of any other weapon, means, and methods of warfare. It is as important to keep in mind the principles of international humanitarian law, noted also in the 2015 GGE report and the annual progress report from this group from last year. The fundamental principles of proportionality, distinction, humanity, and necessity are important tools to help reduce risks and potential harm to both civilians and civilian objects, like, for example, schools and hospitals in the context of armed conflict. IHL and its core principles offer a much-needed additional layer of protection, especially to civilians in the context of armed conflict. We would like to repeat that by no means can the application of IHL in cyberspace be seen to legitimize the militarization of cyberspace. Just yesterday, Estonia, Indonesia, Rwanda, and Switzerland held a successful side event in a cross-regional format on the principles of IHL applicable to the use of ICTs. The high interest from participants and lively discussion reconfirmed the great interest and need to further study these principles and exchange views, however different they may be, on how to apply them to the use of ICTs. Mr. Chair, Estonia highly values this opportunity to express our understanding of international law to this group, and we have listened and continue to do so with great interest on how other states see the existing international law can apply to cyberspace. We also welcome countries who have published their views on the application of international law. I looked at one of the recent repositories, and I saw that 26 countries have done that already. And such a useful overview of these can be found, for example, on the Cyber Law Toolkit website. Kenya mentioned before in their comments the usefulness of such a repository. We would also here like to reiterate our support to the Canadian-Swiss concept paper. We fully support previously made comments and proposals on the need for capacity building on international law, such as underlined by many countries, such as Thailand. We also do see that the discussions on international law would merit greatly from engagement of the expertise from different stakeholders. We therefore are in full support of the expert briefings proposed by the Netherlands, UK, and others. We also support the UK’s proposals on agreeing on a roadmap for the discussion on international law and more dedicated time to international law discussions, as underlined by South Africa and others. Thank you very much, and we are looking forward to the opportunity of further discussions. Thank you.
Ambassador Gafoor
Thank you very much, Estonia, for your statement, and thank you for reminding us about the national submissions which are on the OEWG website on the issue of national views on international law. I think you mentioned 26 countries. Well, I certainly hope that the numbers will increase, and I think it will as we continue our focused discussions in this process. Now, Australia, to be followed by Chile.
Australia
Thank you, Chair. First, I wish to express Australia’s gratitude to you for directing this session’s discussion to specific topics of international law, as was agreed in last year’s Annual Progress Report. We are delighted to be having focused discussions on international law. Whilst we welcome your direction to discuss the first cluster of topics in the report, Australia observes that there is simply not enough time to sufficiently cover each topic in the allocated time. Accordingly, I will focus my remarks on the first topic in your list, the application of international law, including the UN Charter, and go on to address the guiding questions you have asked. The vast majority of states today and yesterday afternoon have reminded us that all states have already agreed that international law, including the UN Charter in its entirety, applies in cyberspace. For Australia, and as our distinguished delegate from Australia also stated, this means the entire corpus of existing international law applies. That is, treaties, custom, and general principles. The application of international law, generally and to cyberspace specifically, ensures stability and predictability in states’ relations with each other. Its purpose is to protect us all from malicious actors and provide a mechanism to hold states accountable for their actions. During this session, Chair, we have heard calls for a treaty. There was an accusation that many states who do not consider it sensible to commence treaty negotiations were simply wanting to keep their hands free. However, Chair, I would like to point out that no states have their hands free in cyberspace. No states have already agreed to a treaty that ties all of our hands and that governs our relations with each other. Chair, that treaty is the UN Charter. The Charter does not only contain high-level principles. It also contains binding obligations. The reason the UN Charter is already the foundational treaty for regulating state conduct in cyberspace is because the challenge we face is not further regulation of technology, as was raised by most states during the session on threats. The technology and the threats they pose are continuously evolving. What we need to address is state use of that technology. Chair, Australia also observes that the Charter already regulates the very issues that were outlined in the proposal for a new treaty. As numerous states have articulated during this item, in Articles 2, 3, and 33, we have our obligation to resolve disputes peacefully and the mechanisms for doing so. In Article 2, 4, we have the obligation to refrain from the threat or use of force. And Article 2, 7 encapsulates the customary international law obligation not to intervene in the internal or external affairs of another state. These obligations apply to cyberspace just as they do in the physical realm. And the matter of capacity building is being addressed right now. We do not need to delay that conversation by entering into treaty negotiations. We need to continue these discussions through a single, permanent, regular dialogue, a matter Australia will address on Friday during the relevant agenda item. Now, Chair, we turn to your question concerning potential gaps in the legal framework that regulates states’ conduct in cyberspace. In Australia’s view, this question preempts the exercise we must engage in first. As Sri Lanka, Thailand, Canada, Sweden, Austria, and many others have reminded us, we need to deepen our common understanding of how international law applies. This exercise goes towards increasing the peace and stability we are all here to ensure. States expressing their views on how international law applies in cyberspace is not only a normal part of the development of international law, as Switzerland reminded us. Such expressions of positions fortify international law by contributing to the development of custom. Seeking to address gaps without first giving due consideration to the legal framework we already have is respectfully, but quite frankly, potentially dangerous. In Australia’s view, it is like sending a patient for surgery without first determining if that person is even ill or injured. With this assessment, I would now like to contribute to how you, Chair, may chart our way forward. In Australia’s experience, there are two components to deepening how international law applies in cyberspace. First is to increase subject matter knowledge, and second is to have more opportunities to apply those international law frameworks. To increase subject matter knowledge, Australia is guided by the experts, including practitioners and academics. To bring this to the OEWG, Australia supports the proposals from Estonia, Switzerland, the UK, and Canada, and others, that we invite diverse experts to brief us on their views on how international law applies in cyberspace. This could be done at an informal session. Australia would be happy to work with a broad sector of states to create an objective list for your consideration. We encourage states to discuss possible experts with us this week in the margins, or submit suggested experts directly to you. To increase opportunities to apply international law frameworks to cyberspace, states need to come together to share views on specific questions or scenarios. We welcome initiatives such as the regional consultations by the ICRC on international humanitarian law and cyber, which facilitate states and NGOs coming together to raise technical legal questions that warrant further consideration. This OEWG is another forum in which we are exchanging views. While general statements on specific topics are a necessary step, we need more time to discuss, and more notice on specific guiding questions on the topics agreed as a roadmap in the annual progress report. In these discussions, Australia joins the long list of countries, including Singapore, Switzerland, Sweden and the Nordic countries, Austria, and Canada, that consider it would be fruitful to come together intersessionally in May or June to have a dedicated session on international law, ideally in a hybrid or virtual format to enable broad participation of legal experts from capitals. This could be done with a view of developing a non-paper on areas of convergence, which we have already seen in the national views that have been expressed and published, as noted by our delegate from Australia. Even where views differ, Chair, developing understanding of respective positions can increase predictability and reduce the risk of miscalculation and potential escalation in state conduct. Finally, Chair, on to your question regarding capacity building. Australia actively supports states in our regions to attend cyber law international courses and is proud to support participation by women in our region in the Women in Cyber Fellowship. We are particularly proud to support these women today and recall it on International Women’s Day. And while we and others in this chamber, in chambers in this building, come together to recognize the progress that has been made in women’s participation on the international stage and consider what more can be done, we know that more can be done on capacity building and international law as well. In this regard, Australia is here to listen, to hear, and to do the work. Thank you, Chair.
Ambassador Gafoor
Thank you very much, Australia. Chile to be followed by New Zealand. Chile, please.
