Ambassador Gafoor
Distinguished Delegates, this sixth meeting of the Fourth Substantive Session on the use of ICTs is now called to order. We will continue with our discussion of the agenda item relating to international law, and as I said this morning, we have closed the speakers’ list and we will continue with the speakers’ list as we have had from this morning, starting with Romania, to be followed by the Syrian Arab Republic. Romania, please.
Romania
Thank you, Chair. We are fully aligned with the statement given by the European Union on this agenda item, as we are on all agenda items. In my national capacity, I’ll be brief and note that the full respect for international law is one of the most important pillars of Romania’s foreign policy. It is our belief that international relations, irrespective of the tools used, must be based on international law. This is true as well for cyberspace. An open, secure, stable, accessible, and peaceful cyberspace is the result of responsible state behavior, which cannot be imagined outside an international rule-based system primarily founded on international law. Thus, Romania makes no distinction between the obligations applicable to states within and outside cyberspace. International law, including the UN Charter in its entirety, treaties, customs, and general principles, as well as the corpus of international humanitarian law and international human rights law, fully apply to state conduct in cyberspace. There exists no genuine reason why it would not. ICTs are tools sometimes used in the interaction between states. ICTs do not change the nature of states as subjects of international law, nor the nature of the interaction among them within the international community. Consequently, my country is of the view that there is no need to develop international legal frameworks to address strictly cyberspace, not least because before considering developing new rules, we need to have a full understanding of the applicability of the corpus of international law in cyberspace. On the issue of clarification of how international law applies, we join the analogy made by Australia on diagnosing the patient prior to sending them for surgery. It represents an analogy that provides clarity to the current state of affairs. Mr. Chair, the prohibition of the threat or use of force is a well-established principle of international law, being included in Article 2.4 of the UN Charter. There are only three well-determined exceptions to this prohibition: self-defense in the event of armed aggression, a UN Security Council Chapter 7 authorization on the use of force, and the consent of the state whose territory the operation takes place in. Even if we look at the situation through these lenses alone, we can see that through its actions in Ukraine, which includes cyber operations, the Russian Federation is in an objective breach of international law. We deplore this objective reality and reiterate an equally objective one that stems from it, that in spite of progress on this topic within the GGE and former Open-Ended Working Group and within our discussions in this format, the manner in which states of the UN can advance their understanding of the applicability of international law to cyberspace is predicated at the very minimum on their genuine intention to respect it, and that their legitimacy is based on the correlation of their conduct with the fundamental rules, norms, and principles which have defined and governed the work of the United Nations and of the entire international community. We indeed advocate for keeping this in mind. And with this in mind, we welcome discussions on the topic of international law within this session and join our voice to those states which strongly favor identifying a time slot within the activity of the Open-Ended Working Group in May or June for an intersessional meeting dedicated to exchanging ideas and views on developing our understanding on the concrete applicability of international law to cyberspace. We see that the hybrid format would be practical for ensuring the widest possible participation. The productivity of our debates at this time, during this session, shows how important it would be to dedicate more time to this topic. In closing, I would like to highlight that a more comprehensive expression of Romania’s view on the manner in which international law applies to cyberspace is also available in our contribution to the 2021 Official Compendium of Voluntary National Contributions on the Subject of How International Law Applies to the Use of Information and Communication Technologies by States, submitted by participating governmental experts in the Group of Governmental Experts on Advancing Responsible State Behavior in Cyberspace in the Context of International Security. Thank you.
Ambassador Gafoor
Thank you very much, Romania, for your statement. Syrian Arab Republic, to be followed by Malaysia. Syria, please.
Syria
Thank you, Chair, for having given me the floor. Syria stresses the importance of the principles that manage the principles of the United Nations in ensuring the maintenance of peace and security in cyberspace. In particular, the respect for the political independence and sovereignty of states, and the non-use or threat of use of force in international relations. Nevertheless, when we examine the specific particularities of ICTs, and as there is no common understanding between countries on the applicability of international law on the use of ICTs, we must clarify several issues here. These are questions that would be the basis for a legal framework that would control these actions carried out in cyberspace. We must also identify gaps in these areas and the ways to fill these gaps. This will allow us to find international norms that would take into account the constant development of ICT activities, and this would be in accordance with an effective, inclusive, and transparent approach. Amongst the most important questions that we must examine and discuss so as to find consensus, I would include the legal basis for the specific use of ICTs and their use to carry out attacks, and the use of ICTs that could be considered as a use of force, a threat, or a threat of use of force. We must establish the responsibility in these areas. My delegation is of the view that we need to find definitions that would be universal amongst countries in terms of international peace and security so as to establish an international legally binding document that would manage the activities of countries in cyberspace. Here, we stress the importance of discussing all international law issues without selectivity or distinction. The GGE worked to elaborate a balanced and exhaustive list which includes those elements that are to be examined during the mid-term report which was adopted by consensus. I thank you.
Ambassador Gafoor
Thank you, Syrian Arab Republic. Malaysia, to be followed by Pakistan. Malaysia, please.
Malaysia
As Member States, we have collectively reaffirmed that international law, in particular the Charter of the United Nations, is applicable and essential to maintaining peace, security, and stability in the ICT environment. Malaysia is pleased that the present session has featured a substantive exchange of views on how international law applies in cyberspace, which is critical in moving the dialogue forward. We have also taken note of specific proposals put forward by several delegations on how the OEWG can best advance its work on these vital topics under its mandate, including through potential inter-sessional focus meetings in a hybrid format, allowing for wide participation. Many delegations have underlined the role of targeted capacity building in deepening Member States’ knowledge and expertise vis-Ã -vis the application of international law in cyberspace. This is important in ensuring that we leverage our cumulative experience and facilitate the active participation of the UN Member States’ membership as a whole in the evolving discourse, with a view to reaching common understandings. In this regard, we should make full use of workshops, seminars, and training programmes, including those undertaken at the regional level. Thank you.
Ambassador Gafoor
Thank you, Malaysia. Pakistan to be followed by Colombia.
Pakistan
Pakistan, please. Thank you, Chair. The application of international law in cyberspace is one of the most important mandatory areas of the OEWG. Pakistan believes that the stability of cyberspace in reality rests on the formulation of a legally binding mechanism to ensure the responsible uses of the global internet, a mechanism which will promote responsible state behavior by holding actors responsible for their acts and forbids the use of cyberspace for destructive purposes. Taking this opportunity, I would like to inform that Pakistan has submitted its position paper, which in detail articulates our position regarding the application of international law in cyberspace. Mr. Chair, Pakistan’s position on the application of international law in cyberspace has remained consistent. Pakistan believes that the principles of non-use of force, sovereign equality, sovereignty, non-interventionism, and peaceful settlement of disputes, as enshrined in the UN Charter, apply to the cyberspace. We are supportive of a rule-based cyberspace open for all for reaping maximum economic benefits. Pakistan believes that compared to the physical world, cyberspace is unique because of its transnational nature, anonymity, and its uses by both states and non-state actors. Thus, the existing framework of international law and IHL has certain gaps. Therefore, Pakistan welcomes the initiation of focused discussions among member states on the application of international law in cyberspace. We believe that such debates shall be helpful in identifying areas of convergence among the member states. We also welcome the proposal of intersessional informal meetings on this topic. In addition to this, Pakistan also proposes the formulation of a common lexicon to get definitional clarities on the different cybersecurity terminologies. Pakistan also stresses the need to fulfill the capacity-building needs of member states in the area of cyber policymaking and regulatory mechanisms to develop expertise of member states in the subject area. In this regard, we welcome the initiatives taken by the EU and the Republic of Singapore. Last but not least, the OEWG must discuss and find ways to solve the challenge of cyber attribution, which we believe is difficult but not insurmountable. I thank you, Chair. Thank you.
Ambassador Gafoor
Thank you, Pakistan, for your statement. Colombia, to be followed by Fiji. Colombia, please.
Colombia
Thank you, Chairman. In addressing this item, as in every other item we address, the human being and dignity must be at the heart of our motivations and our efforts, and international law must always be at the basis of international relations. It should govern all of those spheres, be they physical or virtual, and they must apply to all measures, tools, and developments in science and technology, and govern the conduct of states and their people. Only strict compliance with the UN Charter, without any preconditions, and all legally binding instruments, as well as international customary law, and in general, all norms, rules, and principles of international law will guarantee peace, security, and prosperity for all people. Therefore, international law as a whole, including international customary law, the UN Charter, international humanitarian law, and human rights, apply in the use of ICT. Any use by states of ICT that is incompatible with obligations under voluntarily contracted norms, international law, and confidence-building measures would undermine international peace and security, trust, and stability. Mr. Chairman, in terms of the question on the conduct of states in cyberspace, we would highlight the importance of states’ commitments to the following principles of the Charter and to other norms of international law. I would refer to sovereign equality, the resolution of international disputes through peaceful means, so that international peace and security are not jeopardized, nor is justice jeopardized. In international relations, states should refrain from threatening to use force or using force against the territorial integrity or the political independence of any state or any other form which is incompatible with the UN purposes. Respect for human rights and fundamental freedoms and non-interference in the internal affairs of other states. Existing obligations in the area of international law are also applicable by states in the use of ICTs and must therefore be observed. Mr. Chairman, in order to develop a common understanding of how international law should apply, we need to have a broad discussion, and we therefore welcome the proposal for us to focus on specific issues in the intersessional periods. In accordance with the APR, our discussions will continue at our fifth substantive session. Turning to the items on the non-exhaustive list in the APR, we believe that we should begin with the UN Charter, with the peaceful resolution of disputes, with international humanitarian law, and state responsibility. We agree with the Swiss and Canadian concept paper in this regard. In terms of the type of capacity that’s required to ensure that states understand how to apply international law in the use of ICTs, we must increase the capacity of states in this area, and we need to determine what institutional support and resources are required. We have the following comments. In order to have fruitful participation in this exchange of views, and to have a proper subsequent implementation of our agreements, we need to have the support of states in capacity building in the areas of international law, national legislation, and policies. We believe it would be useful to have regional discussions with like-minded states so that they can share challenges, ask questions, and share experiences in drafting their national positions as they apply international humanitarian law in cyberspace. We have to make sure that the law is understood across the board, in particular when using ICTs. We should use existing tools such as the UNIDIR Cyber Policy Portal. There should be practical simulation exercises based on the Chatham House rules where we discuss the implementation of international law and international humanitarian law in cyberspace. We would ask for the assistance of regional organizations as well as other relevant actors such as the OAS, UNIDIR, ICRC, and NATO Cyber Defense Center, to mention but a few. They already have experience in this area and are working on these issues. We should have a diagnosis of the status of where things stand and consult states about their needs and their offers for cooperation. We are grateful for the UNIDIR meeting on cyber stability, which was held on the 3rd of March, and we’re grateful to the OAS and to the Inter-American Committee to Combat Terrorism, the United Kingdom as well, for the ICT for Peace Foundation, and for holding the meeting in Washington last February. My delegation had the possibility to participate. Thank you.
Ambassador Gafoor
Thank you, Colombia. Fiji, to be followed by the Dominican Republic. Fiji, please, you have the floor.
Fiji
Thank you, Chair. Mbule Winaka Chair and colleagues, Fiji, like fellow Member States, commends the Chair on your decisive leadership and the Secretariat on the progress in this meeting. Chair, I have been listening intently to the contributions from various delegations, including the intersessional that was held last week, and we thank delegations for the insightful interventions. This has indeed been very valuable in enhancing common understanding and is indeed a confidence-building measure. Regarding your guiding question on the existing legal frameworks that are relevant for the regulation of states’ conduct in cyberspace, Fiji reaffirms the shared acquis that existing international law and the UN Charter in its entirety apply in cyberspace. Furthermore, the norms of responsible state behavior sit alongside this. Adherence by all states is imperative. Fiji recalls and values the foundational work that has been undertaken in the rounds of negotiations from 2004 right up to the 2013 UNGGE Conclusion Report stipulating the applicability of international law, including the United Nations Charter, in cyberspace, and which was reemphasized in the 2015 UNGGE report, our annual report, and the progress report. Fiji reaffirms that international human rights law is applicable in cyberspace and that inalienable human rights are not relegated to offline spaces. They must be protected online as well. Like other states, Fiji further reaffirms that the principles of state sovereignty, the settlement of disputes by peaceful means, as stipulated in Articles 2, Sub 3, and Article 33, Sub 1 of the UN Charter, and the non-intervention in the internal affairs of other states apply in cyberspace. Fiji joins other member states in affirming that international humanitarian law applies in cyberspace and that this in no way legitimizes cyber warfare or resorts to conflict in any domain. Chair, regarding the question on needed capacities to bolster states’ understanding of how international law applies, Fiji welcomes further discussions on the many proposals that have been put to the floor, including the proposal by Canada to share experiences and perspectives regarding national position papers on how we can build our own canoe boat, and we welcome this. Chair, you had mentioned earlier this week that what may be simple for one may not be simple for another. Drawing from this and to promote common understanding and to enable all states to be on an equal footing, we also welcome the proposal of a dedicated session with focused discussions and briefings prior to our next substantive meeting. Chair, should this be in a hybrid format, we request consideration of the diverse time zones to ensure that all states are able to actively participate. Chair, we echo other states in that we must be mindful of the varying capacities of each state, in particular the compounded resourcing constraints and the unique challenges of developing states and small island developing states. Therefore, we urge that priority be given to first enhancing common understanding of the current tools that have already been identified in our toolkit and their effective implementation to foster a common baseline level of resilience. This is to ensure that no state is left behind while on this marathon. Also, we ask that this group looks into the requisite institutional support needed to ensure sustained engagement from all states, and we look forward to hearing from states on this and further collaborating in this regard. Chair, work is now already taking shape where we are uncovering the layers of complexities that exist in dealing with these multifaceted challenges. We’re finding potential, practical, holistic, and concrete solutions, and where we can better appreciate and truly realize the benefits of cooperation at all levels with all stakeholders. Chair, in closing, please be rest assured of Fiji’s continued support and engagement in finding consensus in safeguarding our collective progress and in accomplishing our collective objective. Thank you for the opportunity.
