Ambassador Gafoor
The third meeting of the sixth substantive session of the OEWG on security of and in the use of ICTs, established pursuant to General Assembly resolution 75/240, is now called to order. Distinguished delegates, we will now continue with our consideration of agenda item 5. And as I indicated yesterday afternoon, just before we adjourned, we have two more speakers. I’ll take them and then we’ll proceed to the next cluster of issues under the program of work, which is rules and norms. So I now give the floor to Djibouti, to be followed by Indonesia, as the two last speakers under the first cluster of issues. And then those who wish to speak under rules and norms can indicate by pressing the buttons now, so I’ll have a sense of the list of speakers. So we’ll start with Djibouti, to be followed by Indonesia. Djibouti, please.
Djibouti
Thank you, Mr. Chair. Thank you for giving us the floor. This is the first time I’m speaking on this issue, so on behalf of my country, let me congratulate you and your team on the excellent work proceeding here on cybersecurity. My delegation appreciates the progress made in the spirit of consensus with the contribution of all stakeholders. We support this cooperation and wish all of us great success in this working group. Djibouti recognizes that the rapid progress in information technologies around the world has changed the modes of communication and management, and has contributed to greater effectiveness and efficiency, and sometimes helped prevent natural disasters. So we believe that ICT is a necessary technology to accelerate work toward SDGs, based on safe, secure, and responsible governance of the digital domain. Unfortunately, we are concerned by the risks involved in the process, and the potential threats that could lead to malicious use of cyber by cyber criminals and terrorists. Such malicious attacks, as is emphasized in the second report of the working group, are very deeply concerning, and require states to throw enormous amounts of money at the problem. These threats, existing and potential, could undermine the stability of our economies, peace, and security around the world. For developing countries in particular, countering cyber threats is an issue. It requires great funds and competes with other development priorities. We hope that this group, with the support of experts, will arrive at a solution that will allow all of us to protect and make safe our critical infrastructures. We hope that this sixth session would consolidate efforts of the previous sessions. Djibouti supports all initiatives that make it possible to put in place a voluntary and legally binding mechanism to guarantee safety and security in cyberspace. We have supported all the resolutions submitted to the General Assembly on this issue, and we hope that these resolutions do not offer duplication of parallel programs, rather complement the work of OEWG. Mr. Chair, we suggest that the international community redouble its efforts and raise sufficient funds to promote capacity building in countries to counter the cyber threats. We call for a sincere dialogue and a stepwise implementation of a future mechanism under the auspices of the United Nations. Therefore, we welcome the program to implement a point of contact directory. Having said that, we hope that this platform offered by the working group could truly strengthen trust and dialogue. In conclusion, once again, the greatest challenge is to put in place an inclusive legally binding mechanism under the auspices of the United Nations to counter cyber threats. I hope that the intent bringing us together here dominates over things that divide us and that we can move toward this objective. Thank you very much for your attention. I wish every success to this sixth session of the Open-Ended Working Group. Thank you.
Ambassador Gafoor
Thank you very much, Djibouti, for your intervention. I give the floor now to Indonesia, please.
Indonesia
Chair, allow me to first express our appreciation for your able leadership in steering the Open-Ended Working Group into its sixth substantive session. Indonesia welcomes the resumption of the 2021-2025 Open-Ended Working Group on ICT as the only existing mechanism under the United Nations to discuss the issue of ICT in the sphere of international peace and security. Mr. Chair, in the past two years, the Indonesian National Cyber and Crypto Agency detected numerous cyber security incidents, most in the form of data breaches and ransomware attacks towards government sites, national banks, and electronic trading platforms in Indonesia. As many as 900,000 ransomware attacks were detected in 2022, while from January to October 2023, the number was close to 900,000. Three ransomware commonly found in Indonesia are LockBit 3.0, LunaMon, and WannaCry. Ransomware attacks are a serious threat to national security stability and could disrupt the economy, especially supply chains. To further advance efforts on both preventing and responding to existing and potential threats, my delegation wishes to put forward the following three points. First, there is an increased need for cyber security awareness campaigns. Such campaigns will enhance the public’s knowledge on the many forms of cyber threats and ways to better protect themselves and their organizations from cyber attacks. Second, a cross-border information sharing platform needs to be developed to increase situational awareness regarding cyber attacks such as ransomware, as well as other new threats generated by artificial intelligence. This mechanism is particularly important for states that are still at the stage of developing their ICT capability. Third, build a global network of Computer Emergency Response Teams, CERTs, to facilitate exchange of information and continuous coordination for handling cyber incidents and organizing joint exercises to identify and respond to malicious cyberspace activities. I thank you.
Ambassador Gafoor
Thank you very much, Indonesia, for your statement. So that was the last statement on the first cluster. Before we go to the next cluster, I just wanted to highlight a few points, and I’m not intending to make a summary. But I wanted to give all of you top marks and A+ for responding to the guiding questions that I circulated. I think all of you made that effort, and I appreciate that, and I think we are collectively the better for it, because I thought we had a discussion which was very detailed, quite in-depth, and probably for the first time in this context, also very candid. It didn’t mean we agreed on everything, but we had a very candid discussion. And the value of that discussion lies in itself, in having that candid discussion, because I think such a discussion could only have taken place here at the UN, in an open-ended and inclusive setting. So that in itself was very useful, and I hope that it was useful as well for each of your delegations. We also heard from delegations that had not previously expressed a view on this issue, so that too, I think, was very useful to hear from delegations that had previously not spoken on this particular cluster. And that, I think, also makes the discussion richer and more useful. I was struck by the fact that a lot of you said, let’s have more detailed discussions, as if the detailed discussions yesterday and this morning were not enough. So your appetite is there for a deeper discussion, and many of you also referred to the dedicated intersessional meetings, where you hoped that you could go deeper into the discussions. Now that indeed was the idea of the dedicated intersessional meetings. And on this, I wanted to point out that in my letter, dated 17 August 2023, I had laid out a schedule of OEWG meetings, and the letter should be on the website of the OEWG. And in that letter, as part of that schedule, I identified the period 13 to 17 May as the week for all the dedicated intersessional meetings. Now, in the second annual progress report, we agreed to have a series of dedicated intersessional meetings for the various clusters, one dedicated intersessional meeting for each of the clusters, and two for regular institutional dialogue. So my intention is to use the week of 13 to 17 May to organize the various dedicated intersessional meetings in sequence, and that will be the week where we can hopefully go much deeper into the various clusters. And the dedicated intersessional meetings would also be designed such that we hear views of stakeholders with due regard for equitable geographical representation. So I’ll need to give some thought to that, but I just wanted to address that point about dedicated intersessional meetings, because quite a number of you said you supported it and you looked forward to having deeper discussions. So your wish is going to come true. This is the season for making wishes. So your wish will come true next year. We will have deeper discussions on this issue of existing and potential threats. But the usefulness of that discussion lies not just in describing emerging existing potential threats, but also thinking about potential cooperative measures. So as you prepare for the next phase of our discussion on this particular topic of existing and potential threats, please also keep in mind, having identified the existing and potential threats, what do you think we ought to do collectively here at the UN? And what can we do in terms of cooperative measures to address or respond to these threats? In any event, I think we have made a very good start. And the discussion today certainly has raised the level of awareness about the threat landscape. And I hope that each one of you will bring back this heightened level of awareness back to your own capitals and then have your own internal discussions. So that when we come back, we can think about what we can do collectively as cooperative measures. So, I think the appetite to get deeper into the discussion to discuss emerging and existing potential threats seems to be growing. I’ve had one more request from the Russian Federation to address this particular issue. I do not wish to spoil anyone’s appetite, but we do need to cross to the next cluster. So, Russian Federation, I hope to have a brief intervention from you. You have the floor, please.
Russia
Mr. Chair, I will be brief. We wanted to support yesterday’s statement by the Arab Group, presented here by Egypt, on the inadmissibility of politicizing the OEWG process, regardless of the subjects used for that purpose. Thank you.
Ambassador Gafoor
Thank you very much, Russian Federation. Your point is well noted. Before we go to the next cluster, let me just say that at the UN, everything is political and everything can be politicized. So we have to make a choice. I’m happy to have expressions of views, comments made on the issues that are going to be discussed in the Security Council or the emergency special session or in other committees. We can discuss the problems of the world in this Open-Ended Working Group, and we can do that because you take the floor. You are sovereign equals as representatives of your delegations, and you have the right to say what you wish or what your capital has asked you to convey here. But if we did that, there is also the risk that we will be delayed and distracted from our core mandate. Now, yesterday’s discussion was the first day, and I recognize the need for delegations to make certain views and register them, and they are all well noted, well registered. But I hope that for the remaining few days that we have, it is my appeal to all delegations that we focus on the issues directly related to the mandate of the Working Group and to address the different clusters and the different guiding questions. I hope that I would have the understanding and cooperation of all delegations. But at the same time, I can’t stop you from raising other issues, but if you do, others will exercise their right of reply, and rights of reply under the rules of procedure require a certain amount of time, so that will take a fair bit of our time. So that’s the trade-off that is before you, but I do appeal to all of you, having made the views that you have registered yesterday, that we can focus in a laser-like way on the guiding questions and on the clusters of issues under Agenda Item 5 of the mandate of the Working Group. So that’s an appeal from the podium, and I hope that you will take that to heart. It is put to you with good intentions and in the hope of making progress in this Working Group. So, having said that, I’d like to move on to the next cluster of issues, which is rules, norms, and principles of responsible behavior of states and the ways for the implementation and, if necessary, to introduce changes to them or elaborate additional rules of behavior. So the floor is open now for this cluster. Please feel free to press your buttons now so we have a sense of the number of delegations. I start by giving the floor to Tonga, to be followed by the Islamic Republic of Iran. Tonga, please.