Chile
Thank you, Mr. Chair. Chile believes that international law, and in particular the United Nations Charter, provides the normative framework applicable to regulate the behavior of states in cyberspace, including humanitarian international law, human rights, and those laws which regulate international responsibilities of states, since they are essential to maintain the necessary peace and stability to promote an open, secure, stable, accessible, and peaceful situation for ICTs. As you can see in the first report of the Open-Ended Working Group on the security of ICTs and their use 2021-2025, states reaffirmed that international law, and in particular the UN Charter, are fully applicable. Thus, states in using ICTs, in addition to observing the Charter, must also apply the principles and obligations contained therein, such as sovereign equality among states, peaceful settlement of international disputes, so as not to endanger international peace, security, and justice, to refrain in international relations from the threat or use of force against the territorial integrity or the political independence of any state, respect for human rights and fundamental freedoms, and non-interference in the internal affairs of other states. It also seems fundamental to us for the group to recognize the need to continue studying and discussing how and when the principles of international humanitarian law can be applied to the use of ICTs by states. This will help us generate common understandings as to how we can protect the civilian population and to be clear as to what actions are prohibited or unacceptable during a conflict situation. We reaffirm that international humanitarian law applies to cyberspace and that the explanation of how it applies to cyber operations in the framework of armed conflict is a priority in our future debates. Now, in order to continue developing and studying the application of international law to cyberspace, we believe that it is necessary to continue promoting international cooperation, mutual assistance, and exchange of information, so that states can share their experiences and knowledge on that subject. In this manner, the international community will be able to lend comprehensive, sustainable, and long-term technical support to the various states requiring it. In conclusion, we also believe that regional bodies have a significant role to play in developing capacities on this subject. In this regard, we wish to recognize the fundamental role of our region through the cybersecurity program of the Inter-American Counterterrorism Committee of the OAS. Since 2017, it has been developing an intense and permanent work of training of government officials on the application of international law and cyberspace. Thank you, sir.
Ambassador Gafoor
Thank you, Chile. New Zealand, please.
New Zealand
Aotearoa New Zealand welcomes the opportunity to share our views on how international law applies to state activity in cyberspace. New Zealand aligns with the working paper circulated by Canada and Switzerland and its call to prioritize the UN Charter, state responsibility, peaceful settlement of disputes, and international humanitarian law for focused discussions during the OEWG Programme of Work this year through dedicated sessions, including intersessionals, continued capacity building activities, and ongoing briefings. New Zealand’s national statement on the application of international law in cyberspace, published in 2020, articulates our position on many of these issues, and we welcome others’ publication of national statements to help us advance these common understandings. In our view, existing international law applies online as it does offline and is well-placed to deliver what we need to regulate states’ conduct in cyberspace, even if the issues that it covers are novel and still developing. We reaffirm this includes the United Nations Charter and the requirement to settle disputes by peaceful means, customary international law rules and principles, international humanitarian law in situations of armed conflict, and the application of international human rights law. We would like to highlight a couple of areas to advance our common understandings on the existing applicable legal framework. First, we would like to affirm that the UN Charter and customary international law rules concerning the use of force apply to state activity in cyberspace. As others have said, relevant obligations include the requirement to settle disputes by peaceful means, prohibition on the threat or use of force against the territorial integrity or political independence of any state or in any other manner inconsistent with the purposes of the United Nations, and the right of self-defense against an imminent or ongoing armed attack. In this regard, state cyber activity can amount to a use of force under international law if it results in effects of a scale and nature equivalent to those caused by kinetic activity which constitutes a use of force at international law. Therefore, it follows that cyber activity that amounts to a use of force will also constitute an armed attack for the purposes of Article 51 of the UN Charter if it results in effects of a scale and nature equivalent to those caused by a kinetic armed attack. We also reiterate international humanitarian law applies to cyber activities during armed conflict, and a cyber activity may constitute an attack for the purposes of IHL where it results in death, injury, or physical damage, including loss of functionality equivalent to that caused by a kinetic attack. We reaffirm all cyber attacks must comply with the principles of military necessity, humanity, proportionality, and distinction, and that civilian infrastructure should not be targeted. In reiterating the application of IHL, we share the views of others who have said this in no way legitimizes or justifies armed conflict but aims to reduce human suffering. Another important aspect of law applicable to cyberspace is international human rights law. We affirm the importance of obligations to protect and respect human rights online, including the right to freedom of expression and the right not to be subjected to arbitrary and unlawful interference with privacy. We would welcome further discussion and exchange of views on this important topic. Existing international law, together with agreed global norms of responsible state behavior online, in our view, already regulates state activity in cyberspace. As other states have also identified, voluntary norms do not exist in a legal vacuum. We do not agree with a suggestion put forward by Russia yesterday that we can only talk about state accountability in the context of a new legally binding instrument. In our view, this proposal undermines the existing agreed framework on responsible state behavior and the previous work of the OEWG and GGEs, the work of this OEWG, and the development of the Program of Action as a permanent mechanism for the implementation of agreed norms. An inability or unwillingness to discuss state accountability undermines the very principle on which there is consensus that existing international law applies in cyberspace. Like other delegations before me, we do not see the need for a new legally binding treaty but should focus our discussions on developing common understandings on interpretation and implementation of the existing legal framework. Chair, in response to your question as to whether there are any gaps, we reiterate that in our view and as others have said, any gaps are in adherence to existing international law and in the implementation of the norms. When implemented, we consider these are sufficient to achieve responsible state behavior in cyberspace. We understand these are complex questions, and in some cases, we acknowledge this requires the development of further state practice on how the existing international law framework applies. We support the request for further dedicated discussion on how international law applies in cyberspace in virtual or hybrid format ahead of the July session to enhance the participation of all delegations and legal advisors and look forward to continuing these discussions. Thank you.
Ambassador Gafoor
Thank you, New Zealand. Germany, please.
Germany
Thank you, Chair, for facilitating this important focus discussion on the modalities of the application of international law in cyberspace. Germany fully aligns itself with the statement made by the Delegation of the European Union and would like to add a statement in its national capacity. Firstly, in light of the various legal questions that will need to be addressed, Germany would like to thank the Chair for the careful selection of concrete guiding questions which allow us to commence with a substantive exchange with the aim of building a common understanding. With reference to the consensus within the GGE and OEWG, according to which international law is applicable in cyberspace, Germany highly appreciates the continued discussion on how the existing robust and comprehensive international legal framework is applied in cyberspace. In order to lay the foundation for a solid chapter on the legal aspects in the Annual Progress Report, Germany supports the proposal by the UK, the Nordic countries, Canada, South Africa, Australia, Switzerland, and other states regarding international focused discussions with topics identified in advance, enabling a substantive legal exchange among diplomats, legal experts, and stakeholders. As the UN Charter has received explicit reference in all GGE and OEWG reports since 2013, Germany believes the UN Charter in its entirety to constitute an ideal starting point for further extensive discussions in this OEWG, followed by the topics listed in the Canadian-Swiss concept paper, which Germany fully supports. As part of the acquis, member states have repeatedly reaffirmed that the UN Charter is applicable and essential to maintaining peace and stability and promoting an open, secure, peaceful, and accessible ICT environment. Germany is among the states that have published a national position paper on the application of international law in cyberspace, addressing the UN Charter as well. The UN Charter fulfills a core function with regard to the maintenance of international peace and security, also in relation to cyber activities, and applies without any reservation in the context of cyberspace. In this context, Germany welcomes the increasing number of national position papers on the application of international law in cyberspace. The publication of national positions constitutes a solid foundation for further fruitful legal discussions and contributes immensely to the ongoing discussion on the modalities of application of international law. In this context, we would like to put emphasis on the importance of fostering capacity building for states in the area of international law and cyberspace based on their needs. Germany is ready to offer focused capacity-building efforts to further advance legal cyber expertise, and welcomes all endeavors in this regard and encourages states to assess and publish their national positions on the application of international law in cyberspace. Lastly, we would like to refer to the guiding question of the Chair concerning possible gaps within the legal framework with regard to the regulation of states’ conduct in cyberspace. Germany would like to use this opportunity to comment on the notion put forward by a member state, according to which there were no legal grounds for an automatic application of international law in cyberspace. This notion is misleading, as uncertainties as to how international law is applied under new circumstances are generally addressed by having recourse to the established methods of interpretation of international law. Let me reiterate, Germany sees no substantial legal gaps that would justify a treaty process or render such a process necessary. Thank you, Chair.
Ambassador Gafoor
Thank you, Germany, for your statement. Islamic Republic of Iran, to be followed by Japan. Iran, please.
