Ambassador Gafoor
Good morning to all of you. The third meeting of the fifth substantive session of the Open-Ended Working Group on security of and in the use of ICT is now called to order. Distinguished delegates, the group will now continue its consideration of Agenda Item 5, and we will continue the first reading of the draft Second Annual Progress Report. It’s my intention today to begin a discussion on Sections C, Rules, Norms, and Principles of Responsible State Behavior, and Section D on International Law this morning. I’d like to once again ask all of you to be as succinct as possible, and I would recommend that delegations taking the floor on these two sections take three minutes to make their interventions. I expect that there will be a number of delegations who would like to make interventions, and it’s really important that we try and conclude these two sections within the morning session. I do not intend to cut off your microphone if you exceed the three-minute recommended timeframe, but let’s just say that the three-minute timeframe is part of the cumulative and evolving framework of rules, norms, and principles. It does not have a binding character, at least at this point, but I’d like each one of you to be as succinct as possible and also understand that we need to give everyone an opportunity to take the floor. So with those opening remarks, I’d like to continue with the speakers’ list. Yesterday, we had two speakers left from the list: Jordan and India. I’d like to now invite those who wish to make an intervention this morning to press the buttons, and then we’ll go through the speakers’ list. If you are speaking on behalf of a group, do let us know so we can let you make your statement ahead of others, as is the practice at the UN. So let me now start with the remaining speaker from yesterday, Jordan, to be followed by India. Jordan, you have the floor, please.
Jordan
Thank you, Mr. Chair, for giving us the opportunity to speak today. Mr. Chair, Jordan supports the action-oriented discussions approach you called for. We believe that the current text reflects the rich and substantive negotiations among member states during the current and previous sessions. However, we would like to make the following remarks. First, we believe malicious ICT activities against critical infrastructures are the most dangerous threats to international security and stability, and we welcome the emphasis on this fact in paragraph 10. Second, we agree with Germany that paragraph 10 shall include some text about the cross-border spillover effects of ICT conflicts, especially for states not involved in conflicts, which is the case in many countries, including Jordan. Third, we agree with the U.S. that so many dedicated intersessional meetings and roundtable conversations will have budgetary implications and will distract us from focusing on substantive issues mandated by the General Assembly’s resolution 75-240. We hope the number of dedicated intersessional meetings will be at the minimum. Fourth, we also agree with the U.S. and France that the topic of misinformation and disinformation and deepfakes are not within the scope or the mandate of this group, and we support the text suggested by the U.K. in this regard. Fifth, for paragraph 14, related to the emergence of new technologies such as AI and quantum computing, we believe the emphasis here shall be on the misuse of such new technologies, not on the technologies themselves. Finally, Chair, despite these remarks, Jordan supports the proposed text of both paragraphs A and B, and hopes RIF-2 will have more balanced text and take into account the observations made by member states. Thank you, Chair.
Ambassador Gafoor
Thank you very much, Jordan, for keeping within the time limit. India, you have the floor, please.
India
Thank you, Mr. Chen. We would like to suggest the following edits. Para 14: We would like to propose replacing “ICT vectors” with “possible ICT threat vectors.” It is based on our understanding that the mandate of the Working Group is to focus on the existing and potential threats, and hence we need to focus our discussions on possible threat vectors emanating from the misuse of ICTs. Para 11: We would like to suggest that in the third line of Para 11, after “including,” add “vulnerabilities through supply chains.” After that, we would like to suggest the deletion of “and open sources.” Being open sources may not necessarily qualify for having malicious intention. Further, in the same Para, we would like to add reference to “firmware” before reference to “software.” As per our experience, the vulnerabilities are embedded not only in software but in firmware also. It needs separate mention as the firmware is a slightly different layer than the software. Para 10: My delegation has also suggested an edit for adding reference to “quasi-state actors.” I would like to further elaborate on this for the benefit of our colleagues. As we are aware, and as previous OEWG reports and the present Working Group discussed, non-state actors are displaying ICT capabilities that were previously available only to state actors. Today, there are entities that straddle the line between statehood and non-state existence, borrowing characteristics from both without fitting neatly into either designation. The main difference between non-state and quasi-state actors is that non-state actors are not recognized as having the same legal status as states, while quasi-state actors have some degree of recognition as having a political or legal status. Quasi-state actors in cyberspace have significant cyber capabilities, which may be aligned with or even controlled by a state. The availability of resources, training, exposure, etc., makes it easier for these quasi-state actors to gain in-depth knowledge to craft intrusive cyber activities. These quasi-state actors exploit a legal gap in our understanding that allows them some of the advantages of sovereignty without corresponding obligations. These quasi-state actors might appear to be operating independently beyond the supervision of the states, though they are indirectly or directly associated with the state’s ICT framework. This way, they get more room to recruit skilled technical manpower or means to outsource the intended activities. Sometimes the quasi-state actors have agendas that are not aligned with that of a state. Hence, they work towards their own agendas, and in doing so, these actors can pose a significant threat to the national security and peaceful functioning of their own and other states. Some examples of these quasi-state actors in cyberspace include cyber militias, cyber mercenaries, state-sponsored cyber criminals, or groups that are used by states to steal sensitive information or to disrupt critical infrastructure. This also includes hacktivist groups that are sympathetic to the goals of a state and are willing to launch cyber attacks on its behalf. The rise of quasi-state actors in cyberspace, therefore, is a major challenge for international security. These actors are difficult to track and to deter, as they are not subject to the same laws and regulations as states. It is important that we address the issues of lack of accountability of quasi-state actors for their irresponsible behavior in cyberspace. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, India, for your statement. I give the floor now to Portugal, to be followed by South Africa.
Portugal
Mr. Chairman, this being my first intervention in this session, allow me to congratulate you on the excellent draft annual progress report which is now on the table for consensual adoption this week. As the EU representative duly underlined yesterday, your team has managed to include in the revised draft, zero draft, a comprehensive and fair account of our discussions since last year. And as the Australian representative has highlighted, we can now build on this accomplishment by distinguishing clearly between what is our consolidated language, such as on the Framework for Responsible State Behaviour in Cyberspace, and what has only been proposed and/or discussed, and between what is ready for actionable and resource recommendation, such as the Global Points of Contact Directory, and what still has to be further debated in order to become operational. Chair, in spite of international and national efforts to render critical infrastructure more resilient, advance the UN Framework for Responsible State Behaviour, and negotiate a global convention against cybercrime, the insecurity in cyberspace has increased once again in 2022, no less as a consequence of the outrageous invasion of Ukraine by the Russian Federation. Last year, Portugal suffered very serious incidents either from hackers who apparently just wanted to compete among each other in exposing vulnerabilities, from criminals who wanted to collect ransom from flagship companies and services, or from state-sponsored actors who wanted to extract data from government institutions. Exponential digitalization of national critical infrastructure and exciting technological developments and their fast dissemination in all directions of collective and personal life, like artificial intelligence and quantum computing applications, are more than enough to motivate this open-ended working group and your able leadership to carry on countering insecurity through further action-oriented codification and cooperation. Thank you, Chair.
Ambassador Gafoor
Thank you very much, Portugal, for your statement. South Africa, please.
South Africa
Thank you, Chairperson. These are our comments on rules, norms, and principles of responsible state behaviour, as well as international law. States should prioritize the implementation of the existing 11 rules, norms, and principles of responsible state behaviour in cyberspace. As you state in the draft report, the goal of such norms should be to protect critical infrastructure from ICT attacks. As a voluntary measure, the adoption of checklists, capacity building, and assistance is an important part of implementing the agreed norms. As we focus on the implementation of the norms, we may also discover gaps in our current understanding or capacities to secure critical infrastructure and critical information infrastructure. Chairperson, in this regard, we support further consideration of proposals under this topic. We welcome the Chair’s proposal to draw up a checklist which could be used on a voluntary basis to assist states as they develop their ICT security infrastructure and policies. We believe that while this is an intergovernmental process, our discussions would benefit from briefings by relevant experts from regional and sub-regional organizations, businesses, non-governmental organizations, and academia, with due consideration given to equitable geographical representation. Chairperson, we welcome the submission of national views on the applicability of international law to the security of ICTs to the UN Secretariat. A compilation of national views, including those expressed by Member States at previous sessions, would also be a confidence-building measure between States. While we note the amendments made to paragraph 28, focused discussion could be useful, but we must consider how the principles of the UN Charter apply to cyberspace, such as sovereign equality, the settlement of international disputes by peaceful means, respect for human rights and fundamental freedoms, and non-intervention in the internal affairs of other States. Therefore, the inclusion of these aspects in the amendments in sub-paragraph A of paragraph 28 is useful and should be retained. Furthermore, while we acknowledge the attempts in both the Zero Draft and the Rev. 1 to recognize that briefings by international legal bodies would assist our discussion, as many States are still developing their national understandings of how to further understand international law in relation to ICT systems and their security, we feel it would be useful to explicitly reference the International Law Commission in paragraph 33. The ILC is a UN body which is responsible for helping develop and codify international law. We also believe that paragraph 33 could benefit from the addition of some rationale. Therefore, my delegation proposes adding, at the end of the second sentence, “with the aim of developing a common understanding of the applicability of international law.” This would replace, “in order to better inform the OEWG’s deliberations.” We should not force views upon Member States, but let the conversation develop in a bottom-up manner. I thank you.
Ambassador Gafoor
Thank you very much, South Africa, for your statement, as well as your very specific suggestions. I give the floor now to the Islamic Republic of Iran, to be followed by the Philippines. Iran, please.
Iran
Thank you very much, Mr. Chair, and good morning to you and colleagues. My apologies in advance if my intervention exceeds beyond the three minutes’ time; an exception sometimes is part of the rules, Mr. Chair. So, for paragraph 22B.2, we suggest adding the word “agreed” before “interoperable common rules” in the third line. In the same paragraph, C, we would like to suggest replacing the word “proliferation” with “development” in the second line. For subparagraph D, we would like to suggest the addition of “in the field of information and telecommunications in the context of international security” at the end of the first sentence. Also, we would like to remove the phrase “on rules, norms, and principles” at the end of the same sentence. We would like to see the addition of one specific sentence at the end of the same subparagraph, reading, “In this regard, the establishment of a voluntary glossary of national definitions of technical ICT terms was discussed as an initial and concrete first step towards developing a universal terminology in the field of ICT security.” For subparagraph F, we would like to suggest the addition of “development of additional norms” and remove “possibility that could continue to be developed over time” in the middle of the first sentence. In subparagraph G, we would like to add “and development of existing as well as new” at the beginning of the third line. For the section on recommendations, paragraph 25, we would like to suggest the addition of “make a voluntary glossary of national definitions available” in the middle of the paragraph and replace “compile the submission” with “compile the submissions.” We would also like to add one sentence at the end of this paragraph, saying, “At the sixth, seventh, and eighth sessions of the OEWG, states undertake discussions on the voluntary glossary of national definitions with the aim of developing a common consensual terminology in the field of ICT security.” We would like to suggest 27 Bs as a new paragraph, reading, “The OEWG chair is requested to produce an initial draft of new rules, norms, and principles drawn from the annex to the 2021 OEWG chair summary for consideration by states at the informal intersessional meetings, as well as the sixth, seventh, and eighth sessions of the OEWG.” On the chapter for international law, paragraph 27, we’d like to add the following phrase in the middle of the paragraph after “international law applies to the use of ICTs”: “as well as the possibility of additional legally binding obligations.” For paragraph 29, subparagraph D, we would like to add the word “way” in the third line after “including by the word ways and means of ICTs” and “undermine the political, economic, cultural, and social stability, including by means of cognitive operations, disinformation campaigns, and inciting violence.” For paragraph 30A, we would like to enumerate these elements here and therefore suggest “A” before “how international law applies to the use of ICTs,” and “B,” this is a new addition, “the possibility of additional legally binding obligations,” and then a full stop. Before the next sentence, we would like to add “states proposed.” In subparagraph B of the same paragraph, we would like to remove the phrase “including on a state practice” at the end of the subparagraph. For paragraph 31, in the second line, we would like to add “as well as the possibility of additional legally binding obligations.” In paragraph 32, we’d like to remove the phrase “as well as relevant state practice” in the first sentence and also remove “and for further discussions by OEWG at its sixth, seventh, and eighth sessions” at the end of this paragraph. Finally, for paragraph 33, our suggestion is to add “as well as the possibility of additional legally binding obligations” at the end of the first sentence of the paragraph. I thank you, Mr. Chair.
Ambassador Gafoor
Thank you, Iran. Do share the text of your amendments with the Secretariat, so that we can take a look at it. And I want to remind delegations that we are now looking at Sections C and D. Section C on rules, norms, and principles, and Section D on international law. We’ll take the Philippines, to be followed by Uruguay.
