Session 5-4 Transcript
(OEWG 2021-25)

Home » Resources » UN Open-ended Working Group (OEWG) transcripts » Session 5-4 Transcript(OEWG 2021-25)
Ambassador Gafoor

Good afternoon to everyone. The fourth meeting of the fifth substantive session of the Open-Ended Working Group on security of and in the use of ICT is now called to order. Dear friends, distinguished delegates, we’ll continue with the discussion under agenda item five, which is the Rev 1 on the draft annual progress report. This morning we began with a discussion on sections C and D of the draft report relating to rules, norms, and principles, as well as to international law. As I mentioned earlier this morning, we have about 10 speakers left, but it is also my intention to begin at this point a discussion on sections E and F of the draft annual progress report, section E relating to confidence-building measures and section F relating to capacity building. And as I said also this morning, it is my hope that delegations will look at their prepared interventions and do their best to present a succinct summary by highlighting the most important points from the point of view of your delegation. And if you would like to submit your remarks or suggestions, please feel free to do so. You can send it to the secretariat, and we’ll also be happy to put it on the website if that is what you wish. It is important, friends, that we proceed this afternoon by giving everyone a chance to comment on the draft. And as I also said this morning, I have shifted the stakeholder dialogue to Wednesday afternoon so that we can complete the first reading of the draft annual progress report by the end of tomorrow morning. That will then give me the time to start preparing a Rev 2. And it is important also that I have some time to do that because I cannot possibly prepare a second revision if I do not have adequate time as well. So we are operating under very tight time conditions because this is the July session, and the July session is such that we have to adopt an annual progress report. I think it’s doable. I think a consensus report is within grasp, and I think it’s possible that we get there, provided there is a spirit and commitment to work together and provided there is sufficient demonstration of flexibility on all sides. So let’s continue with the discussions and the delegations which are taking the floor, starting with Switzerland. I would also advise them to comment on sections E and F. And I’m afraid that we will have to continue to operate on the basis of a recommended three-minute time limit for all delegations, which, shall we say, is now part of the cumulative and evolving framework for the July session. So please do your best to stick within the three minutes, and if you would like to share your full remarks with me, please feel free to do so. If you would like to share your full remarks with me, please feel free to do so. So on that basis, I also open the floor to all other delegations who wish to take the floor on sections E and F. Please press your buttons now so I have a sense of the length of the speaker’s list for this afternoon. And we’ll go through them one by one, and I will listen carefully to them, and I also would suggest that each one of you listen to each other, because it’s not about persuading me. It’s also about you persuading your colleagues in the room in order to reach consensus. So without further ado, let’s start with the first speaker for this afternoon, Switzerland, to be followed by Croatia.

Switzerland

Thank you, Mr. Chair. This statement will be on sections C and D, and we might take the floor again for a short statement on the sections E and F, or provide you with the written comments depending on the schedule. Starting with the norms section, in paragraph 22a, we do not support the deletion of the third sentence on the elevated risk malicious cyber activities against critical infrastructure may have for the population. Like the US or the Republic of Korea, we propose to reinsert it. On the proposal for a glossary of terms, as other delegations, we are critical of this proposal. We think the exchange of national definitions can contribute to transparency and better mutual understanding, but we see this more as a confidence-building measure. We therefore suggest deleting the reference for a glossary in the norms section and could support the proposal made by Australia for a new paragraph 35 piece. But we would like to point out that establishing and maintaining a compilation of such terminology is very time-consuming and ties up resources that could be needed elsewhere. In paragraph 22f and paragraph 27, we suggest we replace elaboration with implementation, and we support the chairman’s proposal to delete b in paragraph 27 on the possible development of new norms. Switzerland is of the opinion that at the moment we should focus on better understanding, promoting, and implementing existing norms before developing new ones, especially in times when existing norms are being violated on a large scale. We therefore suggest redrafting paragraph 23. The sentence should read as follows: States continue engaging in focused discussions at the open-ended working group with the aim of developing common understandings and continue as before. The second sentence then should state that states also exchange views on the proposals from the non-exhaustive list and continue as before. In paragraph 26, we support the proposal made by Austria to be more specific on the sources of the norms. On the international law section, as expressed in previous sessions of this open-ended working group, it is Switzerland’s position that we currently do not see the need for a new legally binding instrument. This would be premature. At this point, as proposed in our concept paper last December together with Canada, we should continue our work on developing common understandings on the application of existing international law in cyberspace. Regarding concrete proposals, paragraph 28, we, as others, think that it should be mentioned here that the UN Charter applies in its entirety to cyberspace. Brazil, the Republic of Korea, or Fiji have made the same comment. According to that, we also support the call for a broader reference to Article 33 and Chapter 6 of the UN Charter in paragraph 29b. Coming back to paragraph 28, we support the proposal by the Netherlands to add in paragraph 28 that our work builds on previous work at the GGEs and open-ended working groups. As many states underscore the need to implement the existing framework and further develop common understandings on how international law applies in the use of ICTs before being in a position to conclude whether or not there are gaps that would require new rules, we would like to have that reflected in the annual progress report. This could be added at the end of paragraph 28. The addition would read as follows: Many states shared their views on the applicability of international law to state use of ICTs in the December, March, and May 23 sessions of the open-ended working group, demonstrating the value of regular continuing discussions on the topic. The reference in paragraph 28b-a-2 to international humanitarian law is crucial for Switzerland. A very large number of states made reference to IHL in their statements during the formal sessions and informal meetings of the open-ended working group that supported further focused discussion on how IHL applies in cyberspace. We therefore see it as a priority for this group to start such focused discussions in the upcoming sessions and informal meetings of the open-ended group. Paragraph 30. Switzerland supports the sharing and briefing of opinions of legal experts and would therefore not want to limit those to legal bodies, as also China, Mexico, and others have proposed. This change should also be reflected in the recommended next steps in paragraph 33. In paragraph 30b, we prefer retaining the reference to state practice in the text. As many cross-regional efforts and initiatives for continued capacity building have been undertaken, this includes various trainings such as the CLI training that was hosted by the African Union last week that had AU delegates and Women in Cyber Fellows present. It should be mentioned as a concrete success of the ongoing capacity building in paragraph 30c. On the recommended next steps, as the recommendations in the chapter of norms, paragraph 23, we would like to add the reference for focused discussions on how international law applies in the use of ICT for the 6th, 7th, and 8th sessions, as well as informal meetings of the open-ended working group. Our proposed text for paragraph 31 reads as follows in the beginning: At the 6th, 7th, and 8th sessions, as well as intersessional meetings of the open-ended working group, states continue to engage in focused discussion on how international law applies in the use of ICTs, and so on. Switzerland would like to add in recommendation paragraph 33 that expert briefings on how international law applies in the use of ICTs include state responsibility and due diligence, respect for human rights and fundamental freedoms, and in particular, international human rights law, humanitarian law, sorry. Finally, we support Germany’s proposal to add the reference to human rights to this section and welcome the statement by Uruguay on behalf of a group of states. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you, Switzerland. Croatia, followed by Kazakhstan.

Croatia

Thank you, Chair. Croatia fully aligns itself with the intervention of the European Union and, in national capacity, would like to deliver some brief points. We join Costa Rica in gratitude for the reference to the private sector and civil society in PARA 22C. Furthermore, we would like to support requests from several member states to reinsert zero draft text in PARA 22A, and we can also support the German proposal in PARA 27 regarding the implementation of existing norms. Additionally, we would like to reaffirm our support for the national survey of implementation since it can contribute to a better understanding of how existing rules, norms, and principles are applied at different national levels and where states may need help to improve their capacities and performances. Chair, when it comes to international law, we would like to emphasize that cyberspace is not a galaxy far, far away, nor the wild, wild west. It is not a lawless domain, as the Secretary-General in the new Agenda for Peace also confirmed. States have several times affirmed that the Charter of the United Nations in its entirety and international law apply to cyberspace, and therefore we should continue discussions on modalities of application of existing rules and commitments, including also through exchanges at political and expert levels. In this regard, we support Fiji, Brazil, and other states and would also suggest adding “in its entirety” in PARA 28 when the Charter is mentioned, and additionally, we can support the Netherlands’ proposal in the same PARA. Furthermore, we welcome PARA 30C and PARA 33 with the belief that such exchanges could boost capacities and encourage more states to publish their national positions on the application of international law in cyberspace. We can also support PARA 29 and the mentioning of the growing number of statements on international law and the importance of such statements for fostering common understanding. Here we would like to support the German proposal and the mentioning of human rights. In PARA 33, we share views from Mexico and other states and would like to add a reference to the invaluable participation of relevant legal experts in our discussions. We can also support the working paper done by Australia, Colombia, El Salvador, Estonia, and Uruguay. As a small country, we practice efficiency whenever and wherever we can, so allow me to deliver the national position on some key points in the remaining chapters in order to save some time for other speakers. We have already mentioned yesterday how good of an example the Program of Action (POA) concept is and that it could be a role model for future initiatives. Integration of valuable exchanges with regional organizations on their lessons learned, mapping of existing directories, and several fruitful exchanges with member states have brought us to the tangible and sustained results that we can welcome. On capacity building, we would like to stress just two points. Firstly, capacity building should also contribute to the fulfillment of SDGs as much as possible. And second, we need to avoid overlapping and duplication of efforts and ensure that no one is left behind. We would like to thank Germany and Japan, who organized yesterday an excellent exchange with the World Bank on financing cyber capacity building. International and regional financial institutions should be encouraged to dedicate more resources for financing cyber projects and the development of secure ICT infrastructure. And last but not least, the regular institutional dialogue resolution on POA received broad support and 157 votes last year, more than two resolutions on the establishment of OEWG, in fact. Such a clear demonstration of will by the convincing majority of member states surely deserves, if not constructive cooperation by those who voted differently, at least their respect and productive conduct. And as the Chair rightfully mentioned yesterday, this is multilateralism at the UN, and we need to defend it. To defend it, of course. And one final editorial remark, there is a repetition of the same text in PARA 28bisbi and PARA 49cbis, so we suggest deleting the last one and keeping the same reference as it was in the APR last year. Thank you, Chair. And of course, we support multilateralism.

Ambassador Gafoor

Thank you very much, Croatia, for commenting on the rest of the parts of the text. We’ll go to Kazakhstan, to be followed by El Salvador.

Kazakhstan

Thank you for giving the floor. Regarding Section C, Kazakhstan generally supports the rules, norms, and the principles of responsible state behavior. On Paragraph 22C, we confirm that the private sector plays an important role in ensuring the safe use of ICT. In this regard, Kazakhstan cooperates with the private sector on an ongoing basis. Kazakhstan, with the private sector, as well as with the involvement of international organizations such as ITU-UN and the OSCE, annually holds practical training events and conferences dedicated to solving modern problems in the field of cybersecurity. Such events make it possible to use the experience of the private sector to ensure the protection of the country’s cybersecurity. Considering that this paragraph is aimed at the work of the private sector and also taking into account the importance of interaction between private companies and the state, we propose to include in this paragraph the importance of using public-private partnerships in the field of cybersecurity. In addition, according to Paragraph 22D, Kazakhstan fully supports the compilation of a glossary of technical terms and terminology in the field of ICT to develop a common understanding. We believe that the creation of a single glossary will improve the effectiveness of normative work in these international documents in the field of cybersecurity. Regarding Paragraph 27, we propose to delete subparagraphs A and B and suggest the following revision to Paragraph 27: The OEWG chair is requested to convene informal intersessional meetings to discuss the development of a common understanding of rules, norms, and principles, including responsible state behavior in the use of ICT. This would reduce discussions during the next official sessions. As for Sections E and F, by the end of the research, the reference information documents on the global directory of the contact points in general, we have no objections. For our part, we have identified the technical contact of the National Computer Incident Response Service, KZ CERT, which can already be contacted by email today, team@cert.gov.kz. KZ CERT received more than 1,000 incident reports from 48 states in 2023. In addition, Kazakhstan is actively working on capacity building within the framework of the national cybersecurity concept updated this year. In conclusion, we would like to note that our delegation generally supports the session on capacity building as well as the lead of confidence-building measures. Thank you.

Ambassador Gafoor

Thank you very much, Kazakhstan. El Salvador, to be followed by Belgium.

El Salvador

Thank you, Chair. We will present consolidated comments on the rest of the report. On international law, we support the statement made by Uruguay on behalf of the group of countries, and we would add the following in our national capacity. The mentions on sharing voluntary information at the national level in order to deepen the understanding of terminology and national opinions on the application of international law and humanitarian international law in cyberspace are recognized not only as a confidence-building measure but also as an action that would help to bring together visions, sometimes opposing visions, on cyberspace and build our own understanding, our own national understanding based on the experience of countries with similar characteristics. We support the four recommendations in the report on this section. With respect to deepening how international law would be applied in ICTs, we do acknowledge the importance of continuing to make progress in the discussion within the group and to use the expert sessions as well. However, we acknowledge the challenges associated with those informal meetings between sessions on such a diversity of items, considering the progression of the working group but also aware of the number of additional meetings proposed in the report. Now, on capacity building, we do endorse the statement which will be delivered by the delegation of Argentina on behalf of a group of countries of Latin America and the Caribbean, and we would add the following. A cross-cutting element in the work of this group is capacity building. Recognizing the differentiated levels of national capacity in the ICT environment, for that reason, we support the different dimensions throughout the report on the importance of continuing to enhance capacity building in the short and long term. We recognize as well the importance of coordinating existing efforts. The incorporation of a gender perspective within the broad framework of capacity building is a central element that goes towards a broader digital dimension. We highlight the importance of creating concrete action in order to reduce the digital gap, which is a priority for El Salvador. And to conclude, Chair, on the institutional dialogue, we support the way in which it’s framed in the future establishment of the future program of work and its relationship with this working group. El Salvador is one of the promoters of this initiative, and we will continue to make a constructive contribution to this through our discussion on the goals obtained as well as the structure of the program of work, reflecting everyone’s interests and priorities. Thank you.