Ambassador Gafoor
Thank you very much, Fiji. Dominican Republic, to be followed by El Salvador.
Dominican Republic
Thank you, Chairman. The Dominican Republic believes that international law is applicable to cyberspace. Instruments such as the UN Charter, international humanitarian law, and international human rights law are legal frameworks which can be applied to the use of ICTs in cyberspace in the virtual world as well as in the physical world, although they are different. But always there must be respect for human rights and for noninterference in the internal affairs of other states. We understand that prior to exploring the possibility of developing new binding instruments, we should consider how to apply the existing frameworks to cyber activities and to the various scenarios which take place in cyberspace, and then focus on covering the possible gaps that may exist. Therefore, as was discussed yesterday, the possible holes in the canoe, as our Canadian colleagues said yesterday, we believe that the Open-Ended Working Group is an ideal place for developing capacity building as well. The Dominican Republic has been part of a number of initiatives in this area in the Organization for American States, working with cyber law, international law, and Diplo using tools such as workshops, which have been very helpful to us in developing ideas about these new areas. One issue involving capacities we’d like to underscore is that we’d like to congratulate all delegations who are here today, and as we commemorate the International Day of Women, Women in Cyber Fellows, that we believe that they help to reduce the gap when it comes to the participation of women working in the area of cyberspace, and we believe that considerable progress has been made. You need only look around the room to see the gender balance we have in this forum. We recognize and thank Canada and the Netherlands, to mention but a few, as well as other organizations such as the Global Forum on Cyber Expertise, the GFCE, for their support. We support the establishment of devoting items to existing international law during the intersessional periods, and we also believe that states must make every effort to create synergies among – as we respond to cyber attacks, the ministries of foreign affairs and the private sector and service providers as well, both domestically and internationally. We should promote international cooperation and share experiences. Thank you.
Ambassador Gafoor
Thank you, Dominican Republic. El Salvador, to be followed by Nicaragua. El Salvador, please.
El Salvador
Thank you, Chairman. Just a brief comment in view of the time. This is the only issue where initially we did not think that we would participate because we thought it would be difficult for us to add value to how to apply international law to cyberspace. However, in light of today’s discussion, El Salvador would like to join its voice to the many delegations who have reaffirmed the gains that we have achieved in our work and say that international law and the UN Charter are applicable to cyberspace, and that is essential for maintaining peace. We agree with all delegations who proposed a practical focus and specific discussions or a dedicated meeting to discuss the issue of the applicability of international law in cyberspace. Thank you.
Ambassador Gafoor
Thank you, El Salvador. Nicaragua, to be followed by Jordan, please.
Nicaragua
Thank you, Chairman. We agree that the threats related to the misuse of ICTs are quite complex and varied, and the current international law framework is not sufficient. We believe that our effort should be focused on promoting the use of ICT for the development of our peoples and addressing conflicts caused by cyberattacks, particularly when it comes to drafting criteria for defining the misuse of cyberspace and how it impacts international peace and security. At the same time, there’s no current consensus in the international community on how to qualify the misuse of ICTs, such as armed attacks, in accordance with Article 51 of the UN Charter, particularly given the lack of an international mechanism that would investigate and determine the source of a cyberattack without any discrimination whatsoever. We reaffirm the validity of the principles of international law and the UN Charter in cyberspace, particularly the issues of sovereignty, territorial integrity, and non-interference in the internal affairs of states. In the use of ICT technology, we insist on the priority to create a universal regime to govern cyberspace, and here we would welcome the proposal of the Russian Federation on a legally binding convention in the United Nations related to the security of information in cyberspace. That convention would enable us to cover the current legal gaps in cyber security, and that understanding could then become a legally binding instrument through international cooperation. Our working group is the ideal platform for continuing discussion of this mandated item. However, we would not agree to having intersessional meetings devoted exclusively to international law, since it would alter the balance we have with other issues that are more relevant and interrelated. Thank you.
Ambassador Gafoor
Thank you very much, Nicaragua. Jordan to be followed by the ICRC and the OSCE. So, Jordan, please.
Jordan
Thank you, Mr. Chair. Very briefly, I would like to express Jordan’s views on how international law applies to the use of information and communications technologies by States. We emphasize the need to garner the views of the International Law Commission on the applicability of international law to the use of ICTs by States, particularly during a time of peace. Our view is that the general rules of international law do not specifically address the use of ICTs by States during a time of peace. Moreover, it is equally important to request the views of the ICRC on the applicability of international humanitarian law in cyberspace as follows. First, whether the rules of international humanitarian law apply to the use of cyberspace during armed conflicts, for example, if a cyber attack on civilian infrastructure may amount to a violation of international humanitarian law. Second, whether cyber attacks by State actors or other subjects of international law qualify as armed attacks. Mr. Chair, the ICRC has tackled such issues in its literature, but we think that an interaction between the OEWG and the Committee will be fruitful in guiding our discussions. Accordingly, we echo proposals to organize an inter-sessional meeting to further discuss these matters. I thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, Jordan, for your statement. ICRC, please.
ICRC
Thank you, Chair. The ICRC is grateful for the opportunity to address this Open-Ended Working Group on the question of how international law applies to the use of ICT by States, with a view to promoting common understandings. We strongly support the call by delegations and significant efforts by you, Chair, to use this Working Group to identify concrete measures to maintain peace and security. As a humanitarian organization, we strive to see security and protection of people, and this is best achieved in peace. Over the 160 years of our existence, the ICRC has, however, also seen that peace is broken. The UN Charter aims to outlaw the use of force in international relations and to prevent war. International humanitarian law aims to limit warfare if it erupts. Demanding respect for international humanitarian law is of utmost importance in the ICT environment. Even if directed against a specific state during an armed conflict, cyber operations risk affecting countries far away from the physical battlefield. In the interconnected ICT environment, the lack of respect for international humanitarian law by states that possess military cyber capabilities risks harming people, infrastructure, and societies around the world, including countries that may not have such capabilities or may not have any stake in a conflict. Demanding respect for international humanitarian law in the ICT environment should therefore be a shared concern for all states. The ICRC commends this Working Group for having started to build common understandings on how and when international humanitarian law applies to the use of ICTs. Concretely, there is agreement that recalling international humanitarian law principles by no means legitimizes or encourages conflict. Moreover, there’s a common understanding among all states that IHL applies only in situations of armed conflict. There’s also growing common understandings on how the fundamental principles of IHL apply to ICT operations conducted in situations of armed conflict. Distinction demands that cyber attacks must not be directed against civilian infrastructure. Proportionality demands that cyber attacks must not be conducted if they may be expected to cause excessive civilian harm. No one would argue that cyber operations may be conducted to disrupt the functioning of hospitals, not even in times of war. And information operations must not be conducted to threaten violence if the primary purpose of such threats is to terrorize civilian populations. Agreeing on these basics does not, however, mean that there’s full agreement on how IHL applies to the use of ICTs. There’s an urgent need to discuss cyber-specific questions. To be concrete, the published views of states diverge on when digital data enjoys legal protections against damage and destruction similar to physical objects. Common understandings on such an elementary question should be sought to ensure that protection of civilians is upheld in an ever-digitalizing world. The ICRC is conscious that discussions on how international law applies to the ICTs can be technical and requires capacity building. As part of our mandate to work on the understanding and dissemination of knowledge of IHL, the ICRC has yesterday published and will share with this Working Group four short papers on how and when international humanitarian law applies to the use of ICTs. These papers recall when international humanitarian law applies and provide explanations of how the established international humanitarian law principles of humanity, necessity, proportionality, and distinction apply to the use of ICTs during armed conflict. The ICRC hopes that these resources can support the work of states in this group, and we are available to discuss these subjects further with interested delegations. Thank you.
Ambassador Gafoor
Thank you very much, ICRC, for your contribution. OAC, please.
OSCE
Thank you very much, Chair, for giving me the opportunity to take the floor. I will be very brief. Related to increasing capacities of states on how international law applies to the use of ICTs, I would like to share with you information about some activities the OSCE Secretariat has facilitated in the past months. In February 2023, the OSCE organized the Executive Course on the International Law of Cyber Operations in Skopje, North Macedonia, for 27 participants from the sub-region of Southeast Europe. I am also happy to share that 55% of the participants were women. The course was organized with the support of the Netherlands and delivered by Cyber Law International, an international legal firm specializing in such trainings. The training was designed for legal experts dealing with cyber ICT issues and policy advisors responsible for cyber matters, to enable them to better navigate through the complex legal issues involving cyberspace. In particular, the course examined key legal principles such as sovereignty and jurisdiction and regimes of international law that govern cyber operations conducted by or directed against states and was complemented by practical exercises aiming at applying the legal principles to fictional scenarios. In their feedback, all participants indicated that the course proved very useful and improved their level of understanding of the applicability of international law in cyberspace. Furthermore, with the support of the United Kingdom and the Netherlands, the OSCE conducted an advanced training on international cyber diplomacy last November for diplomats from 16 OSCE participating states. The training aimed at familiarizing the participants with the UN Framework of Responsible State Behavior in Cyberspace and the work of the OSCE in the field of cyber confidence-building measures. During interactive sessions, the participants shared their experiences on engaging in international cyber negotiations and delivering national statements in relevant forums. I would like to use this opportunity to thank you and ODA, in particular Ms. Catherine Priceman, for her valuable contribution to the training. Thank you very much.
Ambassador Gafoor
Thank you very much, OSCE, for your contribution. We have no more speakers, and we will now move on to the next item, which is confidence building. But before we do that, I wanted to share some random reflections at this point and certainly not a summary of what was a very, very rich and intense discussion. And in fact, it is my sense that this is probably the most intense and focused discussion we’ve had on international law, at least in the context of this working group. And that, I think, is a good start. I want to thank delegations for responding to some of my guiding questions, which was in itself an attempt to have a focused discussion. And in that sense, I guess we have partially achieved, if not fully achieved, that objective. I think one of you said that this discussion was proving to be an exercise in confidence-building measures in itself, because talking about international law and the Charter and the peaceful settlement of disputes and our understanding of how international law applies can be, and I think is indeed, an exercise in confidence-building measures. So, in some ways, we have already gone on to the next item while talking about international law, and I think that was useful. If we look at the annual progress report, under the section on international law, the recommended steps are for states to engage in a focused discussion on topics in the annual progress report, as well as in the chair’s summary of the previous OEWG. I think we have begun that, and as I said right at the beginning, we needed to start with an initial cluster of issues on the Charter, peaceful settlement of disputes, sovereignty, non-intervention. I think a lot of you spoke about that, but there were also discussions on other issues, IHL, on the possibility of a new legally binding instrument. In a sense, we had a focused discussion, but we also had a discussion on a range of issues. I think some of you said that we would need a roadmap for a future discussion on international law, and in a sense, the annual progress report gives us that roadmap, and the annual progress report plus the chair’s summary gives us a roadmap, plus the guiding questions that I have provided and will continue to provide at future discussions will complement that roadmap. I am not sure whether we should be negotiating a roadmap every year. I think we have a roadmap. What we need to do is travel down that road and try and build common understandings, which I think is what we have done today. Quite a number of you said time was not enough, more would be needed, and many of you had said we need a dedicated session focused on international law. Some of you had a different view on that specific proposal, but whether we call a session a dedicated session to international law, what is clear is that we will need more time for this discussion. I will give some reflection as to how best we can continue on this discussion and how we can build on this discussion between now and July. What is clear is that between now and July, we will definitely need an intersessional meeting, and if you look at decision 77512 adopted in the first committee, which endorsed the report of the Open-Ended Working Group and the first annual progress report, we did decide that we, as a working group, will convene additional intersessional meetings to build on the annual progress report. The question is whether we should have an entire session on international law or have intersessional meetings on a range of issues. Now, I have always taken the approach in this working group that we need to have a balanced discussion on all the agenda items, so I will also give reflection on how to have that discussion not only on international law but also on the range of issues, and there are two big issues ahead of us – more than two, actually – confidence building, capacity building, as well as regular institutional dialogue. So, if we had a dedicated session on each of these agenda items, then your dedication to this process needs to be extended in a permanent way, and you have to relocate to New York. I am happy to have this dedicated session on a continuous basis, but we need to organize our time. So, I will give some thought. I am not saying how we will do it. I will give some thought and share my views at the end as to how we can organize some meetings between March and July on a range of issues, because it is not possible for us to come to the working group in July by doing nothing between this week and July, so we will definitely need to continue the discussions on a range of issues. There was also a proposal put forward by Vietnam, a repository of state practice on international law, which I would suggest delegations reflect on, because the idea of a repository has come up in another context as well. So, this idea of a repository on state practice in terms of application of international law in essence is about sharing information between states, and I would like you to reflect on that idea as well. But what really struck me was how many of you participated in this discussion. We have had about 40 delegations, and in a sense these are 40 national submissions on international law. I think it was Estonia which said that only 26 countries have submitted formal submissions on the application or on the applicability of international law. This afternoon we have heard views from 40 countries, and what is also gratifying is that we have heard the views of countries who have not been involved in the GGE process, smaller countries. So, I want to thank all of them for their very thoughtful interventions. It is quite clear that lawyers have gotten involved in the drafting of these very thoughtful contributions. That is a good sign that legal counsels in your foreign ministries are paying attention to this process, but the very detailed nature of the many statements I think are very helpful to sort of for each one of you to understand what the position of different countries are, but also for me to see how we can find some common ground in terms of next steps. And certainly it seems to be that we should encourage more countries to make national submissions on the applicability of international law. The last submission exercise was carried out in the context of the GGE, and Estonia counted 26. My counting shows less than 26, so we’ll need to reconcile the figures, but in any event it’s a low number. So, we need more countries to get into this discussion on international law, because that provides the foundation for us to have a discussion on not only the Charter and how international law applies, how the principles of international law are applicable in the cyber context, but also for us to consider the possibility of additional legally binding obligations. So, such an understanding and contribution from all states will be welcome. So, this is certainly a discussion we need to continue. I didn’t think that it will take this long, but we need to press on with the other items on our agenda. So, let’s move on to the next item, which is confidence-building measures. And under this item – and there’s no coffee break this afternoon, so I apologize for that. We are behind schedule. So, we need to press on with confidence-building measures. And with regard to confidence-building measures, I draw your attention to, of course, the guiding questions. Now, with regard to the POC directory, I think we are some steps ahead of the discussion as compared to the other CBM issues because we’ve had a discussion over informal virtual means. So, I did not provide any specific question on the POC directory. So, I would like, first of all, to hear your views on the other questions on CBM. What other concrete specific CBMs are already in place at the regional level that we can consider adopting or embracing or endorsing at the global level? And also, whether there are other specific CBMs in other domains outside cyber that we can try and emulate in the field of cyber? And then, a more general question of what other measures can we do? So, I will now open the floor. I welcome you to press your buttons if you need to, if you would like to participate in this discussion. And again, a focused discussion, concrete elements are needed, and we need to find elements that we can capture for the annual progress report. So, the floor is open, starting with the Russian Federation to be followed by Kazakhstan.