Philippines
Thank you, Mr. Chair, and good morning to all the distinguished delegates. On C, Rules, Norms, and Principles of Responsible Behavior, my delegation welcomes paragraph 24 on undertaking focused discussions on strengthening measures to protect critical infrastructure from ICT threats and further cooperation and assistance to ensure the integrity of the supply chain. The Philippines has a high incidence of cyberattacks. From 2020 to 2022, the Philippines’ Department of Information and Communications Technology mentioned about 3,000 cyberattacks. Almost half of them are targeted against the systems and networks of the Philippine government. We therefore support this proposal and hope that this could help the Philippines curb its high incident reports of cyberattacks and help in protecting our government’s critical infrastructure and critical information infrastructure. Meanwhile, on D, International Law, as in the previous outcome document of the OEWG and ICT, member states, including the Philippines, “reaffirmed that international law, in particular the Charter of the United Nations, is applicable and essential to maintaining peace and security, stability, and promoting an open, secure, stable, accessible, and peaceful ICT environment.” States also concluded in the previous OEWG that, “given the unique attributes of the ICT environment, deepening common understandings on how international law applies to states’ use of ICTs can be developed by exchanging views on the issue among states and by identifying specific topics of international law to further in-depth discussion within the United Nations.” We therefore support the recommended steps forward on this matter, including the convening of a dedicated inter-sessional meeting on how international law applies to the use of ICTs. Please allow me to take this opportunity to promote a side event that the Philippines is co-sponsoring with Australia and Uruguay on international law, which will be held tomorrow, Wednesday, 26 July, from 8:30 to 9:30 a.m. As the Philippines has yet to decide on the need for a convention or specific international instrument dealing with the norms, rules, and laws which could apply in the use of ICTs, it is important for us to build common understanding within the international community on the applicability of existing international law concepts and principles in cybersecurity. In this regard, we joined Australia in this workshop, as it serves as a good means to build capacity in the area of international law, national legislation, and policies of member states. The side event will be held at the Australian Mission tomorrow. Thank you.
Ambassador Gafoor
Thank you very much, Philippines, for your contribution and also reference to your side event. And I assume Australia is serving breakfast. Thank you for that confidence-building measure. We’ll go with the rest of the speaker’s list. Uruguay, to be followed by the European Union. Uruguay is speaking on behalf of a group, as I understand it. You have the floor, please.
Uruguay
Thank you, Chair. I am delivering this statement on behalf of Australia, Colombia, El Salvador, Estonia, and Uruguay, co-sponsors of the presented Working Papers on Convergence Language on International Law for the 2023 Annual Progress Report. Our sincere appreciation goes out to you, Chair, and your team for preparing and presenting a draft of an APR that captures the discussion from the last formal and informal meetings of the OEWG on the subject of international law. We are pleased to see that the APR text specifically mentions the cumulative and evolving framework of responsible state behavior in cyberspace and reaffirms that international law, in particular the Charter of the United Nations, is not only applicable to maintaining peace in cyberspace but also essential in the promotion of a secure, stable, open, and accessible ICT environment. Our discussions have been guided by the roadmap set out in last year’s APR. In this regard, and as noted in our paper, we are happy to see that there has been a record number of states who share their views on the applicability of international law to states’ use of ICTs since the adoption of the APR in 2022. Pursuant to the roadmap, as part of and in addition to the discussion on the UN Charter, we have seen states reaffirm the application of sovereignty, sovereign equality, non-intervention in the internal affairs of states, the prohibition of the threat or use of force, and the peaceful settlement of disputes to states’ use of ICTs. We have also seen an increasing number of states reaffirm the importance of capacity building in international law with the aim of ensuring that all states are able to participate on an equal footing in the development of a common understanding of how international law applies in the use of ICTs. We applaud that the draft APR recognized the reaffirmation of these principles and obligations. We also encourage greater reflection on the additional matters that were raised in Paragraph 3 of our working paper. In particular, on the peaceful settlement of disputes, in addition to UN Charter Articles 2 and 33 set out in the APR draft, Article 33 and Chapter 6 also more broadly provide for the pacific settlement of disputes, which is applicable to states’ conduct in cyberspace. We also acknowledge the importance of continuing discussion of how international law applies in cyberspace within the OEWG, as well as the importance of building capacity in the area so that all states can participate meaningfully in these critical discussions that are key to preventing conflicts and maintaining peace and security. In this regard, we draw your attention, Chair, to the numerous initiatives on international law capacity building that have taken place since our last APR. Importantly, many of these are cross-regional and are contributing to the development of a common understanding of international law in accordance with this OEWG mandate. Just last week, more than 40 Women in Cyber Fellows from over 30 member states across Asia, Eastern Europe, South America, the Pacific, and Africa, together with delegates from African Union member states, were hosted by the African Union Commission for training on cyber and international law. These include many delegates in our OEWG in this room today. Moreover, we encourage all UN member states to bring forward their opinions and national positions on the application of international law to cyberspace. We applaud the 30 states which have already done so, and we understand that other national or regional statements are under development. These are very positive developments for our OEWG, and we recognize that this too is a CBM. Regarding the recommendation to continue this discussion during dedicated OEWG intersessional meetings in the future, we strongly support it, and we acknowledge that expert briefings can help all delegations to gain a deeper understanding of our discussions. I thank you, Chair. I should like to speak in my national capacity with your permission, sir. Mr. Chairman, speaking in my national capacity, as we stated previously in the joint intervention from several countries, Uruguay welcomes the fact that the text recognizes the fact that international law, in particular the UN Charter, is not merely applicable to peacekeeping in cyberspace, but it’s also vital to promote a safe, stable, open, and accessible environment. We reassert the principles of sovereign equality, independence of states, peaceful settlement of disputes, abstention from the use of force or the threat thereof, non-intervention in the internal affairs of states, including those affairs linked to information technologies, inter alia. These are some of the important principles of the UN Charter. We must not overlook, sir, the fact that international law is the bedrock of the commitment that we have entered into to prevent conflict and maintain international peace and security, and it is key in order to build confidence among states. Therefore, it is our responsibility to contribute constructively and firmly to international peace and security by means of conduct which allows the peaceful settlement of disputes in cyberspace. Thank you, sir.
Ambassador Gafoor
Thank you very much. Uruguay, European Union, you have the floor, to be followed by Pakistan. EU, please.
EU
Thank you very much, Chair, and I will deliver both our remarks on the rules, norms, and principles of responsible state behavior, as well as international law. Global agreement on responsible state behavior, at multiple occasions since 2015, is a substantial step forward in building international cyber security in a rules-based environment. Since the norms were adopted, we have worked to deepen our understanding of their application and encourage states to adhere to them. We therefore support proposals in the draft annual report concerning the need to further assist states in implementing the rules, norms, and principles of responsible state behavior. Such open discussions develop a joint understanding of the norms of responsible state behavior and protect international peace and security. Norms do not replace or alter states’ obligations or rights under international law. They reflect the expectations of the international community and provide additional specific guidance on what constitutes responsible state behavior in the use of ICTs. In this context, our collective aim should be to better understand each other, build trust and confidence, rather than impose a top-down framework. We welcome, therefore, the reference to the development of a norms implementation checklist, while also making use of the UNIDIR survey of national implementation and the Singapore UNODA norms implementation checklist. As regards paragraph 22d, while we believe it could be useful to exchange our understanding of technical ICT terms, we do not deem it very useful nor feasible to harmonize this at a global level. Since technical ICT terms are subject to specific contexts of each state or each region, in our view, we should focus our attention on discussions that could be more fruitful. We suggest also, therefore, to remove the list in 25. We also appreciate the proposal to undertake more focused discussion on strengthening measures to protect critical infrastructure from ICT threats and on how to further cooperate and assist to ensure the integrity of the supply chain. While it remains up to states to determine which infrastructure is critical, previous Open-Ended Working Group and GGE consensus reports made references to the healthcare sector, technical infrastructure essential to the general availability or integrity of the internet, and political and electoral processes as examples of critical infrastructure, all being highlighted in the current draft and in response to the evolving threat landscape. We believe that international law and the norms provide a robust framework at this stage to guide states’ behavior in cyberspace. The norms have been designed to be technologically neutral, broadly applicable, and to provide a high level of flexibility. We should strive to take forward and implement these norms and not put a main focus on developing new norms. We and organizations have played a key role in encouraging member states to implement norms, including through capacity building activities. We continue this effort, and it’s important that we encourage academia, the private sector, civil society, and the technical community to share their experiences of these cyber threats in relation to international peace and security. We trust that future sessions will allow for the participation of these additional stakeholders. The EU attaches great value to the consensus agreement that international law, in particular the UN Charter, applies to cyberspace. All states have agreed that this applies and that it’s essential for maintaining peace and stability and for promoting an open, secure, stable, accessible, and peaceful ICT environment. We therefore highly appreciate the reference in paragraph 28 of the revised APR that states have reaffirmed the application of international law to the use of ICTs and stimulate further strength in that language. International law is the foundation of rules-based international orders, including in cyberspace, and it must be upheld and enforced in this domain. As called by the 2021 UNGGE report, states must meet their international obligations regarding international wrongful acts attributable to them under international law. This could be clearly stated in the APR. In reiterating the application of IHL, we share the views of other delegations who have said that this in no way legitimizes or justifies armed conflict, but is aimed to reduce human suffering. It is crucial that the Open-Ended Working Group continues to study how international law applies to the use of information and communication technologies by states. We welcome the report’s calls for states to continue to engage in focused discussions at the Open-Ended Working Group on how international law applies and on the topics from the non-exhaustive list in subparagraphs 15a and b of the first APR, as well as the proposals on the topic of international law contained in the 2021 report and the Chair’s summary. In addition, we appreciate the inclusion of paragraph 33 that states requested that you, Mr. Chair, convene a dedicated international meeting on how international law applies to the use of ICTs, as well as arrange further expert briefings on this topic, including by non-governmental experts. We would also like to affirm the importance of obligations to protect and respect human rights online, including the right to freedom of expression and the right to not be subjected to arbitrary and unlawful interference with privacy. We would welcome further discussion and exchange of views on this important topic, and therefore suggest referencing it under paragraph 29. More specifically, the 2023 APR, we would appreciate the reference to chapter six, in particular article 33 of the charter stipulating the peaceful settlement of disputes and the importance of this provision in the cyber context. The importance of peaceful dispute settlement has been previously reiterated, for example, in the GGE reports and in the working paper co-sponsored by Australia, Colombia, El Salvador, Estonia, and Uruguay, as just mentioned by the Ukrainian colleague. A dedicated session would give us the opportunity to involve our international law advisors and therefore have a more in-depth discussion on this important topic, while focusing on identifying areas of consensus and common understanding on how international law applies in cyberspace. This could be done with a view to developing further actions, such as a non-paper on areas of convergence, that would help us to make progress in this field. We also appreciate the call for states to continue voluntarily sharing their national views as relevant state practices on how international law applies in cyberspace. We believe this could build common understandings on this issue. While we are not against a call for the UN Secretary to compile these views, we need to make sure that we’re not duplicating other repositories out there. Chair, we welcome the emphasis on capacity building and international law, which is a high priority for this Open-Ended Working Group. Capacity building, if delivered in a neutral and objective manner, can make tangible differences in states’ ability to develop their own positions and to defend their national interests in this Open-Ended Working Group. Advancing our common understanding on how the existing frameworks apply in cyberspace will help us to determine what issues are most pressing for states in terms of clarifying how international law applies, and is a prerequisite to identifying what, if any, gaps might exist for further discussion in the future. Thank you very much, Chair, and thank you for allowing me the additional time.
Ambassador Gafoor
Thank you very much, European Union. On behalf of your Member States, I give the floor now to Pakistan, to be followed by Japan. Pakistan, please.
Pakistan
Pakistan, in general, agrees with the language concerning the development of rules, norms, and principles of responsible state behavior. Pakistan supports paragraph 22A, which underlines the importance of the protection of critical infrastructure and the prohibition of ICT activity that intentionally damages critical infrastructure which provides essential services to the general public. In addition to this, Pakistan acknowledges the formulation of language in paragraph 22C, respectively, relating to the timely disclosure and sharing of information about hardware and software vulnerabilities, including the formulation of the glossary of technical ICT-related terms and terminologies. However, Pakistan proposes an amendment for this section as well. Considering the importance of cross-border data exchanges and the growing incidence of theft of critical data and its ramifications for national security, Pakistan would like to propose an amendment to subpart E of paragraph 22, which could be read as: “States, in view of the rising trends of data theft, acknowledge the importance of data security and place strong emphasis on the need for measures to guarantee the safe and secure cross-border data exchanges.” Chair, while we acknowledge the importance of non-binding voluntary norms, including the development of new norms to ensure a secure and stable cyberspace, at the same time, Pakistan firmly asserts that non-binding norms cannot serve as a substitute for a legally binding instrument to ensure responsible state behavior in cyberspace. Chair, concerning the application of international law, Pakistan agrees with the formulation of the language in paragraph 28A regarding the applicability of the UN Charter, including its core principles, such as non-use of force, sovereignty, sovereign equality, non-interventionism, and peaceful settlement of disputes. However, in view of the unique nature of cyberspace, we need to determine how these principles could be made applicable in cyberspace. Similarly, Pakistan supports the language of paragraph 30 regarding further discussions in view of the existing gaps on how international law applies to the use of ICTs, as we believe that there is a need for further, near-friendly, and objective debate and discussions on this topic within the UN to build a common understanding among states, and these discussions should also include the formulation of a legally binding instrument. Chair, lastly, Pakistan firmly believes that OEWG must discuss and find ways to address the intricate matter of cyber attribution. We would like to highlight the importance of discussions on cyber attribution in view of the reference to state responsibility and due diligence in paragraph 28A of the APR. Pakistan believes that if this issue remains unsettled, all efforts to apply international law in cyberspace, including determining state responsibility and ensuring due diligence, shall remain futile. Thank you, Chair.
Ambassador Gafoor
Thank you, Pakistan. Japan, to be followed by Cuba, please.