Ambassador Gafoor

Thank you very much, El Salvador. Belgium to be followed by the UK. Belgium, please.

Belgium

Mr. Chair, my country aligns with the statement delivered by the EU and wishes to stress the following elements in its national capacity. On the norms section, on Para 22A, we support the proposal made by the U.S. and others to keep the language on elevated risk of harm to the population. On Para 22D, we have reservations regarding the possible glossary of technical ICT terms and support the proposal made by Australia. On Para 22F and Para 27, we believe that the implementation of existing norms is the priority. We support the edits proposed by Germany. On the international law section D, we share the views expressed by a great number of delegations this year on the application of the UN Charter in its entirety to cyberspace, which should be reflected in Para 29. We also support the language proposed by Australia, Colombia, El Salvador, Estonia, and Uruguay in their working paper on the applicability of international law. Further, Mr. Chair, we would appreciate the inclusion in this section of clearer language on human rights as a framework that also applies to the use of ICTs. We support the proposal made by Germany on Para 29 in this respect. Another element which remains important for our discussion is the principle of due diligence. We encourage your group to pursue its work to gain greater clarity in its understanding of this important concept too. We still have concerns on the reference to legally binding obligations section, a treaty process as proposed by the Russian Federation. It’s premature and not consensual. We would also appreciate it if the group could set itself clear priorities for its work next year, in particular with regards to the application of the UN Charter and IHL. A detailed program of work for the 6th, 7th, and 8th sessions could be useful. Finally, we support the convening of the dedicated intersessional meetings on international law next year and relevant expert briefings but not limited to legal bodies in Para 33. We would appreciate it if this dedicated meeting could focus on a clear set of priorities. I thank you, Mr. Chair.

Ambassador Gafoor

Thank you, Belgium. United Kingdom, followed by Botswana.

United Kingdom

Thank you, Chair. Regarding norms, we endorse the proposals from Malaysia, the Netherlands, and the United States to retain language on the particular relevance of critical infrastructure and the relevant norms in this section. On paragraph 26, we do not see the utility in developing a shared glossary of terms, and we’ve had little discussion on that proposal this year. We believe that states can more usefully continue to share national policies, including through the UNIDIR portal, as well as their statements on international law and threat information. This transparency will increase understanding and will itself demonstrate those terms that are most commonly used by states in describing their use of ICTs. We endorse Germany’s proposed edits to paragraph 28. Meaningful work is taking place by member states and by international organizations to produce guidance on norms implementation, and we believe that this working group should have the time to consider the outcomes of this work. Norms development and norms implementation are not mutually exclusive, but we should allow sufficient time to discuss this guidance, which in turn will allow us to have a focused discussion on any gaps for future development. Turning to the international law section, the United Kingdom wants to first underscore that, contrary to views expressed yesterday, accountability does exist in cyberspace. All UN member states have agreed that international law applies, and this entails existing legally binding obligations, including those in the UN Charter, customary law, and treaty law. It includes the law of state responsibility, which provides an effective means to hold states to account for internationally wrongful acts. Indeed, this group has made significant progress in discussing some of these obligations this year. Japan, Latvia, and others have already described the progress we have made since the last APR, and we welcome the statement from Uruguay this morning on behalf of a cross-regional group of states, which we believe accurately captures the valuable discussions that have taken place this year. We strongly believe in the value of an intersessional on international law, and we support the proposal from the Netherlands and Mexico to broaden the list of relevant briefers in paragraph 33, so this working group can benefit from a breadth of expertise in its future deliberations, including from regional and sub-regional organizations, businesses, NGOs, and academia. On specific edits to the text, much has already been covered. For paragraph 28B on the peaceful settlement of disputes, this should refer not only to articles 2, 3, and 33 of the Charter, but also to Chapter 6 of the Charter, which many states have referred to in their interventions. In this context, we support Brazil’s proposed chapeau language on the applicability of the UN Charter in its entirety. Finally, we take note of the significant increase in international law capacity-building activity over the past year, including the training provided by the African Union for a cross-regional group of states last week. We believe the APR should reflect the progress that has been made in capacity-building this past year, as well as looking forward to ensuring that we can continue to make progress on capacity-building to ensure the equitable participation of all states in those important discussions. In view of time, we’ll follow up with our comments on capacity-building and CBMs in writing. Thank you, Chair.

Ambassador Gafoor

Thank you very much, UK. Botswana, to be followed by the Islamic Republic of Iran.

Botswana

Thank you, Chair. Since it’s Botswana’s first time taking the floor for this session, we wish to express our gratitude for the way you and your team have worked tirelessly to consolidate the wide range of views from the discussions of the past year to produce the REV1 Annual Progress Report, which we are of the opinion is a solid basis for consensus and a generally accurate reflection of the discussions in the past year. We pledge our commitment to support you in building a consensus on the report by the end of the session. On the specific provisions, Chair, we are of the opinion that the text on paragraph 22E, based on section C on rules, norms, and principles of responsible state behavior, is a welcome development, especially for states that face challenges in the implementation of rules, norms, and principles of responsible state behavior in cyberspace. We, however, are of the opinion that it is not enough for states to just identify and study the implementation of the norms, but that it will also be crucial to convey or share their studies with the OEWG or such body that will play a facilitatory role in capacity building. At paragraph 22F, even though the cyber threat landscape is ever-evolving and thereby necessitating the development of additional norms that will address new and emerging issues, we would like to highlight the need to prioritize the implementation of current norms, which has been noted as challenging for some states, and agree with Germany and Austria that the language should be changed from elaborating to implementing under this paragraph. We support South Africa’s view that implementation of the norms may highlight the gaps in the existing normative framework, and our delegation is also of the view that a parallel discussion on existing and additional norms may take a toll on states that already have capacity challenges and may not exactly be ideal. On international law, Botswana agrees with the language proposed under Chapter 28 regarding the reaffirmation of states that international law, in particular the Charter of the United Nations, is applicable and essential to maintain peace, security, and stability and promoting an open, secure, stable, accessible, and peaceful ICT environment. We recognize the need for more dedicated sessions on international law to boost member states’ understanding so as to better inform their deliberations. In this regard, we agree with the Kingdom of the Netherlands that this should not be a one-time session and that more sessions are required to ensure full understanding of international law in this regard. We also align with Malaysia’s proposal to have these meetings in a hybrid format to allow for maximum participation. Thank you, Chair.

Ambassador Gafoor

Thank you, Botswana. Islamic Republic of Iran, followed by India.

Iran

Thank you, Mr. Chairman. Before moving to sections B and F, I would like to deliver the following statement on behalf of a group of countries, including Burundi, Belarus, China, Cuba, DPRK, Nicaragua, Russian Federation, Syria, Venezuela, and my delegation, Iran. Although we, as a group of countries, acknowledge the significance of human rights, we respectfully disagree with the inclusion of specific language on human rights in the draft report. We believe that there are already dedicated platforms which address human rights separately. Incorporating the language on human rights into our work would go beyond the mandate and the scope of the OEWG, potentially diverting our attention from the primary objectives and encroaching on the duty and mandates of others. It is hard to believe that those who disagree with the development of norms, rules, and principles, which is the mandate of the OEWG, now suggest including reference to human rights in this draft. We call on all states to strictly follow the mandate of the OEWG. Thank you, Mr. Chairman. In my national capacity, turning to sections E and F, under Paragraph 35, we would like to propose a subparagraph A piece that reads as follows: A proposal was made for provisional operationalization of the POC directory, proposing that before pressing to establish a global intergovernmental points of contact directory on security in the use of ICTs on a permanent basis, the states need more time for discussions in order to delve deeper into practical aspects of the POC directory. The need for capacity building, especially for developing countries, was also highlighted as an important element which can be achieved to some extent during the provisional period of the POC directory functioning. In subparagraph C, Roman numeral ii of Paragraph 35, after the voluntary information sharing, my delegation would like to add in a politically neutral and non-discriminatory manner. In Paragraph 37, we would like to add on a provisional basis after the contact directory at the end of this paragraph. In Paragraph 38, we would like to add and review after this case to further discuss. And we would like to add provisional before global POC directory. We would also like to add the following sentence at the end of this paragraph: and consider the possibility to replace the provisional POC directory with a permanent one in the final report of the OEWG. In Paragraph 40, Section C, Section F, we would like to add after a holistic, we would like to add an inclusive, and we would like to add entails both coordination of existing capacity building efforts and establishing specific mandates in the context of ICT security. We would like to ask for the deletion of the last part of that sentence in the section, subparagraph A, that starts with as well as the development of a checklist to the end of this paragraph. In subparagraph C, we would like to add the following at the end of this subparagraph: We would like to add as well as identifying gaps in such capacity building programs. In subparagraph E, we would like to ask for the deletion of and the Global Forum on Cyber Expertise, GFCE. And in subparagraph F, in the highlighted part of the end of this subparagraph, after the development of an initial list of, we would like to add the following: Global capacity building measures drawn from the recommendations contained in consensus reports for implementation by states, including through a permanent mechanism for capacity building for ICTs within the UN. And to stop, we would like to ask for the deletion of the rest of this paragraph. In this recommendation section, we also would like to propose subparagraph, paragraph 42B that we already shared with the Secretary. For the sake of time, I’m not going to read this long proposal. In paragraph 43, we would like to add, identify gaps in such efforts almost at the end of this paragraph after capacity building efforts. And finally, in paragraph 44, we would like to ask for the deletion of GFCE. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you, Iran, for your comments. India, to be followed by Greece.

India

Mr. Chair, our delegation would like to make a brief statement on Sections C and D. We propose rephrasing Para 22A in line with the priority highlighted in the General Assembly Resolution 58-199 on the creation of a global culture of cybersecurity and the protection of critical information infrastructure. The modified Para may read as, quote, “States agreed on the creation of a global culture of cybersecurity and protection of CI and CII, as per norms F, G, and H, highlighting that ICT activity, intentionally damaging CI or CII, or otherwise impairing the use and operation of CI to provide services to the public, can have cascading domestic, regional, and global effects. States thus emphasize the need to implement related norms, continue to strengthen measures, and propose exchanges on best practices for CI protection and recovery from ICT incidents.” Our delegation welcomes the language in 22B on ensuring the integrity of the supply chain and preventing the use of harmful hidden functions. Our delegation also welcomes sub-Para 3bis under 22E, which suggests identifying and studying challenges associated with the implementation of the rules, norms, and principles of responsible state behavior to better inform capacity-building efforts. Under international law, our delegation appreciates paragraph 28E regarding convening discussions on specific topics related to international law to identify areas of convergence and consensus. This has been recommended by a good number of member states in the working group. We will be submitting a copy of the statement. Thank you Chair.

Ambassador Gafoor

Thank you, India. Greece to be followed by Sudan please.

Greece

Thank you, Mr. Chair, for giving me the floor. Greece fully aligns with the statements made by the European Union, and allow me, Mr. Chair, to make the following remarks in my national capacity. When it comes to the discussion regarding the implementation of existing norms versus the development of new ones, it is my delegation’s view that these are not in any way mutually exclusive. However, we share the view of other delegations that the implementation of existing norms should be prioritized. We believe it is important to first solidify our existing framework and ensure that all nations reach the same level of norm implementation before considering further expansion of our list of norms. Regarding the view of several delegations on the need for a legally binding instrument beyond the voluntary non-binding norms, we are in full agreement. Such an instrument already exists, as the General Assembly has repeatedly reaffirmed the applicability of international law in cyberspace. In fact, the applicability of international law is also reaffirmed by the mandate of this group. It is therefore essential to continue our discussions on how international law applies in cyberspace, deepening our common understanding and perhaps identifying gaps that require further consideration. Sharing our view of how international law applies in cyberspace is also our obligation, as the mandate of this group explicitly calls for the continuation of this discussion. Finally, we support Germany’s proposal for a reference on human rights. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you. Greece, Sudan, please.