Russia
Mr. Chairman, distinguished colleagues, I wish to congratulate all women experts in the area of security and ICTs on International Women’s Day. I also congratulate all those in the diplomatic missions of our countries as we are working here in the Open-Ended Working Group (OEWG). I would like to wish us all that our work will be reflected in the future international agreements of our group aimed at bolstering security throughout the world. When it comes to confidence-building measures (CBMs), we consider it a priority to agree upon the basic modalities of the Global Intergovernmental Directory of Points of Contact on security of and in the use of ICTs. The Russian Federation will submit a draft of the first universal CBMs a bit later. I will elaborate further on this in my next intervention. CBMs should promote practical interstate interactions and the prevention of conflicts in cyberspace. We must take into account both the positive and negative regional experiences in this area so as to elaborate an effective list of CBMs at the international level. For our part, we suggest considering the following possible measures. First, the exchange of information on national organizational structures, strategies, legislation, policies, and programs in the security of and use of ICTs. Secondly, consultations at the appropriate level so as to reduce the likelihood of misperceptions and the possible political or military tensions. This would be with the participation of diplomatic and technical Points of Contact (POCs). Thirdly, the establishment of a specialized UN information portal to strengthen dialogue, exchange best practices, raise awareness, and enhance the capacity building of member states on security of and in the use of ICTs. In this regard, we believe that a basis for further discussions in the OEWG could be India’s proposal on the establishment of an online portal. We also suggest agreeing upon the basic universal principles of CBMs on security in the use of ICTs. The adoption of such measures should not harm the security of participating states nor that of third states, should not provide any state or group of states with military, intelligence, political, economic, or other advantages. It should not be used as a tool to interfere in the internal affairs of states or for subjective political assessments of the activities and intentions of states in cyberspace with the subsequent imposition of various restrictive measures. Many states participating in the OEWG know firsthand what we’re speaking about. It is crucial to eradicate the practice of unfounded and baseless accusations against states of malicious activity in the field of ICTs. It is inadmissible to use CBMs to substantiate the political attribution of computer attacks. Given the non-binding nature of CBMs, if we do not have the necessary political will, their practical realization could be compromised. In these circumstances, it’s crucial not to lose sight of the strategic goal of consolidating intergovernmental cooperation mechanisms in the field of ICTs into universal, legally binding agreements. Thank you for your attention.
Ambassador Gafoor
Thank you, Russian Federation. Kazakhstan, to be followed by Israel. Kazakhstan, please.
Kazakhstan
Thank you, Mr. Chair. A good example of practical interaction between countries is the OSCE Informal Working Group on ICT Security. Within the OSCE, there are 16 confidence-building measures to reduce the risks of conflict arising from the use of ICTs. Under CBM 4, participating states voluntarily share information about the measures they have taken to ensure the openness, interoperability, security, and reliability of the Internet. Since 2019, representatives of Canada and Kazakhstan have supervised this CBM. According to CBM 8, the participating states define points of contact, political and technical, to facilitate communications and the dialogue of the security issues in the use of ICT. This measure is very important in order to establish interaction between countries. According to CBM 16, participating states encourage, on a voluntary basis, responsible reporting of vulnerabilities in the use of ICTs and how to address them. In principle, we believe that these confidence-building measures should be used at the global level. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you. Thank you very much, Kazakhstan. European Union, to be followed by Brunei Darussalam, so EU please.
EU
Thank you, Mr. Chairman. Mr. Chairman, I have the honor to speak on behalf of the European Union and its member states. North Macedonia, Montenegro, Serbia, Albania, Ukraine, Republic of Moldova, Bosnia and Herzegovina, Georgia, Iceland, Norway, Monaco, and San Marino align themselves with this statement. Mr. Chairman, international law norms, capacity building, and confidence-building measures form an integrated compendium that defines and shapes responsible state behavior in cyberspace. We remain convinced that the objective of the CBMs to develop and maintain communications between states to defuse conflicts and prevent escalation is now more relevant than ever, especially in the context of Russia’s continuing brutal, unprovoked, and unjustified military aggression against Ukraine. The recent years have seen important milestones in several regional organizations, including OSCE, as mentioned, Organization of American States, ASEAN, and ECOWAS. We believe that more effective norms and CBM implementation can be achieved by carefully assessing the experiences in various regional organizations as well as by taking advantage of existing synergies between UN deliberations and the regional CBMs and capacity-building initiatives. Regional fora have proven to be useful platforms for discussion, enabling focus on the regional and local specificities and involvement of a smaller number of stakeholders with common interests and concerns. Many regional organizations have built up experience in developing and implementing CBMs. It would be good to actively invite them to share their experiences in the Open-Ended Working Group. Countries that are members of regional organizations could benefit from joint CBM implementation initiatives and from fairly linking capacity-building initiatives with CBMs. In this regard, the EU has organized a cross-regional event on CBMs at the OSCE and continues to promote the idea of cross-regional CBM cooperation in order to broadly share good practices and be able to launch targeted activities such as cyber training, exercises, or e-learning activities. This inter-regional exchange will help to understand how different regions implement norms and CBMs practically and could enable participants to gain insights into relevant cybersecurity initiatives and assist in identifying common interests. These efforts complement the Open-Ended Working Group and Program of Action discussions and support and incorporate the regional perspectives and best practices into the discussions. They would further provide good grounds for furthering trust and collaboration internationally. Furthermore, concrete implementation is now the key. In that regard, the EU has been engaged within the OSCE in exploring how to develop crisis management procedures to better protect critical infrastructures against cyberattacks in light of the new security environment and the growing cyber threats against those infrastructures. Further steps might lead to mapping participating states’ cyber crisis management mechanisms, including the cooperative mechanisms with third parties or sharing existing assistance mechanisms, including in case of cross-border incidents. Civil society, academia, as well as private sectors, could facilitate the engagement with interested stakeholders that also have a role in supporting the implementation of confidence-building measures, in particular those including public-private partnerships. Moreover, involving actors from the technical level to the diplomatic one is crucial to ensure a comprehensive approach and commitment at all relevant levels. The development and operationalization – sorry, difficult word – of the global points of contact directory is valuable as it allows us to have greater tools and lines of communication to either coordinate or communicate in the event of cyber incidents. In light of the proposed POC directory, it is important that the participation is voluntary, as also highlighted in the Chair’s Elements paper. Too complex and scripted modalities could be difficult to manage to work out. We support a step-by-step approach in this regard. We agree on the importance of capacity building, which would allow states to establish this POC directory, noting that all capacity building related to the framework should be consistent with the principles agreed in the 2021 Open-Ended Working Group report, including corresponding to nationally identified needs and priorities. We also think that such a directory needs to be accompanied by regular comm checks to be effective in the long term, which is a practice regularly used at the OSCE level. Mr. Chairman, we look forward to further discussions and progress for the year to come on this agenda. Thank you very much.
Ambassador Gafoor
Thank you, EU. I now give the floor to Brunei. Ambassador, please.
Brunei
Thank you, Mr. Chair. It is an honor for me to deliver this statement on behalf of the Association of Southeast Asian Nations, ASEAN, on the topic of confidence-building measures. As the OEWG begins its work for the second annual cycle, ASEAN would like to express the view that it is important that we work towards a substantive second annual progress report and have this adopted by consensus at the next substantive session in July. The second APR should build on the first annual progress report agreed to by consensus last July and continue the progress that this working group has made. In particular, it should aim to continue taking steps forward on all pillars under the OEWG mandate. In this regard, it is also critical that we seek to elaborate additional details, including in the areas of key importance to many Member States, such as confidence-building measures and capacity building, and have this captured in the second APR. As we continue to take forward the work of the OEWG, ASEAN reiterates that confidence-building measures, CBMs, are important to develop trust, confidence, and cooperation. In fact, this open-ended working group, in itself, serves as a CBM towards building an open, safe, secure, stable, accessible, interoperable, peaceful, and resilient cyberspace. Enhancing trust and confidence in the use of cyberspace among key actors is essential. ASEAN recognizes that cybersecurity is a cross-cutting issue that requires coordinated expertise from multiple stakeholders from across different domains to address effectively. Mr. Chair, we are therefore strongly supportive of the ongoing initiative to develop a global intergovernmental points of contact directory and to have its implementation. The third part of my presentation is to allow me to share some of ASEAN’s own experience in the implementation efforts of the ASEAN Main Regional Level POC Directory on security of and in the use of ICT and the ASEAN Regional Forum, ARF. To ensure the contact listed in the domain is current, the ARF POC Directory is frequently validated and recirculated. At the same time, with regard to the POCs, the ARF POC Directory accommodates the diverse members, duly recognizing differences in national governmental arrangements relating to ICT security. Second, to strengthen ASEAN’s cybersecurity incident response, ASEAN has agreed to establish the ASEAN Regional Computer Emergency Response Team, CERT, to facilitate the timely exchange of threat and attack-related information among ASEAN member states’ national CERTs. ASEAN’s CERT would also foster CERT-related capacity building and coordination in a manner that does not take over or impinge on the operational role, mandate, and function of each state’s national CERT. Finally, ASEAN has made significant progress in ensuring coordination on cyber policy. As cybersecurity is a cross-cutting issue, the ASEAN Coordinating Committee on Cybersecurity, ASEAN CyberCC, was established to strengthen regional collaboration and coordination in cybersecurity. The ASEAN CyberCC comprises representatives from relevant sectoral bodies to strengthen cross-sectoral coordination on cybersecurity while respecting the work domains of the sectoral bodies. At the same time, cybersecurity cooperation is pursued under the ambit of the ASEAN Digital Master Plan 2025 and the ASEAN Cybersecurity Cooperation Strategy 2021-2025. ASEAN is also currently working on implementing the ASEAN Regional Action Plan on the implementation of the UNGGE norms of responsible state behavior in cyberspace. Mr. Chair, based on its regional experiences, ASEAN is hopeful that we can build on existing CBM mechanisms and leverage the experiences of the regional and sub-regional levels to contribute to our ongoing work in the OEWG, particularly with regard to the establishment of the Global POC Directory. Rest assured, ASEAN and its members will continue to engage constructively in this OEWG with other delegations and regional organizations in the interest of peace, security, and stability in cyberspace. I thank you.
Ambassador Gafoor
Thank you very much, Ambassador, for sharing the experience of ASEAN. Canada, to be followed by Spain. Canada, please.