Japan
Mr. Chair, regarding Section C, Norms and Principles of Responsible State Behaviour, Japan considers that it is important to first focus on deepening the discussion and the steady implementation of the existing norms, rather than the development of additional norms. Regarding Paragraph 22D, the possible glossary of technical ICT terms, Japan supports the EU statement. With regard to Section D, International Law, we are satisfied with the content on strengthening the discussion on international law. Japan would like to reiterate its position that existing international law, including the United Nations Charter in its entirety, applies in cyberspace. In this context, with regard to Paragraph 28B1, Japan does not believe that quoting Paragraph 80 of the 2021 OEWG report reflects the discussion during the previous substantive discussions of the OEWG. We would like to point out that efforts have been made in the OEWG to deepen our understanding of how existing international law applies in cyberspace. Therefore, we would like to suggest a deletion. With regard to Paragraph 33, Japan supports the dedicated intersessional meeting on how international law applies in the use of ICTs. We should address cyberattacks below the threshold of armed conflicts against critical infrastructure as the number of attacks has increased. A better understanding of how international law applies in cyberspace will help deter the attacks. Japan will propose an agenda item for this dedicated intersessional meeting later. Regarding Paragraph 34, Japan fully supports the work on capacity building on international law. The accumulation of state practice will deepen shared understanding of how international law applies in cyberspace. Thank you, Chair.
Ambassador Gafoor
Thank you very much, Japan. Cuba, to be followed by Germany, please.
Cuba
Thank you, Mr. Chairman. In Section C, on Rules, Norms, and Principles, we would propose as follows. We want to see a reference, a factual reference, to the initiative of there being a UN Convention on International Information Security, presented by the OEWG, so that all initiatives set forth can be included. We want to see the reference to the possibility of conflicts in paragraph 22A. We firmly stress this. We would recall that the report of the Group of Governmental Experts was not negotiated by all Member States, and that our delegation has constantly voiced its serious reservations about this, particularly regarding issues where there is no consensus. We would propose that in paragraph 22F, B, there should be direct reference to the development of additional norms, including there the possibility of legally binding obligations. And again, and consistently, we propose the same reference in paragraph 27 of the recommendations. We observe that the draft PR stresses voluntary behavior rules on the part of States. The regulation here in the OEWG referred to the drawing up of rules, norms, and principles on the responsible behavior of States, the applicable modalities for implementation, and the need for changes or drawing up additional rules of behavior. The second Annual Progressive Report should have an explicit reference to the possibility of drawing up legally binding norms, which make State responsibility mandatory. Several delegations, including ours, have continued to stress the need for this from the beginning of the OEWG process. Looking at discussions just on elaborating on existing norms, this would not be consistent with facts and would not embrace other discussions on the development of additional norms, including possible legally binding obligations. We would like to receive greater information and clarification on the endeavors underway, referred to in paragraph 26, to draw up a list on the verification of the implementation of norms to assist States, in particular developing countries and small States, when it comes to implementing the norms of responsible State behavior in the use of ICTs. We support Iran’s proposal on the need for common terminology. Looking at Section D on international developments, we would propose that there be reference to State discussions on how to implement or apply international law to the use of ICTs and how this must also embrace discussions on the possibility of there being additional legally binding obligations in paragraphs 28, 30A, and 31. In paragraph 32, we must strike out the reference to pertinent practices of States and discussions on national views in the 6th, 7th, and 8th OEWG sessions. In paragraph 34, we propose the addition at the end of the fact that the capacity building endeavors must be organized and guided under the UN in order to ensure inclusive and non-discriminatory access of States. In this section, there must be inclusion of a reference based on the fact of the idea of drawing up a UN Convention on International Information Security to be presented to the OEWG. Thank you.
Ambassador Gafoor
Thank you very much, Cuba, for your contribution. Germany to be followed by Brazil. Germany, please.
Germany
Germany is fully aligned with the statement delivered by the EU and makes the following remarks in a national capacity. In the section on rules, norms, and principles, Germany supports the proposal for an informal inter-sessional meeting. The current draft mentions the elaboration of existing norms. However, it seems more appropriate for existing norms to be implemented rather than to be elaborated, which is a process associated with new norms. Germany proposes to change the wording in Para 27 to discuss the implementation of existing norms. Germany proposes deletion of 27b, possible development of new norms. Development of new norms is included in the OEWG’s mandate with the addition, if necessary. Germany does not see that we have reached agreement on this necessity in this group. Germany recognizes that the current draft of the section on international law attempts to reflect elements of the minimum common ground that has been established by previous UN working groups. Germany would have welcomed seeing more concrete language on the specific topics mentioned in Para 28a to reflect important contributions made by delegations in these open-ended working groups on topics of fundamental legal relevance like sovereignty, non-intervention, state responsibility, and due diligence. It should be the ambition of this group to make progress on a shared understanding of how these principles of existing binding international law apply in cyberspace. Germany therefore welcomes the proposal of a dedicated inter-sessional meeting to set the basis for a more meaningful exchange in the upcoming formal session of the OEWG. In light of the many delegations that have insisted on the importance of human rights protection, Germany suggests adding in Para 29.e, which would read as follows: further reaffirmed that respect for human rights and fundamental freedoms are essential for upholding and sustaining peace, security, and stability in cyberspace. In Germany’s view, it is not sufficient to have a mention of the human rights item from past reports, as mentioned in Para 28.a. We need an active reference, and Germany suggests making that inclusion in Para 29.e. Since I am talking about inclusion and I still seem to be within the time limit, let me also say that Germany is hosting a side event today on strengthening inclusivity in cybersecurity policy and strategies over lunch at German House. You will have speakers from Fiji, Ghana, the GFCE, the ITU, and Microsoft, and everyone is welcome. Thank you.
Ambassador Gafoor
Thank you very much, Germany. If one were to use the criteria of lunches and breakfast meetings, then the OEWG is already a spectacular success. And I think it’s a good sign that there are many different activities as well as nourishment provided. It does help to build understanding, not to mention build trust and confidence. So I’m very happy to see that this week is also an occasion for a lot of informal interaction over receptions and side events and informal meetings. And I certainly would encourage all of you to participate in as many as possible because ultimately these interactions do feed back and filter back into the work of the Open-Ended Working Group by increased understanding, increased levels of trust, all of which I hope will translate to an outcome adopted by consensus at the end of the week. So Germany, be generous with your German beer. Thank you. Brazil to be followed by the Netherlands. Brazil, please. Thank you.
Brazil
Thank you, Mr. Chair. Mindful of the time, my delegation will offer the following comments and suggested edits for the draft, for which my delegation is grateful. On Section C, Rules, Norms, and Principles of Responsible State Behavior, my delegation would like to draw attention to paragraph 28, item E3bis, which reads: “identifying and studying challenges associated with implementation of the rules, norms, and principles of responsible state behavior to better inform capacity building efforts.” While capacity building efforts may assist developing states in implementing the framework of responsible state behavior, such efforts are first and foremost aimed at closing the digital gap and at sustainable human development. The current wording seems to reduce the role of capacity building activities. We therefore suggest the deletion of the words “to better inform capacity building efforts.” So the sentence would read: “identifying and studying challenges associated with implementation of the norms, rules, and principles of responsible state behavior.” Mr. Chair, the following comments are regarding Section D on international law, and we take this opportunity to reaffirm that the United Nations Charter is applicable in its entirety, and reference to specific articles in this report does not imply otherwise. The question of how international law applies to cyber studies cannot be rushed, nor can any issues be considered closed at this stage. So we welcome the reference to the cumulative and evolving framework for responsible state behavior in that section, and reiterate that the reports from the GGE and OEWG remain the basis of our work. Respect for the sovereignty of other countries is an obligation in its own right under international law, and it’s more than just a principle. So this delegation prefers the language of paragraph 29, item A, to reflect that sovereignty is applicable as a stand-alone rule, including to the use of ICT by states. We recall in this regard the agreed language in several documents since the 2012-2013 GGE report, which refers to state sovereignty and international norms and principles that follow from sovereignty. This is in paragraph 27, which is also present in the 2021 report later endorsed by the UNGA. Regarding paragraph 30, item B, which refers to the contributions of studies and opinions of international legal bodies to the common understanding of how international law applies in the use of ICTs, it is not clear to this delegation to which entities this category of international legal bodies would comprise. So we welcome clarification on this. The contribution of experts, while appreciated, is not a substitute for state practice, particularly in identifying applicable international law. The language in paragraph 30B should therefore adequately address the need to encourage the continuing sharing of national views and state practice related to the use of ICT by states as a primary objective. We do not oppose acknowledging the possible contributions of experts’ bodies, which we consider to be important reference material. However, it should not be inferred that state practice and studies and opinions of experts have the same standing as state practice as the current version reads. The same reason, Mr. Chair, applies to paragraph 33. In the case of the expert briefings suggested and proposed, we would prefer the group retain the language of the 2021 OEWG report, which recognized the need for neutral and objective efforts to capacity building in the areas of international law. In this light, the proposal for holding informative briefings must acknowledge the need to consider not only equitable geographical representation, but also a balanced offer of expert views, which surely encompasses having representatives of the different legal systems in the world, with the objective of incorporating different perspectives into the discussions and presenting in a clear way doctrinal divergences in each area of discussion. Thank you for your time.
Ambassador Gafoor
Thank you, Brazil, for your statement. Netherlands, to be followed by Malaysia. Netherlands, please.
Netherlands
Thank you, Chair. On rules, norms, and principles: In order to provide context to the discussion and recommendations in this section, in paragraph 22, we call for the inclusion of the following language reflecting the 2021 OEWG consensus report. Quote, “States reaffirmed that voluntary, non-binding norms of responsible state behavior can reduce risks to international peace, security, and stability and play an important role in increasing predictability and reducing risks of misperceptions, thus contributing to the prevention of conflicts. States stressed that such norms reflect the expectations and standards of the international community regarding the behavior of states in their use of ICTs and allow the international community to assess the activities of states.” Unquote. We are pleased to see that the APR stresses the importance of the protection of critical infrastructure. Some of the most worrying and potentially escalatory ICT incidents had cascading effects and inflicted harm on critical infrastructure by spreading widely and rapidly beyond their intended targets. In order to address this risk and building on paragraph 46 of the 2021 GGE report, we encourage the inclusion of additional language to paragraph 22a reflecting that states should incorporate the consideration of the potential cascading effects of the use of ICTs in institutional arrangements and national decision-making processes in the development and use of their ICT capabilities. On paragraph 22d, we remain concerned about the feasibility of the proposal on the sharing of national definitions of commonly used technical ICT terms. The Netherlands does not currently have the types of national definitions that are being referred to here, which is reflective of the wide variety of national systems and structures, and a certain degree of ambiguity is often necessary for us as a group to make progress. We are open to states voluntarily sharing national definitions for transparency purposes and propose to reflect this in the CBM section. With regard to paragraph 27, while we are not dogmatic with regard to the possibility of new norms to be developed by consensus in the future, we consider that there is a need to further develop an understanding of the existing norms and a need to ensure their implementation before we explore the possibility of new norms. As such, we propose to stick to consensus language from paragraph 22f regarding the possibility that additional norms could continue to be developed over time. On international law, Chair, we welcome the reaffirmation that international law, in particular the Charter of the United Nations, is applicable and essential to maintaining peace and stability and for promoting an open, stable, accessible, and peaceful ICT environment. It is important for the focus discussions to recognize the consensus on which the present discussions on international law are based. This could be reflected in paragraph 28 by including that the focus discussions, quote, “built on the assessments and recommendations of the previous OEWG and GGEs on how international law applies to the use of ICTs,” unquote. In order to provide a more complete reflection of the framework governing the peaceful settlement of disputes under the UN Charter, we call for the inclusion of a reference to Article 33 of the UN Charter in its entirety, as well as a reference to Chapter 6 of the UN Charter in paragraph 29b. According to the principle of non-intervention, states must not only refrain from intervening in the internal affairs of another state but must also refrain from such intervention in the external affairs of other states. This could be reflected by adding the words “external affairs” to paragraph 29d. We consider that the references to briefings from international legal bodies in paragraphs 30b and 33 are too restrictive. In deepening our common understanding of how international law applies in the use of ICTs, the OEWG could benefit from the knowledge of international legal experts with a wide variety of affiliations and backgrounds. The Chair could reflect this by broadening the language and referring to briefings, studies, and opinions of international legal experts. Further, we agree that state practice and the studies and opinions of international legal experts could contribute to deepening common understandings of how international law applies in the use of ICTs. In recent sessions, many states have made statements on how international law applies to the use of ICTs, engaging actively in discussions. Recently, Ireland and Costa Rica have joined a growing number of states that have published their national positions. In light of these developments, we call for a specific reference to statements and national positions in paragraph 30b. In paragraph 33, we welcome the proposal to convene a dedicated intersessional meeting on international law but consider that more than one session is needed to advance discussions and common understandings of how international law applies to the use of ICTs. Finally, we are supportive of Germany’s proposal to include a reference to respect for human rights and fundamental freedoms, and we welcome Uruguay’s joint statement on capacity building and international law. I thank you.
Ambassador Gafoor
Thank you, Netherlands. Malaysia to be followed by the United States. Malaysia, please.