Tonga
Chair, I seek your indulgence, please, to add to the discussions on Cluster 1, as it is also Tonga’s first time to add to this cluster, and I apologize for holding everyone up from moving on to the next cluster. Chair, my delegation would like to congratulate you and your team for the dedicated work of advancing further development in our mandate, with the adoption by consensus of the second annual progress report. We remain committed to working with you and all the delegations in this and upcoming sessions of the Working Group. Chair, with regards to the first of your guiding questions, my delegation is of the view that this group should have in-depth discussions on attacks against critical infrastructure, the threat of artificial intelligence and quantum computing, the spillover effects of cyber attacks on developing countries, in particular small island developing states, phishing, and ransomware. We note with concern the attacks against critical infrastructure and society at large as described by the Honorable Delegates from the U.S. and the U.K. These attacks are taking place around the world, and attribution, like in the case of the U.K., helps us all build a world where countries conform to the norms of behavior we have all committed ourselves to. Tonga is a small island developing state with a population of just over 100,000. You can only imagine the destructive nature of such attacks against our country. Technology is developing faster than any government can keep up with. While this offers immense economic opportunities, it is important that we have the appropriate capabilities in place to identify and respond to any new threats that may emerge. This is particularly true on new technologies such as AI and quantum computing, where the exponential proliferation of threats and risks is real to countries, particularly in the developing world. I will also recall the meeting of the Pacific Island Forum in November of this year, where our leaders urged a cautious approach to new developments in the technological field, including artificial intelligence. For Tonga, ransomware remains a real threat. In February of this year, our government-owned telecommunications company suffered a ransomware attack, encrypting and locking access to part of its system. Although the effects were not as far-reaching as seen in other member states, it is evident that we, too, a small island developing state in the South Pacific, are extremely vulnerable to ransomware. It has the potential to inhibit the day-to-day operation of our country. It is also important to remember that with these destructive cyberattacks, the victims are not some abstract computer systems, but very real people who might see their livelihoods or personal lives damaged. Ransomware attacks against government services also have widespread effects. Chair, with regard to your second guiding question, what initiatives can be undertaken at the global level towards this objective? As the distinguished delegate from Australia eloquently explained, there should be adherence to the norms of responsible state behavior in cyberspace. Furthermore, my delegation welcomes Kenya’s proposal for a repository. Lastly, we continue to support the establishment of a global points of contact directory for the sharing of existing and potential threats among member states. We believe these initiatives should allow for sharing of information and threat intelligence to assist CERT to CERT in addressing cyber threats. We have already seen the benefits of these networks at the regional level. How much more, then, at this global level? Thank you, Chair.
Ambassador Gafoor
Thank you very much, Tonga. Islamic Republic of Iran, to be followed by Qatar.
Iran
Thank you, Mr. Chair. Mr. Chair, on a specific note, we reject any politicized and unsubstantiated attribution raised yesterday by the U.S. delegation against my country, and rather, we believe that the U.S. must be held accountable for its role in the notorious Stuxnet attack and others against Iran’s targeted infrastructures. In fact, the U.S. offensive cyber program is a real cause of insecurity in the world. And on the agenda items under consideration, considering the legal and interconnected nature of this section on rules, norms, and principles, and the section on international law, I would like to present my delegation’s perspectives on these sections together. The Islamic Republic of Iran has previously provided detailed insights into these critical issues in our earlier submissions, and those viewpoints remain valid. We have emphasized the importance of preliminary discussions before operationalizing any envisaged norms as outlined in the founding resolution of this OEWG. Our stance calls for further exploration, modification, or addition to the 13 norms outlined in paragraph 1 of resolution 173-27. As you would recall, we have proposed concrete norms for consideration of the OEWG. We have also highlighted the necessity for a structured dialogue addressing the ambiguity surrounding the understanding of these norms. Concerning the international law, again, our position remains consistent with our previous statements. We assert that while behavior in cyberspace may differ from that in the physical world, the application of general principles of the UN Charter to the use of ICTs is not precluded. What remains is the development of a legally binding instrument to address gaps arising from the unique features of ICTs and reconcile the broader possibilities and limitations within the existing international legal framework. It is notable that a coalition of countries predominantly from the developing world, along with Russia and China, contends that existing international law is inadequate for ensuring international peace and security in the realm of ICT. Having thoroughly examined the merits and drawbacks of the need for a legally binding instrument in cyberspace, I’m honored to articulate our rationale as proponents of such a framework and address the observations of those opposing it as follows. One, the UN Charter, given its nature, is different from an international treaty and its internal ratification by the legislative bodies of countries has not been foreseen in treaty law. Although the Charter has provisions that can guide the state’s behavior for ICT security purposes, it is not sufficient to fulfill the main objective. At the same time, given the specific legal nature of the information environment, the activities therein can be anonymous and the application of international law to the use of information and communications technologies should not be automatic and should not be carried out by simple extrapolation. There is a need to substantively discuss the issue of how specific instruments of existing international law apply to the ICT sphere, as well as to elaborate a universal approach to this matter under the UN auspices. Moreover, there are serious doubts regarding the notion of legitimate self-defense in ICT space based on Article 51 of the Charter. The explicit text of the provision recognizes self-defense against an armed attack, but the question is whether an ICT attack constitutes and can be assumed equal to an armed attack. Besides a chaotic implication of factual attribution by states, we know that the tools used in an ICT attack are not conventional military weapons. The belief in the applicability of international humanitarian law in ICT space, even if it is not directly a legal justification for resorting to force in ICT space, certainly will not prevent such actions. In this regard, an analogy can be drawn between the deployment of police with legally binding authority versus deployment of ambulances and first aid without legally binding authority in a tense and crowded stadium. The question is, which one can better deter resorting to force? Whether people comply with their law due to fear of punishment by the police or with confidence in accessing first aid, they can resort to force easily and without caution. Two, should non-binding and voluntary instruments be sufficiently effective for achieving peace and ICT security, we would not witness many ICT disputes among states. There is no obstacle to voluntarily implementing the relevant regulations, and in fact, their voluntary nature does not need to push countries to full and effective implementation because their implementation is optional and countries can choose whether or not to enforce them according to their discretion. Three, the codification and development of all international treaties, including those on disarmament and arms control, has been time-consuming. Despite this, we witness a variety of treaties in different security areas. If the United Nations Charter was sufficient for ensuring international peace and security, why have so many treaties emerged in various security fields? Only in the field of disarmament, non-proliferation, and arms control, there exist 28 treaties and conventions within the UN framework, let alone others. Wouldn’t it have been enough to rely solely on the Charter and not allocate international resources and energy to the development of diverse treaties? Four, all legal documents in the international system, including the United Nations Charter and disarmament treaties, are subject to non-compliance. Why are these documents developed or being developed, and why should we oppose such an approach in ICT space? The solution lies not in ignoring the problem, but in establishing a strong and appropriate compliance mechanism based on lessons learned from previous experiences. Five, one additional argument of a legally binding instrument pertains to the crucial issue of attribution and its legal dimensions. According to this perspective, the assignment of responsibility for an internationally wrongful act hinges on a state violation of its international obligations. The International Law Commission has acknowledged this fundamental principle in its work on responsibility of states. From a legal standpoint, within the realm of information and communication technologies, the argument maintains that attributing a computer attack to a specific state is contingent upon the existence of an international treaty expressly prohibiting such acts. Additionally, for attribution to take place, the implicated state must be a party to the mentioned treaty. In a sense, we argue that without the framework of an internationally binding agreement explicitly prohibiting specific actions in the realm of ICTs, the legal foundation for attributing responsibility to a state becomes precarious and arguably insufficient. It underscores the importance of establishing a robust legal framework through a binding instrument to address the complexities of attribution in the evolving landscape of ICTs related activities. Finally, we emphasize that the current focus should not be on obstructing the request to develop a legally binding instrument given that the creation and implementation of such an instrument cannot be accomplished immediately and on a global level. As one of our distinct wishes, we hope to discuss further on the ways out in a dedicated session of the OEWG relying on technical and legal perspectives without resorting to politicized positions. I thank you, Mr. Chair.
Ambassador Gafoor
Thank you. Iran. Qatar to be followed by the European Union. Qatar, please.
Qatar
Mr. Chair, we resume the discussion of those very important issues that we’re commonly facing in cyberspace, especially responding to the questions on the supply chain and the infrastructure of critical information. Turning to the supply chain and ensuring work in this domain, we would like to highlight our experience in Qatar to ensure the safety of the supply chain in cyberspace. The measures and norms taken in the Qatar scheme adopted through this system respond and prove our commitment to cyberspace safety and security. Implementing such a regime ensures that we abide by all common structures, and this raises the confidence of the user and consumer. We also have a program in the local market to ensure that all service providers will have a certain degree of qualifications in providing services. Mr. Chair, I would also like to stress that the developing countries and least developed countries that are currently modernizing their ICT infrastructure can be supported through the exchange of information, expertise, and lessons learned. We can accelerate this process through specified regional centers on ICT. They can become a hub for the exchange of information. Moreover, the development of the cybersecurity strategy is a roadmap that specifies the opportunities and challenges in this vein. We stress the need to work with all critical infrastructure authorities at the local level and national level. We look forward to constructive participation in the work of the OEWG during this session. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, Qatar. European Union to be followed by Kazakhstan. EU, please.