Iran
Thank you very much, Mr. Chair. Mr. Chair, when discussing international law and cyberspace, some countries claim that existing international law can be applied to cyberspace, rejecting the need for new laws. However, opinions differ on how to apply international law to cyberspace and whether it is adequate. Despite repeated arguments, a definitive answer to this issue remains elusive. Furthermore, the prevalence of cyber attacks raises serious questions and doubts about the sufficiency of current international law in addressing these issues. To address this, a legally binding document is required to define and compile necessary terminology, including cyber weapon, cyber attack, the responsibility of non-state actors in cyberspace, prevention of use or threat to use of force, peaceful settlement of disputes, attribution, and last but not least, the topic of international cooperation. Besides many advantages, including contributing to a concretely safer cyberspace, this will lead to a common understanding of the issue. Mr. Chair, during the first annual progress report of the OEWG, states proposed an open and non-exhaustive list of topics for further discussion on their international law. It was recommended to engage in focused discussions on these topics from their non-exhaustive list, as well as proposals contained in the 2021 OEWG report and chair summary, which were relevant during the fourth and fifth sessions of the OEWG. To implement this recommendation, the OEWG must ensure all topics of the non-exhaustive list, as well as proposals contained in the 2021 OEWG report and the chair summary, are discussed in a balanced and equal manner. A selective approach to these topics is not acceptable. Therefore, by the non-exhaustive list of topics adopted in the annual progress report in paragraphs 15A and 15B, and statements made under the agenda item international law, as well as national positions published by member states, we suggest that the following topics be prioritized for further focused discussions during the 2023 sessions of the OEWG: 1. The possibility of additional legally binding obligations. The Non-Aligned Movement, with 120 member states, acknowledged the need to identify legal gaps in international law through the development of an international legal framework specific to the unique attributes of the ICT environment in its working paper submitted to the first OEWG. Therefore, this topic deserves further consideration. 2. Principle of sovereignty guided and aligned by the principles of sovereign equality, states’ territorial sovereignty, and national jurisdiction over the cyberspace ownership, leadership, and taking into account concentration on states’ national priorities in policymaking. 3. Principle of non-intervention in the internal affairs of other states. Views on what constitutes a violation of the principles of sovereignty and non-intervention in cyberspace differ, and therefore it needs further discussion in the OEWG. Finally, Mr. Chair, regarding the suggestion to convene hybrid meetings, my delegation cannot support any proposal that contradicts the modalities adopted for the OEWG and the UN practice, which emphasizes the importance of holding formal meetings in person. I thank you, Mr. Chair. Thank you.
Ambassador Gafoor
Thank you, Islamic Republic of Iran, for your statement. I give the floor now to Japan, please.
Japan
Thank you, Chair. Japan would like to reiterate its position that existing international law, including the United Nations Charter in its entirety, is applicable to cyber operations. As for Russia’s suggestion on a new legally binding instrument, we do not believe there is a need for a new legally binding instrument at this stage. We would like to recall that GGE reports of 2013 and 2015, agreed by consensus by the governmental experts, affirm that existing international law, in particular the UN Charter in its entirety, is applicable to cyber operations. By the endorsement of the reports by consensus at the UN General Assembly, this affirmation has become the consensus view of all UN member states. At this stage, as many other delegations have stated, we should rather focus on deepening discussion on how international law applies to cyber operations. Therefore, we support discussions focused on specific topics of international law, based on the Annual Progress Report’s recommendations. In this regard, I would like to thank Canada and Switzerland for their constructive roles in advancing the focused discussion. Japan believes that the OEWG should deepen the discussion on international law applicable to cyber operations in peacetime. An act of causing physical damage or loss of functionality by means of cyber operations against critical infrastructure may constitute an unlawful intervention, depending on the circumstances, and at any rate, it may constitute a violation of sovereignty. Various opinions were expressed on the relationship between violation of sovereignty and unlawful intervention at the six GGE and the OEWG. Based on prior discussions in the GGE and OEWG, a common understanding should be fostered that cyber operations which may cause physical damage or loss of functionality against critical infrastructure will not be tolerated under international law. We hope that the announcement of a basic position on international law applicable to cyber operations by the governments of many states and the application of international law in international and domestic courts and tribunals will deepen the shared international understanding on how international law applies to cyber operations. In this regard, as Estonia, New Zealand, and others have noted, we would like to encourage states to announce their basic position through the UNIDIR portal site and the annual progress reports of the OEWG. This will help to promote a common understanding among countries and increase transparency, which will also contribute to dialogue and capacity building. Capacity building on rulemaking is also important. In this context, Japan has provided capacity building programs, including training programs on international law and policy planning for cybersecurity provided by Japan International Cooperation Agency, JICA. Thank you very much.
Ambassador Gafoor
Thank you very much, Japan, for your statement. Distinguished delegates, we have about 20 more speakers under the topic of international law, and I think that’s good because we need to have this conversation. I also note that the interventions are very focused and very detailed in response to my guiding questions, so I thank all of you who have spoken so far. It is my intention now to suspend the meeting for five minutes so that we begin the commemoration of International Women’s Day exactly at 11:30 in this working group. I will await the arrival of Under-Secretary-General Izumi Nakamitsu, and we will then begin sharply at 11:30. I do ask all of you to not leave the room until 11:30. We will resume at 11:30 sharp to commemorate International Women’s Day. Thank you. Distinguished delegates, it’s a great honor for me as Chair of the Open-Ended Working Group on ICT Security to convene this commemoration of International Women’s Day in the Open-Ended Working Group. It gives me great pleasure now to invite Under-Secretary-General and High Representative for Disarmament Affairs to make her remarks. Mrs. Nakamitsu, please.
Under Secretary General and High Representative for Disarmament Affairs (Izumi Nakamitsu)
Thank you very much, Ambassador Gafoor. Your Excellency, Ambassador Gafoor, Excellencies, ladies and gentlemen, happy International Women’s Day. Thank you. And thank you very much, Ambassador Gafoor, for inviting me to offer just a few minutes, a very brief remarks on the occasion of this very important International Women’s Day 2023. This day is an opportunity to reflect on the progress made and the challenges we continue to face to advance gender equality and empower women in all walks of life. This year, the UN’s theme for International Women’s Day is Innovation and Technology for Gender Equality, which is also the focus of the 67th session of the Commission on the Status of Women, happening in parallel here in New York. I just came from the GA Hall with a lot of energy. You know, you get really encouraged being in that energetic GA Hall. We have seen some positive trends in this area in recent years. Let us admit that and let us congratulate ourselves for that. I want to applaud this working group in particular on its successful efforts to enhance women’s equal and meaningful participation in international cybersecurity discussions. According to my office’s tracking, you know that we are tracking data and we are also publishing the data. Last year, 43% of speakers in the first session of this working group and 49% of speakers in the second session were women. And this represents excellent progress towards parity. Women in Cyber Fellowship has proven to be a good practice in raising the profile of women in cybersecurity. I hope the fellowship’s success can be replicated in other areas of international security. Concerted action, targeted action actually can make an impact. Despite these positive shifts, considerable obstacles to achieving women’s equal representation in innovation and technology unfortunately remain. Women in technology continue to face gender bias and discrimination in the workplace and are underrepresented in leadership positions. We cannot and we will not tolerate inequalities that have existed in the offline world for centuries being replicated and amplified in the cyberspace. And we cannot afford to leave women and girls behind as technology goes forward and we will not leave them behind. Excellencies, distinguished participants, the work that you are doing in this working group today can significantly contribute to gender equality and women’s empowerment. I hope the cybersecurity community continues to create space for women’s equality and leadership in technology and innovation. Remember, this is not a woman’s issue, but an issue that is critical for the security and well-being of all of us. I thank you very much for your attention. Thank you.