Canada
Thank you. Thank you, Chair. Before I get into CBMs, I just wanted to pick up really quickly on your last point about intersessionals. Canada supports the calls made by many states, including India, who called for specific intersessional work and additional formal sessions on international law, possibly in May. A specific idea, in one of those sessions, is to have several experts from a list proposed by member states in order to brief on international law. We could have states submit to the Chair the name of one or two experts and then select a panel. This is something that we can discuss specifics offline, but I wanted to share our views. Now, moving to CBMs, I wanted to also react to the statement made by Kazakhstan, with whom, as the distinguished gentleman noted, we worked with on the adoption of CBM4. We see this as a very good example of working with non-traditional partners on CBMs, and one that could potentially be replicated by others in this room. On transparency measures now, you will recall that Canada has for years, since 2016 actually, been advocating for more transparency on active cyber capabilities and conditions surrounding their use. We got an idea along those lines, close to that, in a paper of the cross-regional group on CBMs. It did not, unfortunately, reach consensus in July. We understand that this idea may not be ripe now, so we will put it to the side for now, but we may come back to it later. In the meantime, there’s another idea that came to my attention that I found very appealing. It is one that has been put forward by the Cyber Peace Institute, and it is basically to be transparent about what sectors each country considers as critical infrastructure. This would be done on a voluntary basis, and it would help to, kind of like in our discussions about international law, lead to the emergence of common understandings. Canada has already done this in the context of our critical infrastructure strategy. We have identified 10 sectors, and one of them is ICTs. So we support this idea and encourage others to read the excellent paper by Cyber Peace Institute. I will return to the POC directory in the next section. Thank you.
Ambassador Gafoor
Thank you very much, Canada, for your ideas. I now give the floor to Spain, to be followed by Saudi Arabia. Spain, please.
Spain
Thank you very much, Chairman. At the outset, I’d like to thank the Secretary for organizing the meetings of this OEWG, and particularly we’re grateful for the guiding questions so that we can provide proactive and concise statements. Of course, Spain supports the statements by the EU, and we would like to add a number of comments in our national capacity on some of the proposals and statements made over the past few days. And as you pointed out, Mr. Chairman, all of the items on the agenda are closely interrelated. In the current context of the global geopolitical tension, CBMs are more than ever necessary. We must redouble our efforts in multilateral and bilateral fora, and make sure that states participate in good faith in the discussions and openly. The Open-Ended Working Group has the opportunity to provide a cohesive framework for CBMs, which already exist regionally, and I would focus particularly on the initiatives of the OSCE, the OAS, the ASEAN, and ECOWAS. I would point out that taking advantage of synergies between technical and diplomatic experts has become a necessity in these negotiations, because the current technological development is closely interrelated with our geopolitical environment, and hence the relevance of working on the POC directory. Spain fully supports that. We believe that the private sector is a particularly important actor in the development of CBMs. The private sector should be involved in these discussions not only because it will enrich our discussions with its experience, but because of the responsibility it has in implementing state norms. We support the statement by Canada regarding the participation of NGOs in this group. Spain welcomes Kenya’s initiative to develop a compendium of threats related to new technologies, with emphasis placed on the legal and practical treatment of these threats. We should not be drafting new documents which will just pointlessly make our archives larger. We should draw inspiration from existing instruments, such as the annual report of ENISA on cyber threats. To improve our understanding of vulnerabilities that the international society faces, given the constant and rapid development of new technologies, is extremely important. In point of fact, recognizing the existing rules and the challenges that we are facing in new technologies becomes extremely important. We would use as a basis the 11 norms proposed by the GGE, as well as the successive reports of that group and of the OEWG. We believe that we should focus our consideration on the implementation of these proposals. We support the drafting of a checklist to guide states in the correct interpretation and implementation of this regulatory framework. Spain would also welcome the holding of specific discussions in the intersession period on implementing international law, because this issue is particularly complex. Thank you.
Ambassador Gafoor
Thank you very much, Spain. Saudi Arabia to be followed by Singapore. Saudi Arabia, please.
Saudi Arabia
Mr. Chairman, CBMs are among the most important efforts to reinforce peace and security in cyberspace, and they also raise confidence through our cooperation. CBMs are important in light of the development of cyber threats, which lead to malicious uses and a regression in confidence. We give importance to the role of the United Nations in developing CBMs at the international level through submitting certain recommendations, in addition to facilitating the operation of discussing best practices. We refer to the important efforts to increase cooperation in CBMs. This will have the most significant effect. In this context, my delegation would like to refer to some measures carried out by the Kingdom of Saudi Arabia to increase trust. First, at the regional level, our country played an important role in supporting measures that reinforce CBMs. We also hosted the first meeting of the Ministerial Committee for Cyber Security in the Cooperation Council of Gulf Countries in October 2020. This meeting reinforced cooperation in the field of cyber security in light of new developments. At the international level, the Cyber Global Forum, initiated by the Kingdom of Saudi Arabia during its presidency of the Group of 20, is considered a very important platform for discussions on CBMs. It provides different measures for trust. In its second iteration, this forum included experts and industry leaders from more than 120 countries. At the end, we signed six memoranda of understanding in the field of cyber security. In this field, the Kingdom welcomes all countries to participate in the third iteration of the forum from 8 to 9 November 2023. Mr. Chairman, the Kingdom of Saudi Arabia is committed to recognizing all ways of cooperation with our regional partners and other countries. We look forward to working with other members to continue our discussions in the field of CBMs, and we welcome participation in cooperation in your open-ended team. Thank you.
Ambassador Gafoor
Thank you, Saudi Arabia. Singapore to be followed by Cuba. Singapore, please.
Singapore
Thank you, Mr. Chair. Singapore believes that confidence-building measures are a concrete expression of international cooperation. They play an important role in preventing conflicts, avoiding misunderstandings, and reducing tensions. Regional organizations have taken the lead to outline different types of CBMs aimed at building a system of direct communication between states to diffuse conflicts, prevent miscalculations, or unintentional escalation. There are currently seven CBMs which are being operationalized at the ASEAN Regional Forum. In addition to the ASEAN Regional Forum POC’s directory, which has already been spoken about, there are two CBMs in particular that are useful and could be expanded to the global intergovernmental context. They are, firstly, sharing of information on national laws, policies, best practices, and strategies, as well as rules and regulations. And secondly, awareness-raising and information sharing on emergency responses to security incidents in the use of ICTs. These two CBMs have facilitated the sharing of cyber strategies and incident response strategies and frameworks among ARF member states. It is through such sharing that member states can learn more about one another and better understand how each country operates in cyberspace and responds to malicious ICT activities. In this regard, the CBMs on sharing of cyber strategies and incident response frameworks could be included as part of the first set of CBMs to be operationalized at the OEWG level. Such sharing could facilitate interactions between countries, thus building trust and confidence and leading to more transparency and predictability. As a complement to the sharing in these exchanges, it may be useful to tap on the existing resources such as the UNIDIR Cyber Policy Portal. The portal is a helpful resource for member states to learn about member states’ cybersecurity strategies. States could be encouraged to contribute and grow the shared repository of knowledge, which will facilitate cross-regional exchanges and sharing of good practices. Additionally, conducting joint scenario-based tabletop exercises can also help to operationalize CBMs. In the ASEAN context, Singapore has hosted the ASEAN CERT Incident Drill, or ACID, since 2006, almost 17 years. ACID has been instrumental in building confidence within ASEAN as it provides a platform for member states to understand how their counterparts would respond during cyber incidents. Specifically, ACID has enhanced regional CERT-to-CERT cooperation and has helped national CERTs develop a common understanding so they know what is expected of them when they contact each other. To conclude, it would be useful for us to build on the existing CBM efforts undertaken by the different regional organizations. Strengthening our efforts on this front progressively can be a first step to address mistrust arising from misunderstandings between states by establishing communication, building bridges, and initiating cooperation on a shared objective of mutual interest.
Ambassador Gafoor
Thank you. Thank you very much, Singapore. Cuba to be followed by Argentina.
Cuba
Mr. Chairman, Cuba recognizes the considerable inter-sessional work that has been done on points of contact as well as on CBMs. We are grateful for your efforts and your team’s efforts to reflect the various contributions from member states. We reaffirm the fact that we believe that it is quite appropriate that the document underscores the importance of intergovernmental changes on the basis of mutual respect and on a voluntary basis to ensure peaceful cooperation among states. Any initiative—impartiality, security, and—with third-party—would take place. We should bolster—there should be confidence-building measures with developing countries as well as develop a POC directory. In addition to this, we agree that we should take advantage of existing international mechanisms where all states participate. They already have POC directories. We would not welcome any attempt to impose regional interlocutors and regional organizations to replace all members of a particular region. The POC directory is the only area where we should be focusing our efforts. This open-ended working group should continue to work to ensure that we eliminate the digital divide and we ensure inclusive and non-discriminatory access to information provided through ICTs. We cannot build confidence when obstacles and unilateral coercive measures are taken against international law. CBMs should be seen as a complementary way of improving cooperation and transparency. It should not replace responsible state behavior, which is required to ensure the peaceful use of cyberspace. These should be binding in nature. CBMs implemented at the regional level or sub-regional level cannot be seen as global models because each region is different. In any event, CBMs must be implemented on a voluntary basis without any interference in state sovereignty and independence. As we are a developing country, Cuba is ready to work with other developing countries and share our experience in the area of cyberspace, and we are working on specific actions in our teaching centers. Thank you.
Ambassador Gafoor
Thank you very much, Cuba. Argentina, to be followed by Germany. Argentina, please.
Argentina
Thank you very much, Chairman. Thank you for giving us the floor once again. We’ll be brief, and we will refer to the importance of CBMs for the implementation of the framework, using as a basis your guiding questions. The purpose of CBMs is to ensure levels of predictability globally through a common understanding of what we believe should be responsible state behavior for everyone in cyberspace, and we would do this through cooperation and communication to promote stable cyberspace in our international relations. For CBMs to be useful, they need to be practical, purposeful, and implementable. There needs to be appropriate capacity building if necessary. As we said yesterday, Argentina would highlight the role of regional bodies and international cooperation as catalysts for CBMs among countries with common cultures and similar levels of digital development and threats. In Latin America, we are working on adopting CBMs through the OAS, and we are guided by the 11 CBMs which make up the UN framework. To that end, we have worked collaboratively in my region to add to the CBM repertory. We have five CBMs already, and we are working on four more, which we hope will be adopted at the plenary of the Inter-American Committee Against Terrorism. We believe that this type of work is vital to bolster trust, ensure transparency, and inclusion among states, in the majority of cases with similar threats and similar levels of digital development. We believe that we need to separate the technical and diplomatic points of contact. That’s because of the different roles they play when it comes to exchanging information resulting from an event or an incident. The technical point of contact would facilitate exchanges on hemispheric cyber threats and then, at the national level, would assist in crime prevention, mitigating damage, and guiding public policy, including the development of norms related to security standards or measures. The diplomatic point of contact would facilitate international dialogue on cyber security and ultimately, diplomatic action resulting from incidents so that a better response can be determined. As Singapore pointed out, we have a CBM to exchange information on threats. We must bear in mind that in every regional cooperation mechanism, there will be similar CBMs, and we could explore the possibility of having a repository in the future. Continuing with your questions and guided by Canada’s comment, Argentina believes that we could work on actions to promote transparency. We support initiatives such as the exchange of information between states through the United Nations or through the UNIDIR Cyber Policies Portal. In this context, we believe we must improve the portal. We should be providing updated information, and the organization should also facilitate linguistic accessibility because this would help tear down barriers and overcome disparities. And finally, on this very special day, namely International Women’s Day, Mr. Chairman, I would like to greet all the cyber women here and those who are joining us on UNTV. We would like to encourage you to continue to work on ICT-related issues. Be you representatives of governments, decision-makers, staff of international and regional bodies, academics, representatives of NGOs and businesses, engineers, or scientists who are working on building the necessary critical infrastructure for the development of our countries, and finally, students who are pursuing these very complex careers. We need you to continue to study because we need the best possible professionals in this area. Argentina firmly supports the Women, Peace, and Security Agenda and its cross-cutting nature with the disarmament agenda as a political framework to guide our efforts. Once again, we welcome the Women in Cyber program and its donors. And I think perhaps one day we could imagine a gender-sensitive CBM which promotes inclusion, leadership, and effective participation of women in the decision-making process in ICTs. Thank you.
Ambassador Gafoor
Thank you, Argentina. Germany, to be followed by Ghana. Germany, please.