EU
Thank you, Chair, for giving me the floor. I have the honour to speak on behalf of the European Union and its 27 member states. The candidate countries North Macedonia, Montenegro, Albania, Ukraine, the Republic of Moldova, and Bosnia and Herzegovina, the potential candidate country Georgia, and the EFTA countries Iceland and Norway, members of the European Economic Area, aligned themselves with this statement. The 11 agreed norms, complemented with existing rules of international law, are important and form a comprehensive compendium to guide state behaviour in cyberspace. Given the urgency of preventing damage to critical infrastructure stemming from malicious cyber activities, we welcome the Chair’s guiding questions focusing on norms that strengthen the protection and resilience of critical infrastructure. The recommendations of the UNGGE and the Open-Ended Working Group reports provide an important basis for addressing threats to critical infrastructure. In particular, Norm 13C and the three critical infrastructure-related norms, 13F, G, and H, can serve as a basis for advancing cooperation in order to prevent the use of ICTs to damage critical infrastructure. The norms include elements of restraint, cooperation, and transparency, bolstered by additional CBMs-related recommendations. In this regard, we welcome more substantive discussion on the measures that states have already put in place to implement and adhere to the norms. Such measures can include cybersecurity incident exercises with relevant stakeholders, creating or supporting the creation of national or regional point-of-contact networks of critical infrastructure operators, or developing or assisting other states in developing effective policies and structures to protect critical infrastructure. Such exchanges would help build trust in these initiatives and between those involved. This would help inform targeted capacity-building efforts and build sector-specific understanding. Against this background, the Open-Ended Working Group needs to keep building common understandings of the threat landscape relevant to critical infrastructure, including collecting information on the malicious use of ICTs against critical infrastructure. This is particularly relevant towards clarifications on how existing and potential threats are experienced differently by states and diverse sectors of critical infrastructure. In all of this work, there is a need for cooperation with non-governmental stakeholders, given their active role in threat detection, response, norms promotion, implementation, and capacity building. The Open-Ended Working Group could help to further elaborate the role of different stakeholders with the aim of not only identifying gaps in norms implementation to further protect critical infrastructure from the malicious use of ICTs, but also advancing common understandings on respective responsibilities and providing future guidance. That would, in turn, help with critical infrastructure-related risk management, including with regard to critical infrastructure co-dependencies, as well as identifying, classifying, and managing ICT incidents affecting critical infrastructure. Including multistakeholders’ views in the process is therefore necessary when working towards an effective and sustainable operationalization of the framework. We also think that countries should further develop clarification on the application of international law, and in particular international humanitarian law, in the use of ICTs regarding critical infrastructure. In the context of the Open-Ended Working Group, discussions about norms implementation and how international law applies to cyber operations that target critical infrastructure in peacetime and in conflict are vital for improved accountability. Specifying which laws and norms have been violated or not respected following a malicious cyber incident would assist other countries in applying the framework of responsible behavior. Promoting cooperation with the private sector, civil society, academia, and the technical community in capacity building is a necessary step contributing to a holistic cyber resilience of designated sectors and infrastructure. Similarly, the focus on developing guidance on norms implementation would make the Open-Ended Working Group more effective and enable concrete changes in how countries interpret and track these norms nationally, and how the United Nations could help countries implement them. A discussion that would be enhanced by the participation of non-governmental stakeholders that are or have been working on developing frameworks for supporting implementation. We look forward to continuing conversations on how to implement the existing rules, norms, and principles, including through capacity building, which will be under focus also later this week. Thank you.
Ambassador Gafoor
Thank you, European Union. Kazakhstan to be followed by the Republic of Korea. Kazakhstan, please.
Kazakhstan
Thank you, Chair, for giving the floor. Thank you and your distinguished team for your work in discussing individual sessions yesterday on existing and potential threats and today on rules, norms, and principles. As for the section of rules, norms, and principles, in the ensuring of cybersecurity and personal data protection, we find it important to articulate within the draft report the CIA principles. Emphasizing the adherence to these international principles is critical as they play a crucial role in ensuring cybersecurity and personal data protection. So states acknowledge the fundamental importance of upholding the principles of confidentiality, integrity, and availability within the responsible state behavior and the secure use of ICT. Through the adherence to these principles, states ensure cyber resilience, thereby contributing significantly to the reliability and resilience of the information environment. Additionally, we outline the importance of defining terms, particularly in the context of critical infrastructure, and strengthening the defenses against evolving cyber threats and attacks. We underline the following: states are encouraged to outline the importance of defining the term critical infrastructure in the use of ICT, establishing criteria for its classification, and ensuring the protection against evolving cybersecurity threats and challenges. Furthermore, we highlight the significant importance of states’ collaboration with the private sector in the ICT domain. This collaboration allows for a comprehensive examination of cybersecurity challenges from the perspective of the private sector. It is also important to note the evaluation of states’ cybersecurity strategy, emphasizing the establishment of cyber resilience and considering the integration of international experience in the ICT sector. Within the framework of the national cybersecurity strategy, it is important to underscore the state’s efforts in ensuring awareness. The recommendations to ensure cybersecurity are also deserving of attention. So we propose the following: states recognize the significance of formulating a comprehensive national strategy for the secure use of ICT, encompassing initiatives directed to enhance public awareness, capacity building, and contemplating the development of recommendations within the ICT domain. In our case, Kazakhstan has adopted its second cybersecurity strategy. Within the strategic framework, comprehensive recommendations have been formulated to guide the secure use of ICT. Concurrently, concrete efforts are underway to enhance public awareness, underscoring the nation’s commitment to advancing cybersecurity initiatives. Thank you, Chair.
Ambassador Gafoor
Thank you very much. Kazakhstan, Republic of Korea, to be followed by Slovakia. Korea, please.
South Korea
Thank you for giving the floor. Our delegation believes that, in principle, the existing international law can be applied to cyberspace, but it’s also true that there remains ambiguity as the existing international law does not consistently apply to cyberspace in the same manner as it does to other domains. In these circumstances, the non-binding and voluntary norms can play crucial roles in promoting responsible behavior among states and increasing predictability in cyberspace, thereby fostering confidence among states. We already have the set of norms that was agreed upon in the GGE and adopted at the UN General Assembly. We should try to faithfully implement the norms, focusing on their elaboration and effective implementation. In this regard, we support the recommendation in the APR to elaborate additional guidance on the implementation of norms. Sharing best practices can serve as the starting point. Mr. Chair, attacks against critical infrastructure and critical information infrastructures, CII, can destroy institutions, disrupt the economy, and result in social chaos. To protect CIIs, Korea enacted the CII Protection Act in 2001. Under the Act, the government has established the criteria and procedures for designating CII, which apply not only to public but also to private facilities. We also provide technical support, including guidelines for vulnerability analysis and assessment, and training for cyber attack responses. My delegation believes that sharing each country’s cases can bring us some clarity when implementing the norms. We also support the establishment of the Program of Action, POA, as a permanent, inclusive, and action-oriented mechanism. This can support the UN member states to implement norms in parallel with confidence-building and capacity-building measures. We look forward to having more concrete discussions on POA in the next session. Thank you.
Ambassador Gafoor
Thank you, Republic of Korea. Slovakia to be followed by the United States. Slovakia, please.
Slovakia
Thank you, Mr. Chair. Slovakia aligns itself with the statement delivered by the European Union and wishes to emphasize a couple of points in its national capacity. We have agreed in this format on multiple occasions that the 11 voluntary non-binding norms serve as a baseline for defining responsible behavior while fostering greater stability and predictability in cyberspace. While we may think of these norms as merely normative guidelines to support peaceful cyberspace, their role goes beyond this. These norms are bound up with the evolution of the normative environment, which influences the choices that individual states make with regard to mutual action. Yes, international experience since 2015, especially in the context of Russia’s war of aggression against Ukraine, has shown that agreement on norms, even when politically binding, is by itself not enough to ensure their observation or create the desired stability in cyberspace, nor is their observance proportional to the ever-expanding list of threats linked to the use of ICTs, as we heard yesterday. Compliance with the mentioned norms shall not be achieved by including more or new norms to be complied with. On the contrary, we have arrived at a critical junction where we need to focus on the implementation part of the normative framework. With this aim, we could make use of the UNIDIR survey of national implementations and Singapore’s UNUDA norms implementation checklist. Mr. Chair, we look forward to holding more focused discussions on this very topic on the basis of your draft. More specifically, we would like to point out the GGE reference from 2021 to the fundamental protection of critical infrastructure. It posits that such infrastructure forms the backbone of society’s vital functions, services, and activities, and in case of their disruption, would inflict significant damage or harm. Any activity that intentionally damages critical infrastructure or critical information infrastructure or otherwise impairs the use and operation of critical infrastructure to provide services to the public can have cascading domestic, regional, and global effects in the current connected world. It is therefore precisely at those levels that additional work could be carried out, be it in the form of sharing best practices and information regarding national legislation in this area or developing systems and platforms such as one of the pillars of the Program of Action that would allow states to identify their specific needs. This is the part of the norms implementation that is in many ways closely linked to tailored capacity building, as practical compliance oftentimes requires specific cybersecurity expertise. It is, however, needless to say that the voluntary norms are there to discourage these international wrongdoings to begin with. The incredible power that allows us all to instantly connect comes at a price. More connectivity means more vulnerabilities, more attacks, and more sophisticated strategies. Such increased interconnectivity between the digital and real world puts pressure on various sectors to adopt new safety routines. This brings me to the final point, Mr. Chair. Slovakia wishes to draw attention to norms of the 2015 GGE report, which stipulates that states, in ensuring the secure use of ICTs, should respect Human Rights Council resolutions on the promotion, protection, and enjoyment of human rights on the internet, as well as General Assembly resolutions on the right to privacy in the digital age to guarantee full respect for human rights, including the right to freedom of expression. As we have spoken on the protection of human rights in this format before, we continue to be concerned about the misuse of ICTs for human rights abuses. I did not mention this under the subject of threats, as the protection of human rights should be the norm of behavior and a common practice. We would therefore welcome others’ views on how to uphold this particular norm moving forward. Mr. Chair, Slovakia appreciates your effort to navigate these often difficult discussions, and we would like to express our hope that future sessions of the Open-Ended Working Group should build on these key issues and find ways to mitigate them further. Thank you very much.
Ambassador Gafoor
Thank you, Slovakia. United States, to be followed by Costa Rica. U.S., please.