Malaysia
Thank you, Chair. Malaysia welcomes Section C of the REF1 version of the Second APR on Rules, Norms, and Principles of Responsible State Behaviour. Malaysia welcomes the proposed addition of Para 22 Roman 3bis. Malaysia also supports the additional language by the Netherlands in Para 22a. Malaysia would also like to suggest the following. First, to add critical information infrastructure (CII) in the first sentence of Para 22a that would read as follows: States underline the importance of the protections of critical infrastructure (CI) and critical information infrastructure (CII). In the interest of consistency and recognizing that some states define CI and CII together while others may distinguish them, we propose changes across this document to reflect these differences. The same applies to the last sentence of Para 26a. Here, Malaysia proposes the deletion of the phrase “with regard to CI protections and recovery from ICT incidents involving CI” and its replacement with the phrase “to detect, defend against, or respond to and recover from ICT incidents.” Moving to sections on international law, Malaysia supports the section on international law in the REF1 draft of the Second APR. Malaysia also supports the additional language by the Netherlands in Para 28. Malaysia appreciates the descriptive sections that comprehensively reflect the rich deliberations on international law we have pursued under this OEWG. These discussions have been instrumental in deepening understanding of the application of international law in cyberspace. In this regard, Malaysia welcomes the proposal for additional informal intersessional meetings to build upon the progress made and to foster further productive exchanges in the coming year. We hope this meeting can be held in a hybrid manner to allow greater participation by capital-based delegates. We agree with the proposal in Para 30 and, in particular, Para 30c, which places emphasis on capacity building in this field. The role of targeted capacity building in deepening member states’ knowledge and expertise vis-Ã -vis the application of international law in cyberspace is important in ensuring that we leverage our cumulative experience and facilitate the active participation of UN membership as a whole in the evolving discourse with a view to reaching a common understanding. This approach will remain pivotal in fostering meaningful cooperation and achieving shared objectives for an open, secure, stable, accessible, and peaceful ICT environment. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, Malaysia. United States to be followed by Costa Rica. U.S., please.
United States
Thank you, Chair. Turning to the norms section, I first want to start with paragraph 22A, which we believe should retain the zero-draft text deleted in the first revision that notes that ICT activity affecting critical infrastructure, quote, poses an elevated risk of harm to the population and can be escalatory, possibly leading to conflict, unquote. This is already agreed consensus language from the 2021 GGE report and makes this paragraph stronger. Critical infrastructure is critical because of how important it is to both civilian and government entities, and our consensus should not regress in this regard. In paragraph 22D, the United States does not support the inclusion of a proposal for the development of a common glossary of ICT terms and terminologies. This proposal has been made by a small number of states for many years, and it has never come close to receiving consensus support. Most member states have consistently rejected the notion of a common glossary as impractical, distracting from other priorities, and an unrealistic objective for our international discussions. Paragraph 22D should be deleted. Regarding paragraph 25, for those states that have undertaken national glossary exercises, we would welcome the sharing of national definitions of ICT terms, where feasible, as part of our overall efforts to strengthen information sharing and mutual understanding. That said, we do not support paragraph 25’s mention of any specific terms, such as ICTs or ICT infrastructure, given that states use a variety of terms in their domestic policies. We also recommend moving this recommendation to the CBM section, given its role as a transparency measure. Moving on, we see the need to streamline paragraphs 22F and G and paragraph 23. We do not see a need for multiple references to the previous OEWG chair’s summary document, or a reason to limit further discussions to that document, which is a 2021 compilation of some national ideas proposed at the last OEWG, and is not a consensus product. Instead, we propose to retain paragraph 22F, delete paragraph 22G, retain the first sentence of paragraph 23, and delete its second sentence. Regarding paragraph 26, last year’s APR emphasized the need for states to provide national perspectives on how they have implemented the agreed norms in order to facilitate the group’s discussion on potentially harmonized implementation guidance. This concept should be retained in this year’s APR, as we believe the group could benefit from additional perspectives from states and groups of states on norms implementation before we begin an exercise to develop a consolidated checklist. Regarding paragraph 27, given the amount of work needed on norms implementation, particularly around critical infrastructure protection, we believe any intersessional meeting on norms should focus on implementation of the agreed norms. We support Germany’s proposed edits to this paragraph. Turning to the international law section, we appreciate the chair’s efforts to reflect the rich discussions we’ve had this year, and to highlight in the revised draft the topics previously identified as ones the OEWG should address. However, the text should reflect the fact that many states stressed this year that further discussions are necessary before it is possible to determine whether there are gaps in international law that could require new rules, and that there needs to be more conversations on how international law applies before it would be appropriate to discuss whether new, legally binding rules are necessary. In paragraph 28, we support the proposal from the Netherlands to add language indicating that our current discussions build on the OEWG and GGE reports, as this addition reflects the progress we’ve made in this group this year. In paragraph 29B, we propose to add, quote, including statements on how international law applies to states’ use of ICTs, unquote, after state practice, to reflect the growing number of statements on international law, and the importance of encouraging states to continue to work on this aspect of fostering common understandings. In paragraph 29C, we think the text could be stronger on capacity building to reflect that, as states discussed during our sessions, there are numerous existing cross-regional efforts on capacity building already underway. In this regard, we suggest adding the following text after the first sentence of paragraph 29C, quote, states noted that many cross-regional initiatives have been undertaken in this regard, including workshops and training courses, unquote. In the last sentence, we should add, quote, should continue, unquote, after, quote, such capacity building efforts, unquote. Also, while we were glad to see reference to the continued need to share national views on international law, in particular, in paragraph 29B, we see a need to change the term legal bodies and international legal bodies in that paragraph and in 32, respectively, to legal experts in both instances. States should not be limited to looking to state practice and the views expressed by international legal bodies in developing common understandings of how international law applies in the use of ICTs. In this regard, the text is too narrow. Just as important as state practice are the views expressed by states in their national position statements or other remarks, and the text should reflect this fact. When it comes to expert briefings, the OEWG should be able to hear from a range of international law experts, not just representatives of relevant international legal bodies. We support the calls in paragraph 31 for states to continue to share their national views on how international law applies in the use of ICTs. While we support information sharing on this via the OEWG website, we have also long been supporters of the UNIDIR policy portal and its section hosting states’ international law positions. Paragraph 31 should encourage states to also post their international law positions on the UNIDIR portal. Finally, we support Germany’s proposal to add language on international human rights obligations to this section, as well as the recommendations contained in the joint statement delivered by Uruguay, particularly regarding the adding of references to the UN Charter, Article 33 in its entirety, as well as Chapter 6. Thank you, Chair.
Ambassador Gafoor
Thank you, United States, for your contribution. Costa Rica to be followed by the Russian Federation. Costa Rica, please.
Costa Rica
Thank you very much, Mr. Chairman. In the section on rules, norms, and principles of responsible state behavior, Costa Rica welcomes the inclusion of subparagraph 22C regarding civil society and the private sector in order to improve security for ICTs. We recognize in paragraph 23, there is reference to all interested parties in order to reach a common understanding and to foster the implementation of rules, norms, and principles of responsible behavior, which are non-binding. Looking at the reference to ICTs on international humanitarian law and privacy, we want to see that, and we want all interested parties to be present at any informal meeting between sessions in order to debate the possible development of existing norms and the development of new ones, promoting law and taking into account gender issues with a human-centered approach. In paragraph 29, we would like to see a reference to international humanitarian law. As the Human Rights Council said, rules here have to be protected and guaranteed by states and they apply. On paragraph 33, we approve an inter-sessional meeting being convened, and this could help us to reach common understandings in formal sessions acting together. I’d like to take advantage of this opportunity to draw the attention of the delegates to Costa Rica’s position paper on the implementation of international law in cyberspace, which we trust will improve a contribution to our discussion. Thank you.
Ambassador Gafoor
Thank you, Costa Rica, for your statement. Russian Federation, to be followed by China.
Russia
Distinguished Chair, distinguished colleagues. On the section on rules, norms, and principles of responsible behaviour of states first. The mandate of the OEWG has been endorsed by all UN member states. It tasks us to continue as a priority to further develop rules, norms, and principles for the responsible behaviour of states in the information space. We think it’s indispensable to strictly follow this guideline. We are compelled to state that in the current version of the report, in violation of the mandates of the group, there is first and foremost an unjustifiable skew in favour of implementing the existing list of voluntary and non-binding rules of behaviour. What’s imposed on states are various implementation reporting forms that have not been agreed under the UN auspices. Russia and several other states consistently insist on the need to agree on a comprehensive universal list of rules, norms, and principles of responsible behaviour and make them legally binding. This is due to rapid progress in the field of ICT and the insufficiency of existing voluntary rules to effectively regulate this area. It’s necessary to take concrete steps to shape an international legal regime in the information space. Relevant provisions need to be reflected in the draft report. On paragraph 25 in particular, states could be recommended to determine which of the existing voluntary rules could be included in a future international treaty. We also suggest supplementing this section with provisions that accusations of wrongful acts with the use of ICTs brought against states must be substantiated and that computer incident response must not be politically motivated. These ideas are fundamentally important given what’s been mentioned by a number of delegations, namely threats to information security. In the absence of a universal, generally accepted approach to the classification of critical infrastructure, we consider it more appropriate in paragraph 23 to provide for the exchange of best practices in protecting any type of information infrastructure, including CII. Therefore, we will not limit the scope of possible cooperation between states in this field, and we will provide our concrete proposals in text to the chair. Now, on the section on how international law applies to the use of ICTs by states. Discussions in the OEWG on the subject of international law have shown that most states do not share the view on the full and automatic applicability of international law to the use of ICTs and the sufficiency of existing norms to regulate that domain. There is an urgent need to adapt and develop international law, taking into account the specifics of these technologies. The priority is to shape a universal and just international legal regime in regulating the information space based on legally binding instruments. The chair circulated this draft progress report, and it can serve as a basis for further negotiations on this section. At the same time, it requires serious revision in order to ensure a balanced reflection of the interests of all states. On paragraph 27, it is redundant to restate the idea of international law being applicable, as that’s already mentioned in the introduction section of the draft report. On paragraph 29, here and further in the text, we do not see any added value in repeated references to the cumulative and evolving framework of responsible behaviour. Ensuring international information security will rather be ensured by the adoption of relevant practical measures, and this includes legally binding ones. That is, rather than the repetition like a mantra of statements of commitment to voluntary rules of behaviour. On paragraph 30, we insist on adding a sub-paragraph on the submission of a concept of a UN convention on ensuring international information security and its subsequent discussion along with other proposals by states on the subject of international law. In addition, we also propose merging paragraphs 31 and 33 with regard to further discussion of the applicability of international law, and this includes in the format of informal intersessional meetings. Otherwise, the draft report will remain seriously unbalanced in favour of this topic, and that’s contrary to the mandate of the OEWG, which prioritises the development of rules, norms, and principles of responsible behaviour of states. On paragraph 30b, the term international legal structures is unclear. It should be replaced by relevant international organisations or deleted. On paragraph 32, we do not see any added value in the recommendation to create a compendium of national positions of states on international law. One has already been created as part of the work of the GGE in 2021, and it has not brought any significant practical benefit. At the same time, the statements of delegations on the subject of international law are already posted on the OEWG website, so there’s no need to duplicate work in this way. The Russian proposal on the international law section of the draft report will also be provided to the chair. Thank you very much for your attention.
Ambassador Gafoor
Thank you, Russian Federation, for your contribution. China, you have the floor, to be followed by Bangladesh. China, please.
China
Thank you, Mr. Chair. On paragraph 22b, the second paragraph, at present, supply chain security faces a risk. That is, many countries are forming small cliques against other countries in terms of their discriminatory pressures and policies, which disrupts the stability of the global supply chain. The so-called good practice of regional organizations has become bad. So we support deleting cooperative measures such as exchanges of good practice at the bilateral, regional, and multilateral levels on supply chain risk management. Regarding 22c and 24b, regarding the supply chain security, we support adding the consensus language of 20 of the DGD report. States should foster a transparent, objective, impartial environment for private sectors and develop globally interoperable standards for the supply chain. Regarding 30a, we should lead as proposed additional sessions to be convened into the next intersessional period of the OEWG. We believe there’s no consensus on that. Regarding 30b, fourth line, and paragraph 32, line 2, China suggests state practice should be replaced by state views, because China believes that national positions and national practices could be categorized as national views. Also, China supports the view of Brazil, believing that the international legal bodies are ambivalent and they should be deleted from the text. China supports certain proposals that the International Information Security Convention should be reflected. Thank you.
Ambassador Gafoor
Thank you, China, for your contribution. Bangladesh to be followed by Mexico, please.
Bangladesh
Thank you, Mr. Chair. We believe that rules, norms, and principles of responsible state behavior constitute a cumulative and evolving framework for responsible state behavior in the use of ICTs, and we welcome the formulation of Section C. On paragraph 22a, we support the proposal to include critical information infrastructure, as explained by Malaysia. We believe the private sector plays a significant role in the ICT supply chain. Therefore, in 22c, we propose to include the crucial role that the private sector plays. So the sentence would read, states noted the crucial role that the private sector plays, then the sentence continues. And in the fourth line, we propose to include further strengthened partnership and collaboration with the private sector. So the sentence would read, it was proposed that in addition to the steps and measures outlined above, states should continue to further strengthen partnership with the private sector and civil society to collaboratively enhance the security of, and in the use of, ICT, then the sentence continues. On paragraph E2, we appreciate the inclusion of capacity building needs in the implementation of rules, norms, and principles, which we believe is critically important for developing countries. On paragraph 27, we support the idea of having additional informal intersessional meetings to discuss the elaboration of existing norms and the possible development of additional norms. Turning to international law, in our view, this section adequately reflects the state views on international law during the past sessions. While we do not rule out the possibility of having a future legally binding treaty, we need to understand the gaps in the existing legal framework, keeping in mind the evolving nature of ICT. We must identify if such gaps exist and how they can be effectively addressed to ensure comprehensive and up-to-date regulation of ICT-related issues. In this regard, we support the proposal to engage in a focused discussion at the OEWG on how international law applies in the use of ICTs. We agree that international law applies in cyberspace. We, however, lack a common understanding of how international law applies in the ICT systems. Therefore, we welcome the reflection on the urgent need for continued capacity building efforts in the area of international law, including with the aim of ensuring that all states are able to participate on an equal footing. In the same vein, we support the proposal in paragraph 33 to have a dedicated intersessional meeting on how international law applies. And we look forward to having expert briefings from representatives of relevant international legal bodies on how international law applies in the use of ICT. I thank you, Mr. Chair.