Germany
Thank you, Mr. Chair, for giving us the opportunity to look at the wider picture of confidence-building measures before we discuss the elaboration of the points of contact directory in more detail. Germany is fully aligned with the statement of the EU and would like to touch on two points in a national capacity: the potential of CBMs for the future work of this group and the resilience of CBMs in times of crisis. The primary focus of CBMs is to provide a communication channel for states to exchange information on cyber incidents with a view to preventing misunderstandings and serving de-escalation. We will focus on this in our dedicated exchange on the POC directory later. However, the potential of CBMs is much wider, and it has struck me, listening to the interventions over the last two days, how many touch points this discussion has offered to bring in CBMs as a practical tool to solve the issues that are important to us. Many delegations put forward proposals to work on tools that would guide states in the implementation of norms, rules, and principles. Many also underlined the direct relationship between non-implementation and international security. A dedicated CBM on the exchange of guidance on the implementation of rules, norms, and principles could be a very practical way to advance this. A point that was brought up by India, Malaysia, and other states is the need for dedicated legal capacity building to support states in the implementation of norms, including the development of an implementation roadmap as put forward by South Africa. A CBM serving as a platform for information exchange on targeted capacity building offered by UN agencies, UN member states, or civil society experts could make a direct contribution here. In our long and extensive discussion of threats, a strong recurring item was the request for sharing of best practices on the mitigation of major cyber incidents or in strengthening the protection of critical infrastructure, as Ghana suggested. These could be shared by a dedicated CBM that facilitates the exchange of best practices and mitigation tools. Across the different agenda items, we heard about the importance of elaborating fully gender-inclusive and gender-sensitive security solutions. We have also been convinced by many statements that fully incorporating the gender dimension is essential for attaining the necessary levels of cyber security. It would therefore be natural to also establish a CBM focusing on this particular dimension. If used actively, CBMs are of a strong action-oriented nature. CBMs agreed in this open-ended working group could eventually form one of the pillars of the future Program of Action. As a participating state of the Organization for Security and Cooperation in Europe, Germany is very much guided by the experience of developing and implementing the 16 CBMs of the OSCE. It is our experience in the OSCE that these CBMs show resilience in times of crisis. The OSCE brings together a very diverse set of countries, and Europe is experiencing its most severe security crisis in many decades. However, this has not had a negative impact on the implementation of CBMs. To the contrary, the cyber CBMs have been put to active use by OSCE participating states in this time of crisis, helping us to exchange information on cyber incidents and to advance other important items like the protection of critical infrastructure. At a time when many working groups of the OSCE struggled to operate or even went out of business because of the crisis, the cyber working group of the OSCE continued working actively and, in fact, has taken new steps in the implementation of CBMs. This was due to the resolve of the OSCE participating states, but very importantly also thanks to the inspiring leadership of the chair of the OSCE cyber working group, Ambassador Dan of Hungary, and the unwavering support of the OSCE Secretariat’s cyber unit, led by Sylvia Todt. In closing, let me state that Germany sees CBMs as one of the most promising areas of work for the years ahead of us in this open-ended working group. Germany looks forward to elaborating this line of work further within the open and formal cross-regional group, which is ready to contribute a joint statement later in the discussion on the POC directory. Thank you.
Ambassador Gafoor
Thank you, Germany. Ghana, to be followed by Mexico.
Ghana
On CBMs, Ghana believes that confidence-building measures put in place by the Organization for Security and Cooperation in Europe, OSCE, are relevant. Firstly, CBM1, CBM4, and CBM5 are useful tools. The above-mentioned CBMs can be expanded to global intergovernmental contexts. Furthermore, Ghana supports the development and implementation of CBMs such as communication channels amongst states for crisis management in relevant bilateral, regional, and multilateral forums, including the OSCE, the Open-Ended Working Groups like this, as well as platforms such as those organized by the African Union and the Association for Southeast Asian Nations. Member states can share best practices at a regional level and have tangible conversations on the implementation of these norms, as well as looking at practical and tailor-made solutions that are unique to their own regional context. Mr. Chair, Ghana also supports the FAIRTH recommendation steps under the confidence-building measures section of the annual progress report, which encourages states to voluntarily share information on their concepts, strategies, policies, programs, and ICT institutions and structures related to international security. This can be done through the Secretary-General’s report on development in ICT and international security in the United Nations Institute for Disarmament Research Cyber Policy Portal, as appropriate. Ghana also supports the establishment of the Global Intergovernmental POC for enhancing interactions and cooperation between states as a useful CBM tool by building on existing regional initiatives, as highlighted in paragraph 16A of the annual progress report. Mr. Chair, I’ll very briefly touch on the POC, as this is especially of interest to our delegation, because Ghana established the launch of a cybercrime incidents reporting point of contact at a national level in 2019. This platform was launched with the aim of facilitating the reporting of cybersecurity incidents. This initiative was aimed at bridging the gap across all demographics, including government, private sector, public, and children. To date, the multi-platform approach has provided multiple channels through which incidents can be reported to the cybersecurity authority, and has also bridged the gap between the public and the computer emergency response team. This in itself is a confidence-building measure. To date, there have been 37,358 contacts made, out of which there have been 33,777 advisories. Ghana believes that having designated POCs at an international level will be beneficial, as we have seen this practically at a local level. It is, however, important that a directory of this nature respects state sovereignty, maintains political impartiality, is safe, operable, constantly updated, and complemented as needed by capacity-building initiatives like tabletop exercises. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you. Ghana. Mexico, followed by the Islamic Republic of Iran. Mexico, please.
Mexico
Thank you, Chairman. The CBMs have proven to be effective in other areas of international security, and therefore Mexico believes that the OEWG will continue to be an important part of international dialogue and efforts in the CBMs. Complementary efforts will reinforce the work of the OEWG. In addition to generating certainty and stability, CBMs promote transparency, monitoring, as well as accountability in and among states. For my country, CBMs must be seen as an integral part of the UN framework and are complementary to the implementation of norms on the responsible use of ICT and the application of international law, as well as to generating cooperation and capacities. We also believe they are an essential benchmark for developing cyber diplomacy. We believe that gradual measures will promote dialogue among states and reduce the risk of malicious activities in cyberspace. These measures are essential to further common understanding, reduce the risk of misperception and the escalation of misperceptions, as well as to increase predictability on state behavior and stability in cyberspace. Mexico welcomes the importance of CBMs at the regional and subregional levels. We believe that as a priority, there should be effective joint work on the point of contact directory, as well as cooperation among CSIRTs internationally and regionally, as has been mentioned in previous sessions, and the establishment of an international repository. We believe that we should continue to work on this proposal. The creation of this repository is essential to create trust, transparency, and an exchange of information on lessons learned when it comes to containment, mitigation, and restoration in response to such attacks and incidents. We also recognize the role of regional organizations such as the OSCE in Europe, the OAS, and the ASEAN Regional Forum to develop and use CBMs to reduce tensions stemming from the use of ICT among participating states. In these organizations, valuable platforms can be established to share and exchange information, facilitate communication, provide resources, and exchange best practices. My country also welcomes the participation of expert voices from academia, civil society, the industry and service providers, as well as other NGOs working in this field. Therefore, Mexico is open to continue working under the leadership of the chair of the OEWG in identifying and agreeing on modalities to ensure this substantive participation based on the principles of transparency and representativity.
Ambassador Gafoor
Thank you, Mexico. Iran, to be followed by Czechia, please.
Iran
Thank you, Mr. Chair. Mr. Chair, I will have another statement on POCs when you open the agenda item. In the meantime, and in response to your first guiding question on confidence-building measures, my delegation would like to point out that producing a consensus glossary of terminology is one of the concrete and specific CBMs. Some regional organizations have adopted a similar approach in the ICT security domain. This experience could be universalized in an intergovernmental context. The idea and value of developing a universal terminology in the field of ICT security have been discussed and highlighted during the current and previous OEWG as a practical step for furthering international cooperation and building trust. The first annual progress report of the OEWG has invited the States to share their national views and definitions of technical ICT terms to promote mutual understanding. While we welcome this recommendation of the APR as an initial and first step necessary, we believe that to reduce the risk of misunderstandings in the absence of an agreed terminology, the OEWG could take more concrete steps forward and incorporate it into its future annual progress report the recommendation of developing a universal terminology in the field of ICT security. Mr. Chair, from our viewpoint, a step-by-step approach highlighted by you and many delegations at the informal intersessional meetings in December 2022, as well as the current substantive session, could also be applied to the elaboration of a universal terminology in the field of ICT security. The OEWG could start preparing a list of terms used in consensus UN documents and then proceed to agree upon definitions of the basic terms from the list, for example, ICTs, ICT infrastructure, ICT environment, malicious use of ICTs, etc. Mr. Chair, let me take this opportunity to highlight that restrictive measures against other states in the ICT environment pose serious threats to trust and confidence in the ICT environment. It is an important confidence-building measure that states refrain from adopting any measures to restrict or prevent universal access to the benefits of ICTs. I thank you, Mr. Chair.
Ambassador Gafoor
Thank you, Islamic Republic of Iran, for your statement. Chile, you have the floor next.
Czech Republic
Thank you, Mr. Chair. The Czech Republic aligns itself with the EU statement delivered earlier and wishes to emphasize a couple of points in our national capacity. At the outset, I would like to thank you, Mr. Chair, for your leadership, particularly for your commitment and dedication towards the establishment of a global point of contact directory. We recognize reaching a consensus requires a lot of effort, but we share your vision for it to be endorsed as a part of an annual progress report. We appreciate that the POC negotiations, which we will discuss in more detail later today, are moving in a positive direction. We hope that the same will happen in other areas. Our aim is to have an overall balanced output of the Open-Ended Working Group. I take this opportunity to inform you that we have joined a cross-regional group of states led by Germany, which advances CBMs in the framework of the Open-Ended Working Group by focusing on finding common ground in the field of CBMs. As for the current discussion, I would like to highly acknowledge the very well-prepared guiding questions. From our point of view, they clearly indicate a direction we should take in our future discussion. To respond especially to the first question, what concrete specific CBMs are currently in place at the sub-regional level in the ICT security domain that could be expanded to the global intergovernmental context, I would like to call your attention to the topic of Coordinated Vulnerability Disclosure Policy. It’s not a new topic in our negotiations. I primarily refer here to the Norm J of the 2015 GGE report. It is also intensively discussed within the OSCE. Some countries already mentioned the list of 16 CBMs approved by OSCE. This one is exactly the CBM number 16. We can therefore draw on our experience of this forum. The Czech Republic repeatedly agreed this week that there is no need to develop a new legally binding instrument and instead we have to focus on operationalizing the already established norms of responsible state behavior. Coordinated Vulnerability Disclosure is a concrete area where we can do exactly that. At the end, I would like to react to some previous interventions. First of all, I would like to support a proposal of Canada elaborating the idea of the Cyber Peace Institute to clarify among ourselves what sector we, as the UN member states, consider to be part of the critical infrastructure. And then I would like to support a recommendation of my Singaporean colleague concerning the cyber policy portal of UNIDIR. The Czech Republic considers the cyber policy portal as a very elaborated tool which can be used quite easily and efficiently for the operationalization of our CBMs. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you, Czechia. Chile, followed by Hungary, please.
Chile
Thank you, Chairman. CBMs, which include measures related to transparency, cooperation, and stability, can help prevent conflicts, avoid misperceptions and misunderstandings, and reduce tensions. Moreover, they are a concrete expression of international cooperation. With the necessary resources, capacity, and cooperation, CBMs can bolster security, resilience, and the peaceful use of ICT technology. Our country places great importance on the development and implementation of CBMs, highlighting the work done by international organizations, and in particular, the work done by the OAS Working Group on Cooperation and CBMs in Cyberspace. That group made it possible for us to develop and adopt six measures in our region. Similarly, on the 26th and 27th of October, the fourth meeting of this group was held in Mexico City, chaired by Mexico, and during that meeting, five new CBMs were introduced on the following: 1. Gender approach. 2. Implementation of the 11 voluntary non-binding norms on responsible state behavior in cyberspace, adopted by UNGA Resolution 70-237. 3. International law. 4. Promoting in the area of ICT work and discussions with all interested parties, such as civil society, academia, private sector, technical community, to mention but a few. 5. The drafting of national schemes to determine the severity of cyber incidents and to share information on these incidents. For Chile, the establishment of national points of contact is, in itself, a CBM. It could help with the implementation of other measures, and we think it would be interesting to establish within the United Nations a global point of contact directory. That could function as a genuine community and network, and it could be configured along the same lines as already existing networks at the regional level. Our experience has shown us that points of contact are very valuable when it comes to exchanging information, notifying about incidents, and coordinating in order to create areas for cooperation among states. Finally, at the regional level, it is important for us to implement these measures and to promote inter-regional dialogue so that we are familiar with other experiences and can exchange lessons learned and best practices. And finally, we would echo the comments made by Argentina on the gender issue, inclusivity, and capacity building. Thank you very much, Mr. Chairman.
Ambassador Gafoor
Thank you very much, Chile. Hungary, to be followed by China. Hungary, please.