United States
Thank you, Chair. Chair, in your guiding questions, you asked whether there are specific areas in which the implementation of the consensus norms is currently lacking, or where existing implementation efforts can be improved, and how developing countries and small states can be supported in protecting critical infrastructure. As we have previously proposed, the United States would welcome focused, issue-specific conversation within the OEWG on implementation of key norms. At this halfway point in our negotiations, we are ready to reach for deeper levels of understanding. In particular, based on the OEWG’s discussions thus far, the three norms on critical infrastructure would appear to be of universal priority interest for dedicated work. Collectively, Norms 13F, G, and H express the importance that member states attach to the protection of their critical infrastructure, and ensuring that it remains available to provide services to the public. We note that we are not starting from scratch as we seek to develop guidance on how these norms can be implemented. The 2021 GGE report, which all states have endorsed, provides remarkably robust direction on how to interpret, abide by, and reinforce each of the 11 norms. Norm 13F calls for states to refrain from cyber operations against critical infrastructure that threaten public health or safety or interfere with core governmental functions. We have all recognized that these operations are destabilizing and can be escalatory. And yet we continue to see peacetime malicious cyber activity targeting critical infrastructure that is clearly intended to threaten or coerce the injured state. There is a clear need for this group and the future POA to advance our collective expectations for state adherence to this norm on the peacetime targeting of CI and CII. Implementing Norm 13G, which reaffirms the commitment of all states to protect critical infrastructure, is a continuous effort. As new threats emerge, new protective measures can become necessary. While some of these measures are fully domestic in nature, all states would benefit from improved information sharing on threats to – excuse me – and best practices for the effective protection of critical infrastructure. Many of these resources are already publicly available. It is just a matter of knowing where to find them. For example, the United States frequently issues public cybersecurity advisories, which can raise awareness of tactics, techniques, and procedures used by malicious cyber actors to target critical infrastructure, as well as recommend actions to defend against potentially disruptive activity. These publications are posted on the website of the U.S. Cybersecurity and Infrastructure Security Agency, also known as CISA, and are available to all. CISA’s website also hosts a cyber resources hub that, among other things, provides step-by-step guidance for organizations and agencies to self-assess their resilience in cybersecurity. Perhaps the most fruitful work for this group and the future POA to undertake would be to improve implementation of Norm 13H on responding to requests for assistance. This norm states that states should respond to requests for assistance by a victim state whose critical infrastructure was targeted by malicious cyber activity, including in instances where the malicious cyber activity is emanating from that state’s territory. We note that it shares implementation overlaps with another norm, Norm 13C, which provides that states should not knowingly allow their territory to be used for internationally wrongful acts using ICTs. The expectation that states honor appropriate requests for assistance raises some questions. For example, how can existing POC directories be leveraged? What information should the requesting state include? What are the expectations for response? What communications channel is preferred? To ensure that these norms can be leveraged in times of urgency, the OEWG should provide clear guidance on how victim states should communicate requests and how recipient states should respond. We also should recognize that sufficient domestic structures and mechanisms would need to be in place for states to act effectively in this area. And capacity building issues should also be discussed within this issue set. Some regional organizations have already developed such formats and procedures. The OEWG would provide a significant contribution to international cyber stability if it advanced guidance on the norms calling on states to protect critical infrastructure, refrain from harming such infrastructure, and help victims recover from significant cyber incidents targeting CI. These norms are the heart of our work. Thank you, Chair.
Ambassador Gafoor
Thank you very much, United States. Costa Rica to be followed by the Russian Federation.
Costa Rica
Thank you, Mr. Chairman. On November 13th, Costa Rica launched the National Cybersecurity Strategy 2023-2027, the country’s second in this area. This strategy marks an important milestone in the protection of our nation in the digital realm, the strengthening of cybersecurity, and the construction of a safer country for all people. With the aim of answering some of the generating questions you have raised, I would like to highlight some actions of the strategy that implement the recommendations made in the report of the United Nations Group of Governmental Experts on voluntary standards, rules, and principles for responsible state behavior in the field of information and communication technologies. One, the strategy incorporates as one of its five pillars cooperation, including international cooperation to promote a secure cyber environment. Two, action line 5.2, maximize the benefits of international cyber cooperation management, includes several actions that respond to norm D. For example: A. Establish mechanisms for cooperation in the investigation and prosecution of cybercrime with international security and justice agencies. B. Participate in joint and collaborative operations to dismantle cybercrime networks and protect victims of cybercrime. C. Strengthen CSIRT-CR participation in regional and international networks of incident response teams, such as the OAS CSIRT Americas Network. D. Participate in the discussion and development of international regulations that address cybersecurity challenges and promote a stable, secure, and reliable cyberspace by understanding the impact of malicious cyber operations on vulnerable groups. Three, in application of norm G, the strategy proposes to develop a regulatory framework for the protection of national critical infrastructures and operators of essential services, adopting international norms and standards. Four, the strategy also stresses the relevance of respecting human rights on the internet in line with the resolutions of the United Nations Human Rights Council as set out in norm E. Mr. Chair, it is essential to highlight that the Costa Rican strategy recognizes the need to consider implementation capacity, especially in developing countries, in line with the warning of the Group of Governmental Experts of the immediate applicability of certain measures. We will elaborate on this issue when we come to the discussion of capacity building. Thank you.
Ambassador Gafoor
Thank you very much. Costa Rica. Russian Federation, to be followed by Chile. Russia, please.
Russia
Mr. Chair, the mandate of OEWG, approved by all Member States of the United Nations, sets before us the task to continue as a priority to develop rules, norms, and principles for the responsible behaviour of States in the information space. We consider it imperative to strictly abide by this guideline. In our view, an unjustified bias in favour of implementing only the existing list of voluntary non-binding rules, either during the discussions or in the outcome documents of the Group, is a distortion of the mandate which provides for the development of new norms as a priority. Moreover, it is unacceptable to impose on States various forms of reporting on the implementation that have not been agreed upon under UN auspices. Russia and a number of other countries consistently advocate the need to agree upon a comprehensive universal set of rules, norms, and principles for the responsible behaviour of States and to make them legally binding. We are compelled to do this, both by rapid development in the ICT realm and the insufficiency of existing voluntary rules to effectively regulate this area. In this regard, it would be appropriate to go back to considering States’ views on this matter set out in the Chair’s summary of the first OEWG. For our part, we suggest discussing the following specific principles and proposals. First, the sovereign right of each State to ensure the security of its national information space and to establish norms and mechanisms for governance in its information space in accordance with its national legislation. Second, the prevention of the use of ICTs to undermine or infringe upon the sovereignty of States, territorial integrity, and independence of States, or to interfere in their internal affairs. Third, the inadmissibility of levelling unsubstantiated accusations against States for allegedly organizing and committing wrongful acts with the use of ICTs, including cyber attacks, in particular with a view to imposing various restrictions, unilateral economic measures, or other ways of pressuring States. Fourth, the settlement of interstate conflicts through negotiations, mediation, conciliation, or other peaceful means of the States’ choice, including through consultations involving competent national authorities. These norms are derived from the UN Convention on International Information Security, which Russia, along with a group of States, presented at the beginning of – that document is intended to promote the prevention of peaceful settlement of conflicts and the exclusively peaceful use of ICTs and to serve as a basis for cooperation among States for these purposes. We look forward to a constructive discussion of our initiative in the OEWG on an equal footing with the proposals of other States. We assume that the future universal mechanism should be developed under the auspices of the UN, taking on board the views of all Member States within the framework of a negotiation process to be established and tasked accordingly. Thank you very much.
Ambassador Gafoor
Thank you, Russian Federation. Chile, to be followed by South Africa. Chile, please.
Chile
Thank you, Mr. Chair. A cordial greeting to you and to all here. As we have said before, Chile believes that the norms and behavior of states can present risks to international peace and security and contribute to increasing foreseeability and reducing the risk of mistaken perceptions, thus contributing to preventing conflict. For a country, it is important to implement existing norms, strengthening capacity development at the national level. We also consider it essential to be able to make progress on additional guidelines which would help states have a better mutual understanding of the implementation of those norms. We thank you for your guiding questions, and we will refer to some of them. With regard to measures or best practices by member states to protect critical infrastructure and critical information structures, we think that states should be able to identify these critical and critical information infrastructures through specific policies and legislative frameworks on this, as well as by establishing governance strategies and structures and specific cyber security programs which include budgets and responsibilities, of course, budgets being essential resources among others. The establishment and strengthening of national response mechanisms to respond to information events and cyber security, the adoption of legislative frameworks, and also the adoption of national and international cooperation frameworks. Also, Mr. Chairman, I would like to share that we welcome what was said by the delegation of Costa Rica. Last week, our country launched its second national policy on cyber security, which includes having a robust and resilient information structure to recover from cyber security incidents and socio-environmental effects following a risk perspective. Our congress is discussing a law on critical infrastructure and cyber security, one of the main objectives of which is to create a national cyber security agency. To have counterparties, to have partners, is essential to dialogue. With regard to supply chains, we believe that cyber security is essential to mitigate risks of external attacks. States should be able to share acts which include cyber security practices and prior incidents together with norms, relevant norms, and to implement continuous monitoring systems on any suspicious activity. We also have to have contingency and resiliency plans which should include clear projects on data recovery and continuation of business. States can share best practices and have incident simulation exercises. We think it is possible to improve on existing processes, especially regionally. We would like to mention the recent efforts with regard to the OAS done by the working group on the implementation of confidence-building measures in cyberspace, which adopted a CBM on voluntary norms. In this regard, Chile is presiding over the Inter-American Committee on Terrorism, CICTE, which deals with the cyber security agenda. We hope to be able to improve cooperation in our region in order to strengthen the implementation of all of these norms. Thank you.
Ambassador Gafoor
Thank you very much. Chile, South Africa, to be followed by Cuba. South Africa, please.
South Africa
Chairperson, South Africa supports the agreed normative framework outlined in the 2015 final report of the Group of Governmental Experts on Developments in the Field of Information and Communications Technologies. The report, including the voluntary non-binding norms, was endorsed by consensus by the first OEWG on ICT security from 2019 to 2021. South Africa supports the second annual progress report’s recommendation that states, on a voluntary basis, survey their national efforts to implement norms, develop and share experience and good practice on norms implementation, and continue to voluntarily inform the Secretary-General of their national views and assessments in this regard. As stated in the second APR, the elaboration of checklists to guide states on the implementation of the agreed 11 rules, norms, and principles of responsible state behavior in cyberspace would assist states. These checklists should be voluntary to allow member states to implement them according to their developmental needs. Chairperson, turning to your first guiding question on possible examples of additional norms that could potentially complement existing norms, after a long and deep reflection on this, we found it difficult to come up with examples. We concur with what the Chair said in his reflections yesterday. We concur with what the Chair said in his reflections yesterday on intensifying efforts to implement existing norms, for it is through implementation that we will be able to identify gaps in the existing normative framework and the need for additional norms to close that gap. With regard to the Chair’s second question on support that can be extended to developing and small states to help us better protect our CI and CII from ICT threats, South Africa believes that information sharing as well as knowledge, experience, and expertise exchange seem to be some of the most basic yet practical and easy things to do. This will assist not only in capacitating those who are in the initial stages but will help in accelerating progress that can be made when we join hands and avoid pitfalls that those who have been here before have already found ways to address. There are already good proposals on the table, such as guidelines that some delegations have indicated they are willing to share. These guidelines can be aligned and tailored to meet individual states’ needs. We continue to listen to the ideas and views of other delegations on cooperation to ensure the integrity of the supply chain. Thank you.