Ambassador Gafoor
Thank you, Bangladesh. Mexico, to be followed by Kenya. Mexico, please.
Mexico
Gracias, Chair. Thank you, Mr. Chairman. Well, given the complexity of the discussions and the diversity of viewpoints as to how international law should apply to cyberspace, we need to have a commitment to have a more far-reaching discussion on this, and we believe that this could prove an incentive to this end, taking into account the reference to make particular reference to those aspects which are most crucial for our countries. Mexico has two specific suggestions to make on the international law section. On the one hand, we believe that it’s necessary for the annual report to reflect the international endeavours and inter-regional, regional, and sub-regional ones which are at present being carried out regarding capacity building. This is an aspect where the OAS has driven forward activities and channeled resources for the countries in the region. Last week, my country had the opportunity of participating in a training workshop on the implementation of international law to cyberspace, where there were also representatives from various countries in the south, and so therefore we support the proposal for a language from the US which appears to us to be acceptable. In the same section of the document, my delegation would like to change the references to the term international legal bodies and replace this with international legal experts. This was also mentioned by the delegation from the Netherlands. My delegation views it as important that this reference should not include just established legal bodies, but should also reflect the possibility of having expert voices from other sectors and interested parties, which have constantly followed up this and made valuable contributions to our dialogue. We also believe it is important that this section should reflect the role and the contributions of the many interested parties in leading towards a common understanding of how international law should be applied in cyberspace. Lastly, sir, my delegation does have specific comments for the rest of the sections. I’d just like to refer very briefly to the other parts of the document. We welcome the progress arrived at in consolidating the repertory of points of contact, and we trust that this will be adopted this week and become operational. It is an imperative measure to drive forward the coordination and responses to a malicious use of cyberspace. When it comes to the regular inter-institutional dialogue, we believe that this should clearly reflect that this mechanism does have the potential of being both a tool for following up things as well as the backbone of operationalization in order to achieve the sustainability of the implementation of a framework on cyber security. Thank you.
Ambassador Gafoor
Thank you, Mexico. Kenya to be followed by Sweden. Kenya, please.
Kenya
Thank you, Chair. It’s our view that rules, norms, and principles of responsible state behavior greatly underpin a country’s progress trajectory, particularly in the use of ICTs and the establishment of resilient critical infrastructure as tools of socio-economic growth. In this regard, Kenya is supportive of concrete, action-oriented proposals on rules, norms, and principles as encouraged in Paragraph 22 and Subsection A, including further discussions and exchanges on how countries, regions, and subregions are contextualizing and implementing rules, norms, and principles to better inform capacity building efforts as captured in Paragraph 22E, Subsection 1, 2, and 3Bs. Paragraph 22E, 2 particularly, is a critical recommendation given the different needs of various states and member countries in the implementation of the rules and norms. We recommend the retention or rephrasing of the deleted text in 22A. As a country, we do know that any irresponsible acts from both state and non-state actors targeting critical infrastructure can have a significant impact on the delivery of citizen services and even pose a potential threat to its stability. Paragraph 22B, Section 1, is important given that it highlights the need and efforts in promoting interoperability and open standards for technology to promote integration and diversification of technology used to eliminate technology lock-in and vendor dependency, especially for developing nations. To this extent, Kenya is developing regulations for the management of its critical information infrastructure, including responses and resolutions on cyber threat incidents targeting our CII. Kenya is also supportive of the developments captured in Paragraph 26 on the request to produce an initial draft of a norms implementation checklist, including further discussions on the same in an informal intersessional meeting with the understanding that further development of norms and implementation of existing norms are not mutually exclusive, as reflected in 22F. As a country that has been at the forefront in ICT, we look forward to contributing to this initiative that we believe will enhance OEWG’s efforts and are appreciative and supportive of the principle of equitable geographical representation captured in Paragraph 27. I thank you, Chair.
Ambassador Gafoor
Thank you very much, Kenya. Sweden to be followed by Latvia.
Sweden
Mr. Chair, thank you for giving me the floor. I will speak on behalf of Denmark, Finland, Iceland, Norway, and Sweden in our national capacities, focusing on Section D. The Nordic countries fully aligned themselves with the EU statement already delivered by our colleague from the EU. The Nordic countries are pleased that a session of the OEWG has again been dedicated to the topic of international law and cyber. The responsible behavior of states when using information and communication technologies is not merely a policy issue but concerns legal rules and principles, including those that concern the international community as a whole. Having a forum like the OEWG contributes to a greater understanding of the application of these norms to capacity building and to building confidence in each other. Mr. Chair, let us reiterate that international law, including the UN Charter, applies in cyberspace as affirmed by the previous OEWG and endorsed by the General Assembly. This means that cyberspace is not an unregulated arena or domain with legal gaps that would need to be filled. While the Nordic countries are aware that states may hold different views on how some rules developed for the kinetic world should be interpreted and implemented in the cyber context, we also hold the view that the applicability of international law does not depend on the technological means employed but applies across domains. While the existing rules and principles of international law are applicable in cyberspace, the application of certain provisions may give rise to practical problems due to the specific characteristics of cyberspace. Therefore, it is necessary to continue in-depth discussions on these specific questions of the application of international law. We would like to thank the Chair for sharing the zero draft of the now-in-progress report well in advance of this session, as well as the revised draft. The revised draft includes many key elements relating to international law and gives us a solid basis for discussions. The Nordic countries would like to highlight just a few aspects, starting with that we welcome that the draft so clearly reaffirms that the rules in the UN Charter on the peaceful settlement of disputes and the prohibition of the threat or use of force apply in cyberspace, along with the principles of non-intervention and state sovereignty, noting that these are not merely principles but primary rules under international law. We also think that it would be a fair reflection of the discussion held to include references in the now-in-progress report to our exchanges on due diligence and states’ responsibility. Secondly, the Nordic countries agree that developing and publishing national positions on how international law applies in cyberspace is beneficial for all, as these help to increase our common understandings. Lastly, we welcome the clear recommendation in the draft report to continue detailed discussions on international law and cyber. Focusing the discussion on a few topics would be beneficial. The Canadian and Swiss paper from the end of last year suggests focusing on the Charter of the UN, peaceful settlement of disputes, IHL, and states’ responsibility. We agree with the pertinence of these topics and believe that it would be particularly useful to discuss states’ responsibility and international humanitarian law. Cyberattacks conducted in the context of non-conflict are subject to the same restrictions and regulations under international humanitarian law as conventional attacks, including the principle of humanity and military necessity, as well as distinction, proportionality, and precaution. Thank you, Chair.
Ambassador Gafoor
Thank you. Sweden. Latvia, to be followed by the Republic of Korea. Latvia, please.
Latvia
Mr. Chair, as this is the first time my delegation takes the floor, please let me state that Latvia welcomes their wise draft and considers it as a step in the right direction, although we will still need to work together this week to bring it in the landing zone. Latvia fully aligns itself with the statements of the European Union, and please let me add a couple of points in national capacity. When it comes to Section C, we retain the position that our main effort should be on deepening our understanding and implementation of the existing norms, which have been endorsed by the UNGA. While this does not exclude the possibility of eventually developing additional norms, we believe it would be important to focus our work and scarce time available on achieving the maximum benefit that full implementation of existing consensual norms can deliver. In this context, we believe that the current draft, namely PAR 27, puts too much emphasis on the establishment of additional norms. Furthermore, we remain skeptical regarding the proposal in PAR 22D to establish a glossary of technical ICT definitions, as we do not see this as a practical proposal for reasons well elaborated by several delegations before us. On Section D, as outlined in the Secretary-General’s report on the new agenda for peace, cyberspace is not a lawless domain. We see it as very important to uphold our common understanding that international law applies to cyberspace. In this context, we also support the ideas expressed in the group statement delivered by Uruguay. Furthermore, we fully support the dedicated intersessional meeting on how international law applies in the use of ICTs, as envisaged in PAR 33. For Latvia, it would bring additional value as we are working to form a national position on the applicability of international law to cyberspace. We note the reference to the possibility of developing additional legally binding norms in PAR 28B1. As stated previously, in our view, such a step would be premature. Furthermore, we notice a very similar duplicative reference to legally binding norms in Section G on regular institutional dialogue. While we recognize that this reference comes from last year’s report, however, as stated by Japan, we believe that discussions on these matters have developed since last year. Therefore, we do not see merit in having two duplicative references on legally binding norms in the current draft. At least one of them should be deleted. Finally, we would like to support Germany’s proposal on human rights. We remain committed to working closely with you to achieve a successful outcome of our deliberations this week. I thank you.
Ambassador Gafoor
Thank you. Latvia, Republic of Korea, to be followed by Austria.
Korea
Thank you, Chair. On the rules, norms, and principles, under Paragraph 22A, as mentioned by the U.S. and others, we also would like to suggest retaining the language which poses a relevant risk of harm to the population and can be escalatory, possibly leading to conflict. I think it’s worthy of reaffirming this particular language because it shows why we need to focus on the security of the CI. Also, on Paragraph 22A, we believe that it should be mentioned somehow in the text that these norms are from the 11 norms of the Group of Governmental Experts reports, noting that a specific set of norms has already reached consensus among the member states. With respect to Paragraph 22D and 25, on the proposal to establish a glossary of ICT terms and terminologies, Korea shares the view expressed by the U.S., Japan, and others. On Paragraph 22F, we agree that the implementation of existing norms and further development of norms are not mutually exclusive but could take place in parallel. Nevertheless, my delegation believes that existing norms, especially the 11 norms of the GGE report, have been adopted by the General Assembly and undoubtedly established consensus in this domain. Therefore, we think there should be more focus on the discussion on the implementation of elaboration of the already existing IGEs. On the international law part, Mr. Chair, the Republic of Korea reaffirms its view that existing international law, including universal international treaties, customary international law, international human rights law, international humanitarian law, principles of international law, and in particular the Charter of the United Nations in its entirety, is applicable to cyberspace. We also reiterate that the OEWG should discuss the specific application of existing international law rather than the idea of creating a new convention. On Paragraph 28B, subparagraph I, my delegation does not think it is necessary to include the phrase, including the possibility of additional legally binding obligations. Let me just recall that there has been a longstanding agreement in the United Nations framework, especially the GGE and OEWG, reflecting the consensus in its reports that international law applies in cyberspace. We would like to make some suggestions on Paragraph 29. First, we suggest supplementing the current wording with the phrase the principles that flow from sovereignty in subparagraph A as it is reflected in the report of the 2021 GGE. Second, it would be desirable also to include international human rights law and international law on state responsibility. Lastly, on Paragraph 33, like many previous speakers, we have the view that having discussions on specific international law topics during the international meeting is useful and necessary, so we want to retain relevant wording in this paragraph. Thank you, Mr. Chairman.
Ambassador Gafoor
Thank you, Korea. Austria to be followed by Singapore.
Austria
Thank you very much, Mr. Chair. I’ll do my best to stay within the time frame, but I’m afraid that my lawyers gave me some points to say, so deflecting blame here. Starting on rules, norms, and principles, paragraph 22a, we appreciate the reference to the norms protecting critical infrastructure, and we support the U.S. proposal to reinsert the struck-out sentence about elevated risks. The reference to norms F, G, and H, we would suggest to be precise about the source of those norms and to point out the exact source to avoid misunderstandings to uninformed readers. We all know what the 11 norms are that have been approved and reaffirmed by consensus, but we’ve seen attempts to promote new non-consensual norms in different resolutions, so for us, it’s important to be precise. On paragraph 27, we would support the comments made by Germany on rephrasing paragraph 27, subpoint a, to replace “elaborate” with “implement” and to delete paragraph 27b because of the reasons pointed out by Germany. Going to international law, on paragraph 28, we welcome the re-inclusion of the affirmation that international law is applicable. We would suggest including further that many states also in the discussions that we had shared their views on the applicability of international law, which contributed to a more fruitful discussion on this topic. We can also support the proposals on language to paragraph 28 made by the Netherlands. On paragraph 29b, the group around Uruguay and others pointed out that chapter 6 of the UN Charter is important. The current reference to two articles of the UN Charter is, in our view, too narrow and a step backward compared to previous versions. Therefore, we propose a broader reference that includes the whole chapter 6 of the UN Charter dedicated to peaceful settlements of disputes. Paragraph 29e, we support Germany’s proposal for a reference to human rights. As my German colleague pointed out, this has been a topic that has been discussed extensively and at length, and international human rights law is extremely pertinent in the framework of the legal discussions that we’re having, and therefore it should be reflected as such. On paragraph 30b, we’ve heard several proposals by states to delete the reference to state practice, and we would like to retain this reference. If there is state practice that states would like to share in this group, it should be there, and it’s because state practice is the correct legal term. Paragraph 30c, we support the U.S. proposals on capacity building international law. Paragraph 33, we support a dedicated intersessional meeting on international law as referenced in paragraph 33. And finally, a little bit of a broader point on a legally binding instrument. We’ve heard many proposals and statements of the applicability of international law that, in our view, do not correspond with the facts. We’ve heard in the past year that a number of states have repeatedly stated that they do not see the need to elaborate a treaty as international law sufficiently covers cyber operations. We reject the argument presented that there are no legally binding norms governing cyber activities. This argument goes counter to the repeated affirmation by all states that international law and the UN Charter are applicable. Furthermore, we’ve heard arguments that there are gaps in international law leading us to the necessity of a treaty. Despite repeated calls for such explanations, we’ve never heard where those gaps are. Therefore, on this issue, it’s just important to point out to my delegation that the APR accurately reflects the discussions held in this group. Based on what we just set out, we do not believe that repeated calls to include references to a legally binding instrument provide such an accurate reflection. This week, we should reflect on the progress achieved, and we should not attempt to rewrite or reframe the discussions we held. The same goes for the proposal on the UN Convention, which has not and does not gather consensus in this group. And I thank you.