Ambassador Gafoor
Thank you very much, Mrs. Nakamitsu. If you will allow me, I’d like to make a few reflections as well. First of all, I want to say, Izumi, my dear friend, that you are a role model and inspiration for all of us here, not just for the women but also for the men, because you deal with some of the most challenging issues on the agenda of the United Nations, and you do it with such grace, effortlessness, and wisdom. Therefore, I want to, on this occasion, thank you and also recognize your many contributions and achievements, as well as those of your staff. In that context, I want to also thank Catherine Priceman, who sits next to me. Thank you, Catherine, for supporting the work of this working group, and I know all of you would know that she has been working hard right from the beginning. I also want to take this opportunity to acknowledge the women in my team, Gillian Goh and Clarice Lim, who also… And I really am grateful that I have such wonderful people in my team. But I also want to acknowledge each one of you, the women representatives here. You have made an immense contribution, and if I can kindly beg you to rise for a moment so that we can recognize and celebrate your contributions as well. So please, please rise. Do not… Please rise. Thank you. You know, I have often said that the working group is an exercise in confidence-building measures. And I think women play an important role in building confidence and in rebuilding confidence, as may be needed in some cases. Women play critical roles as leaders, as peacemakers, as consensus builders. And we need your energy, intellect, and ideas for this process in order to build convergence. Because what we are trying to do, like what we are trying to do on a range of issues at the United Nations, is to build convergence so that the United Nations is stronger, the international community is better off, and our people live safe, secure, peaceful, and prosperous lives. So, over the last few days, the whole issue of gender and the importance to address gender in the context of our work has come in the context of various agenda items. And it is important that we do pay some attention to that and make that a part of our work. As we work to implement and improve the cumulative and evolving framework of responsible state behavior in cyberspace, it is also important that we future-proof this framework so that it is inclusive, it is resilient, and it achieves greater equity for all. In particular, gender equity, gender equality, and closing the gender digital gap. Let me say that it is a great honor for me, as Chair, to be involved in the work of this working group, and I count on all of you, especially the women delegates, to help me find consensus in July. Now, at this point of the commemoration, I’d like to invite all the women representatives to gather for a family photo in the presence of Ms. Izumi Nakamitsu. So, please go to the back of the room where you see these terraces so that we can fit everyone in the family photo. And please don’t forget to put the hashtag OEWG and IWG in your social media postings if you intend to put any photos. So, the commemoration is suspended, and we will go back for a family photo with Ms. Izumi Nakamitsu. I invite all the women representatives to join this photo. Thank you very much. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Dear colleagues. Dear colleagues. Dear colleagues, if you could kindly spread out into the aisles. No, I will. I will. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Thank you. Distinguished delegates, thank you very much for your cooperation. I sensed so much energy and laughter in the room. It’s very heartening. Let’s channel all that energy, not only to our work but also to finding consensus on a progress report in July. And I’d like to once again thank you all for your participation in this very brief but meaningful commemoration event of the Working Group. We’ll now return to the speakers list. I do have a list of speakers, but we will go through them. It’s an important discussion, but I do encourage you, if you are in a position to summarize your statement in a succinct way and make your statements available to me, as well as to consider posting your statement on the OEWG website by sending it to the Secretariat. That way, we will be able to see your full statement, and it will be part of the records of the Working Group, so to speak. So, Croatia now, to be followed by Costa Rica. Croatia, please.
Croatia
Thank you, Chair, and since it’s our first intervention, we would like to thank you and your whole team for dedication and hard work, and also for the revised non-paper on points of contact directory. We appreciate a lot the informal inter-sessional meeting of POC held last week, and would like to encourage conducting more inter-sessionals on topics such as the application of international law in cyberspace and on capacity building efforts. And happy International Women’s Day; we wish that all women are treated with dignity, respect, and equality. Let me continue by stating that Croatia aligns itself with all interventions of the European Union, and before expressing the national position on the international law section, we would like to briefly reflect on exchanges during the last two days and support some interventions. So you will actually get three in one intervention. As stated already in July last year, we do see ransomware as a serious and rising threat to our societies and economies, and we need to address it in our discussions and in the annual progress report. We would like to recall the intervention of Denmark regarding cyber attacks and malicious cyber behavior against our democratic institutions and processes, and we would like to emphasize Vanuatu’s remark that cyber threats do not recognize borders, and that we should face them together. So the hashtag of this session is stronger together. And together also means hand in hand with multistakeholder communities, since good cooperation and exchanges between governments, NGOs, academia, and the private sector will benefit our mutual resilience. In this spirit, we would like to support interventions by Canada, the Philippines, Argentina, Bangladesh, and many others on the valuable contribution of stakeholders to our discussions. We would also like to recall interventions by Indonesia on the importance of adopting national cyber security strategies and establishing computer emergency response teams, and Mauritius’ comment on their role in implementing norms. This could be one of the topics for capacity building efforts, but more on that on Thursday. Moreover, we strongly support calls by Argentina, Australia, Ecuador, Uruguay, Costa Rica, Ireland, and many, many others for greater involvement of women and mainstreaming gender perspective into cyber policies, and by Chile concerning the impact that cyber activities have on vulnerable groups. We agree with Portugal on the need for due diligence and a code of conduct for responsible behavior in cyberspace. And we need to focus first on the implementation of existing norms and principles. In this regard, we would like to support guidelines which were mentioned by Canada, and also checklists for norms implementation mentioned by Singapore. Furthermore, we agree with France on the need to have security by design principles for products, and with Japan on cooperation with the private sector, which is key for the protection of critical infrastructure. When it comes to international law, Croatia would like to reiterate its support for the excellent concept paper by Canada and Switzerland on a practical approach to international law, and the suggestion to have dedicated sessions, both formally and intersessionally, on this subject, and support the Swedish proposal in this regard. We believe this is also a very interesting area for capacity building efforts where we see a valuable role for academia and civil society. For example, both Tallinn Manuals were written by an international group of legal scholars and practitioners, and they’re still quite valuable guidelines for discussions on the applicability of international law in cyberspace. Then again, the fact that the work on the next 3.0 version of the manual is already in progress only proves the rapidly changing security landscape and related emerging legal issues. It also clearly indicates the necessity for us to engage more closely with academic experts in this respect. We have all recognized the existing key and applicability of international law in cyberspace through the adoption of last year’s annual progress report, but also through the final report of the previous Open-Ended Working Group. Now we need to talk about the practicalities of the implementation. So we applaud the states that have already done so and encourage all other states to share their national positions, but also the challenges that they are faced with in the implementation. We agree with states that have mentioned that we need to deepen our common understanding of the implementation of international law in cyberspace. Chair, cyberspace and physical space are both part of one world. Cyber is not part of a parallel universe, so rules of international law, including the UN Charter in its entirety, that are applicable offline are also applicable online, including the principle of sovereignty. And like in the physical world, the violation of international law and the UN Charter in cyberspace needs to be sanctioned, especially when it is used in an armed conflict. Regrettably, Russia’s unprovoked and unjustified aggression against Ukraine that clearly started with several malicious cyber activities has challenged the foundation of the global security architecture and eroded the rule-based international order, with profound consequences for years to come. Croatia stands firm, like many, in supporting the territorial integrity, independence, and sovereignty of Ukraine within its internationally recognized borders, and we strongly condemn using ICT for aggressive purposes and in particular for harming civilians. Thank you, Chair.
Ambassador Gafoor
Thank you. Thank you, Croatia. Costa Rica, to be followed by Cuba, please. Costa Rica, please.
Costa Rica
Thank you very much, Mr. Chair, and happy International Women’s Day to the women delegates in this room. We recognize that much still remains to be done, but I see that many of us working on cyber security are women, and we have to continue making progress. We’re seeing that with our levels of participation in this room. Costa Rica reiterates its conviction that cyberspace is ruled by international law, including the Charter of the United Nations as a whole, international human rights law, international humanitarian law, and international criminal law. Costa Rica, however, would like to focus its statement on international humanitarian law, that is, the norms that all states have agreed upon in order to preserve a minimum of humanity in times of war. In the 2022 progress report, we recognized the need to continue to study how and when to apply the principles of IHL to the use of ICTs by states. International humanitarian law provides norms for the purpose of protecting civilians and civilian infrastructure against damage, including through the use of ICTs by states. We must respect these norms and build a common understanding of how they apply to cyber operations during armed conflict and exchange practices on how to operationalize these legal limits, which is essential to protect civil society. We must also recognize how international humanitarian law addresses the growing participation of non-state actors in cyber operations during armed conflict, as private information hackers, terrorists, or all of them must respect international humanitarian law during war. Mr. Chair, states need to continue to develop knowledge and share experiences to build common understanding. Thus, we value the current efforts at training, and we encourage other countries to support them. Costa Rica would like to propose to you, Mr. Chair, that you organize informal intersessional consultations on matters of international humanitarian law, where experts from different parts of the world may inform delegations and therefore contribute to capacity development. That intersessional discussion could help us to identify common understanding at the formal meetings collectively. Thank you.