Hungary
Thank you, Chair. Thank you for giving me the floor. Hungary aligns itself with the statement delivered today by the European Union and wishes to add some further comments in our national capacity and also would like to address some of your guiding questions on CBMs. First, let me tell you that my delegation highly values the work carried out by this particular working group on many parallel and strongly interrelated tracks. As mentioned by many others, this group continues to base its work on previously agreed norms and principles by different UNGGEs and OEWG. Just quickly referring back to the very intense discussions in the previous session, Hungary would like to reconfirm its support for the application of international law in cyberspace and does not see the need for a new legally binding instrument at this moment in time. However, this topic deserves further examination, and therefore we welcome Member States’ call for further in-depth discussion in attendance of legal experts in the intersessional period before the July session. This exercise, as part of our roadmap, could also assist and encourage additional States to actively participate in the discussion, also as a confidence-building measure, and as a consequence, publish their own national positions. This should actually be understood as a voluntary next step for each country’s legal expert communities, but also other communities of national security and military, to publicly state what might already be applied in practice. Chair, turning to the topic of confidence-building measures and specifically to the question of the POC directory, Hungary welcomes the Chair’s revised non-paper on the establishment of the global directory, which is a good basis for our further discussion. Hungary welcomes the recommendation to establish a global point of contact directory as a confidence-building measure, allowing also to reduce risk stemming from the use of ICTs and making concrete progress on advancing international security and stability. We felt inspired by the many interventions made today and earlier by Member States, regional organizations, and other observers on their specific experiences and ideas on how such a UN directory would fit into the global discussions on cyber or ICT security. Mr. Chair, on a practical note, I would like to highlight the role of the managers of existing directories in general. Managers, however, can also assist in interactions between Member States that are part of different regional organizations with an existing POC directory but that have not yet nominated points of contact themselves. It’s important to remember that not all UN Member States are party to regional groupings, and not all UN Member States that are have actually nominated a POC for any particular reason. Of course, all Member States have to agree in advance that the contact details, for example, from any given POC directories can be transferred to another directory. A POC can actually be understood as a kind of an IP address, which should directly and clearly pinpoint the responsible person or entity with the necessary capacity to contribute to easing tensions arising from a cyber incident. Although nominating a POC at a national level is a relatively easy step, something that we usually refer to as a low-hanging fruit, further development of the directory should, however, happen in a step-by-step manner, also to ensure that Member States possess the necessary capacities. We also have to think about how to combine existing tools like the openly available cyber country profiles of the UNIDIR’s Cyber Policy Portal with the envisioned directory to better inform our future and existing POCs about the national context and structures they are operating in. Chair, to answer your questions with regards to further measures to promote increased confidence and transparency between States, I wish to refer to the 2018 initiative of the Hungarian chair of the informal OSCE working group on the development of confidence-building measures to reduce the risk of conflict stemming from the use of ICTs, the so-called Adopt-a-CBM initiative, which invites States or a group of States to champion the elaboration of modalities for implementing a specific CBM, taking into account a growing number of adopters and CBM-related projects, as has already been mentioned by the representative of the OSCE. This initiative is already producing tangible results at the regional level. Finally, Hungary supports the efforts aimed at closer cooperation between the UN processes and other relevant regional organizations like the OSCE and others like the OAS or ASEAN. We are also in favor of elaborating on the globalization of regional CBMs in the context of the OEWG and hope that our experiences could serve as inspiration for other regions and countries. Member States with regional expertise in implementing cyber CBMs should promote cross-regional discussions on best practices and encourage others to be the first to actually engage in the implementation of a global cyber CBM, like the nomination of a national POC once the POC directory has been established, or any other potential CBMs. Thank you very much, Mr. Chair.
Ambassador Gafoor
Thank you very much, Hungary. I didn’t want to interrupt your statement, but I wanted to make clear that it’s my intention to come back to a discussion on the PoA modalities later, because I really do want to go through the discussion on the rest of the CBM aspects of the agenda, which has not received the same level of attention as the PoA directory. And I know the two issues are interrelated; it’s very difficult to separate them, but I do want to go with the rest of the speakers’ list and invite them to focus on the CBM aspect of the discussion, keeping in mind that we’ll come back to discuss the modalities of the PoA directory. So I continue with China, to be followed by Malaysia. China, please.
China
Thank you, Mr. Chair. China believes that the purpose of CBMs is to enhance mutual trust and predictability and reduce miscalculations, which is of positive significance to safeguarding cybersecurity. China supports the implementation of CBMs such as policy exchange, law enforcement cooperation, technical exchange, and information sharing by all countries on a voluntary basis. We also support a gradualistic approach to increase mutual trust and reduce misunderstanding. At the same time, all countries must not use CBMs as an excuse to cause the proliferation of cyber weapons, which undermines cybersecurity and stability. Additionally, we stress that CBMs alone cannot effectively safeguard cybersecurity. CBMs cannot substitute international rulemaking in cyberspace. The two are mutually reinforcing and complementary. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, China. Malaysia to be followed by Mauritius. Malaysia, please.
Malaysia
Malaysia aligns itself with the statement delivered by Brunei on behalf of ASEAN. We would also like to put forward certain points in our national capacity. Malaysia strongly supports confidence-building measures as tools to address misunderstanding and misperceptions of events which may lead to miscalculations, escalations of tensions, and potentially conflict. The distinct contributions of CBMs in instilling trust and confidence among states are widely recognized. New and emerging disruptive technologies have immense potential for innovation’s digital transformation. However, the trustworthiness of technologies can only be achieved through transparent verification where threat visibilities are necessary. In this regard, the participation of stakeholders is important. Malaysia values the elaboration from Switzerland during the informal intersessional meeting last December on existing initiatives, standards, and platforms that are being used by cybersecurity practitioners to manage incidents and vulnerabilities. One of the initiatives mentioned was the Common Vulnerability Scoring System, CVSS, which is used to evaluate the threat level of vulnerabilities. The Common Vulnerabilities and Exposures, CVE, score is often used by cybersecurity practitioners to prioritize security vulnerabilities. The CVE identifier serves to standardize vulnerabilities information and unify communications among practitioners, including for security advisories and vulnerabilities databases. The National Cyber Coordination and Command Center of Malaysia utilizes CVE scoring as one of the indicators in determining our national cyber threat level. This is also the case with the Traffic Light Protocol, TLP, that is widely used to facilitate the sharing of sensitive information with the appropriate parties. Having said this, Malaysia believes that the OEWG should consider how best to leverage upon and find convergence on existing initiatives as part of CBMs that we may focus on. This can also facilitate the development of the UN Global Point of Contacts Directory. The ASEAN Cybersecurity Cooperation Strategy 2021-2025 provides a roadmap for cooperation to achieve the objective of a safe and secure ASEAN cyberspace through the application of voluntary, non-binding norms of responsible state behaviors, confidence-building measures, and coordinated capacity building. The ARF Work Plan on ICT Security and the ARF Open-Ended Study Group on CBMs to Reduce the Risk of Conflicts Stemming from the Use of ICTs were established specifically to focus on CBM initiatives among ARF participants, recognizing the special characteristics of the cyber environment that need to be addressed differently. In this regard, Malaysia supports the proposal from Singapore to elevate two CBMs from the ARF to be considered as CBMs under the OEWG. Malaysia believes that member states would benefit from greater sharing of best practices, experiences, and assessments focused on the implementation of CBMs at the national and regional level to advance ICT security. Lastly, Malaysia would like to join the others in recognizing the value of the UNIDIR Cyber Policy Portal as a confidence-building tool to promote trust, transparency, and cooperation in cyberspace and should be further leveraged by the OEWG. Thank you, Chair.
Ambassador Gafoor
Thank you, Malaysia. Mauritius to be followed by the Republic of Korea.
Mauritius
Thank you, Chair. Mauritius is of the opinion that transparency and confidence-building measures fundamentally contribute to the security, safety, and sustainability of activities in cyberspace. Confronting emerging cyber threats and existing cyber crimes requires coherent and sustained efforts, as well as extensive and comprehensive international cooperation and partnerships that encompass governments, regional and international organizations, the private sector, academia, business organizations, and civil society. With reference to your guiding questions on specific CBMs that are currently in place and further measures that could be taken, Mauritius would like to state the following. Firstly, as pointed out yesterday, an information-sharing platform has been set up in Mauritius to allow organizations at national, regional, and international levels to share threat-related information and therefore stay ahead of existing and potential cyber threats. Interested states are encouraged to apply for membership to benefit from the information exchange. Secondly, on the regional front, computer emergency response teams can take advantage of the working group established by AFRICA CERT if they are also working towards building a strategy to implement norms and CBMs. Thirdly, still referring to computer emergency response teams, as there is no official process for them to become established and visible to other security teams in the international context, they can consider going for the Trusted Introducer or TI certification based on the Security Incident Management Maturity Model, also known as SIM3. This will prove to the international community their maturity and commitment to keep up with modern security challenges and adhere to agreed best practices and standards. Finally, allow me to briefly indicate that Mauritius welcomes the Chair’s proposal on the Global Intergovernmental Points of Contact Directory comprising POCs at both diplomatic and technical levels that serves as a CBM in itself. Thank you very much, Chair.
Ambassador Gafoor
Thank you very much, Mauritius, for your statement. Republic of Korea, followed by Switzerland. ROK, please.
Republic of Korea
Thank you, Mr. Chairman. We think the CBM is an important part of the mandates of this Working Group. CBMs contribute not only to mitigating escalations and avoiding the risk of conflicts, but also to facilitating cooperation among countries, which is essential to ensuring security in cyberspace. CBMs could include various measures; voluntary exchange of information on national legislation, policy, incidents, and best practices is an essential element of CBMs. Establishing points of contact that we will be discussing later is also an important way of confidence building. CBM is basically between governments, but we believe that, as pointed out by Spain and others, confidence building can be further enhanced through a multistakeholder approach. Active exchanges between academia, IT experts from the private sector, NGOs, and others can contribute to strengthening CBMs. Regional dialogues provide a diverse set of CBMs that strengthen mutual trust between member states in the region. Therefore, in its efforts to establish global CBMs in the field of ICT, this Working Group can benefit from the successful examples of CBMs that have been achieved in the regional context. As many ASEAN colleagues have pointed out in previous statements, one noteworthy example of a regional CBM is the ASEAN Regional Forum’s intersessional meetings on ICTs. CBM is one of the core aspects of the ICT pillar of the ASEAN Regional Forum. The ARF Work Plan on Security of and in the Use of ICTs adopted in 2015 is the first consensus document regarding CBMs in the Asia-Pacific. As the current co-chair of the ASEAN Regional Forum’s intersessional meeting on ICTs, the Republic of Korea has focused on CBMs and capacity building in the Asia-Pacific region. The 2022 intersessional meeting provided a timely opportunity for member states to exchange their views on regional CBMs. This year, under the ARF framework, the Republic of Korea and Vietnam will be hosting a workshop on fostering cybersecurity professionals. The workshop will provide a valuable opportunity for security experts and government officials from member states to exchange views on the issue of the cybersecurity workforce. The Korean government also launched an initiative in 2016, namely the Cybersecurity Alliance for Mutual Progress, a dialogue functioning as a platform for sharing recent trends in cybersecurity policy and the development of new security technologies. In addition, the Asia-Pacific Information Security Center is an initiative providing training for our partner states’ computer agency response teams. We share our best practices to enhance and further explore possible ICT cooperation in the region, which builds mutual trust between our partners. Future discussions of the OEWG can extract lessons learned from regional CBMs. Successful regional CBMs that have enhanced trust and transparency in the ICT environment can be replicated at the global level to achieve a secure ICT environment for all member states. I thank you, Mr. Chairman.
Ambassador Gafoor
Thank you, Korea. Switzerland to be followed by Uruguay. Switzerland, please.
Switzerland
Thank you, Mr. Chair. I will base my intervention on the experience we have had in the OECD. Within the framework of the OECD, there are several CBMs that concern the exchange of information between participating states and are implemented in practice. The delegation of Kazakhstan mentioned a concrete example. The logical channel for such an exchange of information could be the POC network. But until it is established, all the existing forums or portals, such as the OEWG itself or the UNIDIR cyber policy portal, can serve as a platform. Information exchange could be on national perspectives, on various aspects of national and transnational threats to ICT, on measures taken to ensure an open, free, and secure cyberspace, or on national organizations, strategies, programs, and projects, as others have mentioned before. The exchange of information would take place on a voluntary basis. Here, I would briefly also address the proposal that has been made on the universal terminology. From our point of view, such an undertaking would take a lot of time and tie up a lot of resources unnecessarily. The mandate of this open-ended working group running until 2025 would not provide enough time for such an exercise. We see more merit in sharing information on national definitions or terminology to better understand other states’ positions and prevent misunderstandings. This is what we do in the framework of the OECD. CBM9 provides a platform for such an exchange, and Serbia is doing a lot of very valuable work on this. I think they have collected over a thousand terms until now, and you can imagine trying to find a common terminology on all these terms is almost impossible, or in our view, it is impossible. Also, within the OECD, we have developed a procedure for consultations in order to help reduce the risks of misperception, political or military tension, or conflict that may stem from the use of ICTs, and to protect critical national and international infrastructure, including their integrity. Such a procedure could be developed on the global level too. Recent cyber incidents and the actual geopolitical situation have shown that the protection of critical infrastructure becomes ever more important. The OECD’s CBM15 is dedicated precisely to this topic and intends participating states to encourage, facilitate, and/or participate in regional and sub-regional collaboration between legally authorized authorities responsible for securing critical infrastructures to discuss opportunities and address challenges to national as well as trans-border ICT networks upon which such critical infrastructures rely. Such cooperation could also be promoted at the global level. Another example is CBM14 on the promotion of public-private partnerships. States could exchange information on how to promote public-private partnerships. An important CBM in place is the sharing of vulnerability information. The Czech Republic made reference to this, and I would like to thank the delegation of Malaysia for mentioning the Common Vulnerability Scoring System. Participating states should, on a voluntary basis, encourage responsible reporting of vulnerabilities affecting the security of and in the use of ICTs and share associated information on available remedies to such vulnerabilities. States should use proportionately authorized and secured communication channels for sharing such information. Mr. Chair, as with the issue of the POC network, we should take a step-by-step approach to this issue. We should therefore start with CBMs that are easier to implement. Information exchange on the threat landscape, national organization, and programs or strategies would fall in this category in our review. Thank you.
Ambassador Gafoor
Thank you, Switzerland. Uruguay, followed by South Africa. Uruguay, please.