Sudan

Thank you, Mr. President. Sudan highly values your efforts and your patience in undertaking a very noble effort in light of the cyber race currently going on. We now need more refreshed issues in order to face the challenges. We welcome the possibility of having a joint glossary despite the challenges referred to in that regard by a number of delegations. We have heard a number of perspectives on controversial issues in the report, and we need more discussion to reach consensus and understand more information and sharing in terms of what has been agreed upon in terms of cyberspace. We also need to look into existing norms and look into the differences in terms of capacity building needs in terms of different states. We also need to review these norms in a manner that achieves the minimum requirements in terms of ICT. The report should reflect the expertise of different states and best practices and efforts all over the world in terms of increasing capacities and abilities and developing states’ needs for special assistance. We believe that there must be shared measures and multiple conversations on international responsibility and states’ and communities’ responsibilities in addition to those agreed upon by the General Assembly in a way that dispels all confusion and guarantees minimum consensus among them. We also need to achieve synergy between different proposals in order to achieve balance and push forward any further needed norms, as the presidency has suggested. Of course, here this is the best platform for such discussions, but we must absorb all different perspectives without any selectivity or discrimination. And here we welcome what has been mentioned in multiple delegations, and we specifically welcome and agree with what has been expressed by both Syria, Iran, and Russia, especially in terms of human rights and matters concerned with the implementation of international law and its applicability on cyberspace and international conflicts therein. And in addition to matters of due diligence, we need more clarity on these due diligence matters in order to be aware of different perspectives so that we do not fall behind in the elements that complement the efforts of this team and ensure its fulfillment of its mandate. Thank you, Mr. President.

Ambassador Gafoor

Thank you, Sudan, for your statement. I’ll now give the floor to the European Union, to be followed by Argentina, and both of them, I believe, are speaking on behalf of a group of states. EU, please.

Thank you, Chair. I will make both my remarks on CBMs as well as capacity building, and I’ve been trying to cut my statement to save some time, so bear with me as I’m representing 27 Member States. I won’t do 27 times 3, I promise. The EU is keen to continue the discussion on CBMs and actively contribute to the implementation, including in the context of regional organizations, such as we do actually with Singapore in the Asian Regional Forum on the Protection of Critical Infrastructure. Broad engagement on CBMs will enable us to strengthen linkages between regional groups and those countries that may not be part of a regional organization to share lessons learned from our regional experiences with CBMs in this Open-Ended Working Group. These discussions also provide a helpful starting point in developing a list of global CBMs, as proposed by yourself in paragraph 35, which the Open-Ended Working Group can work towards implementing in a practical way. For these reasons, the EU and its Member States see the Open-Ended Working Group as an opportunity to share practical tools, best practices, and examples to engage and further advance the development of the implementation of CBMs, including in cooperation with the multistakeholder community. Regional CBMs are also echoed in the UNGGE report, such as in 2015, which encourages transparency by sharing national views and information on aspects of national and transnational threats and vulnerabilities. And we would also further support a discussion on the recommendations for transparency measures around the use of capabilities. Chair, the EU is supportive of establishing a global cyber POC directory under the auspices of the UN, and we appreciate that regional organizations, such as ARF, OAS, and OSCE, have been able to share their lessons learned. These organizations have acquired experience in the development of CBMs, and we need to make sure that the complementary nature of the POC directory with other mechanisms remains. And we suggest expanding the annex upon this. As for the draft, we think that the annex of the POC directory could still better elaborate on the purpose of the POC directory and see a role, rather, for the secretariat, for instance, in paragraph 15 and 16 of the annex. With regard to capacity building, the EU recognizes that cyber capacity building, supporting cyber security and resilience, and the implementation of the UN Framework for Responsible State Behavior is key in promoting peaceful and stable cyberspace. The role of cyber capacity building as a mechanism in the EU international cyber engagement and cooperation has been steadily increasing in the last decade, and it’s clear that cyber capacity building efforts and initiatives cannot be considered in a bubble, but have to be contextualized against a constantly evolving cyber threat landscape. At the same time, the ecosystem has also been evolving, and there has been a steady growth in the number and financing of projects and initiatives, the involved actors and the communities, as well as the concrete activities. And we still have a way to go, and the coordination mechanisms and practices among donors, implementers, partner countries, regional organizations, but also the private sector, civil society, and the technical community. Our coordination, therefore, has to mature, especially against this complex backdrop. A role of the UN in this coordination should complement existing mechanisms. For example, the mechanisms from UNIDIR or the Global Forum on Cyber Expertise that has worked to ensure coherence between different capacity building programs and the needs of partner countries. Therefore, we see merit for the UN Secretary to conduct a mapping exercise to survey the landscape of capacity building programs and initiatives within and outside of the United Nations, and at the global, regional, and sub-regional level, including by seeking the views of member states. On this basis, the UN can encourage the creation of formal and informal cooperation frameworks between states and serve as a platform to enhance the implementation of UN agreements and stipulate capacity building in this context, including in cooperation with the multistakeholder community. As stakeholders are driving many capacity building initiatives, and a number of stakeholders from industry and academia focus their respective efforts to involve groups in vulnerable situations and local communities for effective capacity building. We also think that a future UN Program of Action designed as an implementation platform could serve as a valuable practical tool to deliver some cyber capacity building solutions and good practices in UN member states. And we’re open to further discuss proposals to enhance further cooperation on cyber capacity building. Chair, the EU will continue to prioritize cyber capacity building, and we will continue to invest in global cyber resilience based on the needs of states. Thank you very much.

Ambassador Gafoor

Thank you very much, European Union, for your statement. I give now the floor to Argentina, please.

Argentina

Mr. President, Chairman, thank you for giving us the opportunity to exchange ideas on draft number one of the APR. I’d like to make this statement on behalf of the following Latin American countries – Argentina, Brazil, Chile, Colombia, Costa Rica, Ecuador, El Salvador, Mexico, Paraguay, Peru, Dominican Republic, and Uruguay. We would like to welcome you for presenting this new draft that includes many of the comments that were made by our countries throughout the last year of work. First of all, we believe that the main objective of capacity building is to guarantee safe, effective, and significant participation of all states in cyberspace in order to benefit from the opportunities for sustainable development that can stem from it. Given the framework of the work of the Open-Ended Working Group, this means the need to move forward with a comprehensive approach which would give rise to the development of specific actions in terms of assistance in all the pillars of the group’s work. As a result, we do agree that the commitment of all states in capacity building is a confidence-building measure in itself and of a cross-cutting nature, and we support the inclusion of this concept in paragraph 40 of the draft of the annual report. This tailored vision on capacity building does not only refer to its important treatment in every section of the annual report, but we maintain as well that it should take into account the existing and future asymmetries in the international community with respect to the digital capabilities of states. We think it’s important to refer to the digital gap and the fundamental role that capacity building has within this framework because we believe that digital transformation is required in order to close this gap, and it will contribute to building a cyberspace which is open, safe, stable, accessible, peaceful, free, and interoperable for all. And that is why we welcome the inclusion of paragraph 40B, this taken from the first APR, insofar as it incorporates both concepts. We emphasize the importance of regional initiatives such as coordination and cooperation mechanisms between states. The interregional and regional mechanisms and organizations have an important value to add to the processes and initiatives in terms of capacity building because they have acquired experience in designing training tools which are created especially for their members. Similarly, their experience and their lessons learned can contribute significantly to the work of the working group. These efforts, along with ones that can arise from cooperation mechanisms such as the traditional North-South, South-South, and triangular cooperation, could generate specific actions in terms of technical assistance for capacity building, including those directed to the application of the 11 norms of responsible behavior of states in cyberspace. We also highlight the important work for capacity building that were done by other agents, such as international organizations, regional and sub-regional bodies, civil society, the private sector, academia, specialized technical bodies. And we reaffirm the importance of adopting a multistakeholder approach under the corresponding modalities which would tackle the technical and legislative gaps in all of the relevant sectors of society. In this context, we support the initiatives aimed at enhancing the effective participation of developing countries in the digital ecosystem, because in this way we will guarantee both the reduction of the digital gap as well as a more resilient environment for all. We also are grateful for the inclusion of NXE, which contains the principles of capacity building which were agreed to in the first – in the final report, rather, of the first Open-Ended Working Group. We accompany the efforts aimed at continuing to discuss how we can consolidate this into concrete action. Once again, thank you for producing draft number one of the annual report and for giving us the opportunity to share ideas today. You’ve encouraged us to continue to build the necessary consensus in order to agree on a new annual report. Thank you very much.

Ambassador Gafoor

Thank you, Argentina, for your statement. I give the floor now to Fiji, followed by Singapore.

Fiji

Chair, please allow me to speak on behalf of the Open, Informal, and Cross-Regional Group of States to advance confidence-building measures within the OEWG, which brings together Argentina, Australia, Brazil, Canada, Chile, Colombia, the Czech Republic, Fiji, Germany, Israel, Jordan, the Republic of Korea, Mexico, the Netherlands, Singapore, and Uruguay. Our group welcomes the CBM section contained in the Draft Annual Progress Report and in Annexes A and B, and calls on all UN Member States to join consensus in adopting the recommendations on the establishment of a Global Points of Contact Directory and on the elaboration of a first set of practical CBMs. In our view, the draft APR clearly shows that even in these very challenging times, substantial progress can be achieved in advancing the evolving framework of responsible state behavior in cyberspace at the very practical level of confidence-building. The CBM section reflects many of the proposals made by our group. We support the dual-track approach taken by the APR in both opening the way for the establishment of the POC Directory and in clearing the way for the development of practical CBMs. It is our conviction that both avenues need to be pursued at the same time to ensure that the POC Directory has an immediate range of practical functions to perform from the day of its inception. Members of our group also stand ready to take an active role in the operationalization of CBMs with targeted capacity-building initiatives to ensure all states wishing to do so can fully participate in the range of confidence and trust-building activities facilitated by the Global POC Directory. Finally, we welcome the opportunity for a review of the initial functioning of the Directory at a dedicated meeting to be convened in 2024. Thank you, Chair.

Ambassador Gafoor

Thank you, Fiji, for the statement on behalf of the Cross-Regional Group. I’ll give the floor now to Singapore, followed by Mauritius.

Singapore

Thank you, Chair. Singapore supports the proposals in the section on Confidence-Building Measures, including Annex A, as it reflects suggestions from the Cross-Regional Confidence-Builders Group, which Singapore is a member of, including the four CBMs to support the Global POC Directory. Specific to Annex A, we are supportive of the efforts by the Chair to include detailed guidance to support the operationalization of the Global POC Directory. This, we believe, provides the scaffolding needed to support the meaningful participation of small and developing states, especially those which may not be part of regional groupings or other existing networks and directories. With reference to paragraph 13E on the Chair’s convening of a simulation exercise, Singapore had previously proposed a TTX, a tabletop exercise of similar nature. We stand ready to work with interested states and UNIDIR to expand upon it to support the Chair in the implementation of the exercise. For capacity building, Singapore supports the section on Capacity Building and the revised APR, including Annex C on Agreed Principles of Capacity Building, which is drawn from the 2021 OEWG Final Report. Singapore recognizes the importance of capacity building as key in supporting states across all pillars of the OEWG’s work, as noted in paragraph 40. This is also the impetus for Singapore’s continued capacity building efforts through the ASEAN-Singapore Cyber Security Centre of Excellence and the UN-Singapore Cyber Programme. Specific to the proposal in paragraph 40F, Singapore supports the development of the list of capacities required by states to implement the norms of responsible state behavior. This will support states in seeking out targeted capacity building activities to support them in norms implementation, while encouraging providers of capacity building to develop initiatives specific to these needs. In this regard, Singapore has been supporting the mapping of such capacities in the ASEAN-Toronto Norms Implementation Checklist. Singapore welcomes the Chair’s proposal to convene a dedicated global roundtable meeting on capacity building best practices in paragraph 45. Multistakeholder engagement is essential to harness expertise from different stakeholders for holistic capacity building efforts. In this regard, Singapore further encourages the engagement of regional organizations in the proposed roundtable, given their role in supporting regional capacity building. Thank you, Chair.

Ambassador Gafoor

Thank you, Singapore. Mauritius to be followed by Pakistan.

Mauritius

Chair, we would like to commend the effort your team has put in to come up with this report. MERSHES is supportive of the development and operationalization of the Point of Contact Directory at paragraph 35. We believe that this effort would largely help in promoting a secure digital landscape through the sharing of voluntary information, particularly in the event of ICT security incidents. It is important that the information shared is not limited to urgent or significant incidents, as it was in the previous version. In line with paragraph 35, MERSHES has set up an online national platform, which is being used by SADC and Africa CERT, for sharing cyber threat information. Chair, MERSHES is in the process of finalizing its national cybersecurity strategy later this year. The strategy’s guiding principles are supportive of the recommendations contained in the APR Revision 1. MERSHES is engaged in capacity building efforts in the African region. Work is being done in the region for carrying out cyber drills. A center of excellence with a focus area on cybersecurity has been set up. The center has an objective to raise cybersecurity awareness and to support capacity building in the field of cybersecurity, both locally and regionally. For instance, last year MERSHES conducted a cyber norms training in which nine countries participated. With regards to paragraph 35D, MERSHES believes that further discussions would be necessary on the issue of addressing ICT vulnerabilities. Prevention of ICT security incidents is key, and for the timely discovery of ICT vulnerabilities, the conduct of regular information security audits to ascertain the security levels of IT infrastructures should be considered. Thank you, Chair.

Ambassador Gafoor

Thank you very much, Mauritius. Pakistan, to be followed by Timor-Leste. Pakistan, please.