Ambassador Gafoor
Thank you very much, Ambassador, for your statement. Cuba, to be followed by the United States. Cuba, please.
Cuba
Thank you, Mr. Chair. Cyberspace is an extremely dynamic space in which the nature of events, full of controversy, is different from other areas that have an impact on international security. For example, the determination of the origin of incidents related to the use of ICTs faces difficulties, and unilateral attributions are questionable since there is no multilateral mechanism for determining impartially and for sure the origins of incidents. Nor do we have a common terminology to facilitate understanding among states when it comes to cyber incidents and their responses. In that context, we note a trend toward taking a simplistic approach to the applicability of existing international law to ICTs and a rejection of the need for new norms. In keeping with the above, there is an attempt to force consensus on areas that seek to equalize a cyber attack with a traditional armed attack to try and justify, in the context of cyber security, the presumed applicability of self-defense provided for in Article 51 of the UN Charter. Our delegation firmly opposes this approach. It’s also a matter of strengthening the concept of the applicability of international humanitarian law to the use of ICTs in the context of international security. We recall that the conventions which are part of international humanitarian law were agreed to in order to address armed conflict scenarios and are only applicable to those cases. To assume that such norms apply to ICTs would entail tacitly accepting the possibility of there being an armed conflict scenario in that arena. It would contribute to the militarization of cyberspace and would be a first step toward equalizing a cyber attack to a traditional armed attack. All of the above strengthens our conviction that we cannot pretend that growing threats related to the malicious use of ICTs can be faced and mitigated through an automatic application of existing tools of international law. As a result, a discussion of the way in which international law should apply to the use of ICTs strengthens their importance. However, it cannot follow an approach in which what prevails is the consideration of international law-related topics over others selectively, especially when there is no consensus. Discussions in the framework of the GTCA must follow the mandate given to this group in resolution 75-240. To approach the matter we are discussing today, we believe it essential to start from the point that the security of cyberspace, although it may involve other actors, is a responsibility of states. We reaffirm the validity of the principles of international law and the UN Charter in cyberspace. In particular, those of sovereignty, territorial integrity, and non-interference in the internal affairs of states with regard to the use of ICTs. Mr. Chair, we need a legally binding instrument that is broad on ICTs in the context of international security, which responds to the significant legal vacuums and matters of cyber security, and which makes it possible to effectively address the growing challenges and threats through international cooperation. This instrument must be negotiated multilaterally within the framework of the United Nations. We invite the use of this working group to start these negotiations. Thank you.
Ambassador Gafoor
Thank you, Cuba. United States to be followed by Israel. U.S., please.
United States
Thank you, Chair. We welcome your invitation for a focused discussion on how international law applies to the use of ICTs by states and your guiding questions for areas on which to focus our discussion. We would also like to thank Canada and Switzerland for their thoughtful paper on specific areas this group may want to consider in its work. International law plays a crucial role in promoting international peace and stability in a number of ways. It enables states to work together to meet common goals, including the pursuit of stability in cyberspace. Discussions of how international law applies to state conduct in cyberspace will help give rise to more settled expectations of state behavior and thereby contribute to greater predictability and stability in cyberspace. International law sets binding standards of state behavior that not only induce compliance by states but also provide a basis for states to work together to change the behavior of other states when they violate those standards. The Chair has asked us to consider what existing legal frameworks are relevant to the regulation of states’ conduct in cyberspace. In some respects, this is an easy question because ICTs are just tools that states use to achieve their goals. States must comply with their international law obligations when they use these tools, just as they must in carrying out their other activities. In that sense, there are no gaps to be filled because international law already provides a comprehensive and time-tested set of rules governing state conduct, from the law of state responsibility, including rules on legal attribution, to the rules on the use of force. The difficulty, of course, is in clarifying how this well-developed body of international law applies to the way states use ICTs. And in this regard, we have made a great deal of progress through multiple GGE reports, the previous OEWG, and in the growing number of statements that states have made about how they understand international law to apply in cyberspace. We believe this OEWG can contribute to the growing richness of the discussion on this question. One issue that has been identified as worthy of further discussion is how the UN Charter applies to states’ use of ICTs. For nearly 80 years, the Charter has served as the cornerstone for international peace and security. Its founding principles include the sovereign equality of all UN member states and the settlement of disputes by peaceful means, which remain the foundation for fostering cooperation among states and mitigating threats to international peace, including when it comes to states’ use of ICTs. The GGE and previous OEWG have unanimously confirmed that international law, including the UN Charter, applies to states’ conduct in cyberspace. This means that states must carry out their cyber activities consistent with the Charter, including its core principles of sovereign equality and the peaceful settlement of disputes. States conducting activities in cyberspace must take into account the sovereignty of other states. They may not engage in coercive action that bears on a matter that each state is entitled, by the principle of state sovereignty, to decide freely, such as the choice of a political, economic, social, and cultural system. When disputes arise involving the use of ICTs, states should look to peaceful means of settling their differences, including through negotiation, mediation, conciliation, and, of course, diplomacy. Diplomatic efforts can include much of what states already do in practice, including bringing attention to issues of concern in order to promote responsible state behavior in cyberspace. The OEWG should continue to encourage legal and policy capacity building on international law to enable more states to contribute to the international discourse on this issue. Such discussions and the sharing of national positions on international law are critical confidence-building measures that decrease the risk of misperception and misunderstanding between states. We take note of the Progress Report’s recommendation for states to share their national views via existing platforms, like the UNIDIR Cyber Policy Portal, and call for further work in this regard. Finally, Chair, we concur that all states are welcome to bring forward proposals for discussion within the scope of the OEWG’s issue areas. States, including the United States, have demonstrated a willingness to engage substantively on the question of the need for new legally binding obligations and other questions of international law. By the same token, states should be encouraged and indeed expected to express views on those proposals and the rationales provided for them, including by pointing out any disconnect between the proposals and the acquis. Thank you, Chair.
Ambassador Gafoor
Thank you very much, United States, for your statement. Israel, to be followed by Kiribati. Israel, please.
Israel
Thank you, Chair, for giving us the floor. We wish to present the Israeli perspective on the issue of the application of international law to cyberspace, and I will do my best to be as concise as possible. Israel supports discussions on the application of international law to cyberspace. We believe, however, that deepening our understanding of how international law applies is a continuing and long-term process, one that involves states forming national views and exchanging positions, as we witnessed, that the landscape and the threats that exist in it continue to develop. Israel’s position on the application of international law to cyberspace has been consistently expressed over the years. We consider that international law is applicable to cyberspace. However, Chair, given the unique features of cyberspace and the fact that many traditional rules of international law have been developed and adopted in a domain-specific context, the automatic application of these rules will be difficult and requires further study. It may be useful to evaluate whether rules of international law do not fully relate or apply to the cyber domain, in order to understand whether adjustments and clarifications are necessary. For example, data changes and travels globally across networks and infrastructures located in multiple jurisdictions, transcending national borders and lacking meaningful physical manifestations. Moreover, cyber infrastructure is, to a large extent, privately owned and decentralized, both at the domestic and international levels. The cyber domain is also highly dynamic, with technological developments and innovation advancing at a rapid pace. When considering the applicability of specific rules of international law to cyberspace, it is important to be mindful of such distinctive features and to carry out a meticulous examination of the rules at play and the context in which these rules emerged. Mr. Chair, the Open-Ended Working Group (OEWG) has played a key role in enabling states to present and publish their views on the application of international law. As the landscape continues to evolve, states will no doubt seek to continue to make their views known, relate to the international law aspects of new threats that are emerging, refine previous positions, and perhaps revise and update previous statements. In Israel’s view, the Open-Ended Working Group can and should continue to play a role in facilitating discussions on international law by continuing to provide a platform for states to present and publish their views on a voluntary basis. Finally, Chair, we feel that building a common understanding of how international law applies to the use of ICTs by states should be the first step before moving to the creation or adoption of new rules and norms. Additionally, we wish to echo other speakers and to reiterate that Israel does not see any need for the development or adoption of a legally binding instrument in this context. Thank you.