Ambassador Gafoor
Thank you, South Africa. Cuba, to be followed by Argentina. Cuba, please.
Cuba
Mr. Chairman, we reiterate the pressing need to strengthen the normative framework to regulate matters in the area of security and use of information and communications technologies. In that regard, we reaffirm the need to have a legally binding instrument which considers in general matters relative to cyber security and to the use of ICTs and which regulates responsible state behavior in cyberspace. Differently from voluntary norms of implementation for states, a binding instrument would establish obligations and it would therefore be the more effective contribution to a model of action for member states in order to address the diversity and complexity of the threats we have referred to before. It would be a vital element in evaluating the implementation of international law in this field. Non-binding norms are an intermediate step toward the achievement of that goal. Resolution 75/240 of the General Assembly established the priority nature of preparing in this working group rules, norms, and principles of responsible state behavior and the relevant modalities of implementation. And if necessary, the introduction of changes or the preparation of additional behavior rules. The norms, rules, and principles prepared by Groups of Governmental Experts before, where not all member states participated, do not enjoy universal acceptance and therefore they must be reviewed in the framework of the OEWG and to prepare new ones. To draw up additional norms, the working group must use as the basis the proposed new norms presented by states which appear in the annex to the report of the working group’s chair in 2019-2021. The preparation and implementation of norms on responsible state behavior in cyberspace must be based on respect for the principles of sovereignty, sovereign equality, political independence, and territorial integrity. They must promote peaceful coexistence and international cooperation to mutual benefit and interest. We view with favor the progress made by countries and regional groups in the establishment of binding norms in their jurisdictions. That may be an important step toward achieving that purpose globally. We emphasize that norms are needed which refer to preventing the militarization of cyberspace and the non-imposition of unilateral coercive measures. Single prescriptions for the implementation of norms negotiated at the United Nations are not an option since every country has its own characteristics and in general developing countries do not have the same technical and technological conditions as developed countries. Therefore, although we have common responsibilities, these, Mr. Chairman, must be differentiated. Thank you.
Ambassador Gafoor
Thank you. Cuba. Argentina, to be followed by Czechia. Argentina, please.
Argentina
Thank you, Mr. Chairman, for giving us the floor once again. We will be brief, and we will refer to the implementation of the 11 responsible state behavior norms following your questions. Mr. Chair, during these years, we have reached consensus so that the norms on responsible behavior could help prevent conflict with regard to ICTs and contribute to increasing global economic and social development. We have also concluded that there is an important relationship among these norms, confidence building, and capacity development. Argentina bears in mind that while every state belongs to a specific region marked by its own characteristics and threats, we are not blind to the challenges faced by other regions. Thus, we must commit to the responsible use of ICTs in a globally interoperable space. In this context, we also realize that for developing countries, the implementation of norms must be compatible with international cooperation and transfer of technology, with the expansion of innovation for peaceful purposes, and with the economic development of our countries in a just and non-discriminatory landscape. In this regard, assistance on capacity development is very necessary. Argentina also understands that it is difficult to move toward commitments that go beyond the real possibilities of implementation. Thus, my delegation supports the initiatives on assistance to implement what we have been deciding in this group, such as using checklists and national surveys, and we would like this to lead to a sustainable and lasting implementation of the 11 norms. Furthermore, my delegation would also like to refer to the importance of protecting critical infrastructure, which provides essential services in our countries. Yesterday, we discussed the growing threats to them, and we shared concrete examples of the effects of the malicious uses of ICTs. Mr. Chair, sustainable digital transformation also entails creating a culture of cybersecurity aimed at protecting critical infrastructure. Overcoming the digital divide also requires that we all have robust and protected infrastructure. My delegation believes that capacity development must include these points. A cybersecurity program for critical infrastructure should include assistance on the methodologies to identify essential sectors. It should also include improvements in the productivity of cyber incident management in priority sectors, and, of course, also consolidating human talent on cybersecurity. Finally, we would like to highlight the role of regional agencies in international cooperation with regard to capacity building as well as confidence building as the basis for implementation. The delegation of Argentina wants to highlight the OAS working group on mutual trust measures, which is committed to the implementation of the 11 norms on responsible behavior on the understanding that regional cooperation is vital to generating trust, transparency, and inclusion among member states who, in most cases, face similar threats and digital development issues. Thank you.
Ambassador Gafoor
Thank you, Argentina. Czechia to be followed by Colombia. Czechia, please.
Czechia
Thank you, Mr. Chair. The Czechia Alliance aligns itself with the EU statement and wishes to emphasize a couple of points in its national capacity. We have repeatedly highlighted during the Open-Ended Working Group sessions that we put priority on the implementation of the existing normative framework. In our view, the 11 norms of responsible state behavior are a key element of the normative framework and are complementary to international law. We reiterate that norms of responsible state behavior can reduce risks to peace, security, and stability and play an important role in increasing predictability and reducing risks of misperceptions, thus contributing to the prevention of conflicts. Mr. Chair, in the guiding questions, you are highlighting Norm G and I of the 2015 GGE report, focusing on the protection of critical information infrastructure (CII) and the security of the supply chain. We thank you and welcome the shift in this direction as it is our long-standing priority. When we are speaking about Norm G, the first step to the amplification of critical information infrastructure is to establish at the national level what are the essential and vital sectors the state needs to maintain its functioning. The sectors may differ in regards to the local context, but the core priorities remain the same. Thus, it is beneficial for states to learn from each other and share their best practices. As for Norm G, Norm J of the 2015 GGE report on the supply chain, strengthening cooperation in this field goes hand-in-hand with trust not only between states but also towards suppliers. Ensuring responsible behavior of supply chain suppliers could be a way forward in this regard. As for policies and programs, Czechia, together with other partners, adopted back in 2021 the BRAC proposals, which outline guidance for states to make the supply chain secure. There are also similar policies on the regional level, such as the EU, which adopted last year the Council Conclusions on ICT Supply Chain Security. These policies could serve as supporting documents when setting our guidelines. When discussing policies and cooperation, we would like to mention that it is important to invite all stakeholders to the table, especially since we are talking about vendors and suppliers, as mentioned in the second annual progress report. An important issue towards strengthening the norms of implementation is cyber capacity building, as was already mentioned a couple of times. We are aware that the compliance with the 11 norms of responsible state behavior requires an adequate level of cybersecurity expertise. We therefore appreciate the potential development of a norms implementation checklist, as mentioned by a couple of countries, the latest by Argentina immediately before me now in my intervention, to assist states, in particular developing countries and small states, in their effort to implement the norms of responsible state behavior and the use of ICT. Czechia also supports that a dedicated inter-sessional meeting with relevant experts from regional organizations, the private sector, NGOs, and academia will be organized. From our point of view, the session should primarily focus on Norm J and I of the GGE report, which is related to the protection of critical infrastructure and the integrity of the supply chain. In addition, Czechia has the same position as Slovakia and wishes that the implementation of Norm E of the 2015 GGE report is discussed in more detail. This norm stipulates that states, in assuring the security of ICTs, should respect Human Rights Council resolutions and the promotion, protection, and enjoyment of human rights on the Internet, as well as General Assembly resolutions on the right to privacy in the digital age to guarantee full respect of human rights, including the rights to freedom of expression. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, Czechia. Colombia to be followed by Portugal. Colombia, please.
Colombia
Thank you, Mr. Chair. With regard to the question about some examples of additional norms that could supplement existing ones, for the moment we don’t identify any. We agree with your comments stated yesterday. Efforts should, for the moment, focus on understanding and adequate implementation of existing norms, without disregarding, of course, future normative frameworks taking into account the changing and evolving nature of cyberspace. In any case, we reiterate that any future norm or proposal should be consistent with international law, the purposes and principles of the UN Charter, including the maintenance of international peace and security, international humanitarian law, and human rights. With regard to the question on the eventual checklist for the implementation of norms, we think that we should have a methodological proposal to identify the actions required for compliance. That would allow states to review, on the basis of each norm and relevant act, the areas that would require support on capacity building and those where they could offer cooperation. In this regard, we reiterate what was stated by the GFCE last December, on the 6th of December, on the cooperative efforts together with UNIDIR on the cyber policy portal. We also highlight the proposals and comments by Canada in the present OEWG and in the previous one. They are an important contribution. Finally, with regard to the specific areas where improvements can be made, we believe that one of them is the monitoring of national implementation. This is one of the tools that could be included in the future mechanism for periodic institutional dialogue and achieved through national implementation reports. For the moment, we would have voluntary development of peer review exercises, and this could be used as the basis of the checklist to be prepared in the OEWG.
Ambassador Gafoor
Thank you. Thank you very much, Colombia. Portugal to be followed by Spain. Portugal, please.
Portugal
Mr. Chairman, as this is the first time I am taking the floor during this substantive session, allow me to thank you for your able guidance of this group’s work, which was instrumental in fostering incremental and meaningful progress in our common endeavors. At the outset, let me also stress the advantage of fully involving all interested parties in the work of the OEWG, including from civil society and especially from the industry. In this regard, we are concerned with the continued objection to the accreditation of independent civil society organizations. This limits their ability to follow our intergovernmental discussions and, perhaps more importantly, it prevents us from benefiting from their knowledge, thus limiting the reach of these discussions, including on norms. Mr. Chair, Portugal aligns itself with the statement delivered by the EU and would like to add some remarks in its national capacity, focusing on the topic of due diligence. Due diligence is one of the most promising tools in the framework for responsible state behavior in cyberspace, which, in our view, includes binding international law and voluntary norms applicable to the prevention and regulation of conflicts among states in cyberspace. The growing use of proxies by hackers, including official proxies, is concerning and can precipitate the use of unjustified countermeasures, which are especially dangerous in the context of an armed conflict, such as the war of aggression of Russia against Ukraine. In all cases, before resorting to cyber weapons to retaliate against malicious operations apparently originating in another state, this state must be immediately called upon by the targeted state to confirm swiftly if digital devices on its territory have indeed been manipulated. Though the technical and management obstacles are numerous and difficult to overcome, we should not give up on agreeing on a set of standards that increase the attractiveness of due diligence as a means to afford a pause before a crisis generated by an attack against critical infrastructure unfolds. Given that the vast majority of critical infrastructure in our societies are privately owned and/or managed, some form of due diligence applicable to the private sector could also be considered. The scholars who have been defending this development could be invited to make contributions to this debate. Once their views have been heard, a group of member states with the required expertise could draft a paper to foster further debate on the practical implementation of due diligence, which in our view could be in our work for 2024. In this regard, Portugal commends France for the availability expressed last March to lead such an effort and hopes that member states from all regions can join this effort. Thank you, Mr. Chairman.