Pakistan

Thank you, Chair. To save time, I will only be highlighting the amendments proposed by Pakistan in the APR section E and F. However, later we will share our detailed statements with the Secretary. In the Capacity Building section, Pakistan would like to propose a minor amendment in CBM-2 Part D, contained in Annex B of the APR, which would be read as: “States voluntarily engage in transparency measures by sharing relevant information, including best practices with regards to critical infrastructure protection and recovery from ICT incidents involving CI.” And the paragraph continues. Chair, concerning the elements paper for the Intergovernmental POC Directory, Pakistan considers the revised version 4 as balanced and calls for its early adoption, keeping in mind that the actual operationalization process will be a time-consuming thing, and will involve detailed discussions on different technical aspects of the directory. Turning to the Capacity Building section, Pakistan in general welcomes the formulation of language, especially with the agreed principles of capacity building contained in Annex C. However, we propose an amendment in line 4 of paragraph 40C, which could be read as: “through tools, surveys to identify impediments in view of fair, equitable, and unconditional availability of capacity building opportunities, and facilitating access by states to capacity building programs.” These are some amendments proposed by Pakistan in section E and F. I thank you, Chair.

Ambassador Gafoor

Thank you very much, Pakistan. Timor-Leste, followed by South Africa.

Timor-Leste

Chair, as this is the first time we’re taking the floor, my delegation wishes to join others in congratulating you for your leadership in this working group. On the confidence-building measures, we view that there is a value in making the global points of contact directory voluntary and accessible to all member states, as this will be one of the indicators in measuring the improvement of communication among states and as part of the confidence-building measures mechanisms. In personalizing this directory, we view the role of the UN Secretary as pertinent in assisting states, especially the developing ones. In this line, we welcome the proposed actions by the UN Secretariat as laid down in paragraph 13 A, B, and C of Annex A, considering that education, learning, sharing, and cooperation are key to the full personalization of the directory. For developing states, engagement in regular discussions, seminars, and training programs are essential to developing the skills and capacities needed for the POCs in addressing cyber threats and risks. Specifically, on the section of capacity building of this report, Timor-Leste considered this to be important and the section balanced in capturing proposals presented during the previous sessions. Timor-Leste shares the vision of a peaceful use of ICT, especially for socioeconomic development and security, to be founded by international law, in particular the United Nations Charter, as essential to maintaining peace and stability. Nationally, states share the responsibility in securing their national ICT environment, together with the collaboration with the private sector and international partners. In this regard, we welcome points shared in the reports on the importance of a holistic approach to capacity building in the context of ICT security. As the gap in capacities to secure information systems continues to widen, capacities to develop resilience and protect critical information, identify threats, and respond to them in a timely manner also differ from state to state. These differences will continue to create risks and increase vulnerabilities for all states. To have the greatest possible impact, capacity-building initiatives must be nationally owned and led and tailored based and targeted based on states’ priorities and conditions. In this regard, we welcome the initiative to develop a global cybersecurity cooperation portal as a one-stop-shop tool for states under the auspices of the UN, and we look forward to more detailed discussions on this matter. We also view the value of a repository of best practices of ICT security capacity building as an important element to be integrated into the GCSCP as highlighted in paragraph 40E. The recommendation section provides clear and feasible guidelines for our future work, and we support in principle the recommendation in paragraph 43 in requesting the UN Secretary to conduct a mapping exercise to survey the landscape of capacity-building programs and initiatives within the UN and other international forums. We also appreciate the formulation in recommendations 47 and 48 as we view the inclusion of general dimension capacity-building efforts and the role of regional and sub-regional organizations and other interested stakeholders and academia as important. Thank you, Chair.

Ambassador Gafoor

Thank you, Timor-Leste. South Africa, followed by Thailand.

South Africa

Thank you, Chairperson. This statement will refer to capacity building and confidence-building measures. On capacity building, my delegation finds the Draft Rev. 1 a solid basis for our discussion and consensus. With regards to capacity building, we wish to state at the outset that the addition of Annex C, Agreed Principles of Capacity Building, to the Draft APR is a key contribution to this document. We support the inclusion of Para 40 Bbis on understanding the needs of developing countries. Para 44 on further discussion on a global cybersecurity cooperation portal is welcomed. This proposed portal would operate under the auspices of the United Nations, which would be a reaffirmation of the importance we attach to discussions on international peace and security at the multilateral level. We support Para 45, which requests the OEWG Chair to convene a dedicated global roundtable meeting on ICT security capacity building during the intersessional period to allow for an exchange of information and best practices. Chairperson, CBMs are a vital tool that we currently have to prevent cyber-related conflict between states, and it is therefore important that we adopt Annex A, Elements for the Development and Operationalization of a Global Intergovernmental Points of Contact Directory, in the Second Annual Progress Report of the OEWG. In the Annex, we support the inclusion in Para 5b of “with possible implications for international peace and security” to build confidence between states and the inclusion of communication in Para 5c. The inclusion of “possible” to Paras 9a and b is a welcome addition that allows states to determine the nature of an incident. Similarly, we support retaining Para 10 on the interaction between PLCs, including Paras 10a and b as they are. We can live with the formulations of Para 12a and b on how the global PLC directory interacts with information from other directories. As it has been finely balanced text, we prefer to retain the language as it is. We support the request of the Secretariat to develop a background paper on capacity building for points of contact by January 2024. We also prefer to retain Annex B, the initial list of voluntary global confidence-building measures, as it is, given that they are directly linked to the POC as envisioned in Annex A. I thank you.

Ambassador Gafoor

Thank you very much, South Africa. Thailand, to be followed by the Philippines.

Thailand

Mr. Chair, thank you for giving me the floor. With regard to the sections on capacity building measures, especially on the global POC directories, Thailand wishes to share the following points. First, Thailand welcomes the progress made on the establishment of the POC directory as they serve as a global CBM. We believe that it is important to operationalize the POC directory at the earliest to facilitate real-time communications, information exchange, swift response, and mitigation measures among the participating states in times of cyber incidents. Second, to encourage the utilization of the POC directory to its full potential, Thailand attaches great importance to capacity-building initiatives, particularly for developing countries, to enable their active participation in the POC platform to improve their cyber incident response capabilities. We also support the role of the UN, the OEWG chairs, and the states in the capacity to do so, to provide such assistance in this regard. Third, Thailand believes the global POC directory should leverage the groundwork established at the regional level, including the POC directory within the ASEAN Regional Forum framework. We also support the interaction between directories and services to swiftly and effectively respond to cyber incidents. Mr. Chair, in this regard, Thailand supports the current version of the draft element paper on the POCs as contained in Annex A of the draft APR, along with its substantive elements of capacity building. We look forward to its adoption during this session of the OEWG, serving as a concrete outcome of our work toward peace, security, and stability in cyberspace. Thank you.

Ambassador Gafoor

Thank you very much, Thailand. Philippines, to be followed by Bangladesh.

Philippines

Mr. Chair, my delegation takes this opportunity to give its statement on Sections E and F. One of the main concrete results of our discussion since 2021 is contained in the section on Confidence-Building Measures. We therefore welcome the recommended steps in this section, including the establishment of a global intergovernmental points of contact directory and adoption of the paper containing elements for its development and operationalization. We hope that member states would have utmost flexibility on the adoption of this concrete step forward to bring us closer to achieving an open, secure, stable, accessible, and peaceful ICT environment. On capacity building, the Philippines, like many others, attaches great importance to capacity building. Since the Philippines’ cybersecurity sector is still in its infancy, it welcomes the very rich recommendation part on capacity building, including the engagement with relevant UN entities and international organizations offering capacity building programs on cybersecurity, a mapping exercise to be conducted by the Secretariat in order to survey the landscape of capacity building programs and initiatives within and outside the UN, and continued discussion on the proposal for our global cybersecurity cooperation portal as a one-stop-shop tool for states under the auspices of the UN, and sharing of voluntary checklists and other tools that would assist states in mainstreaming capacity building principles, including incorporating a gender perspective in such efforts. The Philippines aims to build up its cyber defense capability and secure the Philippines against organized cybercriminals as well as state-sponsored attacks. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you, Philippines. Bangladesh, to be followed by Venezuela.

Bangladesh

Thank you, Mr. Chair. On Section E, confidence-building measures, we look forward to the operationalization of the Global Intergovernmental Points of Contact Directory, which will be a concrete achievement of the Open-Ended Working Group for this year. Operationalization of the Global POC is a CBM by itself, by building trust and confidence between and among States. This directory will help build trust as a vital platform for fostering effective communication and cooperation between States to address cyber incidents and strengthen confidence in the global ICT environment. On paragraph 36, we propose to add two inclusive consultations and expert dialogues after exchanging views at the Open-Ended Working Group. The sentence would read, “States continue exchanging views at the Open-Ended Working Group, including through inclusive consultation and expert dialogues on the development and implementation,” then the sentence continues. This addition would give due importance to engaging various stakeholders and experts to shape the CBMs effectively. On paragraph 38, we propose to include the phrase, “States to engage actively in the operationalization,” instead of “further discuss.” On capacity building, we recognize that capacity building has a cross-cutting element throughout all pillars of the work of the Open-Ended Working Group, and we underline the importance of seeing it from a holistic approach. We welcome the Chair’s formulation on capacity building. We appreciate that the draft adequately reflects the gender-sensitive approach to capacity building, strengthening cooperation with stakeholders, promoting synergy and access to capacity building programs, and tailor-made capacity building for developing states. We look forward to the adoption of this section as drafted. I thank you, Chair.

Ambassador Gafoor

Thank you, Bangladesh. Venezuela, to be followed by Cuba.

Venezuela

Thank you, Mr. Chairman. First of all, I’d like to make clear that no lawyers were involved in the making of this statement. And I shall be brief. As you know, brevity is the soul of wit. Mr. Chairman, the Bolivarian Republic of Venezuela would like to express its concern over the existing digital gap, which continues to be on the rise between developing countries and developed countries. The implications of this gap for the creation of a comprehensive and holistic system of security within the framework of ICTs are significant. A comprehensive security system requires that all of its components show similar capacities, and that is why the gap represents a great challenge for collective security. For all these reasons, Venezuela prefers the development of an institutional approach, of an interdisciplinary nature, which would further the development in recipient states of technical assistance, with a view to strengthening their skills in the planning and follow-up of national policies on ICTs within the context of international security. And here, at least, we do agree with the vision that was presented by Argentina. Venezuela believes that the contributions and expertise that can be offered by non-governmental associations, academia, as well as the private sector, in order to improve security systems for ICTs, should all be adapted to the existing national legal framework and the specific needs of the countries that receive those aspects and also their development strategies. Those contributions should be adapted to the work of this Open-Ended Working Group. Venezuela also believes that an excellent first step would be the creation of a global directory for points of contact, because this is an appropriate instrument for international cooperation as well as technical assistance among the different states. We believe that the system should be a platform to exchange knowledge and solutions to practical problems among the states that make up the directory, beyond simply monitoring and noting attacks in cyberspace. Finally, given the fact that here we are assessing the threats that develop from the creation of capacity building, we also have to look at the topic of the destruction of capacities. And in this respect, it’s the opposite process. The destruction of the capacities of a state by one or more states in order to be able to maintain their infrastructure, their technological infrastructure, for example. This destruction of capacity is usually generated through the imposition of coercive unilateral measures, the same ones that attack international law, which we are assessing within the meetings of this working group. The coercive unilateral measures destroy the capacity of states to develop their technological security infrastructure, and it deepens the digital gap. And therefore, it also reduces the effectiveness of developing and implementing a system which is truly global, holistic, and comprehensive in terms of security. Capacity building in this area of the security of ICTs necessarily must go through a process of rejecting these coercive measures with a view to leveling the capacities of all countries and closing instead of expanding the digital gap, which prevents the implementation of a truly global approach for the security of ICTs. Chairman, thank you very much for your attention.

Ambassador Gafoor

Thank you very much, Venezuela, for your statement. Cuba, followed by Austria, please.

Cuba

Mr. President, Mr. Chairman, in response to the discussions that took place on Section D referring to international law, the delegation of Cuba cannot accept the proposal to introduce a paragraph that would intend to reaffirm the automatic applicability of international law, including the UN Charter as a whole, if there is no consensus on this. The position of our delegation on this topic is very well known. We call upon all delegations to refrain from introducing non-consensual language which comes from reports of a governmental group of experts that are closed in composition. In the confidence-building measures, we propose to add the following as a third sentence in paragraph 35, and I quote, states reaffirmed that confidence-building measures must be implemented on the basis of the noninterference in internal affairs of states, on respect for their sovereignty, and must be of a voluntary nature. In paragraph 36 of the recommendations, we propose to add, at the end, including confidence-building measures in order to reduce the digital gap and to ensure universal, inclusive, and non-discriminatory access to information and knowledge through the ICTs. In the section F on capacity-building, we propose to add in paragraph 40 in the second sentence that the capacity-building efforts must be undertaken in accordance with the principles that appear in paragraph 56 of the report of the Open-Ended Working Group of 2021. Though this is mentioned in other parts of the draft report, we believe that it’s crucial to mention it as well in this section. And at the end of paragraph 40, when we refer to questions that were emphasized in the OEWG, we propose to add as well the principle of common but differentiated responsibilities, which should be applied with respect to the provision of capacity-building, as well as the call to refrain from any coercive unilateral measure which would prevent universal access to the benefits of the ICTs, which would restrict or deny in any way developing countries – deny them science, knowledge, technology, as well as services related to the ICTs in all of their aspects and with peaceful purposes. These two items are part of the position of the Non-Aligned Movement presented in our working document at the previous Open-Ended Working Group. We do agree with Argentina and other delegations that capacity-building is an important confidence-building measure, as was acknowledged in paragraph 40. We welcome the reference to the need to reduce the digital gap in paragraph 40bbis. In paragraph 40, we propose to delete the reference to South-North cooperation and to add at the end of the last sentence the phrase that I quote as a complement to North-South cooperation. We would ask, lastly, for the elimination of specific references to the Global Forum on Cyber Expertise in this section. Thank you very much.