Ambassador Gafoor
Thank you, Austria. It’s 12 o’clock, and we have about 20 speakers left who have inscribed to speak under sections C and D. If we stick to the three-minute rule, then it’s possible that we can cover these two sections by 1 p.m., and I would really like you to do that. Second, I’m getting the sense that there is a restating of positions, and I’m also getting the sense that interventions are being made to describe the virtue of your own positions, while stating also that you don’t see the need to recognize the proposals and positions being put forward by the other side. Now, those are entirely valid interventions and statements, especially if they’ve been drafted by your own delegations in your own capitals. I understand that. But, my friends, we are at a stage of the process where we have to adopt an annual progress report at the end of this week. And this week is the culmination, in a sense, of 12 months of work in a second cycle of this OEWG. So, I think we need to begin to recognize, and I urge all of you to do that, that we need to achieve some balance. And balance needs to be achieved in a way that accommodates the positions of all delegations, that accommodates the difference of views and the range of proposals that have been put forward. So, much as I would like to say that, you know, you can go on making your statements, I will listen to all of them, and I will look very carefully at the proposals you have made. And the proposals are very detailed. But if we compiled all those proposals that have been made, they don’t necessarily overlap. And so, we still are not getting nearer on some of these issues, especially the issue of implementing norms and discussing the need for additional norms. There are still gaps there. The reference to legally binding obligations and whether that has command consensus and how we reflect them. And I know that these are issues that have been discussed for over 25 years. We have the option of just using agreed language, but if we used agreed language, then frankly, you don’t need an OEWG chair. You can use generative AI, feed it with data of 25 years of discussions, and say, produce a text using agreed language. So, my predicament is that we have to find consensus. And if every delegation were to extol the virtues of its own position, then we will still be stuck with gaps. And if we are stuck with gaps, then we will not be able to get to a consensus document. So, my friends, please help me. Please help me find solutions. Please help me bridge the gaps, because that’s what we need to do if we want to adopt an annual progress report at the end of the week. The floor is still open, and I’ll go through the speakers list. And I do really urge you to stick to the three-minute rule. Singapore, no pressure on you. Singapore to be followed by Israel.
Singapore
Thank you, Chair. Singapore broadly agrees with the proposals under the section on Rules, Norms, Principles of Responsible State Behaviour. We support the emphasis on the importance of protecting CII and the need to strengthen measures to protect all CII from ICT threats. As noted by the Philippines, Pakistan, and others, this is key for all Member States given that CIIs play a critical role in delivering essential services to the population, ensuring the effective functioning of the economy and society. Similarly, CIIs which provide essential services across borders and jurisdictions must be protected. We also support the proposals in Paragraph 22E to further assist States in implementing rules, norms, and principles of responsible state behaviour. Doing so through various means, including the Norms Implementation Checklist, would be helpful in supporting small and developing States in their norms implementation efforts. We look forward to the Chair’s convening of the informal inter-sessional meeting involving both States and norm stakeholders to discuss the elaboration of existing norms. For international law, Singapore fully supports the section of the Zero Draft on International Law in this revised draft APR, which is a balanced text specific on Paragraph 29C. Singapore wishes to highlight that while reference has been made to Article 2 of the UN Charter, it is important to recall that these obligations do not impair a State’s inherent right of self-defense as provided in Article 51 of the UN Charter. This right to self-defense applies in cyberspace as well. We support the proposals on international law set out in Paragraph 30, in particular Paragraph 30B on sharing views on international law. Singapore has already shared our national views publicly. Our delegation has also found the documents containing national views of other States to be an invaluable resource, which is extremely helpful when trying to understand the broad range of views of other delegations in this room. We believe that if even more national views can be shared, this will further enhance our deliberations and also serve to dispel any misunderstanding of each other’s positions. There is great value in understanding how States apply international law, including their State practice. Hence, we suggest that for Paragraph 30B, we should insert the words, the application of, before international law, including on State practice, so that there is more targeted sharing of views on this. Thank you.
Ambassador Gafoor
Top marks to Singapore for keeping within the time limit, and I’d like others to follow the same example. Israel, to be followed by New Zealand.
Israel
Thank you, Mr. Chair, and I certainly hope to keep up with the standard set by the Singaporean delegation. Mr. Chair, on the issue of rules, norms, and principles of responsible state behavior, we wish to reiterate our position that it is important that states first implement currently existing norms, and only at a later stage should additional norms be considered. Therefore, in reference to Article 27b in the recommended next steps portion, we can support the German suggestion to delete the reference to the development of additional norms, or, alternatively, support the Netherlands that has suggested using the previously agreed language, both from last year’s APR as well as the final report of the 2021 Open-Ended Working Group, that refers to the possibility that additional norms could continue to be developed over time. On the section of international law, Israel welcomes the statements made by other delegations during our deliberations on the general application of international law to the field of ICTs. This contributes to enhancing our mutual understanding and creates a positive starting point for discussion of this topic. Israel, for its part, expressed support for the position that existing international law provides the appropriate normative framework for this discussion, and the focus should be on understanding how the current framework applies rather than creating new rules. We think that the approach suggested in paragraph 33 of the draft APR of convening a dedicated intersessional meeting on the application of international law to states’ use of ICTs can contribute to the discussion. With respect to the reference to the principle of non-intervention, we suggest aligning the text with the language previously used during the Open-Ended Working Group and deleting the words “directly or indirectly,” which may create, in the context of cyberspace, more questions than clarity. In our view, the APR should refrain from introducing interpretive elements to the enumerated principles. The list of principles that can be included in future discussions is already quite long, and there is no need to elaborate further in the APR on any given usable principles. Finally, Mr. Chair, some states have mentioned during our discussion the need to add a direct reference to the promotion of a legally binding instrument. We’d like to caution that the carefully balanced text might be destabilized by this suggestion, and that it might negatively influence our ability to achieve consensus during our discussions. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you. Israel, New Zealand, to be followed by Argentina.
New Zealand
Thank you, Chair, and kia ora everyone. New Zealand views the proposed text in sections C and D of the revised draft as a good starting point to achieve a balanced APR, which, in our view, is one that not only captures the breadth of discussions but accurately captures the weight of discussions the OEWG has held over the past 12 months. On rules, norms, and principles, we’re supportive of amendments to paragraph 22 to clarify and explicitly note the call by states for the implementation of norms F, G, and H on the protection of critical infrastructure. However, as the Netherlands, Republic of Korea, and others have said, we suggest reverting to already agreed language in the paragraph, which recognizes that intentional damage to critical infrastructure poses an elevated risk of harm to the population and can be escalatory, possibly leading to conflict. In our view, the weight of this section should focus on the implementation of agreed norms, which reflects both the detailed and focused discussions held during this OEWG over the past year and also reflects General Assembly Resolution 75/240, paragraph 4, which confirms that introducing changes to the rules, norms, and principles or elaboration of additional rules of behavior should occur if necessary. As we and others have consistently said, unless and until gaps are found in the existing framework, discussion of new norms is premature. As currently drafted, the recommendation contained in paragraph 27 goes beyond consensus agreement, and we recommend this is redrafted so that discussion is on implementation rather than elaboration of existing norms. Regarding the proposed glossary of terms, we note that this proposal is not new and has not gained traction during discussions in this OEWG, the previous one, nor in other regional fora. While, in our view, the amended language encouraging states on a voluntary basis to share national definitions is an improvement from the zero draft, we see room for further improvement, given the strong concerns expressed on the proposal by a number of states, including New Zealand. We could support amended language that proposes further exchanges of views by states and recommend this is shifted to the section on confidence-building measures. In our view, references to additional legally binding obligations in this section would be unlikely to gain consensus, given the divergence of opinion on this issue. Turning to section D on international law, New Zealand notes, as we and many others have done before, that cyberspace is not a lawless space and that international law applies online as it does offline. The revised language in paragraph 28 more accurately conveys this principle, and we recommend, as others have also said, explicitly reinforcing that the Charter of the United Nations in its entirety is applicable and essential to maintaining peace, security, and stability in cyberspace. We also support calls from the EU, Uruguay, and others for language reflecting Article 33 and Chapter 6 of the UN Charter more broadly. New Zealand has been heartened to see states continuing to share their national perspectives. This includes states sharing views on the applicability of international humanitarian law and international human rights law. While New Zealand welcomes the references to international humanitarian and international human rights law in paragraphs 28bis a and b2 respectively, both of which are drawn from previous reports, we would also recommend inserting specific reaffirmations to the applicability of international humanitarian law in the context of armed conflict and support the proposal by Germany to add a new paragraph on international human rights law in paragraph 29, given states explicitly noted and affirmed these during OEWG discussions. In paragraph 30b, we agree with others that references to international legal bodies are too limiting and support proposals to change this to international legal experts. Chair, we do not agree with the suggestion made today that most states do not accept the full and automatic applicability of international law. In our view, the detailed and focused discussions held in this room over the past 12 months, together with the volume of national statements detailing national views on the applicability of international law to cyberspace, as well as the consensus views in the 2021 OEWG report on its applicability, are strongly indicative of a need to continue exchanging views on how, not whether, international law applies. Given the low likelihood of reaching consensus, we recommend the text avoids any references to a treaty in the recommended next sections on international law. Thank you.
Ambassador Gafoor
Thank you. Argentina, followed by Thailand.
Argentina
Thank you very much, Mr. Chairman. We’ll just briefly refer to the section on international law. Over the last year, sessions have shown that there is a great interest in participation amongst Member States in order to better understand the implementation and application of international law to cyberspace, including the UN Charter and IHL. We welcome your proposal that there be a report for this section, and we would like to see the drafting of paragraph 29 as an introduction, referring to what has occurred this year, that is, that there are various positions on each of the particular issues which are then subsequently identified. We also support the proposals coming from several colleagues on capacity building, particularly referring to paragraph 30C. And then lastly, regarding future steps, next steps, we support the drafting proposal in paragraph 33 on there being a dedicated inter-sessional meeting on how to exchange ideas on international law, and we suggest that the International Law Commission be convened for these discussions. This would give greater substance to the analysis of the issues of international law. Thank you.
Ambassador Gafoor
Thank you, Argentina. Thailand, to be followed by Canada.
Thailand
Thank you, Mr. Chair. As my delegation takes the floor for the first time, allow me to express our appreciation for your work on this revised draft. Thailand aligns itself with the statement delivered by Brunei on behalf of us yesterday on Section D, international law. Thailand reaffirms that international law, in particular the UN Charter, is applicable in the context of ICTs. Thailand also believes that there remain questions as to how international law applies, as well as whether gaps exist. Therefore, Thailand supports the proposal that states continue to engage in focused discussions at the OEWG, among other forums, on this issue to resolve a convergence of views and develop a universally accepted understanding of how international law applies in cyberspace, as well as to address existing gaps, if any, including the issue of peaceful settlement of disputes. Thailand is also supportive of the recommendations that states in the position to do so continue to support additional efforts to build capacity in the areas of international law in order for all states to contribute to building common understandings of how international law applies in the use of ICTs. Finally, Thailand wishes to highlight the issue of due diligence, which we have placed utmost importance on, and wish to emphasize the need to further elaborate on its scope and application, particularly as a developing country, since it directly impacts our practices, policies, and obligations under international law. The implementation of due diligence varies according to each state’s cyber capacity, making it a critical priority to address in our efforts to enhance cyber security and promote responsible behaviors in cyberspace. I thank you, Mr. Chair.
Ambassador Gafoor
Thank you, Thailand. Canada, followed by Fiji. Microphone for Canada, please. Thank you.