Ambassador Gafoor
Thank you very much. Portugal, Spain, to be followed by El Salvador. Spain, please.
Spain
Thank you, Mr. Chair. Since I take the floor for the first time, I would like to thank the Chair and the group for their work, in addition to the guiding questions. Spain joins in the statement by the European Union and would like to highlight a few elements in the national capacity. Spain is unfortunately very much aware of the cyber attacks on critical infrastructure. In this regard, we want to stress the need to scale up the implementation of the agreed framework contained in the 2015 and 2021 reports, in particular norms on cooperation, transparency, and protecting critical infrastructure. We believe that these discussions cannot take place without the participation of other actors and stakeholders. Since these infrastructures are often operated by the private sector and only with their support, promoting an exchange of information and incident notification, can we learn the magnitude of the challenges we face. However, this will not be of value unless we move forward on CBMs at the same time and also capacity development, since all of this feeds on each other toward responsible behavior in cyberspace. To make progress on the implementation of these rules, norms, and principles, we should work on best practice codes and on exchange of information mechanisms to avoid the cascading effect of these cyber attacks. With regard to specific sessions, training activities for national experts and simulations on critical areas like telecommunications, energy, and health, all of this could contribute to identifying possible threats and gaps when applying international laws. Only thus will we be able to make progress on responsible state behavior in cyberspace. Thank you.
Ambassador Gafoor
Thank you very much. Spain. El Salvador, to be followed by the United Kingdom. El Salvador, please.
El Salvador
Thank you, Chair. We are grateful for the opportunity to address the voluntary framework of state behavior in cyberspace in accordance with international law, including human rights, international humanitarian law, and the principles and purposes of the United Nations. We believe that these guidelines are applicable to information and communications technologies by states. States have endorsed the 11 norms of responsible state behavior in cyberspace, and we have a solid normative structure. However, in our view, it is imperative to speed up implementation through concrete action, such as capacity gaps and cyber responses. The implementation of this normative framework requires having robust national institutions which strengthen the use of ICTs. El Salvador has a Secretariat on Innovation to implement the 2020-2030 digital agenda, which guides government action to modernize the state through innovation, education, competitiveness, identity, and digital governance. Together with this framework and following shared experiences, as mentioned by Costa Rica and Chile, my country has also proposed a cybersecurity law, which in general addresses responsible norms of behavior previously mentioned. Cross-cuttingly, our state strengthens an awareness of cybersecurity, contributing resilience as we address ICT threats. This is in line with relevant resolutions of the General Assembly on establishing a global cybersecurity culture to protect critical infrastructure. However, we recognize that strengthening international cooperation at all times and promoting capacity building and technical assistance are needed. El Salvador is open to relationships of cooperation with other states which have more developed cybersecurity structures. Chair, we welcome the specific discussion we’re having today on norms, especially F, G, and H on critical infrastructure, which we have paid special attention to. In response to your specific question on how to improve cooperation to guarantee the integrity of the supply chain and prevent malicious acts, we want to highlight the importance of sharing best practices with regard to risks in the supply chain. We also highlight the crucial role of ethical hackers and cybersecurity researchers who, in a preventive way, look for vulnerabilities in our ICT systems. This last contribution could be explored together with other norms, and we could consider the possibility of an additional norm on this. Thank you, sir.
Ambassador Gafoor
Thank you very much, El Salvador. United Kingdom, to be followed by Canada. UK, please.
United Kingdom
Thank you, Chair. You asked States to consider supply chain integrity, the use of harmful hidden functions, and measures to promote the adoption of good practices by suppliers and vendors of ICT equipment and systems. Your question may be considered in the context of norm 13i, which reads: States should take reasonable steps to ensure the integrity of the supply chain so that end users can have confidence in the security of ICT products. States should seek to prevent the proliferation of malicious ICT tools and techniques and the use of harmful hidden functions. In this context, the United Kingdom is concerned by the growing commercial market for intrusive ICT capabilities. Intrusive commercially available ICT capabilities include spyware and a range of other sophisticated tools and services. This market is expanding rapidly and will likely transform the existing cybersecurity landscape. Chair, like many of the topics discussed at this OEWG, this is a particularly complex issue. There are narrow circumstances in which such capabilities have legitimate uses by all States, for example, to prevent serious crime. However, it is also our view that this growing commercial market contains risks for stability between States in cyberspace by increasing the potential for escalation. These tools can be used in ways that undermine human rights and threaten a free, open, peaceful, and secure cyberspace. Acting responsibly in cyberspace means States should have appropriate oversight, safeguards, and protections that tightly restrict how these tools are used. The existing rules, norms, and principles of responsible State behavior, confidence-building measures, and capacity-building together provide a robust framework to guide the behavior of States in this market. All actors in this market, including the private sector, have a responsibility to ensure that the development, facilitation, and use of commercially available ICT capabilities do not undermine stability in cyberspace. There is significant opportunity to further State cooperation to address the challenges posed by the proliferation and irresponsible use of intrusive commercial cyber capabilities and to further the implementation of Norm 13i. With this in mind, the United Kingdom and France have launched a joint initiative to discuss good practice by States, the private sector, and civil society on the development, facilitation, and use of commercially available intrusion capabilities. The UK acknowledges existing positive efforts by States in this area, including the joint statement on efforts to counter the proliferation and misuse of commercial spyware, the inclusion of intrusion software in the control list of the Wassenaar Arrangement, and initiatives by regional institutions such as the European Parliament. We welcome the efforts taken across the multistakeholder community to raise awareness of this issue and note in particular the letter to you, Chair, dated 20th of September from the multistakeholder community on the topic of cyber mercenaries and the irresponsible use of hack-as-a-service solutions. Thank you, Chair.
Ambassador Gafoor
Thank you, UK. Canada to be followed by France. Canada, please.
Canada
Thank you for this opportunity to address the group, Mr. Chair. The 11 voluntary non-binding norms for state behavior, responsible behavior in cyberspace, are a key part of the group’s mandate. Canada takes note of your effort to orient our discussion in this regard. The voluntary non-binding norms which we support serve as guidelines to show our goodwill in supporting international security. Even though they are non-binding, we have to be clear-eyed in approaching them with reasonable expectations. The international community expects all of us to respect these norms, and this is why we agreed to them in the 2015 General Assembly and are working to implement them. Canada believes that voluntary non-binding norms are broad and flexible enough to guide the behavior in states when they are confronted with a large array of situations. Therefore, the OEWG should consider the implementation progress already accomplished. There is a lot of work remaining in this regard, and many initiatives have been put forward. We recognize that this work requires significant effort, but we welcome the progress already achieved, particularly in capacity building in that regard. Canada is of the view that, as of the present time, the best use of our resources would be to consolidate what has already been accomplished, rather than work on additional norms. In other words, a pragmatic and reasonable approach, in our view, is to validate what exists before adding to it. Your second guiding question had to do with good practices to protect critical infrastructure. This is an issue that is close to our hearts, and this is something on which the Group of Governmental Experts, GGE, and OEWG have respectively submitted reports. The consensus report of GGE 2021, endorsed by the General Assembly also in 2021, provides guidelines that, in a practical way, assist the implementation of voluntary non-binding norms. While detailing the actions required, it lets us implement them with greater facility, and it contributes to capacity building. We recognize the potential for further strengthening of capabilities to implement voluntary norms, and we believe that the guidelines based on GGE 2021 are promising in that regard. Now, let me suggest an example of the current work to implement these norms in Canada. In our parliament, we are currently debating a draft law to implement the norm protecting critical infrastructures. Draft law C26 on cybersecurity aims to protect cyber systems regulated by the federal government in Canada in such areas as finance, energy, telecommunications, and transport. If the law is enacted, it will require operators to put in place cybersecurity programs which reduce the risks linked to supply chains and third parties. They will be obliged to flag incidents related to cybersecurity and abide by certain directives in that regard. Now, on the issue of the checklist that you referred to in your guiding questions, we believe this is a complementary tool to the text formulating voluntary and non-binding guidelines. It could be considered as an additional tool to emphasize various ways to strengthen capabilities with regard to the most vulnerable targets. We take good note of the work carried out by Singapore on this checklist. Furthermore, we welcome the efforts of the chair to develop this promising tool through contributions by member states to be reflected in the second annual program’s report. Canada will continue to be fully engaged in implementing non-binding voluntary norms, and we appreciate your efforts in this regard. Thank you, Chair.
Ambassador Gafoor
Thank you very much, Canada. France to be followed by Japan.