Ambassador Gafoor

Thank you, Cuba, for your statement. Austria to be followed by China. Austria, please.

Austria

Thank you very much, Mr. Chair. I’ll be brief. On capacity building, paragraph 30F in the last sentence, proposing the development of an initial list of capacities required by states for the implementation of the framework of responsible state behavior, we question the feasibility of this proposal because we think capacities of states vary very much depending on factors that depend on each country. So we think that such a list of capacities should better be maybe discussed in a bilateral setting and then propose the deletion of this sentence. On the general note in this section, while we fully support the importance of capacity building, we just are questioning whether the various proposals and recommendations in this section might be too much of a good thing because with so many proposals being there, we are asking ourselves how do we have the capacity to implement all those capacity building measures. So there might be some place for streamlining. And just to come back on what we just heard of international law, I think it’s important to reaffirm that not only various GGEs reaffirmed the applicability of international law and the UN Charter in cyberspace, but also the previous Open-Ended Working Group and this Open-Ended Working Group in its annual progress report. So such a reference is absolutely essential for us. Thank you.

Ambassador Gafoor

Thank you. Austria, China, to be followed by Uruguay.

China

Thank you, Chair. Regarding CBM, paragraph 35B, in view of some countries’ issuance of export restriction policies, that is, restricting many countries, including China, from sharing some information, for disclosure, we would like to suggest we add “non-discriminatory.” For paragraph 40B, it is differentiating long-term and short-term goals. Capacity building and sustainable processes are contradictory. I would like to suggest that we delete this language. About peer-to-peer, we offer the view that peer-to-peer is not on the same dimension as the regional level. Under regional frameworks, there can be peer-to-peer cooperation. Therefore, we suggest we delete “peer-to-peer.” Paragraph F, capacity directory or list of capacity, it is hard – it can hardly be implemented. And next, A, POC, paragraph 5. The main function of POC is to enhance security and stability. It may not be able to serve the function of peace, transparency, and predictability. Paragraph 9, China supports member states making independent decisions on POC. POC can engage in dialogue on CBM. Technical POC can be in charge of responding to incidents. Paragraph 14, China supports a gradual approach to the POC. We suggest that in line with the – they can work on the POC for the discussions carried out on future steps. Paragraph 15, we suggest that in light of the OEWG formal meetings, exchanges of experiences can be carried out. Thank you, Chair.

Ambassador Gafoor

Thank you. China. Uruguay, to be followed by Hungary.

Uruguay

Thank you, Mr. Chairman. My delegation is pleased to be able to make our statement on Sections E and F. We support the statement made by Fiji on behalf of the group of countries, and we also welcome the inclusion of an initial list of voluntary confidence-building measures, even though we reaffirm its exhaustive nature and the need to include more measures that would lead to a peaceful approach of states through confidence-building. As was mentioned by the distinguished delegate of Fiji in her statement, Uruguay is ready to play, along with other countries, a very active and constructive role in implementing these measures. We need the support of all in order to build a peaceful and safe world in cyberspace. For example, with respect to Medical Measure 2 and Annex B of the text, in the last year Uruguay has shared information with a voluntary nature, conceptual information on ICTs, strategies, programs, national legislation, and good practices. We did this in a voluntary way with Honduras, the Dominican Republic, Argentina, Chile, Brazil, among other countries. And also along with the Latin American Cyber Confidence Center, we are organizing on the 8th of August the first cybersecurity exercise for the Southern Cone region. And these are simply a couple of examples of how we can build confidence and trust through the exchange of information and through training for capacity-building. And with respect to capacity-building, Uruguay also supports the statement made by the distinguished delegate of Argentina on behalf of a group of countries. Uruguay reaffirms the importance of enhancing cooperation as well as technology transfer for developing countries, bearing in mind the differences that exist when it comes to technological capacities as well as the know-how. We highlight that capacity-building and international cooperation in all its forms – North-South, South-South, triangular, regional, et cetera – are confidence-building measures in themselves. And within that framework, the joint activities that we carry out are a contribution to international peace and security, generating an atmosphere of mutual trust as well as multilateralism. For Uruguay, the gender perspective is fundamental when it comes to thinking about cyber capabilities, and that’s why we welcome the initiative of Women in Cyber Fellows, which allowed our delegation to be able to be represented by our electronic government agency. Sir, Uruguay supports what is said in paragraph 40C, through which we attempt to improve the coordination efforts when it comes to capacity-building and the particular role that the UN can play in this area. However, we would prefer that we give more emphasis to that topic, and that’s why we suggest the possibility of changing the word “could” to “must” play an important role in the same paragraph. And we also support the course of action contained in paragraph 43 in order to have mapping of the needs of states as well as unifying different proposals and possibilities for cooperation that are offered by different entities in the organization, but also by other relevant players. And finally, we could not help but mention the importance of NGOs and other interested parties that make significant efforts to support states in capacity-building. Thank you very much, Mr. Chairman.

Ambassador Gafoor

Thank you, Uruguay, for your statement. Hungary, to be followed by Indonesia.

Hungary

Thank you, thank you, Mr. Chair. As I take the floor for the first time, let me start by thanking you and your team for the hard work put into organizing the session, the focused discussion, and the drafting of the second annual progress report. Hungary aligns itself with the statement delivered by the European Union but also wishes to add the following remarks in its national capacity. We especially agree with the need to better coordinate the efforts among the growing number of donors, implementers, partner countries, and organizations on the ground. In this crowded sphere, the UN could certainly play a complementary role, but other stakeholders have their own role to play. We would like to express our gratitude to Singapore and the UN Secretariat for developing the Cyber Diplomacy e-learning course mentioned in the recommendations section of the second APR IMPERA 46. We express our readiness to contribute to the updating of the course in 2024 with the perspectives of small and medium-sized states engaging in cyber diplomacy talks. In addition to that, in our view, the UN-Singapore Cyber Diplomacy Fellowship is another valuable contribution for high-level cyber security officials to cultivate a greater understanding of the issues around the implications of ICT technologies on international peace and stability. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you, Hungary, for your statement. Indonesia to be followed by Vietnam.

Indonesia

Thank you, Mr. Chair. My delegation welcomes the content and structure of Sections E and F in general. On Section E, we are pleased with the emphasis on the establishment of a Global Point of Contact Directory. This will be a good first step in the exercise of global confidence-building measures in the field of ICT security. This will also demonstrate the commitment of States in developing concrete and action-oriented outcomes within the OEWG process. We support the recommendation in paragraph 37 and encourage States to agree to adopt the paper as contained in Annex A, with a view to operationalizing the Global POC Directory. We believe that practical guidance and capacity-building action plans related to the implementation of the POC Directory, as outlined in Annex A, will help ensure the effective participation of States, especially developing countries, in the Directory. Moving on, the list of initial voluntary Global Confidence-Building Measures is particularly helpful for countries to refer to in the future. The Annex will also be beneficial to become the benchmark in developing further Global Confidence-Building Measures as we progress in our deliberation. On Section F, we observe that the recommendations in the draft APR have offered concrete and actionable steps for follow-ups. In paragraph 43, we welcome the idea for the UN Secretariat to carry out a mapping exercise on capacity-building needs. We suggest that such an exercise be equipped with a mapping of potential sources of funding and the objectives that it seeks to achieve against the 11 cyber norms. We also highlight the need that such capacity-building could also address aspects such as building capacity for cyber incident response, including through training and support for computer security incident response teams (CSIRTs) and computer emergency response teams (CERTs), implementation of emergency response, formulation of contingency plans on cyber crisis management, and safe information exchange mechanisms. We also appreciate the effort to mainstream the principle of capacity-building as contained in Annex C across all capacity-building initiatives. This will help in devising more targeted programs in accordance with the shared objectives. Finally, we also appreciate the consideration of gender perspective in the context of capacity-building. Indonesia values the capacity-building programs targeted for women in this field, such as the Women in Cyber training that was held this week. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you, Indonesia. Vietnam, to be followed by Egypt.

Vietnam

Thank you, Mr. Chair. Thank you for giving me the floor to speak on Section E and F on the draft ARF APR regarding confidence-building measures and cybersecurity capacity-building. Vietnam believes that confidence and transparency serve as the basis to build common understanding on many cross-cutting issues, including, among others, the understanding of the cyber-threat landscape and how international law, including norms and rules of responsible state behaviors, apply. In this regard, we welcome the draft Section E of the second APR, including a non-exhaustive list of voluntary global CBMs. With regards to the Global Intergovernmental POC Directory, we welcome the fourth revision of the elements for its development and operation and look forward to its adoption as the first substantive outcome of the OEWG process. For the consideration of this working group, we consider the inclusion of the principle in which the information shared therein must be in conformity with regulations on personal data protection and intellectual property. At the same time, we hold the view that the information-sharing mechanism, including the procedure for inquiry and response, does not necessarily substitute traditional legal assessment channels already established between states. Mr. Chair, turning to Section F of the report, we align ourselves with many delegations, reaffirming the importance of cybersecurity capacity building. This plays a pivotal role in bolstering cooperation between states to improve our collective global resilience against malicious cyber activities toward the ultimate goal of promoting an open, peaceful, secure, and accessible cyberspace. Therefore, we welcome the inclusion of Paragraph 40B BITS, as this is the language of the agreed first APR, which underscores the needs of developing countries for capacity-building support and, at the same time, highlights the importance of a need-based approach to all capacity-building initiatives to better address recipient needs. In line with that, we would like to propose the inclusion of non-exhaustive in the last sentence of Paragraph 40F, which reads, quote, the development of a non-exhaustive initial BITS, end quote, to ensure the evolving needs of states are reflected from time to time so that all needs are adequately addressed. Mr. Chair, let me take this opportunity to commend the ongoing efforts of all states in enhancing and promoting capacity-building activities. In particular, we underline that the capacity building of cyber professionals as the peacekeepers of cyberspace is of great importance to the maintenance of a peaceful and secure ICT environment, and that states should develop their national policies on the improvement of the cyber workforce for the support of international stakeholders. In this regard, the ASEAN Regional Forum Workshop on Fostering Professionals in the Field of Security of and in the Use of ICT, coordinated by Vietnam and the Republic of Korea, taking place last month in Vietnam, gathered government officials, experts, and professionals from ARF member countries to share their experiences and best practices in nurturing professionals specializing in ICT security. Furthermore, we are glad to take note that the gender perspective is repeatedly reaffirmed throughout the draft APR. We hereby share our views that it is essential to consider and include gender-sensitive capacity-building efforts in addressing ICT threats, and we agree with the proposal to replace dimension with perspective, as this is the language that we agreed on in the first APR, and it also helps ensure the consistency of language used across the second report. Particularly on capacitating women, let me express our appreciation to the Women in Cyber Fellows, organized and sponsored by the governments of Australia, Canada, New Zealand, the Netherlands, the United Kingdom, and the United States, to promote and facilitate greater participation by women in the OEWG and in future discussions on responsible state behavior in cyberspace. I thank you, Mr. Chair.

Ambassador Gafoor

Thank you, Vietnam, for your statement. Egypt, to be followed by Ecuador.

Egypt

Thank you, Mr. Chair, and since it’s my first time to take the floor, let me express my delegation’s appreciation to you, Mr. Chair, your team, and the Secretariat for the tireless efforts and also your stewardship to steer forward the work of this group. We will have very succinct observations on Sections E and F. For Section E, Egypt recognizes the progress made in our discussions on CPM section throughout this process as well as the former related processes, and we believe that this OEWG is assigned to build upon the related existing acquis. We generally commend the language included under this section, and we would like to highlight the following. On paragraph 35C, we understand that elements included in the paragraph as stated are already included as operational elements in the paper of the POC’s directory proposal annex A; therefore, we believe it should be streamlined from this paragraph. On paragraph 39, we also have questions on the rationale behind re-endorsing the agreed CBMs reflected in the 2021 OEWG outcome report, as we previously stated that this OEWG should be building upon the existing acquis. Therefore, we believe that it would be sufficient to recall those endorsed CBMs while encouraging member states to further discuss their operationalization and synchronization with the proposed POC’s directory. We also stress the importance of initiating the POC’s directory at the earliest following the thorough discussion that we had throughout this process and also the formal cyber processes. We will provide specific comments on the annex that will come to its discussion later on. For Section F, we fully support all efforts aiming to elevate states’ capacities related to cybersecurity as an enabler to the effective implementation of the agreed framework, and we commend the concrete proposals and actionable steps reflected in this section. Moreover, while noting the added value of the regional and sub-regional organizations that could play in the context of cybersecurity, we believe that we should not refer to specific regional or sub-regional organizations. Hence, on sub-paragraph 40E, we believe that the second sentence of this paragraph should stop right after “existing portals.” Similar observations also apply to paragraph 44. On paragraph 41, we also have a question on the rationale behind reproducing the principles of capacity building that have been already endorsed in the 2021 OEWG final report, and we similarly believe that we can just be recalling those principles here while we encourage their mainstreaming in all capacity building-related proposals in this second APR. Furthermore, we commend the proposals included in the recommended next steps, including paragraphs 43, 45, and 46. And I thank you, Mr. Chair.