Ambassador Gafoor
Thank you, Israel, for your statement. Kiribati, you have the floor, please.
Kiribati
Thank you, Chair. At the outset, we would like to express our appreciation to you, Mr. Chair, for convening this important session. We would like to focus our intervention on the importance for this Open-Ended Working Group to address questions of how and when principles of international humanitarian law apply to the use of ICTs by States. Kiribati is not involved in any armed conflict. However, in the OEWG report in 2021, we collectively expressed concern that the use of ICTs in future conflicts between States is becoming more likely. In fact, this risk is today a reality. Moreover, due to the interconnectedness of the ICT environment, malware risk can cross borders, oceans, and affect States that have no stake in any conflict. Against this background, Kiribati believes that building common understandings on how international humanitarian law applies in the ICT environment is of interest to all States and should be a priority for this Working Group. Collectively, in the progress report, we have noted the principles of international humanitarian law, including necessity, distinction, and proportionality. We must now strive to build common understandings on how they apply. As a concrete suggestion, Kiribati would like to see agreement that these principles do not permit the use of cyber tools during war that would spread indiscriminately and affect not only civilian infrastructure in conflict-affected States, but in all States. I thank you.
Ambassador Gafoor
Thank you very much, Kiribati, for your statement. China, to be followed by Belgium. China, please, you have the floor.
China
Thank you, Mr. Chair. As regards the application of international law, it is our position that we approach this issue from the perspective of maintaining international peace and security and discuss it within the UN framework, taking into account the unique attributes of cyberspace to reach greater consensus, to prevent conflicts, and maintain peace and stability in cyberspace. When we discuss the application of international law, the primary focus should be to affirm the application of the UN Charter to cyberspace, especially the principles of sovereign equality, no threat or use of force, peaceful settlement of international disputes, non-interference in internal affairs, et cetera. At present, a certain country is attempting to dominate cyberspace. It continuously increases its investment in cyberspace for monetary purposes and vigorously develops and deploys offensive cyber weapons. It even turns its back on the UN consensus on cybersecurity, openly launching offensive cyber activities against other countries and explicitly including other countries’ critical infrastructure as targets of wartime cyber attacks. This fully illustrates that some countries’ vigorous effort to promote the application of international humanitarian law has not resolved any problems but rather provided a veneer of legitimacy so this individual country can provoke cyber conflicts, thus leading the relevant international discussions astray. In this context, we must be extremely cautious about the cyberspace application of the law of armed conflict and the law of recourse to force. We must avoid tabling any proposals that would encourage or potentially legitimize cyber conflict. We take note of the Russian proposal to develop an international convention on information security. We think it advisable to make it a priority of our future discussions under this agenda item, the application of international law. In addition, we’ve also noted the proposals by some colleagues, in other words, that they were hoping to have informal intersession meetings to discuss international law applications. We believe that the topic of intersession discussions must be balanced. We must not simply put forward a single topic. At the same time, the number of intersession meetings must not just increase. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, China, for your statement. Belgium to be followed by Ireland. Belgium, please.
Belgium
Thank you, Mr. Chair. My country aligns with the statement delivered by the EU and wishes to stress the following elements in its national capacity. First, Mr. Chair, my country is currently working on its own national interpretation of the application of international law in cyberspace and has not yet finalized its official position in this respect. Nonetheless, we would like to stress the following elements. The existing acquis, based on the reports of the GGE and consensual resolution of the UNGA, including the 11 norms of responsible behavior, remains relevant, and my country strongly supports it. As previously affirmed by the GGE and this group, international law fully applies to cyberspace. This includes the UN Charter, international humanitarian law and its principles, as well as international human rights law. We support further discussions on the modalities of the application of international law to cyberspace within our group, including through a dedicated session during the inter-sessional period, as was suggested by the EU, Sweden, and other delegations before me. We are also of the view that international law is sufficient to regulate state conduct in cyberspace. We are not favorable to a new legally binding instrument. We do not support the proposal for a treaty process presented by the Russian Federation. We view such a process as premature. We reiterate our support for the paper presented by Canada and Switzerland on a practical approach to international law. We second the views shared by several delegations on the application of the UN Charter in its entirety to cyberspace and on the obligatory character of the settlement of disputes between states by peaceful means, in line with Article 33 of the Charter. One element mentioned in the 2022 Annual Progress Report, which remains important for our discussion on international law and is particularly relevant for our work, is the principle of due diligence, which is part of customary international law and which is also applicable to cyberspace. We encourage the group to pursue its work to gain greater clarity in its understanding of this important concept. Next, we would like to stress also the important work carried out within the International Criminal Court by Liechtenstein, which my country supported, on the application of the Rome Statute of the ICC to cyber warfare and, in particular, the provisions regarding the crime of aggression, war crimes, crimes against humanity, and genocide. Finally, Mr. Chair, to answer your question on the types of capacities needed to bolster states’ understandings of how international law applies in the use of ICT, we would like to refer to trainings and transfer of knowledge as good means to that end. The resources of the Global Forum on Cyber Expertise and the European Security and Defense College can be useful in this respect. The latter, in particular, organizes sessions for EU and third countries. Thank you.
Ambassador Gafoor
Thank you, Belgium, for your statement. Ireland, to be followed by Vietnam. Ireland, please.
Ireland
Thank you, Chair. Ireland fully aligns itself with the comments made yesterday by the EU. Chair, Ireland is strongly supportive of the suggestion by Canada and others for a dedicated intersessional on international law before we meet again in July. To get full value from this session, it would be important to agree well in advance on topics to be addressed and to ensure that our experts can be prepared for the discussion and would support others in asking that it might be held in hybrid format. We also support further consideration of international law at the fifth session in July and to be properly reflected in the annual report. Ireland is supportive of the paper prepared by our Swiss and Canadian colleagues and of prioritizing consideration of international humanitarian law, the UN Charter, the obligation to peacefully settle disputes, and the law of state responsibility in the cyber context. Consideration of these issues will provide a solid foundation to advance our common understanding of the application of international law in cyberspace. Chair, Ireland is in the process of finalizing its national position paper on how international law applies in cyberspace, and we expect to publish it shortly. In preparing this paper, we have found immense value in studying the national position papers of other states. We recognize the importance of capacity building in this area, and we are presently exploring possibilities on how we can best contribute to capacity building activities. Given that capacity building should be a needs-based exercise, we are particularly interested in hearing from other states as to what their needs are and how best these might be addressed by way of capacity building modalities. Chair, as we have yet to finalize our national position paper, we will not be speaking in detail on the substantive issues identified in the program of work. However, we would make a few general remarks. First and foremost, it is beyond question that international law, international humanitarian law, and the Charter of the United Nations in its entirety apply in cyberspace. In our view, a new legally binding agreement is not necessary, and we would benefit instead from further focused discussions in this format to clarify, where necessary, the application of existing international law in the context of cyber activities. As it stands, we are not in a position to support the proposal on a legally binding instrument, given that, as it was presented, it appears to question and undermine the clear applicability of international law and the UN Charter to activities in cyberspace. Secondly, state sovereignty and international norms and principles that flow from it apply to the conduct by states of ICT-related activities and to their jurisdiction over ICT infrastructure. Finally, we wish to emphasize that sovereignty may not be relied on to justify a state’s non-compliance with applicable obligations under international law. Ireland notes with regret that sovereignty has been at times cited by certain states as justification for cyber measures and/or restrictions within their jurisdiction that compromise human rights, in particular the right to freedom of expression, freedom of thought, conscience, and religion, and the right to privacy. Thank you, Chair.
Ambassador Gafoor
Thank you, Ireland. Vietnam, to be followed by France. Vietnam, please.