Uruguay
Thank you very much, Mr. Chairman. Our country recognizes the key role of the United Nations in drafting CBMs, and we support its implementation worldwide. That has been reflected in previous reports of the GGE and the Open-Ended Working Group. Similarly, we believe it is important to listen to regional and sub-regional organizations who have already done enormous work to draft CBMs and adapt them to their specific contexts and priorities. One example is the OAS. In this regard, Uruguay believes that the OEWG should reflect on possible mechanisms or initiatives which would develop cooperation and the exchange of experiences and good practices among different regional and sub-regional organizations in this area. Mr. Chairman, Uruguay welcomes the informal documents submitted by the Chair as the basis for future discussions, and we support the creation of points of contact directories. We believe that this will help promote confidence in and of itself, and it will lead to an open, safe, accessible, and peaceful use of ICT for all states to participate actively in this instrument. We must build the technical capacities to do this, bearing in mind that needs may vary and they are specific to each region and country, and to address the creation and the development of capacities. Uruguay supports the comments by Chile and Argentina on the capacity building with a gender-based approach to promote inclusiveness. Thank you.
Ambassador Gafoor
Thank you, Uruguay. South Africa, to be followed by Australia.
South Africa
Thank you, Chairperson. We will keep our comments on this item brief as we have already elaborated in detail on the points of contact directory. Firstly, it is important for us to recognize the value that delegations have already derived from the fruitful and action-oriented engagement in the OEWG. We believe that this forum has proved itself to be a confidence-building measure. Secondly, South Africa believes that the extensive work done in the development of ideas around the establishment of the POC directory, as expressed in your revised non-paper, is a good basis for further discussion. In accordance with the 2022 Annual Progress Report, in which we agreed to establish a POC directory, we would like to move forward with this project. Thirdly, another area where we could build confidence through global cybersecurity cooperation is the establishment of an integrated platform as proposed by the Delegation of India. We support the proposal to voluntarily share concept papers, national strategies, policies, and programs, as well as information on institutions and structures relevant to ICT security on such a portal. Fourthly, given the fact that so many delegations have referred to CBMs used in regional organizations, it might be useful for us to consolidate a list of these for background information. Finally, we believe that the proposal to establish a repository for information on cyber threats is also a proposal we should consider. Thank you.
Ambassador Gafoor
Thank you very much, South Africa, for your succinct and focused intervention. Australia to be followed by Belgium.
Australia
Thank you, Chair. Chair, I want to commend you for your commitment and work to take a core proposal for a Cooperative Confidence Building Measure, that is, a Global Points of Contact Directory, which had been suggested and recommended by the 2015 and 2021 GGE reports and the 2021 OEWG report, and put meat on the bones, operationalizing and implementing these words on a page into something that we can all participate in hopefully very soon. Australia made a detailed intervention on the PoC directory at our informal last week, with the intention of providing constructive suggestions for improving that non-paper, and we look forward to your update of that non-paper based on our conversations last Thursday and this week. You asked about what other CBMs we should focus upon in the work of the Open-Ended Working Group. Rather than looking at new ideas and new proposals, I suggest that the model that we are following in relation to the PoC directory could serve us in the next steps that we take on broader topics of CBMs. There are many rich and practical ideas for increasing trust and confidence between countries in cyberspace, which are for the most part still words on a page in our foundational key. I suggest that we look at those recommendations and follow the roadmap that you have set for us, discussing and agreeing in detail how we would implement a CBM, putting resources towards that implementation, and then ensuring that all countries have the capacity and the capability to meaningfully engage in that CBM. A brief look at the confidence-building measures recommended from our key provides several possibilities for our next project. For example, drawing from the 2021 GGE report, we could elaborate upon a few of those proposals. First, sharing and disseminating information and good practices on establishing and sustaining national computer emergency response teams. Secondly, exercising transparency by sharing cybersecurity agency missions and functions and the legal and oversight mechanisms under which they operate. Or thirdly, exercising transparency through the exchange of national views and practices on cybersecurity incidents and related threats, and making cybersecurity advice, guidance, evidence bases, and data supporting decisions publicly available to assist good risk management decisions. I want to thank those many states who have also raised the issue of threat sharing this week and support those. And Australia would suggest in the theme of this week that where appropriate, this threat sharing would include through the collection and making publicly available gender disaggregated data. Because the ongoing collection of gender disaggregated data by governments, civil society, and researchers, when cyber incidents take place, including analysis of the way that men, women, non-binary identifying individuals, and different communities are affected, can enable more effective policy responses when these events take place and strengthen efforts to support women’s and whole-of-society relief and recovery following an incident. And Australia sees one of the key benefits of this approach, that is, taking and implementing the GGE and OEWG recommended CBMs one by one in a detailed way. The benefit of this is the way that this group can promote and encourage operationalization of these CBMs by all countries. Because once we have a specific proposal for action, which we all agree, and guidance on how to implement it, it becomes clearer how to tailor capacity building projects so that all countries can meaningfully implement, participate, and engage in those specific confidence-building measures. Thank you, Chair.
Ambassador Gafoor
Thank you, Australia. Belgium to be followed by the Netherlands. Belgium, please.
Belgium
Thank you, Chair. I’m speaking on behalf of the six countries adopting CBM 14 of OECD, on preparedness in general and on public-private partnership in particular, to respond to guiding question one on specific CBM at the regional level in the ICT domain. The six countries are Austria, Belgium, Estonia, Finland, Italy, and Sweden. These countries have been actively engaged in the OECD discussion as adopters of CBM 14, which focuses on promoting public-private partnership and developing mechanisms to exchange best practices of responses to common security challenges stemming from the use of ICTs. The six countries would therefore like to underline that the OEWG discussion on CBM should take into account the role of and opportunities stemming from public-private partnership. One example could be that public-private cooperation may be necessary to protect the integrity, functioning, and availability of critical infrastructure and critical information infrastructure. The six countries sponsored a study on the positive feedback one could collect about PPP’s experiences in various OECD countries. The study is ready in the form of a report that should be published this week or next week at the latest. The report will be available on the OECD public website. The launch of the report would be the subject of a specific event at the OECD informal working group in June 2023, as well as possibly during the session of the open-ended working group in July. Thank you, Chair.
Ambassador Gafoor
Thank you, Belgium, for your contribution. Netherlands, to be followed by Venezuela, please. Netherlands.
The Netherlands
Thank you, Chair. The Netherlands is fully committed to multilateralism, respects the right of all delegations to make proposals, and actively encourages states to express their views here in the Open-Ended Working Group. We value the Open-Ended Working Group as a platform for inclusive dialogue and consider all proposals based on their substance and merit. In doing so, we put up front the core principles essential to the maintenance of international peace and security. Chair, confidence-building measures are essential for reducing the risk of misinterpretation, miscalculation, and unintended escalation of cyber incidents. This week, it took us more than a day to discuss threats. This demonstrates the increasing sense of urgency around the current threat landscape, making our work on confidence building all the more pressing. We’ve heard many delegations refer to the work that has been done in regional organizations on CBMs, while at the same time underlining the importance of bringing on board states that are not a member of these organizations, and we believe the global POC directory could be highly beneficial in this regard. Let me share our thinking on topics that may help us make further progress on CBMs. From our perspective, this could include encouraging further transparency in areas such as national policies, national approaches to classifying ICT incidents in terms of the scale and seriousness, and, of course, positions relevant to multilateral discussions. The submission of national views to the Secretary-General’s report is a key tool in this regard, as is the UNIDIR cyber policy portal. Finally, Chair, allow me to share one of our experiences in implementing a CBM agreed within the OSCE on coordinated vulnerability disclosures. We identified that an important first step in promoting regional cooperation in this area is for states to develop national coordinated vulnerability disclosure policies, or CVD. The Netherlands has done so, and I would also like to bring the OSCE e-learning course on CVD to the attention of all delegations. This course provides an overview of CVD as a tool to strengthen national, regional, and international cyber security. Delegations interested in this tool can find it on the website of the OSCE. Thank you, Chair.
Ambassador Gafoor
Thank you, Netherlands. Venezuela to be followed by Romania. Venezuela, please.
Venezuela
Thank you, Chairman. In this segment of the program devoted to CBMs, my delegation had the intention of referring exclusively to the creation of a point-of-contact directory. Last week, Venezuela submitted a concept paper which condensed our viewpoint on this issue. It is available online for members of this working group to consult. In order to save time in heeding your appeal, we will discuss this at a later stage. We will make that statement later. Thank you.
Ambassador Gafoor
Thank you, Venezuela. Romania, to be followed by Thailand. Romania, please.
Romania
Thank you, Chair. I also very briefly take advantage of this occasion to issue a short comment on your sharing of ideas on the multitude of appeals in the room concerning dedicating an intersessional to international law. My delegation would like to mention that we have noted the expression of the need for balance between the various topics on the agenda of the Open-Ended Working Group. On the basis of the objective significance of this topic within the mandate of the Open-Ended Working Group, keeping in mind the visible fruitfulness of the discussion on international law within the dedicated agenda item in our current session with a wide participation that I think is without precedent, and taking into consideration the content of the APR that you have mentioned, we would like to note our interpretation that the concept of balance might not necessarily be identical to that of equal time slots. This is shown by the wide number of appeals on the topic heard in the room, and potentially of the need to explore the substance of the topic to a similar extent as in the case of other topics, even though this might require a bit more time. I recall that among other indicators this is the only agenda item where you have been forced to close the list of speakers. We humbly assess that there is value in allowing the space for the organic evolution of the debates within this Open-Ended Working Group to manifest itself, even if this is not strictly in line with the idea of equal time slots. We see this as a beneficial evolution that can only assist with the achievement of the Open-Ended Working Group mandate. And I am finished with abusing your indulgence, Mr. Chair, and wish to state that on CBMs as well as on the rest of the agenda items we are fully aligned with the EU statement. Responsible state action in cyberspace is about respecting international law and taking all reasonable steps in order to mitigate risks to international peace and security. These steps include respecting voluntary norms and also engaging in confidence-building measures. We support and encourage dialogue and cooperation between members of the United Nations at the bilateral, regional, and multilateral level. We encourage exchange of information between member states, cooperation in the establishment, and between CERT-type entities responsible with mitigating the impact of malicious cyber operations, measures of legislative and decision-making transparency, the explicit declaration of doctrines, cooperation with multistakeholders, and the voluntary exchange of information and good practices of relevance for the implementation of the norms for responsible state conduct. In identifying the manner in which to best make use of confidence-building measures in supporting international peace and security, an ever-larger set of examples and good practices have been developed at various levels, including regionally, some of which we’ve heard described today. They refer to the work of the Organization for Security and Co-operation in Europe, the Organization of American States, the Association of Southeast Asian Nations, the Regional Forum, and the Economic Community of West African States. Their contribution to the pool of good practice in this regard is significant and should be taken into account. We fully adhere to the calls to actively ensure the integration of the gender component to initiatives aimed at increasing our common security, resilience, and transparency, as well as we recently heard in the processes of reporting. We are also engaged in the development and implementation of the open-ended OSCE CBMs and fully share the view that they both show and promote resilience in times of crisis. We highlight the example significance of coordinated vulnerability disclosure as an experience. We also assess positively the clear added value of the cyber policy portal of UNIDIR. On the POSC directory, we look forward to the dedicated discussion on the topic. Thank you.
Ambassador Gafoor
Thank you, Romania. Your points on CBMs are well noted. As for your comments on international law, I’ll just say that when I closed the speakers list, everyone who had wanted to speak had been given an opportunity, including those who had inscribed even after I had closed the speakers list. So the speakers list was not in effect closed. I just wanted to make that clear that I had not shut down a discussion. I’m sure you were not suggesting that, but we had a rich discussion. But my goal at the March session is to be in a listening mode, so the more people we have on every agenda item, the better it is. Provided you’re prepared to work on a Saturday, all of you, and if you’re prepared to work without interpretation, as a working group, I’m prepared to continue this evening, as well as tomorrow evening, as well as Friday evening. So let that be clear. So I would like to give everyone an opportunity. The other point I would add is that, it’s something I said earlier, balance too, like simplicity, lies in the eyes of the beholder. So that is the typical assessment we all need to make collectively as to what would be a good way to proceed. I think we all want to proceed. I’m really energized by the discussions, frankly, because I see such engagement, such thorough preparedness in having come to the discussion with so many good ideas. So let’s keep those ideas coming. I want to listen this whole week, and then maybe on Friday, I’ll share some reflections on how we move forward. So at this point, I don’t want to get into a discussion about how much time equals balance, or what is the exact allocation of time, because everyone has come to this process with great commitment, and of course with their own ideas about how we should proceed in a balanced way, in accordance with the mandate and the annual progress report. So let’s continue with the discussion. We have four more speakers on this item of confidence building, not getting into the Program of Action at this point, but let’s see if we can finish the four speakers this evening. Thailand to be followed by Israel. Thailand, please.
Thailand
Mr. Chair, Thailand associates ourselves with a statement made by Brunei Darussalam earlier on behalf of ASEAN. Thailand considers the ongoing discussion in the OEWG as a constructive and crucial part of the CBM efforts. We recognize that the OEWG plays a crucial role in the development and support of global CBMs. Such roles should be further strengthened, and Thailand would like to briefly share our views in this regard. First, it is important to draw upon our experiences on the different frameworks at the regional level. In this regard, Thailand supports the intervention made by our friend Singapore, supported by Malaysia, that two CBMs under the ASEAN framework could be expanded to the global intergovernmental context, namely sharing of information on national laws, policies, best practices and strategies, as well as rules and regulations, and awareness-raising and information-sharing on emergency response to security incidents in the use of ICTs. Second, while we are focusing on global CBM efforts, we should also encourage more CBMs at the cross-regional level. We believe that with ideas floating around under this forum, concrete outcomes in the form of cross-regional dialogue could be materialized, if only supported under this framework. And third, it is important that we achieve concrete outcomes on the points-of-contact directory. We welcome the elements paper prepared by the Chair, especially on its flexible and voluntary nature, and the importance that it gives on improving efficiency and the rebuilding mechanism, as well as the capacity building elements. We are looking forward to sharing our views in detail on this matter later. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you, Thailand. Israel, to be followed by Colombia. Israel, please.