Ambassador Gafoor

Thank you, Egypt, for your statement. Ecuador, to be followed by Poland.

Ecuador

Thank you, Chairman. My delegation would like to support the statement made by Argentina on behalf of a group of countries of Latin America. And as we said yesterday, Ecuador welcomes the fact that the capacity building has been presented in a cross-cutting fashion in Rev. 1, taking into consideration the fact that the actions that are implemented within this framework are confidence-building measures in themselves. Chairman, in every session of this working group, we have repeated the need to ensure an equal, full, and effective participation of women in the negotiating processes on cybersecurity, as well as in other areas which would include the cyberspace dimension and its components. And along these lines, Ecuador believes that the common efforts are already bearing fruit. We have observed the growing and substantive contribution made by women from all regions of the world in this plenary session. As a result, Ecuador highlights initiatives such as EU Cyber Diplomacy, as well as Women in Cyber Fellowships, programs that would involve government efforts of regional organizations and agencies within the system that contribute substantively to this process, as well as to institutional strengthening. And this is a concrete example of capacity building, and therefore it must be mentioned in the text of the APR. And lastly, Ecuador reiterates its support for the adoption of the Directory of Points of Contact as one of the tangible results of the deliberations of this group. Thank you very much, Mr. Chairman.

Ambassador Gafoor

Thank you, Ecuador, for your statement. Poland, to be followed by New Zealand.

Poland

Thank you, Chair. Seeking a less orthodox approach in order to drastically limit the time of my intervention, I was listening to the previous speakers’ proposals to check which of them covers best the remarks I was planning to make. In general, we obviously align with the views presented by the European Union. In my national capacity, let me bring to the floor the following elements. In Section C on Rules, Norms, and Principles, and in Section D on International Law, our views are very well covered by Croatia, so we can copy them. In Section E on Confidence-Building Measures, we support the creation of the Global POC Directory as soon as practical. However, the purpose and operation mode of the Directory shall be further elaborated. We shall also consider making better use of CBMs elaborated and implemented within various regional groups. In this context, Poland, with willing partners, may try to analyze how and which CBMs adopted by the OSCE can be translated and extrapolated to the global UN platform through the works of this open-ended working group. As for Section F on Capacity-Building, we want to notice that we consider capacity-building international cooperation to be both an important CBM and a crucial tool to expand the security of global cyberspace across the nations. When it comes to further work of this open-ended working group on capacity-building, we believe we shall consider focusing on better mapping of the already existing numerous programs and projects offering international assistance in capacity-building, including those offered and supported by non-state actors like the private sector, NGOs, and academia. We can draw here from, but not limit ourselves to, experiences of UNIDIR or GFCE, since our achievements of this working group shall be transformed to envisage a UN Program of Action that is designed as an implementation-focused platform. Chair, I think covering four sections in less than three minutes is my personal best in over 30 years of diplomatic work, and I hope you will praise me for that in private. Thank you.

Ambassador Gafoor

Thank you, Poland, and I should praise you in public. This is a multilateral process, and I’ve always been transparent, so thank you very much for your statement. I give the floor now to New Zealand, to be followed by Colombia.

New Zealand

Thank you, Chair. Aotearoa New Zealand is pleased to support the establishment of a Global Points of Contact directory, and we offer a brief suggestion for improvement. In paragraph 35b, in our view, the directory is not a framework, and we suggest this text is changed to read, “States further recognized that the global POC directory in building confidence could positively influence the development of future confidence-building measures.” This change would flow through to paragraph 2 of the elements in Annex A. On section F, we fully support the importance of capacity building as a confidence-building measure and a cross-cutting topic. We acknowledge the positive contribution of the many cybersecurity capacity-building initiatives and activities that are already occurring and support references to the agreed principles as a valuable foundation for capacity building. The Global Cybersecurity Cooperation Portal, raised at the fourth substantive session and noted in paragraphs 40e and 44, is an interesting proposal that, in our view, merits further discussion to better understand its purpose and distinguish it from existing initiatives to ensure there is no overlap. We therefore suggest that text relating to a proposed portal is kept in the descriptive paragraphs of the report to allow time for the proposal to be discussed. We also suggest further exchanges of views would be useful before deciding whether mapping exercises and/or alignment is required, and if so, who is best placed to take that work forward. As others have mentioned previously, we recommend ensuring language in paragraph 45 that refers to a global roundtable is consistent with proposals for intersessional meetings and other sections of the APR. We will submit some additional comments in writing. Thank you.

Ambassador Gafoor

Thank you very much, New Zealand, for your statement. Colombia, to be followed by Germany.

Colombia

Mr. President, Mr. Chairman, with respect to confidence-building measures, we support the statement made by Fiji on behalf of a group of countries. And on this section, we would also like to make the following comments. With respect to paragraph 35A, we reiterate our support for the establishment of an intergovernmental global directory of points of contact. With respect to paragraph 35B, we believe that the initial global list of CBMs is a step forward in promoting an environment which is open, safe, stable, accessible, and peaceful in cyberspace. With respect to paragraph 35C and the measures stemming from the establishment of the global directory of points of contact, we support its adoption and we suggest that we add the following – discuss initiatives to motivate and expand the volunteer participation of states in the global directory. Mr. Chairman, with respect to capacity-building, we support the statement made by Argentina on behalf of a group of countries. We believe that the considerations and the steps that are recommended in this section C reflect our deliberations on this very fundamental aspect and cross-cutting aspect of the mandate of this working group. We agree that capacity-building is in itself a confidence-building measure where we need a comprehensive approach and sustainable and effective solutions, as well as incorporating the principles of capacity-building in all of the initiatives in this area. We stress the role of regional organizations as well as civil society in efforts on this. Chairman, with respect to the proposal to develop and to share checklists as well as other tools which can assist states in incorporating the gender dimension in their capacity-building efforts contained in paragraph 47, which we do support, we would like to point out the Cyber 3 Policymaking Toolkit drawn up by the organization Global Partners Digital. This toolkit will be presented in a side event called Shaping Inclusive and Rights-Respecting Cyber Norms Toolkit and Lessons from Latin America, co-sponsored by Colombia. And it will take place tomorrow morning – tomorrow afternoon, rather, at 1 p.m. in Room 7. To conclude, we’d like to mention and welcome the capacity-building initiatives put forward by some states, which Colombia has had the opportunity to benefit from – in particular, the Tallinn Summer School of Cyber Diplomacy, the Women in Cyber Program, the Cybernetic Yellow Shirt Program of the UN in Singapore, and the invitation to the Cyber Security Mission, which will take place in the Czech Republic. Thank you.

Ambassador Gafoor

Thank you, Colombia, for your statement. Germany, to be followed by Chile.

Germany

Germany is aligned with the statement delivered by Fiji on behalf of the Confidence Builders Group and wishes to thank the Chair and his team for compiling a very strong CBM section for this draft APR, consisting in fact of multiple pillars reinforcing each other, including annexes A and B and the appendix to annex A. It is encouraging to hear support for this particular section of the report across so many states and regional groups. In Germany’s view, the Global POC Directory has the potential to fulfill an important confidence and trust-building function at a time when international tensions extend to many domains, including cyberspace. Germany fully supports the establishment of the Directory at the earliest possible date, realizing that UN procedures will only allow for a start in early 2024. On a point of terminology, annex A mentions in PARA 13 a dedicated action plan to support capacity building in view of operationalizing the POC Directory. Germany cannot accept the term action plan. Our suggestion is to use either the term assistance plan or targeted onboarding plan to underline the focus of the specific capacity building mentioned under this item. The existing draft language risks creating unnecessary confusion with the Program of Action which UN member states have decided to elaborate in parallel. Germany can support the very ambitious chapter on cyber capacity building that we have in front of us. This chapter mirrors the strong call from many delegations during previous sessions to considerably strengthen access to sources of capacity building. On PARA 40F, Germany suggests the following amendment. The last sentence presently reads, “In this regard it was proposed that states could discuss the development of an initial list of capacities required by states for the implementation of the framework of responsible state behavior.” Germany suggests reverting that into, “It was proposed that states could discuss the development of an initial list of capacities that can be of assistance to states in the implementation of the framework of responsible state behavior.” The APR should be clear that capacity building is not the prerequisite but a source of support for implementing the framework which in Talia consists of binding international law and has already been endorsed by all UN member states. In closing, Germany would like to draw delegations’ attention to the global conference on cyber capacity building that will be held in Ghana from 29th to 30th November this year with the aim of mainstreaming cyber security into the global development agenda and strengthening dialogue between the development community, including the UN system, and the cyber security community. This conference is organized by the Cyber Peace Institute, the GFCE, the World Bank, the World Economic Forum, and hosted by Ghana. Thank you.

Ambassador Gafoor

Thank you, Germany. Chile, to be followed by the United States.

Chile

Thank you, Chairman. With respect to Sections E and F, and in order to be brief, our delegation would like to make the following comments. Chile supports the statement made by Fiji and Argentina, both on behalf of a group of countries, and we would also like to make the following comments in our national capacity in addition to these statements. With respect to the confidence-building measures section, we reaffirm that the Directory of Points of Contact is an important step forward in promoting confidence and trust among states at the global level, and we believe that this should be operational as soon as possible. Similarly, we support the proposal for additional measures contained in paragraph 35C. We also welcome the mention of regional organizations, as well as sub-regional organizations, as well as the stakeholders in paragraph 35E. A comment that we feel is important has to do with the voluntary exchange of information, in particular between the points of contact and with respect to the drafting in Annex A. Even though we agree with the expression ICT security incidents with possible implications for international peace and security, and the expression with a view to avoid misunderstandings and to reduce tension, we believe that it’s important that communication between the points of contact, above all at the diplomatic level, not be limited simply to this type of incident, situation, or event. Our practical experience with respect to the work of the POCs is that very often the exchange of information is justified or is done also to become familiar with malicious activities that don’t necessarily impact international security or which are required to avoid misunderstandings between states, but also as an example of malicious action which could be repeated in other countries and which other states would like to become familiar with. In this respect, we hope that the POC directory will be a mechanism which would facilitate the exchange of information, collaboration, and cooperation among the countries. And we don’t establish the perception that the communication between the POCs is simply limited to a few specific situations. As for the section on capacity building, we do agree with paragraph 40 and reaffirm that capacity building is also an important confidence-building measure and a cross-cutting measure which affects all of the pillars of the work of this group. With respect to paragraph 48, we welcome the mention of gender perspective, in particular when we consider forming national capacity building strategies. We welcome once again the initiative that has established a fellowship for the participation of Women in Cyber Fellows in the processes on cybersecurity and cyberspace. And we thank the donor countries, the United States, Australia, the UK, Netherlands, New Zealand, and Canada, who contributed to this initiative. We support the mention in all of this section of the principles of capacity building adopted in the report of the Group of 2021, reaffirming the importance and validity of these principles. We support the inclusion of a paragraph that the group could promote a better understanding of the needs of developing states with a view to reducing the digital gap through capacity building measures. In paragraphs 40E and 44, we support the mention of UNIDIR and the Global Forum on Cyber Expertise. In paragraph G, we request that we include a more explicit reference that would acknowledge that stakeholders also contribute to a wide range of efforts in capacity building, including in training and technical assistance. We support paragraph 5, that a global roundtable devoted to capacity building during the period between sessions would allow for an exchange of information and best practices. In paragraph 47, we recommend that we include a direct reference to the fact that capacity building should respect human rights and fundamental freedoms, and it should be sensitive to gender, and it should be inclusive, universal, and non-discriminatory. Thank you very much, Mr. Chairman.

Ambassador Gafoor

Thank you, Chile, for your statement. United States, to be followed by Israel. U.S., please.

United States

Thank you, Chair. We are generally supportive of the text of the CBM section of this draft and have one minor edit. In paragraph 35b, we propose changing “can provide a framework for” to “can facilitate” or the proposed revision from New Zealand to avoid using the important framework term here in a different context. Regarding the POC directory, we have been supportive of the development of this directory and over the last year have provided input to enable its implementation. We note that the latest version of the elements paper no longer mentions the potential for this directory to assist in conflict prevention in times of urgency. This fact is why the POC directory is particularly relevant for our work within the First Committee. The 2021 OEWG report confirms that a POC directory can be a helpful measure in times of crisis. In the 2022 APR, it called for a directory of POCs that could be reached in times of urgency. We recommend the paper reflect this understanding as articulated in previous OEWG consensus documents. Separately, as was discussed at the May informal, we understand the directory’s establishment as occurring no earlier than January 2024 and therefore the paper’s targets of December 2023 for an exercise in January 2024 for a paper from UNODA would not be feasible. These dates should be deleted or replaced. Turning to the capacity building section, we recommend changing the word “initial” to “cumulative and evolving” when describing the framework in paragraph 40b to match how the framework is referenced throughout the document. Regarding the proposal for the portal mentioned in 40e and 44, we are interested in discussing the proposal further and agree it could have merit. That said, we support New Zealand’s suggestion to retain the proposal in the first portion of the section only, not the recommendation section, to accurately reflect the stage of our discussion. Regarding the mapping exercise proposed in paragraph 43, we welcome such an exercise and encourage the Secretariat to leverage other ongoing mapping projects both within and outside the UN. For example, the ITU Council recently agreed to work on a similar mapping of cybersecurity capacity building programs. We also strongly support Indonesia’s proposal to connect the mapping of these programs to the implementation of the framework’s recommendations. Finally, we are pleased to hear that the UN Secretariat is updating its cyber diplomacy course by 2024, as mentioned in paragraph 46. Given the important role of non-UN entities in similar training, we propose adding, quote, “Secretariat is also encouraged to consult with relevant multistakeholder entities and multilateral institutions involved in cyber diplomacy training.” Thank you, Chair.