Vietnam
Thank you, Mr. Chair, for giving us the floor. Mr. Chair, Vietnam highly values the opportunity to discuss how international law applies to the ICT environment. It should be recalled that the members of this working group have consistently affirmed that international law, including the UN Charter in its entirety, applies to state conduct in cyberspace. Our understanding is that the application of international law will naturally lead to a state-based framework for an open, secure, stable, accessible, interoperable, and peaceful ICT environment, either in the form of abiding and non-abiding rules to inform treaties, customs, and principles of international law. Mr. Chair, this delegation is positive about the suggestion to organize a dedicated session attended by legal advisers of states to discuss how, in detail, international law applies in cyberspace. We observe that right here in New York, legal advisers gather every November on the sidelines of the Sixth Committee, so this working group may consider seizing this opportunity to discuss international law in cyberspace. Mr. Chair, I want to turn to your guiding questions. Regarding the first question about what are the existing legal frameworks that might be relevant to the regulation of states’ conduct in cyberspace, this question requires a clear understanding of the legal nature of cyberspace. Indeed, we need to agree amongst ourselves, first, whether cyberspace has international and national parts; second, which part of cyberspace is qualified as global commons; and third, how states can identify their national cyberspace by territorial or nationality links. We share a view with those delegations that say that the UN Charter in its entirety applies to activities in cyberspace so that states could find the preliminary treaty rules in their conduct in cyberspace. Accordingly, specific principles of international law that are relevant to the regulation of state conduct in cyberspace include state sovereignty, sovereign equality, peaceful settlement of international disputes, refraining from the threat or use of force, non-intervention, and respect for human rights. While the applicability of principles of international humanitarian law in ICT operations needs further clarification, it should be underscored that IHL does not legitimize resorting to conflicts in any domain. The second question is about gaps in such legal frameworks. This delegation notes that during our discussion about the ICT threat landscape yesterday, many delegations shared a view that the threat environment and the severity of the risk are quickly evolving. Such facts highlight the need for states to develop further rules and undertake deeper cooperation to address wrongful ICT activities. The development of such rules should consider in good faith the concerns and interests of our states, take place within the UN, with active and equal participation of our states, and be agreed upon by consensus. We note that a legally binding instrument agreed between states may also create rights and obligations for other entities. For example, the Geneva Conventions have given a mandate to the ICRC, or investment promotion treaties allow companies to sue governments before international arbitration. Therefore, a discussion on a possible UN convention may not necessarily alter the current multistakeholder nature of cyberspace. Indeed, some gaps need urgent clarification. As for now, a framework of political commitment for the peaceful use of cyberspace is still missing. There is no common understanding of the contours of sovereignty in national cyberspace or sovereignty over the ICT infrastructure, so that states may exercise their right to self-determination and be free from external interference. International rules of attribution and countermeasures need further clarification when moving online, given the peculiar technical nature of cyberspace. The right to self-defense under the UN Charter needs further deliberation on how states consider an armed cyber attack, as well as procedural requirements of notification to the UN Security Council when conducting countermeasures. To clarify rules of international law at the United Nations, there are several ways that this working group can consider. First, a request for an advisory opinion to the International Court of Justice. Second, a mandate for a study by the UN International Law Commission. Or third, a topic for discussion at the Sixth Committee. If the proposal for a legally binding instrument is still immature, the working group may consider these options. For the next question about the type of capability needed to bolster states’ understanding of international laws, we believe that capacity building will benefit from a common understanding of the international legal rules applicable to the cyber landscape. Policymaking and regulatory capacities, as well as technical understanding, are among those capacities that could help states build an understanding of the issues. These capacities can be improved through, for example, dialogue, training, research, and in-depth discussion on the divergence and limitation in the application of international law in cyberspace and the management and regulation of national cyberspace. In this respect, we welcome and appreciate initiatives by Australia and Singapore to select and support cyber fellows from developing countries. Regarding the last question about how to increase states’ capacity thresholds, we believe that repositories or a compendium on state practice on international and national cyberspace will be a meaningful resource for states. Together with a dedicated and regular session for discussion at the UN on the formulation and application of norms, rules, and principles, this will be helpful. This could be a CBM in itself. I thank you, Mr. Chair, for your kind attention.
Ambassador Gafoor
Thank you very much, Vietnam, for your statement. France, to be followed by India.
France
Thank you, Mr. President. Therefore, our priority in the context of this work should be to deepen discussions on the modalities regarding the application of existing law to the use of ICTs in the context of international security. These discussions can certainly lead us, as a secondary matter that is later on down the line, to identify gaps in this legal framework and to look into possible ways of closing those gaps. However, this is more of a long-term possibility for our work. The prerequisite for that effort will be a discussion on existing international law. France shared with this group its national stance on how international law applies to cyber operations. We stand ready to participate in those discussions. These discussions are really a long-term consideration, and those discussions can help to set the agendas for another Program of Action or another agenda. Secondly, in order to distribute – to answer the questions that you asked, Mr. President, France stands ready to apply the legal principles to the program of work that you set out, especially the principles that are operational. First of all, France reaffirms the obligation of states to respect the principles of the Charter of the United Nations. The importance of this was eloquently recalled by Australia. Second, sovereignty and the norms and principles stemming from it apply to the use of ICTs by states. Of course, the exercise of sovereignty is not a blank check to exonerate one from the need to abide by the other principles of international law. For example, it doesn’t allow one to violate the sovereignty of other states. That was recalled by Switzerland and by Estonia. Therefore, France thinks it is not illegitimate per se for states to carry out cyberspace operations, but some cyberattacks could be tantamount to a breach of the principles of sovereignty and noninterference, and this would depend on how intrusive they are and what effects they have. The states targeted by such cyberattacks have the right to respond. This must happen in the context of possibilities offered by international law. Third, sovereignty also means that states exercise jurisdiction over the information systems on their territory. And here we support the position of South Africa and Belgium and other states about the question of due diligence. For us, due diligence is an obligation, as was recalled yesterday, and it’s not about the results. It’s about – it is up to the capacity of every state, and that point should be emphasized. It depends on the capacity of every state and the degree of knowledge that states can have about malicious activities that are undertaken on the territory of the state. France encourages in work on the work of this group the continuation of discussions about the concrete implications of these issues to allow for cooperation in managing cyber incidents. Finally, France – my last remark – France reserves the right to attribute publicly or not attribution for a cyberattack that it was the victim of. France believes that the decision about attribution to be a sovereign decision that falls under its exclusive purview, even if international coordination might be undertaken in order to attribute an information-based attack collectively. This could be done with the support of partner states or regional organizations. Next, international law, as we’ve heard during this session, does not compel states to disclose the elements of evidence they have that form the basis for publicly attributing such a cyberattack. These elements, however, can be used to justify that an attribution is well-founded. Finally, and I’ll conclude with this, I’ll respond to the question about the capacity that states need in the legal realm and on the means of building those capacities. My delegation reiterates its full support to the proposals of Switzerland and Canada in their joint document, which proposes a practical approach to international law and the work of this group. I thank you, Mr. Chair.
Ambassador Gafoor
Thank you, France. India, to be followed by Iraq. India, please.
India
Thank you, Mr. Chair. As the international security landscape is becoming more and more ICT-based and the potential risks that come from misuse of ICT capabilities against a state, there is an additional need to further study the foundational elements of the application of international law to cyberspace and improve the common understanding and interpretation for member states. International law is the basis of a state’s shared commitment to preventing conflict and maintaining international peace and security, and is key to enhancing confidence among member states. Any further discussion on this agenda topic itself could act as a confidence-building measure for member states, building trust and confidence. The work by previous GGEs and OEWG agreeing to the application of international law, and in particular the Charter of the United Nations to cyberspace, is significant. The assessments and recommendations, in conjunction with other substantive elements of previous reports, emphasize that adherence by states to international law is an essential framework for their actions in the use of ICTs. We believe that international law is a vital deterrent in preventing conflicts, misunderstandings, and maintaining international peace and security. The principles of sovereign equality of states, non-use of force and threat of force, settlement of international disputes by peaceful means, and non-interference into internal affairs of states are the foundational elements to take forward the discussion on international law. As recommended by the Annual Progress Report, Mr. Chair, from last year, this working group could convene discussions on specific topics related to international law. Such discussions should focus on identifying areas of convergence and gaps in the common understanding and interpretation of member states. These discussions would help in exploring new areas of cooperation in the application of international law to the use of ICTs by states and would bring in diverse opinions from member states. The OEWG needs to build on such discussions to form a matrix of areas of convergence and divergence to further consolidate our understanding as a group on this subject. Promoting capacity-building efforts as part of these specific discussions on international law through seminars, workshops, training courses, and sharing best practices at international, inter-regional, regional, and sub-regional levels, as well as engaging relevant regional organizations, must be considered while convening international law-focused discussions in this working group. Thank you, Mr. Chair. Thank you.