Israel
Thank you, Chair, for giving us the floor to present our national perspectives on CBMs. Israel regards the discussion on confidence-building measures as an essential and important part of the Open-Ended Working Group. Developing effective and sustainable international cooperation requires, in Israel’s view, a solid base of trust. In this context, exchanges of know-how, best practices, cybersecurity methodologies, risk assessment models, threat analysis trends, patterns, etc., can play an important role. CBMs attempt to build relationships and procedures in times of peace and stability, elements that can be used for de-escalation in times of crisis. Mr. Chair, in order to offer concrete suggestions that can be elaborated within the Open-Ended Working Group process, and with a view to advanced CBMs that can be operationalized in a voluntary, non-binding manner at the UN level, Israel, together with an open group of cross-regional member states, continues to hold joint discussions aiming to present some novel and practical ideas. We wish to commend our German colleague for initiating and leading our group, as well as thank the group members for their active participation and useful contributions. During recent sessions of the Open-Ended Working Group, considerable progress has been achieved on the way to operationalizing CBMs at the global level. In order to use this positive momentum, the group’s work is dedicated to discussing and advancing ideas on how we can learn from national experiences and the multifold regional expertise, and how CBMs can best be used at the global level to build the needed trust, reduce the chances of misunderstandings, and assist in making cyberspace more secure and stable. The group has been extensively working on advancing the POC directory, and we will elaborate as a group on this later at the dedicated discussion that will be dedicated to the POC directory. Mr. Chair, in addition to extensive bilateral information sharing, Israel supports CBM efforts on a regional and cross-regional level. Israel supports the important work that has been carried out by the OSCE, and as a Mediterranean partner, Israel also contributes its vast experience in this field. Furthermore, Israel is one of the founding members of the Global Forum on Cyber Expertise, GFCE, and is an active partner in developing various CBMs and capacity-building initiatives in the GFCE framework. Multistakeholders and cross-regional fora like the GFCE can contribute and assist states and all stakeholders to better share and build the needed trust. To conclude, at the heart of Israel’s international cyber strategy, we have stressed our efforts to help build and advance global cyber resilience, and we are ready to work together with all partners. Thank you, Chair.
Ambassador Gafoor
Thank you, Israel. Colombia to be followed by Vietnam. Colombia, please.
Colombia
Mr. Chairman, CBMs mean that we need to listen to all parties and hear different perspectives. This must be a transparent and inclusive discussion. Today, on International Women’s Day, I’m pleased to be in a room where there appears to be gender parity. In fact, this is an area where women used to be underrepresented. Once again, my country would like to thank countries for supporting women in cyber, and my government has benefited from this. We’ve had advice and support, in particular when it comes to gender parity. Women must be involved in national and international discussions because of the added value of having women participate on an equal footing. And we support a gender-based approach. It helps build confidence, and there must be equal access to discussions. This must be sustained over time. Mr. Chairman, my delegation would like to extend our gratitude to delegations within this group for all of their work. There are different views on some issues, but we are able to share the positions of our states transparently, and this builds confidence. We are addressing issues where we have commonalities. Argentina, Chile, and Mexico regionally in the OAS are working towards creating and implementing CBMs, in particular when it comes to cybersecurity. Other regions have also made progress in this area, and therefore we underscore the importance of interregional dialogue and the exchange of views and best practices. This is part of the initiatives that will help us to implement a number of CBMs. We believe that a mapping of best practices at the regional level could be considered at the global level because it would be useful. Mr. Chairman, promoting confidence is a progressive and long-term task to ensure international peace and security and to address technical, political, and legal issues, and adopting practical approaches such as setting up points of contact, something we’ll discuss at a later stage. Thank you.
Ambassador Gafoor
Thank you, Colombia. Vietnam, to be followed by Kenya. Vietnam, please.
Vietnam
Mr. Chair, this delegation also associates with the statement delivered by the Brunei delegation on behalf of ASEAN on Confidence-Building Measures. Upon instruction, this delegation will reserve its statement on the PLC until the discussion on this initiative is opened. At this point, we would like to share the assessment of some delegations that the CBM experiments at the regional levels may not be relevant or even should not be universalized at the United Nations. It is simply because the United Nations and this working group are placed at different levels and should represent the highest orders in terms of international peace and security. Therefore, it is imperative that delegations in this group take advantage of the unique roles and mandate of the United Nations in the field of international peace and security. In light of this UN centrality approach, this delegation would like to propose two important components of confidence-building for the group to consider. First, transparency on state initiatives relating to cyberspace. In the past few days, many delegations have mentioned several initiatives by states to enhance cooperation activities in cyberspace, such as the Paris Call for Trust and Security in Cyberspace, the Global Forum on Cyber Expertise, or the Counter-Ransomware Initiative. We believe that the discussion in this group will be enriched by learning from progress made in these initiatives through a formal briefing procedure. Second, information sharing. We believe that the UN Secretariat possesses sufficient knowledge and resources to provide its member states with the most up-to-date information on the current situation of any particular topic of concern. In other parts of the UN system, the practice of appointing mandate holders is common, but it’s worth considering the appointment of experts who may prepare reports and brief the group at a session on important cyber issues, such as spyware, darknet, artificial intelligence, quantum computing, et cetera. These briefings will help level the playing field between member states in their understanding of cyberspace and its evolving threat landscape. I thank you, Mr. Chair, for your kind attention.
Ambassador Gafoor
Thank you, Vietnam. Kenya, to be followed by India, please.
Kenya
Thank you, Mr. Chair. Confidence-building measures remain critical in facilitating collaboration between states and stakeholders on strategies and policies in cyberspace. This is part of the reason why Kenya supports the establishment of a POC directorate initiative as an important CBM. In order to mitigate the risks posed by cyber threats and foster a safer cyberspace, Kenya established the national CSIRTs, which is also Kenya’s national point of contact on cyber security matters. CSIRTs undertakes the detection, prevention, and response to various cyber threats targeted both at the country and at various strategic partners. It is also involved in building collaboration and information sharing through partnerships and development of awareness programs geared towards promoting a national culture of cyber hygiene. Again, CSIRTs is a collaboration within the East Africa region under the umbrella of the East African Communications Organization, EACO, where it plays a major role. Additionally, Kenya has developed frameworks and mechanisms to promote cross-certification of digital certificates among its states and enhance participation in the web trust program for certification authorities, which goes a long way in promoting confidence and trust in electronic transactions. In conclusion, Mr. Chair, the development of frameworks for mutual legal assistance in light of the borderless nature of internet and cyber crime matters will assist states in the resolution of transactional and transnational crimes and hence act as a confidence-building measure. Thank you, Chair.
Ambassador Gafoor
Thank you, Kenya, for your statement. India, you have the floor, please.
India
Thank you, Mr. Chair. Confidence-building measures have a critical role in building trust and confidence among Member States. The CBMs in cyberspace have a unique role and carry much higher importance, as it is not just governments that have to act to build trust and confidence, but also the stakeholders, such as the private sector, academia, and civil society. Any CBM that we may consider may have to involve all the stakeholders to achieve the desired results. To answer Mr. Chair, what CBMs this Working Group should consider and discuss, we think that we need to understand where different countries stand today in terms of their cyber capabilities. As often referred and agreed in this Working Group, ensuring the security and safety of the ICTs is an inclusive effort of all Member States. To this end, the normative framework would give us clear guidance on creating CBMs. We also echo here the views expressed by Mexico that CBMs are complementary to the normative framework. For instance, Norm 13A refers to applying measures to increase stability and security in the use of ICTs. Norm 13B talks about ICT incidents and underlines that the State should consider all relevant information to understand the consequences of cyber incidents. Norm 13D highlights how best Member States can cooperate to exchange information and assist each other. Norm 13G refers to taking appropriate measures. In the same spirit, the proposal by India for a Global Cyber Security Cooperation Portal is a CBM that is rooted in the normative framework we all agreed on and attempts to address the existing gaps. We have shared a working paper on the proposed portal for the kind views of the Member States. We thank Russia, South Africa, Brazil, and other delegations who appreciated the merit of the portal and supported discussing the portal in this Working Group. We have shared it with the Secretariat to place on the OEWG website so that all Member States can study the working paper and share their feedback. We believe that the intergovernmental POC directory is a measure of CBM. The diverse views expressed by Member States on the operationalization of POC have really helped to understand various perspectives on this POC directory. Mr. Chair, as the Indian statement on the application of international law mentioned, convening focused discussions on the gaps in the interpretation of the application of international law to cyberspace and building common understanding is itself a CBM. Exchanging views on any difficult topic that has no consensus so far is a CBM for this Working Group. We have heard from the Kenyan delegation an idea of a repository for threats which would help in mitigating the risks. We think that certain ideas have been presented to the group and may help us build further trust and confidence. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, India. I have no further speakers at this point who have asked for the floor, and it’s six o’clock. Once again, I would hesitate to give you a summary, but I wanted to give you some maybe quick reflections. I mean, I really have been energized and encouraged by the discussions today. It has been really very thoughtful, not only on the earlier part on international law but also on CBMs. Now it’s clear that everyone says the Open-Ended Working Group is in itself a CBM, and that I think was demonstrated by a discussion on CBMs in the OEWG, which is already a CBM. So we have seen the utility in some ways of having an open, inclusive framework to have some of these discussions, because even if views are different, I think the very act of discussing it and sharing our different perspectives, I think, contributes to building trust, if not rebuilding trust. In the APR, with regard to the CBM section, we did talk about sharing concepts, papers, national strategies, policies, and programs, etc. I think a lot of the ideas that came up in the discussions also had to do with sharing of information, best practices, data, so the whole range of ideas about potential CBMs at the global level. There are also many examples of CBMs within the regional level that were shared, and I appreciate those who had brought their regional experiences, but also some of you referred to CBM projects or exercises that were done bilaterally. That, too, I think was useful for the discussions. In some ways, everything can contribute to CBM or contribute to confidence building, but not everything can become a CBM, because otherwise we will have a whole long list, and I think, as some of you said, it has to be something that can be operationalized. It’s obviously a difficult word for this working group. Operationalizing anything is difficult at the United Nations and in an intergovernmental process, so the idea of CBMs that can be operationalized, something that will add value to the work of the working group, is something that we need to reflect more on. Now, it is also clear that there are enough elements there, in my view, to put together some kind of list or initial list of CBMs that could potentially apply at the global level. I think we have enough material, and we certainly will need to discuss these CBM ideas further. I think comments were also made about how the CBMs are related to the normative framework, to the rules and norms. I think that’s a very good point that we also need to keep that in mind. So I think we do have enough material based on this brief discussion to think of looking at some kind of initial list of potential CBMs that can be applied at the global level, and I’ll give this further thought. Now, there was also some of you, or there was a view expressed by some of you that perhaps we should implement what we have before we discuss new CBMs. There were others who suggested that, well, we can also look at new CBMs. And this whole idea of should we implement what we have, or should we do new things, is a recurring tension that I see in this working group. It came up also in the context of norms. There was a view by some of you that let’s implement what we have instead of discussing new norms. To some extent, that same tension is present here when some of you said, let’s implement what we have before we discuss new CBMs. But I think it’s also important to keep in mind that discussing new CBMs or CBMs at the global level while implementing what we have agreed is not mutually exclusive. And a willingness to discuss possible new ideas is in itself a demonstration of confidence, which could itself lead to rebuilding trust and confidence. So what I’m saying is that if in this working group we can all keep an open mind to different proposals we’ve heard, and we know that we need to adopt a step-by-step approach, I think that is a good thing that everyone seems to sort of agree, an incremental step-by-step approach. We can’t do everything at the same time. This working group will go to 2025, so we need to adopt a step-by-step approach. But the idea that we are open to discussing what could potentially happen later while discussing something that could happen now, the idea that we implement as we also discuss potentially new things, is also something that I think we need to keep in mind. Because otherwise, if we focus on entirely implementing what we already have, then I think there will be many delegations which may not be very satisfied. Certainly not a summary. These are random reflections late in the evening. The last thing I want to say is that for tomorrow, the work program, we will start with capacity building. It is my intention that tomorrow we will begin in the morning with capacity building as is reflected in the provisional program of work. And in the afternoon, we are going to have the dedicated stakeholder session, which will be focused on capacity building as well. And after the dedicated stakeholder session completes its discussion, then we will resume the discussion on confidence-building measures, specifically on the POC directory. My sense is that the stakeholder session may not take the entire three hours. But again, I’m not going to shut down the stakeholder discussion either. Because I think we really need to be listening more, especially as this is the first substantive session after the last annual progress report. So we’ll start with capacity building tomorrow. Please look at the questions. Please come prepared to address the questions. Look at the annual progress report. There are very specific issues in the annual progress report, plus, of course, the mandate. And then we’ll get through the other items throughout the rest of the day. And thank you once again for all your very committed engagement and constructive tone today. I wish you a pleasant evening. See you tomorrow morning. The meeting is adjourned.
Leave a Reply