Ambassador Gafoor

Thank you, United States, for your contribution. Israel, to be followed by Japan. Israel, please.

Israel

Thank you, Mr. Chairperson. I would like to comment briefly on sections E and F. Israel aligns itself with the statement made by Fiji on behalf of the Cross-Regional Working Group on CBMs, of which we are a member. Through the Open-Ended Working Group work, our group contributed working papers and innovative ideas that helped push forward the discussion and create better understanding and hopefully contributed to achieving a consensus on this important pillar of the Working Group’s work. We hope that the Open-Ended Working Group continues to remain ambitious and make progress incrementally towards practical organization of the POC Directory and other global CBMs, CBM measures that can build trust and confidence between the member states. As recognized and agreed in previous Open-Ended Working Group and the GGE reports, CBMs promote trust among states, help to reduce the risk of conflict by initiating interstate cooperation, and promote transparency, predictability, and stability. Israel would like to add in our own national capacity that we welcome the extensive and fruitful discussions on confidence-building measures during the Open-Ended formal and informal sessions since the last APR was adopted, as we regard this issue as an essential and important part of the Open-Ended Working Group’s work. Developing effective and sustainable international cooperation requires, in Israel’s view, a solid base of trust to which the CBMs can contribute. In this context, having an operational POC Directory and carrying out voluntary exchanges of know-how, best practices, cybersecurity methodologies, risk assessment models, threat analysis, trends, patterns, etc., can play an important role. CBMs attempt to build relationships and procedures in times of peace and stability, elements that can be used in times of crisis. Mr. Chair, Israel welcomes the details and practical Annex A, elaborating the various elements for the development and operation of the Global and Governmental Points of Contact Directory, and regards this paper as a good basis for our work going forward, as we hope to further streamline the text and start as early as possible our work building and operationalizing the Global POC Directory. On capacity building, as many members have mentioned, cybersecurity is an urgent issue. Currently, the growth of risk far outpaces defensive capabilities and capacity building efforts. The global community needs to do more and to do it much faster. Israel’s capacity building efforts are aimed at improving global resilience on a politically neutral basis, thus adopting a constructive and cooperative approach while encouraging innovation. Mr. Chair, Israel is actively sharing best practices with many countries and organizations who wish to build their own national cybersecurity capacities, and we are ready to collaborate with additional states and organizations on this important matter. Last January, the permanent mission official to the UN here in New York, in cooperation with Israel’s National Cyber Directorate, hosted a special event at the UN headquarters named Stronger Together: Collaboration for a Cyber-Safe World, a special cyber summit featuring some of Israel’s top experts discussing how nations can stay safe in a world full of existing and new threats. Israel can support in principle the idea presented in the Indian initiative mentioned in paragraphs 40E and 44 to develop a global cybersecurity cooperation portal. This idea still requires further discussion in order to understand how the suggested new portal, the GCSCP, can add on and complement the existing frameworks for capacity building and portals developed and maintained by the GFCE, of which Israel is proud to be among its founders. Thank you, Mr. Chairman.

Ambassador Gafoor

Thank you, Israel, for your contribution. Japan to be followed by Australia.

Japan

Thank you, Mr. Chair. Thank you for giving me the floor to make a statement on Section E and F. With regard to Section E, confidence-building measures, Japan is of the view that it is important to promote confidence-building measures and therefore welcomes the establishment and operationalization of the Global POC Directory as an important step forward in building confidence between states at the global level. On Section F, capacity building, Japan strongly believes that capacity building is essential for maintaining peace and stability and promoting a free, fair, and secure cyberspace. In this context, we welcome lots of interesting proposals made in the recommendation section, but as the Australian delegation has stated, it is also true that there is a concern about resources. The UN Secretariat could be overburdened. In this regard, Japan is of the view that we should make the most of the existing capacity-building efforts conducted by other international organizations such as UNIDIR, ITU, and the World Bank, regional and sub-regional organizations including ASEAN, as well as other relevant stakeholders such as GFCE. In this context, we would like to support the U.S. proposal regarding Paragraph 43. Regarding Paragraph 40E and 44, Japan is of the view that the proposal for a Global Cyber Security Cooperation Portal is an interesting idea which merits further discussions, including on how to synergize with other existing portals of UNIDIR and GFCE. In this regard, we support the proposal made by New Zealand and the United States. Thank you, Chair.

Ambassador Gafoor

Thank you, Japan. Australia, to be followed by the Netherlands. Australia, please.

Australia

Thank you, Chair. Australia aligns with the statement delivered by Fiji on behalf of a cross-regional group of confidence builders, and we very much welcome the depth being added to our ambition here in the confidence building measures chapter. But I will focus very briefly on some additional proposals to improve the chapter, we hope. First, on paragraph 35, the chapeau, we suggest including a reference to the purpose of confidence building measures here, that is, that they promote stability and help to reduce the risk of misunderstanding, escalation, and conflict by fostering trust, cooperation, transparency, and predictability. And this is a direct quote from all of the reports in various forms. We’d also like to see this purpose replace the second half of the sentence in paragraph 35F on how the OEWG itself contributes to the building of trust and confidence. As mentioned yesterday, we think that paragraph 35D is very closely linked to the proposal set out in paragraphs 14 and 20 of the threats chapter, and that the proposal from the threats chapter could be moved here. In paragraph 39, we would request the replacement of the term endorse here with recommend to better reflect what this group does. Turning to the annex, setting out the point of contacts directory, apart from expressing considerable support for the very practical nature of this annex, we have two small tweaks to suggest. First, in paragraph 13 of the annex, we would like to make sure that it is very clear that the capacity building programs are voluntary, so as not to overburden any new point of contacts, and also that they will be developed consistent with the principles for capacity building set out at annex C. We’d also support Germany’s proposal to update the language describing the capacity building roadmap in this paragraph. In paragraph 15, we would suggest that the Secretariat convene meetings of the point of contacts rather than the Chair of the Open-Ended Working Group to ensure that this mechanism remains permanent even if and after 2025. Turning to the chapter on capacity building, Australia considers this a very strong chapter, and it reflects the importance of this topic to many of us in the room. We do have a couple of proposals. In paragraph 40’s chapeau, we think that the third sentence could be replaced to flip the references. So first, we stress the importance of capacity building to all elements of our cumulative and evolving framework, and then we include that this includes confidence building and building trust and confidence between states. On this paragraph, Australia can also support Cuba’s proposal to include reference to the capacity building principles from the 2021 OEWG, which is also at annex C. In paragraph 40, subparagraph C, we’d suggest some changes to streamline this paragraph so that it emphasizes the importance of coordination without singling out particularly specific roles, but rather than going into detail, I will simply support the proposals from Indonesia, the U.S., and Japan to streamline this paragraph. In the first sentence of paragraph 40E, we would suggest replacing the reference to the initiative with to a proposal, and this is for consistency across the references to proposals in the report, and we’d also propose replacing the word develop with engage in further focused discussions. This proposal has been discussed, and Australia is supportive of this proposal being reflected in our report, and we want to engage in further focused discussions on the proposal similar to the way that we did over the past year regarding the point of contacts directory. With Chile, we think it is very important in this paragraph to retain specific references to UNIDIR and GFCE and their existing mechanisms, and we’d support New Zealand’s proposal to keep references to this initiative and this proposal within the descriptive part of our report rather than the recommendations. We could support the proposal from Germany to reword the last sentence of paragraph 40F, and finally, I finish by noting that it is very important to Australia to retain references in both of these chapters to regional and sub-regional organizations and their roles, also to the role of the private sector and civil society, and references to gender dimensions. We’ll submit all of these in writing to the Secretariat and the Chair. Thank you.

Ambassador Gafoor

Thank you, Australia, for your statement. Netherlands to be followed by Malaysia.

Netherlands

Thank you very much, Chair. The Netherlands aligns with the statements made by the European Union, as well as the statement delivered by Fiji on behalf of the informal and cross-regional group of states to advance confidence-building measures within the Open-Ended Working Group. On paragraph 35E, the Netherlands believes that engaging with regional organizations and sub-regional organizations and interested stakeholders, including businesses, non-governmental organizations, and academia in aspects of confidence-building, is very important. In annex A, paragraph 3, we welcome the language around the voluntary and complementary nature of the POC directory. We also welcome the initial list of voluntary CBMs, and we look forward to working together to operationalize and implement this. Then on capacity-building, capacity-building is a cornerstone to ensure a peaceful, stable, and secure cyberspace. All stakeholders have a role in building capacity. Therefore, we would like to see all stakeholders enumerated, meaning the private sector, civil society, academia, and the technical community. In paragraph 40A, we would like to propose instead of gender-sensitive capacity-building, using gender-responsive capacity-building. Then in paragraph 40B, the adjectives short-term and long-term add complexity and unclarity to the kind of capacity-building we are talking about. We would like to see those adjectives deleted. We welcome the mapping exercise in paragraph 43. The Netherlands believes that this proposal would benefit from taking into account already existing tools that reference capacity-building programs and initiatives. Capacity-building efforts are done through international and global organizations within the UN family and outside the UN family, and rightly mentioned in this report. However, we are missing the sub-regional aspects and propose this to be added after regional levels throughout the capacity-building section. There are interesting proposals that have been put forward and that are reflected in the current draft, such as the Indian proposal on a global cybersecurity cooperation portal. Such a proposal deserves further discussion. We understand that there is no intention to duplicate existing tools, and we would therefore welcome replacing synergize by complementing and building upon other existing portals in paragraph 44. Lastly, in 2021, we all agreed upon the principles for capacity-building, and we welcome work to mainstream those principles with the support of relevant stakeholders. This aspect could be added to paragraph 47. I thank you, Chair.

Ambassador Gafoor

Thank you, Netherlands, for your statement. Malaysia, to be followed by the Russian Federation.

Malaysia

In general, Malaysia is pleased with the section on CBMs in the REF1 draft of the second APR. Malaysia joins other member states to support the development of a global intergovernmental POC directory and looks forward to the adoption of NXA as the next step in the operationalization of the global POC directory. Hence, we support the recommended next steps. We also support the four proposals in paragraph 35C. For the NXA specifically, Malaysia supports the suggestions by Germany on PARA 13, and Malaysia prefers using the term onboarding. Malaysia also supports the proposal by Australia to add voluntary. Malaysia supports the proposal from New Zealand and the United States to replace the word framework and further supports the language proposed by New Zealand. On section F, capacity building, Malaysia is pleased with the section on capacity building. We support the addition of the sentence that capacity building is also an important confidence-building measure. Chair, cyber security is not amenable to a one-size-fits-all approach. So, as the capacity building needed by each state, capacity building is needed to allow states to have threat visibility to identify, detect, respond to, and recover from cyber incidents. Cyber security situational awareness will allow states to manage the threats and vulnerabilities in a proper manner in accordance with the framework of responsible states’ behavior. Having said that, Malaysia supports the addition of PARA 40BBIS addressing the digital divide and tailored capacity-building efforts, which have a clear linkage with the level of cyber security readiness and the associated needs to continuously assess the level of cyber security maturity as well as conduct national surveys. Malaysia appreciates the mention of PARA 40E on the objective of capacity building within the OEWG, which is to assist states in building institutional strength so as to enable responsible behavior in the use of ICT security. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you, Malaysia, for your statement. Russian Federation to be followed by Nicaragua.