Canada
Thank you, Mr. Chair. As we noted yesterday, Canada believes that it’s important that the Annual Progress Report faithfully reflects the substance, weight, and nature of our discussions. We are therefore disappointed to have heard certain delegations stating that the APR should not approach the issue of norms implementation. This is an important element of our discussions, and that was the case last year. Several states discussed the excellent work undertaken by ASEAN on a checklist for norms and the document on the implementation of norms submitted by my delegation on behalf of 40 states. Canada commends the idea of tangibly contributing to the proposal to draw up additional guidelines on the implementation of norms in the year to come. Indeed, continuing discussions on the implementation of norms is a prior condition for the effective examination of new potential norms. If we don’t understand how, why, and whether states implement their current commitments, it’s difficult to determine which new norms could be necessary, if that’s so the case. Having said that, Chair, one area that Canada thinks it’s not necessary to continue work relates to the proposal to draw up a UN glossary on cyber terms. Unlike several new proposals presented over the last year, which deserve more in-depth consideration, this proposal has been considered several times and it was rejected. This includes during the GGE 2016-2017 and the previous OEWG. Canada also recommends removing the reference to the list in paragraph 25, and that section should be in the CBMs section. With regards to international law, we will be submitting with Estonia specific proposed editorial comments in writing, which we assess will help us achieve a consensus report. One of the issues we see as necessary to include in the APR is the progress and momentum that we, under your able leadership, have achieved in this OEWG on the topic of international law. In our view, the APR could more aptly and accurately reflect this tangible success made on this very topic in accordance with our mandate. Mr. Chair, you have previously asked what success on the topic of international law looks like. In our view, the following concrete examples of success we have achieved should be reflected in the APR, specifically in paragraphs 29 and 30. We have had substantive and focused discussions, notably on the Charter of the United Nations, and how much it has to offer in clarifying how existing international law applies in cyberspace. This includes on the topic of the use of force, sovereignty, equality of states, and the peaceful settlement of disputes. These discussions have demonstrated real progress on developing common understandings of how existing law applies in cyberspace and is a tangible mark of success. The increased number of national statements, as many states have pointed out, including those recently put forward by our Irish and Costa Rican colleagues, are another sign of success. We are also aware that many other states, as well as regional organizations, are in the process of developing their statements on how international law applies to cyberspace. Such statements are concrete actions by states to demonstrate their commitment. We note, as more states continue to develop and publish national positions, the substance and specificity of our discussions on international law have dramatically increased. As noted, capacity building is another area that should be listed as a success. We note Uruguay’s statement on behalf of a group of states that outlined recent training last week. I would also note that last year, Canada has funded training courses for 194 participants from 53 member states, both virtual and in person. Chair, recalling the analogy of the tradition of Indigenous Peoples of Canada to building a birchbark canoe, we are happy to say that we see our boat taking shape and we believe we are well on our way to the creation of a seaworthy craft that will serve us well in the future. We look forward to further work in the coming year on this topic. Thank you.
Ambassador Gafoor
Thank you, Canada. Fiji, to be followed by Australia.
Fiji
Mbula Vinaka, Chair and colleagues. Chair, with regards to paragraph 22A, Fiji supports Malaysia’s amendments to include critical information infrastructure across the report. With regard to paragraph 24, and to further provide focused discussions, the OEWG can look at exchanging views and/or providing targeted support for the identification of critical infrastructure and critical information infrastructure. A text option that can be considered is the following: Paragraph 24A, which can read as, “At the 6th, 7th, and 8th sessions of the OEWG, states to also undertake focused discussions on and strengthen cooperation and support for developing states to undertake identification of critical infrastructure, including critical information infrastructure.” Chair, this amendment is critically important for small island states, developing states, and small states. We cannot talk about critical infrastructure protection or recovery from ICT incidents without first determining the categorization or identification of critical infrastructure and CIIs and the risk management frameworks that exist. Therefore, we seek support in this important area as Fiji is currently reviewing its national cybersecurity strategy, and this critical component can be captured in this review. Moreover, this text inclusion will ensure equal footing amongst all states to be in a position to adhere to the voluntary existing norms. Chair, with regards to paragraph 27, and as a small island developing state with finite resources and competing priorities, Fiji is of the view that priorities should be placed on the implementation of existing norms as proposed by Germany and supported by the U.S. and other states. One such norm that we are looking forward to is the operationalization of the POC. Chair, in our quest to gain consensus, we support the recommendation by the Netherlands regarding reverting to the consensus language within paragraph 27. Chair, turning to international law, we welcome the statement delivered by Uruguay on behalf of the Group of States on International Law. With regards to paragraph 28, and for completeness, it is recommended that the paragraph be amended to state that the UN Charter is applicable in its entirety, and this has been raised and supported by numerous delegations. We also support the language proposed by the Netherlands in this regard. With regards to paragraph 29d, Fiji supports the recommendation by the Netherlands in adding “or external affairs” and the amendment regarding section 33 of the UN Charter. With regards to paragraph 29e, Fiji supports the amendment proposed by Germany in paragraph 29e regarding the respect for human rights and fundamental freedoms and is supported by a number of delegations. And finally, Chair, with regards to paragraph 30b, like Brazil and other states, we further seek clarification on the reference to international legal bodies, and we welcome the amendments suggested by the U.S., Netherlands, New Zealand, and Mexico. Thank you, Chair.
Ambassador Gafoor
Thank you, Fiji. Australia to be followed by Nicaragua.
Australia
Thank you, Chair. In the interest of brevity, I will simply set out a few specific text proposals I have negotiated with my lawyer. We will send the full intervention to the Secretary to be uploaded. Turning very briefly to the norms chapter, in paragraph 22, we think that the reaffirmation here should more clearly reference the 11 voluntary, non-binding norms of responsible state behavior which have been elaborated and endorsed by consensus. We would also support the additional text proposed by the Netherlands reflecting the role and the importance of the norms. We support the proposal from Bangladesh on paragraph 22c regarding the crucial role of the private sector. Regarding paragraphs 22d and 25 on terminology, we hope to find a way forward that reflects our discussions appropriately and does not pre-empt or assume a particular outcome, nor set up an impractical tangent to distract our work. Our proposal is therefore to merge paragraphs 22d and 25, and then, as has also been suggested by several other delegations, to move the combined and rephrased paragraph from the norms chapter to the CBMs chapter, as in essence this proposal could better be formulated as a transparency measure. Specifically, we would move the paragraph to come under paragraph 35d as a new 35d BIS. We suggest that this new paragraph 35d BIS would read: “States discussed a proposal to share national approaches to technical terms that could assist states in building trust and predictability and reduce the possibility of misinterpretation and escalation. It was proposed that this issue could be further discussed within the OEWG.” On paragraphs 22e and 26, we would like to be clear that the proposals for checklists and guidance are related to norms implementation. We support the proposal from Fiji to include in paragraph 24 a reference to assisting countries to identify their own critical infrastructure, as we agree that identification is the first step towards protection. We also align with the points raised by Israel and New Zealand on the difficulty of including references to non-consensus ideas, such as that of new legally binding instruments. Turning to the international law chapter, Australia aligns with the statement of Uruguay, reflecting the views of the co-authors of the working paper on areas of convergence in international law, and we underscore that the obligations in that chapter are not voluntary. They are binding obligations for which states can be held accountable, including under the law of state responsibility. A few additional points in addition to those set out in Uruguay’s statement: On paragraph 28, we would replace the phrase “for the first time” with “markedly,” as we’ve been talking about international law for a long time now. We would also support the additional text proposed by the Netherlands drawn from the 2021 GGE report, which anchors our discussions upon the acquis. We support the proposal from Brazil to make sure that the chapeau of paragraph 29 reaffirms the application of the UN Charter in its entirety, and that the focus of particular articles in this section should not imply otherwise. We also agree with the other arguments on this point put forward by Singapore. We concur with the delegates from China, Brazil, Netherlands, New Mexico, and several others on paragraph 30b, and we find the phrase “international legal bodies” to be ambiguous and would support the proposed change to replace it with “experts.” In paragraph 32, we would not support the reference to the UN Secretariat compiling national views, noting that this is a duplication of existing efforts, particularly those undertaken by UNIDIR. Finally, in line with Australia’s intervention yesterday, we again emphasize the importance of consistency across our recommendations, especially in reference to inviting expert briefings and convening intersessional meetings. As with the textual amendments proposed yesterday, we shall provide these in writing to the Chair for uploading in the interests of transparency. Thank you.
Ambassador Gafoor
Thank you, Australia. Nicaragua to be followed by Vietnam.
Nicaragua
Thank you very much, Mr. Chairman. In our opinion, we should fulfill the mandate of this Working Group, where we are supposed to develop new norms, rules, and principles for the responsible behavior of states in cyberspace. Alas, in this new draft report, this priority is not reflected, as the basis is only the implementation of voluntary rather than binding rules, including other norms which have not been agreed upon under the auspices of the UN, for example, as in PAGOF 22. We see a clear trend to not commit ourselves to a legally binding instrument, just trusting that there will be purely voluntary implementation. This is to the detriment of the aims of this group when it comes to the peaceful and responsible use of ICTs to the benefit of our peoples and in order to avoid possible conflict in their use, looking at political borders and other malicious actions. Nicaragua, together with other countries, states once again that it’s important to have an exhaustive universal list of rules, norms, and principles on responsible behavior, and these should be legally binding. Therefore, it is important to take real steps in order to draw up an international legal regime to cover information, and this could be in the draft report, particularly in PAGOF 22E, F23, 26, and 25, as well as the new 22B. In PAGOF 25, we could identify which of the voluntary rules could be binding under a future international treaty. When it comes to the implementation of international law, we agree with those states which do not believe that there should be an automatic share out of these rules. When it comes to ICTs, there are existing norms here, so therefore we need to look at developing international law which can take into account the specificities of these technologies. The most important thing here is a universal legal structure for cyberspace, for information, based on a legally binding instrument. The draft report from the group could provide a basis for future negotiations on this section. It also requires serious work to ensure balanced interests of all states. In PAGOF 30, we would like to have a subparagraph added on the proposal for there to be a UN convention on information and international security, as well as other similar proposals on international law, as in PAGOF 31. We would also propose merging PAGOF 31 and 33 on this, and to continue debating the applicability of international law. Thank you very much.
Ambassador Gafoor
Thank you, Nicaragua. Vietnam, to be followed by Ireland.
Vietnam
Mr. Chair, thank you for giving us the floor again to speak on this section C and D on rules, norms, principles, as well as international law. Regarding paragraph 22, this delegation supports the Iranian suggestion to replace the word “proliferation” with “developments” in the second line. We also support a proposal which analyzes the need to develop a more detailed discussion on responsible state behaviors in developing new technologies by churches, as well as a proposal from France about practical guidance that would help facilitate the implementation of due diligence responsibility. This delegation expects that those proposals are acknowledged in this report. Regarding a possible glossary of ICT terms, this delegation is of the view that this proposal is worth considering in detail in the coming session of this working group. Indeed, when reviewing a number of position papers submitted to this group, such as the French and German papers, we have come across a list of terms which were very helpful in understanding their approaches in the application of norms, rules, and principles in cyberspace. Regarding the next steps in paragraph 27, we agree with the German suggestion to rewrite the second sentence as “the implementation of existing norms and elaboration of additional norms.” In our view, the implementation of existing norms, rules, and principles should also link to the issue of emerging information technologies. Mr. Chair, turning to section D on international law, we suggest that paragraph 28 should contain the reaffirmation of states that international law helps to prevent and reduce interstate conflicts, govern state behaviors, and maintain international peace and security. Moreover, the draft report should reflect the necessity to develop a common understanding of how international laws apply to cyberspace to reduce misperception and miscalculation and to identify the consequences of the violation of international law applicable to cyberspace. We noted this morning that several delegations expressed a view that gaps did not exist in international law applicable to cyberspace. However, if we look at all the position papers of a variety of countries from both developed and developing countries submitted to this group, we may find that states have different definitions of even the fundamental thing like cyberspace, such as whether it is wholly a global commons as a common heritage of mankind, like outer space or high seas, or even when referring to national jurisdiction or national cyberspace. States do not agree on whether their jurisdiction extends only to the ICT infrastructure located in their territory, or also to the persons living in their territories, or even the data generated by the users of the ICT networks in their territories. And when it comes to national jurisdiction, again, the states do not agree on how many layers there are in cyberspace, some mentioned like physical, logical, application, or social layers. Not to mention that the fundamental terms like domain reserves are even not understood in the same way. Mr. Chair, we take the view that paragraph 29 should elaborate further the focused discussion on how international law applies to the use of ICTs. For example, regarding the principle of sovereignty and sovereign equality, many states emphasize that, first, a breach of sovereignty in cyberspace might amount to an internationally wrongful act and may also give rise to state responsibilities if attributable to a state. Second, state sovereignty extends to the protection of critical infrastructures on a state’s territory against unauthorized intrusion, physical damages, or loss of functionality through cyber operations. Third, states also have the responsibility not to breach the sovereignty of other states and to make reasonable efforts to ensure that their territories are not used to adversely affect the rights of other states. Mr. Chair, confidence-building and capacity-building will benefit the implementation of voluntary norms of responsible states’ behaviors and international law applicable to cyberspace. We underline the need to build capacity to effectively implement and realize these norms and international law obligations, taking into account the consideration of national circumstances in the ICT landscape. It is a matter of fact that many countries, including Vietnam, are working on the process of improving their own national legislation on the use of ICTs. Therefore, promoting capacity-building efforts in improving national legislation will help shape the stance of – help shape the position of countries toward a common understanding and standard of regulating the use of ICT. In this regard, we suggest the retention of the phrase “and national legislation and policy” in paragraph 34 of section D. I thank you, Mr. Chair, for your kind attention.
Ambassador Gafoor
Thank you, Vietnam. Ireland, to be followed by the Syrian Arab Republic.