France
Thank you, Mr. Chair. State behavior norms in cyberspace are a key part of the normative framework being developed here to date. We support deepening these behavior norms, existing norms, and their effective implementation. Are we, however, opposed to the creation of new norms when that is necessary? We encourage all states to present the details on good practices of the implementation of existing norms at their national level. However, I’d like to recall that these norms do not replace international law. They contribute to strengthening transparency, predictability, and trust in cyberspace. I would like to refer to proposals made by the U.S., Portugal, and other states with regard to operationalizing work on due diligence, and to put this item on the work program of our group for 2024. Furthermore, I’d like to focus on norm 13.1 of the 2015 GGE, 13i. This norm stipulates that states should take reasonable measures to guarantee the integrity of the supply chain so that the final users should have trust in the safety of the digital products, and should commit to preventing the proliferation of digital technologies and tools that are malicious or contain hidden malicious uses. This norm is very rich. It covers both the security of digital products and the issue of the proliferation of malicious digital tools. I’d like to go back to these two elements. On the security and safety of digital products, we have had occasion to recall within this group to reduce the area of attack. It is necessary that states impose a level of security on the sum total of digital products developed and commercialized in their territories. With this in mind, a political agreement was found a few days ago on the European regulation of cyber resilience, Cyber Resilience Act. This European Act, which is close to being adopted, aims to ensure security by design of digital products sold in the EU, specifically connected objects. The aim is to guarantee such security of products throughout the lifecycle of these products, from conception to marketing. We hope that this European initiative could open the door toward an ambitious implementation of the norm 13i globally. This regulation, as well as preparatory work that has made it possible, specifically the work carried out within OECD, are public and could feed the work to elaborate a checklist with regard to this norm. Now, on the issue of proliferation, yesterday I spoke and our UK colleague also mentioned it. For a number of years now, we have seen a rapid increase in a private non-regulated market of cyber capabilities that could be used for offensive purposes. This market includes a complete array of capabilities, building blocks, exploiting vulnerabilities through service, and all the way to spyware and similar tools. This market is developing at an alarming pace and could proliferate horizontally. That is to say, lead to the emergence of new actors, including non-state actors, and also proliferate vertically, with the appearance of offensive capabilities that would be more and more sophisticated and could threaten international peace and security. In terms of the agreed framework of regulation, the proliferation of cyber offensive capabilities available on the market thus represents a threat both to human rights and the stability of cyberspace. In this regard, effective implementation of the norm related to proliferation must be a priority for the international community. This is the direction of the discussion that was initiated on the occasion of the latest forum, the Paris Forum on Peace, in November. This discussion was organized in partnership with our colleagues from the United Kingdom. We wish that OEWG could also become a platform for exchanging views on these risks of proliferation and on the responsibilities involved therein within the framework of that norm. Thank you very much.
Ambassador Gafoor
Thank you very much, France, for your statement. I give the floor now to Japan, to be followed by the Syrian Arab Republic. Japan, please.
Japan
Mr. Chair, Japan is strongly of the view that voluntary and non-binding norms of responsible state behavior can reduce risks to international peace, security, and stability. Japan considers that it is important to focus first on deepening the discussion and steady implementation of the existing norms. During yesterday’s discussion, many delegations mentioned malicious cyber activities impacting critical infrastructure. In this regard, norms C, F, G, and H should be focused on, and it is important to discuss strengthening measures to protect critical infrastructure from cyber threats, including sharing information on best practices for protecting critical infrastructure and supporting states in their identification of national critical infrastructure, where requested. In Japan, we designated 14 critical infrastructure sectors, such as information and communication, electric power supply, gas supply, water, and medical. We revised the cybersecurity policy for critical infrastructure protection, which is shared by the public and the private sectors as a basic framework for critical infrastructure protection. The policy includes strengthening the national CERT function and information sharing between the public-private sectors, responding to new threats related to supply chains and the use of cloud services, integrated operation of risk management and crisis management when an incident happens, clarification of organizational risks by top management, strengthening the failure response system as part of organizational governance, and conducting cross-sector exercises. Mr. Chair, in order to facilitate the implementation of the norms, we would like to reiterate that in the second annual progress report, states elaborate additional guidance, including a checklist on the implementation. We welcome the chair’s leadership for preparing an initial draft of the checklist, and we will contribute to providing constructive inputs to produce that draft. In this regard, Canada’s proposed norms guidance in the annex to the chair’s summary of the final report of the OEWG in 2021 will be a good reference to deepen our discussions. We also consider case studies on the application and the violation of the norms will be beneficial. We would also like to emphasize the importance of the discussion on the future Program of Action as an action-oriented platform for deepening our common understanding of the norms. In addition, capacity building is important for the states to deepen their understanding of the norms of responsible state behavior and to implement them appropriately. Japan, through the Japan International Cooperation Agency, provides the training programs to support these efforts and continues to do so. I thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, Japan. Syria and Arab Republic, to be followed by Ecuador. Syria, please.
Syria
Thank you, Mr. Chair. Turning to the rules, norms, and principles of responsible behaviour, I would like to highlight the following. The current framework for the rules and principles of responsible behaviour of States could contribute to reducing the risks to international peace, safety, and security. However, due to the unique nature of the ICT environment and its rapidly evolving nature, as well as the huge consequences and dangers resulting from this, we believe that there is a need to deepen our cooperation to address the shortfalls in the norms of responsible behaviour. They are not enough to address all aspects of ICT security challenges. This is due to its voluntary nature and the fact that its implementation is subject to the interests and priorities of States. Moreover, such rules lack a clear vision on the threshold for the use of force or the legal description of the use of force in cyberspace. We do not support the frameworks agreed upon outside the United Nations since they lack inclusivity, and my delegation stresses the need to reach an inclusive international checklist of the rules and norms of responsible behaviour. It should be legally binding on all States. This would help to establish a comprehensive international legal regime in the field of ICT. The initiative presented to the OEWG by the like-minded group of States, which includes Syria, is worthy of consideration in this group. We stress the need to reach legally binding rules that would make State responsibility compulsory. At the same time, it will represent a basis for a comprehensive international legal regime. It would also ensure that we address all aspects of ICT safety. We do not agree to the trend towards a non-binding legal instrument and only implement a normative framework because it would increase the potential of using accusations for political objectives, leading to tension and reversing the aspired reaction on international safety and stability. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, Syria. I give the floor now to Ecuador, followed by the Netherlands. Ecuador, please.
Ecuador
Thank you very much, Mr. Chair. Since this is the first time that my delegation takes the floor, I wish to congratulate you and thank you for everything you have done to facilitate the organization of this session. Ecuador also thanks the Secretariat for its work. Ecuador recognizes the need to continue strengthening the norms of responsible behavior, as well as the international normative structure on the subject. We value and support the recommendations and conclusions of the Groups of Governmental Experts and the working groups on the subject, also reflected in General Assembly resolutions, on the progress and use of information and communications in the context of international security. In this regard, Ecuador, concerned over the very rapid evolution of telecommunications and emerging technologies and the challenges posed by current threats to critical infrastructure, which impair global efforts toward peaceful uses of cyberspace, in 2021 set out to strengthen its institutional regulatory, administrative, and managerial capacity on cyber security, cyber defense, cyber intelligence, and cyber diplomacy. To this end, we adopted a national cyber security strategy whose pillars are cyber resilience and international cooperation and aims at the priority implementation of the monitoring of cyber security development and evaluation and capacity evaluation in the various stakeholders. To implement this strategy requires shared responsibility and efforts at coordination between the public and private sectors, and we are convinced that during this hard path of creating and strengthening our capacities, we must recognize the major challenges faced by developing countries. Therefore, we need to work together and among multistakeholders to include state partners, private sector, academia, specialized agencies, and thus build resilience and be more cyber secure to the benefit of all. Mr. Chairman, Ecuador is convinced that to protect the security of citizens and states in cyberspace is an ongoing global trend which includes Ecuador, and we therefore reiterate our commitment to the responsible use of ICTs as key to guarantee stability and security in cyberspace. In conclusion, Mr. Chair, be assured that you have Ecuador’s support during this new cycle of discussions, and we expect a productive session under your leadership. Thank you.
Ambassador Gafoor
Thank you very much, Ecuador. Netherlands, to be followed by India. Netherlands, please.
Netherlands
Chair, distinguished delegates, the Netherlands aligns itself with the statement of the European Union, and I would like to add the following remarks in my national capacity. While this second annual progress report highlights that harmful and malicious ICT incidents are increasing in frequency and sophistication, the Netherlands is of the view that, when implemented and adhered to, the existing norms, complemented with existing rules of international law, provide a comprehensive framework capable of guiding state behavior in a responsible way. This is why it is our view that our focus should be on the implementation of existing norms before we look towards the development of new norms. The Netherlands considers that additional guidance on the implementation of existing norms should build on our agreed understanding of these norms, as reflected in the GGE and Open-Ended Working Group consensus reports, including the APRs of this Open-Ended Working Group. Chair, many states have highlighted the fundamental importance of the protection of critical infrastructure and critical information infrastructure. States have also recognized that some of the most worrying and potentially escalatory ICT incidents had cascading effects and inflicted harm on critical infrastructure by spreading widely and rapidly beyond their intended target. This is why the Netherlands holds the view that further norms implementation guidance should not only consider the direct impact of malicious cyber activities but also take into account the cascading effects that such activities may have, as well as their impact on citizens, such as on healthcare, essential services, or rights. Let me turn to some concrete suggestions on Norm F. Existing guidance on Norm F encourages states to put in place relevant policy and legislative measures at the national level to ensure that ICT activities that may impact critical infrastructure or the delivery of essential services in another state are consistent with this norm. Similar to the existing guidance, states should also consider and incorporate the potential of cascading effects in the use of ICTs in institutional arrangements and national decision-making processes related to the development and use of their ICT capabilities. We also consider that respect for human rights is relevant for the implementation of all norms and that the proposed checklist or implementation guidance should take this into account. For instance, in further implementing Norm I, as addressed by the UK, the Netherlands supports the notion that for the responsible use of commercially available ICT capabilities, there should be the commitment to respect and protect democratic principles, human rights, and fundamental freedoms consistent with international commitments. Finally, the Netherlands recognizes that considerable capacity is required to implement the existing norms. We therefore welcome initiatives such as the UNIDIR study mapping the foundational cyber capabilities needed to implement the norms, the UNIDIR survey on national implementation, and Singapore UNODA norms implementation guidance. We also welcome efforts made to synergize and to ensure the complementarity of these initiatives. I thank you, Chair.
Ambassador Gafoor
Thank you very much, Netherlands. India to be followed by China. India, please.