Russia

Distinguished Chair, distinguished colleagues, the Russian delegation supports the statement made by the Cuban delegation on international law. On the section on confidence-building measures, paragraph 35B, we believe it is unacceptable to reduce the scope of the Directory to this famous framework of responsible behavior of States. This wording should be deleted in paragraph 2 of Annex A as well. This paragraph needs to be supplemented with the idea that the Directory will create a basis for cooperation between States, which in turn will help prevent conflict in information space. Paragraph 35C, this should be deleted from the draft report and from Annex B. Retaining this paragraph would only make sense in Annex A. Its provisions relate to the development and operationalization of the POC’s Directory and cannot be considered as a separate confidence-building measure. Paragraph 35E, this needs to be deleted because interaction with regional organizations and non-State actors is already reflected in the preamble and is not relevant to confidence-building measures between States. With regard to Annex A on the POC’s Directory, I would like to make the following remarks. First of all, interaction between POCs should be built on an ongoing basis regardless of the significance of a computer incident. If not properly addressed, even a minor computer attack can turn into a national-scale or even international incident. In this regard, we consider it inappropriate to limit cooperation to incidents with possible implications for international peace and security. The scope of the Directory needs to be clarified as well. Preventing escalation of tensions between States resulting from the use of ICTs and the technical aspects of computer incident response, as well as investigation of persons responsible for computer attacks, should be carried out by law enforcement agencies. To ensure the effectiveness of the Directory, it’s necessary to clearly identify the functions of each type of POC and describe the areas of their interaction. Participation in the Directory is voluntary for States, as is the implementation of any other confidence-building measure. In this regard, we consider it inappropriate to reiterate the voluntary nature of the POC’s functions in paragraph 9. The Global Intergovernmental POC’s Directory should become the cornerstone of the interaction of countries in response to computer attacks and incidents. Relevant regional initiatives could feed into and complement the UN’s activities within this proposed Directory, but not the other way around. This fundamental aspect of interaction between the Directory that we’re about to establish and the existing regional initiatives should be reflected in paragraphs 4 and 12. Conducting simulation exercises of POCs by December 2023, which means even before the actual establishment of the Directory, would be premature. We propose scheduling practical activities involving POCs for 2024, for example, in June after the possible operationalization of this mechanism. In Annex B, we propose making CBM 4 on the appointment of POCs into the first CBM and adjusting its wording in accordance with the provisions of Annex A on the POC’s Directory. CBM 5, as I mentioned earlier, should be excluded. In CBM 2, subparagraph C, we suggest adding content on the voluntary exchange of national legislation on the use of ICTs. This exchange of views should be organized within the OEWG itself. As for capacity building, that section, we’re paying increasing attention to capacity building and the use of ICTs, taking into account the vast unifying potential of this topic. We propose amending a number of provisions of this section of the draft report in order to ensure true security for those countries that are the most vulnerable in information space. We have repeatedly pointed out the need for a balanced reflection in the text of the implementation of existing rules, norms, and principles of responsible behavior of States in the digital sphere and the development of new norms. Following this logic, it’s important to provide in paragraph 40B for the possibility of further development of the initial framework of responsible behavior of States along with its observance and implementation. In paragraph 42, it is inappropriate to limit the capacity building effort undertaken by specialized UN agencies and international organizations to the mere implementation of norms. In paragraph 40, we consider it unreasonable to single out the program on capacity building, dividing it into a short-term, medium-term, and long-term. We believe it is unjustified to single out the Global Forum on Cyber Expertise or the GFCE among all of the existing non-state entities that are prepared to engage in capacity building activities within the OEWG. That is paragraphs 40E and 44. We believe that all those who wish to participate in the process should have equal opportunity to do so. It is also unacceptable to place this NGO on the same level as a UN entity, that is UNIDIR. We propose not linking capacity building efforts to gender aspects in paragraph 40A. As previously mentioned in the preamble of the draft report, the non-consensual term stakeholders should be replaced by other interested parties, which is enshrined in the mandate of the OEWG. It would be advisable to remove from paragraph 40G provisions that are not related to the mandate of the OEWG, in particular on the role of the private sector in the provision of internet access and digital services. The role of States’ engagement with nongovernmental actors when it comes to policymaking and confidence building in the area of capacity building is overstated, paragraph 40G. Mr. Chair, we’ll send specific proposals for amendments to the text in separate sections. The Russian Federation also supports the statement made by Venezuela, especially the unpredictability of unilateral restrictions in the context of capacity building. Thank you.

Ambassador Gafoor

Thank you for your statement, Russian Federation. Nicaragua, to be followed by Kenya.

Nicaragua

Thank you very much, Mr. Chairman. We welcome the inclusion in the draft report of a recommendation to establish a global directory and intergovernmental directory of points of contact in the POC for the exchange of information on cyberattacks as well as incidents, which will be one of the most specific and operative results of this working group. As a result, it should be reflected as confidence-building measure number one. We reiterate that the directory is voluntary for states as well as the application of any other confidence-building measure. In paragraph 36 of the recommendation, we favor the proposal of Cuba to include confidence-building measures in order to reduce the digital gap and to ensure universal, inclusive, and non-discriminatory access to information and to knowledge through ICTs. In section F on capacity building, bearing in mind the difference in digital access for all as well as inequalities between countries, we should reflect that it’s developing countries that must take the leadership to provide the technology transfer capacity building, among other measures. If they don’t do this, there will be a greater burden for the developing countries that will not have the abilities or the training which is necessary to tackle the threats that we have identified in this working group. We support the proposal of Cuba at the end of the paragraph – at the end of paragraph 40, when we refer to questions such as – well, that was – were emphasized by the working group. We propose to add the principle of common but differentiated responsibilities, which should be applied with respect to the provision of training, as well as a call to refrain from any coercive unilateral measure which would prevent universal access to the benefits of ICTs or which would restrict or deny in any way to developing countries the science and knowledge and technology services related to ICTs and other aspects for peaceful purposes. In paragraph D, we would like to limit the reference – the North-South cooperation reference to add the sense as a complement to North-South cooperation. Thank you very much.

Ambassador Gafoor

Thank you, Nicaragua, for your statement. Kenya, to be followed by Costa Rica. Kenya, please.

Kenya

Thank you, Chair. Kenya strongly supports capacity building measures. Capacity building is a core tenet in strengthening a country’s position for protection against malicious cyber activity. This is true from legal, technical, and policy perspectives, hence the need to double up efforts in promoting capacity building. We appreciate the various aspects that have been initiated by global partners and agencies, for instance, the GFCE and the just concluded Women in Cyber Training and World Bank initiatives in promoting cyber security capacity building. We encourage members to support additional avenues specifically targeted at capacity building in cyber security. Indeed, various delegates have expressed interest in online learning portals in which member states can tap into and leverage. We support the statement in paragraph 44 for discussions on the proposal of a global cyber security cooperation portal developed under the auspices of the UN. Further discussions can take place on how to synergize the exercise with existing works. We support paragraph 45 in a request to convene a dedicated global roundtable meeting on ICT security capacity building measures during the intersessional period to allow for an exchange of information and best practices. Kenya further reiterates that any capacity building process should capitalize on both local and international expertise for peer-to-peer capacity building in acknowledgment of the diverse growth and unique circumstances of the various member states. With regards to gaps, based on our experience, there is a need to build capacity to ensure that all critical sectors have a fully-fledged sector-specific CSIRT to deal with the ever-evolving and increasing cyber threats. The development of these CSIRTs has assisted Kenya in implementing a coordinated and structured framework for response to cyber threats in various sectors. Kenya strongly urges for enhanced capacity building to assure safety for all users, including marginalized communities, disadvantaged groups, women, and children. The program is a critical investment in ensuring that children, the youth, and other vulnerable groups can derive full benefits from ICTs in a safe and secure manner. We will submit additional statements in writing. I thank you, Chair.

Ambassador Gafoor

Thank you very much, Kenya, for your statement. Costa Rica, please.

Costa Rica

Thank you, Chair. In the section on confidence-building measures, Costa Rica agrees with what was said by the delegation of Fiji. In our national capacity, we would like to make the following comments and to encourage the participation of regional and sub-regional organizations, of stakeholders, as we see in sub-paragraph 35E. We welcome the swift consolidation of the POC directory. We recommend that we consider in the future policies, frameworks, and norms to be followed with respect to the exchange of information, including policies and protocols which were agreed to by the existing CSIRTs, as well as relevant laws and standards concerning data protection and respect for human rights. And we urge states to consider their link with the Computer Incident Response Center for Civil Society. In the capacity-building section, Costa Rica agrees with the statement made by Argentina on behalf of the group of countries in this area. In paragraph 40, Costa Rica recommends that we strengthen language, recognizing that stakeholders contribute to a broad range of capacity-building efforts, including training, research, as well as the facilitation of access. We would like the wording of the report to better reflect the contributions of stakeholders and non-governmental stakeholders in the improvement of capacity-building, as well as the added value in the implementation of results of cybernetic capacity. This could be achieved by adding to the text in paragraph 42 that non-governmental organizations should also participate along with UN entities and international organizations, and should be included in the mapping exercise that is referred to in paragraph 43. We support the maintenance of paragraph 45. Costa Rica supports the references to the promotion of capacity-building, which take into account gender, in paragraphs 40 and 47, and we recommend that we make a direct reference to the principles of capacity-building of the report of 2021 of the Open-Ended Working Group, that capacity-building should respect human rights as well as fundamental freedoms, should be sensitive to gender, inclusive – that be inclusive, universal, and non-discriminatory. And lastly, Costa Rica would like to strengthen the importance of strengthening international cooperation as a global public good. In this respect, we do support the inclusion of the regional cooperation approach of paragraph 48, and we acknowledge the positive impact of capacity-building at the regional level as well as dialogues between multiple stakeholders. Thank you very much.

Ambassador Gafoor

Thank you very much, Costa Rica. I’d like to give the floor now to the ICRC, which has requested the floor, please.

Thank you very much, Chair. In the interest of time, I’ll keep my statement very brief. The International Committee of the Red Cross is grateful for the opportunity to address this fifth session of the Open-Ended Working Group. The ICRC’s mandate as a neutral, impartial humanitarian organization is to protect the lives and dignity of victims of armed conflict. Based on our operations in all contemporary armed conflicts, we share the concern expressed in the draft progress report that, quote, “ICTs have been used in conflicts in different regions,” unquote, and that their use, quote, “in future conflicts between states is becoming more likely,” unquote. We strongly support the clear statement of concern about the impact that ICT activities can have on civilian infrastructure. In light of the threats identified in the draft progress report, we cannot overemphasize the need for dedicated discussions on topics of international law, as recommended in the Chair’s draft progress report, in particular on international humanitarian law. Focused, non-politicized, and inclusive exchanges can provide a forum for states to further study how and when IHL applies, and therefore imposes limits on the use of ICTs during armed conflict. Such discussions should by no means legitimize or encourage conflict, but instead address very real humanitarian concerns. As an observer in this Open-Ended Working Group and a humanitarian organization with a mandate to work for the understanding and dissemination of knowledge of international humanitarian law applicable in armed conflicts, we are available to contribute to such discussions. We will also continue to support exchanges between states and capacity building on international humanitarian law, for example, through consultations and training courses in different regions of the world. We are delighted to announce that we have just released the reports of a regional consultation in the Asia-Pacific region on international humanitarian law and cyber operations during armed conflict, which we organized jointly with the government of the Republic of Indonesia. I thank you very much.

Ambassador Gafoor

Thank you very much, ICRC, for your statement. It’s six o’clock, and I have no other requests for the floor on this section. We have to wrap up for the day, but I wanted to say that, so far, I’d like to publicly praise all of you. If you were in a school in Singapore, you would get top marks for having come thoroughly prepared, for having done your homework by looking through the draft report very, very carefully. This encourages me a great deal because it demonstrates your commitment to the process, your commitment to an outcome at the end of the week, and your commitment to own the outcome collectively. So that’s very, very encouraging. Second, of course, many of you had a long list of suggestions, edits, proposals, modifications, etc. I’ve listened carefully, I’ve taken notes, and so has my team. Many of you have said you will submit your remarks, and we will look at them as well in writing when you send your proposals, if you wish to send them to us. I’ll do my best to see how we can reflect all the comments that have been made. There were many comments that were echoing each other, but there were also comments where there were clearly disagreements, and so a choice would have to be made. A path has to be found for those kinds of amendments, and that will require me to reflect quite carefully. In finding a path forward, I think we all need to keep in mind that ultimately it’s about finding the balance necessary for us as a working group to be in a position to adopt an outcome document by consensus. This is not an exact science. This is not arithmetic in terms of how many delegations have said what and in support of which proposal. It’s not an algorithm that works here. It is ultimately a question of judgment. It’s a question of finding that balance. And so that is going to be the challenge. Finding that balance is going to be a challenge because balance, as I’ve said before, always lies in the eye of the beholder. Balance, like beauty, is difficult to define, let alone capture. So it may well look like something that may not be very beautiful for every one of you, but what is important is that each one of you will need to keep an open mind, demonstrate your flexibility, and look at the overall balance of the text, not whether every single proposal that you have made has been accommodated. So these are some broad comments that I want to make. There’s plenty of good material that has come from the first two days of discussions, and I think this bodes well. I sense that there is a lot of commitment to having an outcome and quite a fair bit of convergence on the CBMs as well as the capacity building section. The discussions on international law and norms were a little more animated, with greater gaps in that discussion earlier in the morning. But overall, I think it has been a very, very good two days. Tomorrow morning, I intend for us to start the discussion on regular institutional dialogue, which is the last section, and then we will have completed the first reading of the REP1. Tomorrow afternoon, we will go to that dedicated stakeholder session, which has been scheduled as part of the agreed modalities of this working group. That is for the afternoon. As I told you at the outset this afternoon, it is my intention to produce a REP2 by the end of the day tomorrow. I can’t say at this point at precisely what time a second revision will be available because it depends on what time we finish our discussions in the morning and whether I can find some time to sit down with my team to go through the drafting and then also in the afternoon. It is my hope that the stakeholder discussion will not take the entire three hours of the afternoon so that I will have some additional time to work on the revised draft as well. So friends, colleagues, thank you so much for all your contributions today. I think you deserve a drink and you deserve a rest, and I wish all of you a very pleasant evening. See you tomorrow at 10 a.m. The meeting is adjourned. Thank you.

Leave a Reply

Your email address will not be published. Required fields are marked *