Ireland
Chair, Ireland aligned itself with the statement delivered on behalf of the European Union earlier this morning. In my national capacity, I would like to make the following points. Chair, the OEWG’s work in international law is important. It is an area to which Ireland is committed to contributing as best we can. To this end, Ireland published its national position paper on the application of international law in cyberspace earlier this month. This has been made available on the OEWG document portal. On the terms of the OEWG’s work, I would like to acknowledge the level of engagement in the discussions of international law over the past year, as well as the value of these discussions and the progress made. From our experience in putting together our own national position paper, we found that the exchanges in this group, as well as the publication of other states’ position papers, to be invaluable in helping us to develop our own knowledge and our own thinking in this regard. Indeed, the process itself, and of itself, is a valuable form of capacity building for all states. This is clear from the increasingly specific, detailed, and sophisticated contributions, with more areas of shared understanding evident. For these reasons, we welcome the proposals for additional language at the end of paragraph 28. Ireland welcomes the recommendation at paragraph 31, inviting states to continue to share their national views, as well as relevant state practice on how international law applies in the use of ICTs. It would be appropriate to complement this with language elsewhere in the text, perhaps in paragraph 28, noting that a significant number of national statements have been made in national position papers published, thereby advancing the dialogue on a range of issues. We agree with the inclusion of language by the Netherlands in the same paragraph. We strongly support the proposal in paragraph 32 for a dedicated international meeting on how international law applies in the use of ICTs. We also support the proposal for expert briefings, although like other states here, we suggest that these need not necessarily be limited to briefings by representatives of international legal bodies. We support the recommendation at paragraph 33, calling for support for capacity building initiatives. While there remain considerable unmet capacity building needs, we do, however, feel it is important to acknowledge the good work that has been done and has been undertaken, including at cross-regional level in the form of workshops, training courses, and other activities. We feel this could best be included in paragraph 30c and suggest adding language to read: States acknowledge the ongoing capacity building efforts in respect of international law and underscore the urgent need to continue these efforts, including with the aim of ensuring that all states are able to participate on equal footing in the development of common understandings on how international law applies in the use of ICTs. Finally, Ireland supports German language on the inclusion of international human rights obligations in part 29 and supports the statement made by Uruguay and other states this morning. Thank you very much.
Ambassador Gafoor
Thank you, Ireland. Syrian Arab Republic, to be followed by Colombia.
Syria
Thank you, Mr. Chairman. With regards to responsible behavior norms, the draft report excessively focuses on responsible behavior norms and how they are implemented as a foundation for the work of the Open-Ended Working Group, and only in a minor way does it refer to the development of new norms, despite this being one of the components of the group’s mandate. This allows for providing a strong foundation for a mandatory nature and also contributes to filling the gaps left by the inadequate responsible behavior norms to deal with all the natures of the security challenges proposed by the use of ICT, considering the voluntary nature of these norms and the fact that their implementation is based on the interests of the states and their national priorities. In addition to this, the excessive focus on responsible behavior norms does not just reflect the discussions that took place as part of the Open-Ended Working Group and harms the needed balance in dealing with the components of the mandate of the Open-Ended Working Group. Therefore, my delegation supports the proposals from Cuba, Iran, and the Russian Federation regarding strengthening the language regarding developing new norms and developing other binding norms, including the possibility to work on an independent legal instrument to ensure ICT security. And in this delegation, we call on discussing the updated concept of the United Nations Convention on International Information Security as presented by the Russian Federation and co-sponsored by a number of states, including Syria. With regards to international law, the draft report emphasizes the importance of discussing how international law applies to ICT uses and does not give the necessary attention to the possibility of working on an independent legal instrument, despite many countries having emphasized the importance of this to fill the gaps in the implementation of international law given the unique nature of cyberspace and how it is different from the physical world. My delegation sees that the focus on international law as a topic for discussion in an inter-sessional meeting could harm the needed balance in dealing with the items suggested as part of the Open-Ended Working Group’s agenda, and we emphasize the need to deal with all initiatives in this regard and with all the components of the group’s mandate in an equal and balanced way to ensure achieving integration and inclusiveness in our work and to deal with all aspects related to ensuring ICT security in the required manner. Thank you.
Ambassador Gafoor
Thank you, Syrian Arab Republic. Colombia, to be followed by France.
Colombia
Mr. Chairman, we would refer to the specific proposals on action on rules, norms, and principles in paragraph 22. Like other delegations, we believe it’s important to maintain the language in paragraph 22A indicating that attacks on critical infrastructure do constitute a high risk for people and could lead to conflict. When it comes to the integrity, stability, and security of supply chains and preventing the harmful use of hidden functions, we would emphasize the role and responsibility of the private sector and civil society in improving ICT security. Regarding the proposal for a possible glossary of terms and terminology, the technical nature on ICTs in paragraph 22D, we do understand that, as has been said, not all delegations can be involved at present. As we said in the informal meeting on the 27th of June, we suggest that we make progress on an initial attempt to draw up a glossary coming from the academic sector, which could make very important contributions for states here. We also believe it’s appropriate to learn from the experience of regional organizations such as the OSCE in relation to confidence-building measure 9 on terminology. This point could be dealt with in the proposed intersessional meeting in paragraph 27. We support the recommendations in paragraphs 23 to 27, emphasizing the need to increase state assistance for the implementation of rules, norms, and principles for responsible behavior in cyberspace. This would also contribute to moving to a safe digital transition. In paragraph 28, we agree with Brazil’s proposal that the UN Charter applies as a whole. We also support Fiji’s support in paragraph 24 for critical infrastructure. Regarding section D on international law, we firmly support Uruguay’s words on behalf of a group of countries, Colombia amongst them. We recognize the progress made in this working group in order to achieve a common understanding and implementation of international law. We work on the inclusion of paragraph 29 and its sub-paragraphs, which recognize the established principle of responsible behavior of states in the use and security of ICTs, as well as the elements of our discussions, including paragraph 30. On details, we believe that it’s necessary that paragraph 29 should include a reference to the importance of respect for human rights and fundamental freedoms as indicated by Germany, and we support the language proposed here. So we support the recommendations on next steps in paragraphs 31 to 34, again highlighting the importance of endeavors to build capacity. We believe it appropriate for there to be an intersessional meeting, and we believe that this should address issues such as the inclusion of international humanitarian law, as well as the implementation of international law and human rights. Thank you.
Ambassador Gafoor
Thank you, Colombia. France, to be followed by Czechia.
France
Thank you very much, Sir. May I first of all say that I fully endorse the words of the European Union. Regarding Section C, my delegation in its national capacity would like to make the following comments. Looking at Paragraph 22D, my delegation is not favorable to the reference to the proposal for a glossary of technical terms. This proposal was not included in the 2022 POR, and it doesn’t seem to us that there has been much support for it in discussions this year. My delegation also supports the recommendations in Paragraphs 26 and 27 regarding continuing discussions on the development of guidance for the implementation of norms, the drawing up of possible new standards, and working out for other ones. In Paragraph 29, we support the general proposal for there to be a reference to international law and fundamental freedoms. Coming to Section D on international law, my delegation can support it as it stands. We particularly welcome the reaffirmation of the applicability of international law when it comes to the use of ICTs, as well as the articles of the Charter which were discussed in the last session. On Paragraph 33, my delegation supports its new draft. We certainly support pursuing discussions in an intersessional meeting, a dedicated intersessional meeting, on the way in which international law applies to the use of ICTs. We can also support the idea that during this meeting, experts should be convened, coming from relevant bodies to give presentations to provide information to the group in their discussions. Lastly, given the absence in our view of the need for early negotiations on a treaty to be started, we support the view voiced particularly by Austria, New Zealand, South Korea, and many other delegations. Thank you.
Ambassador Gafoor
Thank you, France. Czechia, to be followed by Slovakia.
Czechia
Thank you, Mr. Chair. The Czech Republic aligns itself with the EU statement delivered earlier and wishes to emphasize a couple of points in its national capacity. As for Part C, the Czech Republic believes that the 11 norms of responsible state behavior that were unanimously endorsed by the UN General Assembly promote predictability and reduce risks of misperception between states. Therefore, we have been, during the Open-Ended Working Group session, repeatedly highlighting that our top priority is the implementation of those norms. We have consistently emphasized the importance of norms for the protection of critical infrastructure and supply chain. More specifically, we should progress in the implementation of norms F, G, and H of the 2015 GGE report concerning the protection of critical infrastructure and norm I of the same report related to the integrity of the supply chain. As stated in APR, the first step could be to increase sharing our views and lessons learned. In this regard, we appreciate a proposal to convene focused discussions as well as elaborate additional guidance on the implementation of norms in the current APR. I would also like to highlight the importance of cyber capacity building in the context of norms of responsible state behavior. The Czech Republic is aware that compliance with the 11 norms of responsible state behavior requires an adequate level of cybersecurity expertise. We therefore appreciate that the APR mentioned the development of a norms implementation checklist to assist states, in particular developing countries and small states, in their effort to implement norms of responsible state behavior in the use of ICT. At the same time, we agree that we should continuously evaluate our cyber capacity building efforts, which includes identifying challenges associated with the implementation of norms and principles of responsible state behavior to better inform capacity building efforts as stated in PARA 22E 3Bs. Following my earlier intervention, I would like to highlight the importance the Czech Republic places on the impact of human rights online as well as offline. We are of the opinion that we have more elaborated norm E of the 2015 GGE report, which stipulates that states, in ensuring the secure use of ICT, should respect Human Rights Council resolutions and promote the protection and enjoyment of human rights. We also support a proposal of Bangladesh concerning the private sector, Fiji concerning Article 24, and the Netherlands’ proposal concerning Article 27. As for international law, the Czech Republic welcomes the reflection of the year’s fruitful discussions that took place during both regular and intersessional meetings and supports the addition under paragraph 33 that recommends convening a dedicated intersessional meeting on how international law applies in the use of ICT, including expert briefings. In order to meet your request, Chair, and to save time, I will limit myself to supporting the proposals that have already been presented by our esteemed colleagues and which reflect our remarks on the current version of the international law section. The Czech Republic supports the context of our proposal by Germany concerning the respect of human rights and fundamental freedoms. We also support the joint statement presented by Uruguay, in particular its proposal to include a reference to Article 33 of the UN Charter in its entirety. We also support the textual proposal made by the Netherlands in part 28 as well as the U.S. proposal on textual amendments in part 30b and c on capacity building initiatives and replacing international legal bodies with international legal experts. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you. Czechia, Slovakia, you have the floor, please.
Slovakia
Thank you, Mr. Chair. Slovakia aligns itself with the statement delivered by the European Union and wishes to emphasize a couple of points in its national capacity, primarily focusing on Section C. The 11 non-legally binding norms serve as a baseline for defining responsible behavior while fostering greater stability and predictability in cyberspace. While we may think of these norms as merely normative guidelines to support peaceful cyberspace, their role goes beyond this. These norms are bound up with the evolution of the normative environment, which influences the choices that individual states make in regard to mutual action. We therefore support the Dutch text proposal, which is previously agreed language in paragraph 22. We have arrived at a critical junction where we need to focus on the implementation part of the normative framework. With this aim, we could make use of the UNIDIR survey of national implementation and the norms implementation checklist. As already underlined today, although it depends on states to determine the infrastructure that could be deemed critical, previous OEWG and GGE reports and their mention of several critical infrastructure sectors could serve as a starting point for our discussions. We would therefore especially like to point out the GGE reference from 2021 to the fundamental protection of critical infrastructure. It posits that such infrastructure forms a backbone of society’s vital functions, services, and activities and, in cases of their disruption, could inflict significant damage or harm. We therefore welcome the proposal to hold more focused discussions on this, while of course taking into account that the evolving threat landscape will unavoidably influence the way forward on this. We take note of the proposal for a glossary of commonly used technical ICT terms in paragraph 22d. However, we agree with many other countries that this proposal seems rather contradictory, as the commonality in this is largely generalized and thus at the expense of every state’s own approach to classifying these terms. We would therefore rather agree with the proposal to, on a voluntary basis, share national definitions of used technical ICT terms drawn from previous consensus reports. The incredible power that allows us all to instantly connect comes as a surprise. More connectivity also means more vulnerabilities, more attacks, and more sophisticated strategies. Such increased interconnectivity between the digital and real world puts pressure on the public and private infrastructure sectors to adopt new safety routines. This brings me to my final point, Mr. Chair. We welcome the noteworthy reference to the invaluable role private sector and more broadly relevant stakeholders play in ensuring the integrity of supply chain and in preventing the proliferation of malicious ICT tools and techniques in paragraph 22c. That said, working with the broadest possible range of stakeholder experts could also feed into an enhanced implementation of the norms. There are many countries here today who have experience with working closely with the private and non-governmental sector, for instance, on the protection of vital services, and could attest to how including relevant stakeholders could foster the resonance of agreed norms. We would therefore like to express our hope that future sessions shall also build on this further.
Ambassador Gafoor
Thank you very much, Slovakia. It’s one o’clock, we’ll have to stop, and I’d like to thank the interpreters for giving me a few additional minutes. But before you adjourn, I want to say that the three-minute limit, obviously, has encouraged all of you to read very fast. And this has put a strain on the interpreters. They have been pleading with me for the last two days to ask you to provide them with the text of your remarks, and also to ask you to read slowly. Now, reading fast is not making it more succinct. So I’d like to plead with you that even though you may have longer interventions prepared and approved by your lawyers, I would suggest that this afternoon you come prepared with a sense of the key suggestions and comments you would like to highlight. And then give us the secretariat, and to be shared on the website, the amendments in their entirety as you have them prepared and approved by your lawyers in capital. So this will help us really to get to the rest of the speakers. And I really plead with you. It’s not that I am not patient. I am patient and listening to all, but I think we are operating under a time constraint. Secondly, this afternoon, we will also begin consideration of the next two sections, which is section E, on confidence-building measures, as well as section F on capacity building. So when we resume this afternoon, I am also inviting comments on section E and F because we have to begin a discussion on the next two sections, confidence-building measures and capacity building sections. We have about 10 speakers left from this morning, and I will give them the floor in the order that they have appeared. And I should also say that this afternoon, when we look at the section on CBMs, that would include the paper on the POC directory that is part of the CBM section. So this afternoon, the discussions will focus on section E and F, and we’ll start with the remaining 10 speakers, starting with Switzerland as the first speaker for the afternoon session to be followed by Croatia. And then we go through the rest of the speakers, and then we will take more indications of others who wish to speak as well. I wish you a pleasant afternoon and see you at 3 p.m. Thank you. The meeting is adjourned.
Leave a Reply