Ambassador Gafoor
Thank you very much, India. Iraq, to be followed by Malawi. Iraq, please.
Iraq
Thank you, Chair. First, my delegation wishes to congratulate you for the efforts that you have made with regard to the guiding questions, the aim here being to reach an agreement that takes into consideration the concerns of all states. Chair, international law constitutes the bedrock of the principles that govern the behaviors of states in cyberspace. The Charter of the United Nations and international instruments are relevant here. They provide a legal framework. This is what states – or rather, these are what states need to use in order to govern their rights in cyberspace. As for states, freedom of expression needs to be ensured, as do other rules followed by states, rules used to prosecute cybercrimes and to govern the use of ICTs for criminal ends. However, there are some gaps that exist here in our legal framework. They have to do with the governance of the behavior of states in cyberspace. Above all, this pertains to a lack of an acceptable definition, an international definition of what an electronic attack is. There are other gaps, too, for example, with regard to the application of the current legal framework to cyberthreats. There are also questions about how states can arrive at legal instruments, including a new international convention, a convention that would implement essential principles, above all, as concerns the attribution of responsibility. Here, states need to clarify the framework, and they need to clarify what rules apply to cyberspace. In this regard, Iraq upholds the fact that international law applies to cyberspace, or rather that this depends on the nature of the crimes, depends on the nature of the crimes committed by states, depends on the nationality of those committing the crime. And there’s another very important point: the application of international law to crimes depends on who is responsible and it depends on where the crimes are committed. Also, we wish to recall the need for several initiatives to be taken to build capacity to allow for states to have a good understanding of the application of international law in the realm of ICTs. This includes the building of legal capacity. That is to say, states need to be able to have recourse to legal experts to study the applicability of international law to cybercrimes. These experts should also have a sound understanding of international law and of its applicability to cyberspace. Next, capacity building – technical capacity building is needed because states need this in the context of ICTs to set out their positions with regard to cyberspace. These experts need to have a sound understanding of technical issues in connection with cyberspace. Thirdly, we need to develop policies. That is, states must develop guidelines. They need to ensure that they abide by international law in doing so. These policies could govern cybercrimes and the criminal use of ICTs. Fourth, coordination is needed – common coordination – through joint work in order to address cyberthreats. This should be done through exchanging information, expertise, and common strategies – common strategies to be applied. Finally, there’s a need to raise awareness. This can be done through cooperation – cooperation among politicians and the broader public. And this has to do with how ICTs are used. Politicians need to understand very well the legal principles at work in cyberspace. There’s also a need to manage ICTs properly. Thank you.
Ambassador Gafoor
Thank you, Iraq, for your statement. Malawi, to be followed by the Republic of Korea. Malawi, please.
Malawi
Mr. Chair, as it is our first time taking the podium, we would like to extend our commendations to you for your incredible coordination and facilitation of this critical discourse. We shall attempt to be brief and concise. Mr. Chair, member states in the OEWG 2021 report acknowledge that international law, particularly the Charter of the United Nations, applies to the use of ICTs. For the avoidance of doubt, Malawi reiterates its position as being that international law crosses the boundary into cyberspace. Malawi would like to state that the function of the law being to provide enforceable means to govern the conduct of specified matters, it is important to acknowledge that ICTs have a continually evolving nature that can make the consideration of the specifics of how international law applies to the use of ICTs complex. However, Malawi is of the view that the current international law scheme adequately provides for the regulation of cyber interactions between states. Generally speaking, the principles of international law that govern the relations between states apply in all jurisdictions, including the jurisdiction of cyberspace. In the context of conflict, international humanitarian law equally applies to applicable violations in cyberspace. Malawi agrees with the European Union, Sweden, India, the United Kingdom, and other delegations that the principles of international law are well established, and these have been comprehensively covered and will not be gone into at this stage. Whilst ICTs do not always fit perfectly within the scheme of these standards and instruments, it must be noted that any new area of law may leave room for variances in interpretation. Differences in interpretation are an inevitable part of legal construction and cannot be avoided completely. As mentioned by Austria and the UK, there is an ambit of amicable dispute settlement mechanisms available to state parties at an international law level that may be utilized to address disputes, thereby settling any ambiguities. Malawi also aligns itself with the statement of Canada that there is a need to first utilize the existing legal frameworks before determining that there is a need to create a new legislative instrument in this area, if such a need should arise. With respect to capacity, as has been mentioned by several delegations, there is a significant capacity challenge faced by many states, including Malawi. These capacity differences impact the ability of state parties to appreciate and enforce international law obligations in cyberspace. The international community must pursue the bridging of this gap to ensure parties can reach a common understanding, particularly as the developments in ICTs continue to grow more complex. Malawi reiterates its position from other OEWG sessions that as a developing country, we recognize the critical role we play in identifying our needs to ensure that the capacity building process is needs-driven and therefore effective, non-discriminatory, and sustainable. Malawi aligns itself with the suggestion by Botswana, the European Union, the Nordic countries, Australia, and numerous other delegations that there is a need for a dedicated session on the applicability of international law to cyberspace. There is a need for this training to not only be objective, but be focused on the topical discourses taking place, particularly on the principles of sovereignty and the consequential responsibilities that lie on state parties, the principle of non-intervention, and the principle of countermeasures, amongst others. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, Malawi, for your statement. Republic of Korea, please.
Republic of Korea
Thank you, Mr. Chair. The Republic of Korea reaffirms that international law, in particular the Charter of the United Nations in its entirety, as well as international humanitarian law and international human rights law, all apply to states’ conduct in cyberspace. Moreover, multiple General Assembly resolutions have clearly stated that international law is essential to maintaining peace and stability and promoting an open, secure, stable, accessible, and peaceful ICT environment, and previous GGE-OEWG reports confirm the applicability of international law. Therefore, we should not be questioning its applicability. Some states express the view that the distinctive nature of cyberspace hinders the implementation of existing international law and that a new global convention is needed to address this problem. My delegation does not deem it appropriate at the current stage. As some other delegations indicated, international law may not apply in cyberspace in exactly the same way that it does in other domains. Nevertheless, this should not be a reason for states to neglect the existing legal framework. Instead, the major question that needs addressing is how we can clarify the application of the law in a uniform manner. There was a long and detailed discussion on existing and potential threats by many delegations on Monday and Tuesday morning. A number of cyber incidents were presented. Many proposals were put forward to address them. This clearly shows that there is a shared sense of urgency and gravity of the threats. We cannot let them happen relying on the excuse of the so-called legal vacuum while there is an established set of international law. Some prominent features of the cyber domain are that it is transboundary and that activities there can be anonymous. In this regard, my delegation would like to point out the principle of territorial sovereignty and due diligence. Cyberspace is transboundary, and as such, the spatial boundary has no limits. Nevertheless, cyberspace operates in connection with the cyber infrastructures located in states’ territories. This means that an actor engaging in illicit cyber activities through these infrastructures is causing harm inside states’ territory, and these activities are subject to that state’s jurisdiction. In a similar vein, due diligence should be highlighted as that principle is crucial in both preventing and responding to cyber incidents as well. Lastly, my delegation takes note of diverse topics written in the first annual progress report. My delegation also echoes that there should be further elaborations on how international law applies in cyberspace during or before the drafting of the 2023 annual progress report through a set of thorough discussions or dedicated sessions as suggested by many delegations. Thank you.
Ambassador Gafoor
Thank you very much, Korea, for your statement. Distinguished delegates, we have 10 more speakers: 8 delegations, 8 member states, and 2 observers. I’d like to propose that we close the speakers list for this particular item because we have to move on to other items on our agenda. So this afternoon, we will continue with the speakers list to hear the remaining 10 speakers, 8 members, and 2 observers, and then we will move on to confidence-building measures. The meeting is now adjourned. I wish you a pleasant lunch break. Thank you.
Leave a Reply