India
Mr. Chair, India believes that maintaining international peace and security in cyberspace is a collective responsibility. Voluntary, non-binding norms of responsible state behavior can reduce risks to international peace, security, and stability, and play an important role in increasing predictability and reducing risks of misconceptions, thus contributing to the prevention of conflict. Norms, rules, and principles for responsible behavior of states in cyberspace emanate from international law. They ensure stability, security, peaceful use, and resilience in cyberspace. As an important element in discussions on norms, rules, and principles, we need to emphasize the need for universalizing the recommendations outlined in the previous GGE reports and OEWG’s Second Annual Progress Report, and to develop mechanisms for ensuring adherence and implementation. The norms, rules, and principles elaborated in the GGE report of 2021 form an excellent foundation to build the superstructure of responsible behavior of states. Following these norms, rules, and principles in their letter and spirit will help to secure international peace and security. This OEWG, during its mandate until 2025, may further refine the existing norms, rules, and principles that form the basis for responsible behavior of states, and may develop additional norms, rules, and principles on a need basis. As outlined in the second APR, our delegation underscores the importance of integration between norms, confidence-building measures, application of international law to cyberspace, international cooperation, and capacity building. Considering the mandate and the time duration that the OEWG has at hand, our delegation believes that our deliberations and the group should focus on further developing an additional layer to the existing understanding of these norms, underscoring their value with regard to the expected behavior of states in the use of ICTs in the context of international peace and security, and provide the requisite institutional arrangements that states can put in place at the national and regional levels to support their implementation. In this regard, India would like to highlight the need to discuss the obligations between member states that could help with fixing responsibility for malicious activities, especially as we confront the challenge of attribution in cyberspace. We all appreciate that attribution is a complex exercise. We need to go further in elaborating upon the obligation of states to alert the victim state of possible attacks that may emanate from their territory and which have come to their notice while monitoring activity within their own territory. It is crucial to recognize that the digital realm is a shared space, and our actions in cyberspace have repercussions that extend far beyond our borders. Therefore, it is in our collective interest to foster a cyberspace governed by rules that reflect our shared values of peace, security, and respect for human rights. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much. India. China, to be followed by Singapore. China, please.
China
Mr. Chair. At the outset, China has taken note that all member states in their intervention emphasize the importance for the observance of the framework for the rules, norms and principles for responsible state behavior. China suggests that new measures be taken by this working group to translate the aforementioned political commitment into elements that are legally binding in order to better safeguard the authority of the existing rules regarding cybersecurity, cyberspace. Second, China notes with appreciation that in the Chair’s opening remarks it is recommended that the OEWG focus on substantive discussions instead of trying to stage an ideologically based discussion between the development of new norms vis a vis the implementation of existing norms. On the basis of the guiding question number one, posed by the chair, with regard to possible new norms, China is of the view that it is possible to develop new norms on data security issues. At present, we believe that a good basis already exists for the formulation of such new norms on data security. The continuous improvement in data security governance and practice at the national level has provided strong underpinnings for substantive discussions in the framework of the OEWG. Based on prior discussions in multilateral forums such as the UN as well as state practices in cyber governance China took the lead to propose the global initiative on data security. We are of the view that this initiative can serve as the basis for relevant discussions and for the formulation of possible new norms. Specifically, these may include the following. States should safeguard an open, secure and stable global supply chain. States should stand against ICT activities that impair other states’ critical infrastructure or steal important data. States should take actions to prevent and suppress ICT activities that jeopardize personal information and oppose mass surveillance against other states. States should not mandatorily require their national businesses to store in their national territories data generated and obtained overseas. Respect the sovereignty of other states and the judicial jurisdiction of other states. And respect the administrative right of other states with regard to data security. Data access requests for law enforcement purposes should be addressed through mutual legal systems or other bilateral channels. ICT products and service providers should not install back doors in their products and services. ICT businesses should not seek illegitimate interests by taking advantage of users’ dependence on their products. Mr. Chair, most member states stressed the importance of implementing the existing framework of norms. In the 2021 UN GGE report, Norm 13i stresses… I’m going to repeat norm recommendation 13i in Chinese: “Implementing global interoperable common rules and standards for supply chain security.” Regrettably, the practices of certain states are inconsistent with the aforementioned consensus. Those states, by abusing the pretext of so-called state security, and without any evidence, piecing together so-called small cliques of supply chains and develop their own standards with the view of suppressing the business enterprises of certain countries and denying the legitimate rights of other countries to development. Such practices undermine fair competition in the industry. Thirdly, during yesterday’s discussion, many delegations stated that ICT should not be used to interfere in the internal affairs of other countries, including the attempts to influence and affect other countries’ political systems. China suggests that in this year’s APR, the following elements be included. The political systems and development paths of all states should be respected. States should not use ICT to interfere in the internal affairs of other states or undermine the political and social stability of other countries, nor should they use ICT to carry out regime changes. In addition, some countries chose to selectively apply the framework. Their actions have undermined the integrity of the framework as a whole, and also harmed the confidence of all states in the integrity of the framework. Fourthly, we have noticed that during our discussions, the OEWG highlighted the potential spillover risks brought about by the proliferation of offensive cyber technologies. We have the view that all countries should explicitly commit themselves to not proliferating offensive cyber technologies. Compared with commercially available software, the proliferation of offensive cyber technology between state governments is a more worrying trend. There is a need for us to develop new guidelines in this regard. In closing, with regard to the protection of critical infrastructure, in his new agenda for peace, the UN Secretary-General has proposed relevant recommendations with regard to the protection of critical infrastructure. China is of the view that OEWG may wish to consider using it as the basis for discussion. Before I conclude, I would like to stress that in all the consensus documents with regard to the norms framework for responsible state behavior reached by the OEWG, the so-called term peace time has never been used in those consensus documents. China will not support any reference to those terms or any revisionist language that tries to alter the agreed language of the OEWG. China has made clear the above-mentioned position on – repeated on many occasions. Given the fact that there are many colleagues who are joining the OEWG process for the first time, myself included, China wishes to take this opportunity to stress once again our position on this issue. Thank you, Mr. Chairman.
Ambassador Gafoor
Thank you very much, China, for your statement. Singapore to be followed by Switzerland.
Singapore
Thank you, Chair. My delegation would like to take this opportunity to make some comments on your guiding questions related to norms, the protection of critical information infrastructures from ICT threats, and strengthening cooperation to ensure the integrity of the supply chain. First, on norms, Mr. Chair, we note consensus on the existing 11 voluntary non-binding norms of responsible State behaviour. Many States are still in the process of discussing and studying how these voluntary non-binding norms should be implemented. As set out in the second APR, it would be useful for the OEWG to continue developing a checklist for guidance on how these voluntary non-binding norms can be implemented, even as we do not preclude the development of new norms in the future. Mr. Chair, Singapore has been working on a regional ASEAN norms implementation checklist for these 11 norms since 2018, together with our colleagues from Malaysia and other ASEAN partners. From this exercise, it is clear that any effective norm implementation effort requires a multi-dimensional perspective from the policy, technical, diplomatic, and legal aspects in the implementation of these norms. Successful norms implementation needs to take into consideration all these various areas. Taking this approach has allowed us to work with our regional partners to take into account the different national contexts and capacities according to the different stages of the cyber resilience journey of the various ASEAN member States. We also understand that similar norms implementation efforts are also taking place in many other regions, together with guidance already developed during UN discussions, including the previous first OEWG. It is timely that we consider how we can build on these efforts to develop broader norms implementation guidance through the development of a checklist. Such norms implementation guidance can also be linked to the cyber security capacity building efforts, so as to also sharpen these capacity building efforts. Singapore looks forward to supporting the Chair in the effort in developing norms implementation guidance as set out in the second APR, and welcomes the opportunity to work with interested countries to develop a norms implementation checklist to provide guidance on this. Mr. Chair, under protection of critical information infrastructures, CIIs play a critical role in delivering essential services to the population and ensuring the effective functioning of the economy and society. Similarly, CIIs which provide essential services across borders and jurisdictions must be protected. Singapore has enacted a cyber security act with the aim of also strengthening the protection of these critical systems, and we have since progressively identified our CII systems. We believe that inter and intra-regional exchanges on best practices and insights on regulatory and legislative frameworks are important to raise awareness of and international cooperation in the protection of CIIs. The software supply chain is a worrisome major initial attack factor for cyber criminals. Earlier this year, a zero-day vulnerability in a file transfer tool was exploited by a ransomware group, resulting in the breach of data belonging to over 2,000 organizations worldwide as of the end of September. There is also a need to improve IoT security to raise the overall cyber hygiene levels and better secure our cyberspace. It has been estimated there could be some 50 billion IoT devices in use worldwide by 2030. Yet many of these devices are developed without proper cyber security features. This is because developers tend to prioritize speed to market and cost. In our view, States can take measures to provide greater transparency for security of consumer smart devices by using a trusted label or mark based on a series of assessments. This security by design approach would raise standards and incentivize the development of more secure products. For instance, Singapore mandates a cyber security labeling scheme for key IoT devices such as routers, as these are gateway devices through which cyber operators may enter. We have recently expanded this to cover medical devices, which are currently under the sandbox stage. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you, Singapore. Switzerland, to be followed by Australia. Switzerland, please.
Switzerland
Thank you, Mr. Chair. Switzerland is of the opinion that at the moment we should focus on better understanding, promoting, and implementing the existing 11 norms before developing new ones. The 2021 GGE report provides a good basis for this. It lists the norms and provides further guidance on how to implement them, and we should develop that guidance further. This does not exclude that we could develop new norms over time where useful or needed. Switzerland would see merit in focusing on norms 13C, F, G, and H, calling for the protection of all critical infrastructure, supporting essential services to the public, in particular medical and healthcare facilities, as well as cooperation between States for this purpose. In regard to protecting and identifying critical infrastructure from ICT threats, there are a wide variety of good practice guides available, and our National Cyber Security Centre also publishes some of these guides. It has also been mentioned that regional organizations have already done a lot of valuable work from which we can benefit. As an example, I would like to mention the work of the OSCE on the protection of critical infrastructure. A continued in-depth exchange between the Open-Ended Working Group and regional organizations would therefore be useful. One of the key elements to protecting and identifying critical infrastructure from ICT threats is establishing a trusted exchange between the CI operators and the relevant government authorities, which is guided by clearly defined responsibilities and mandates on all levels. It also should entail an understanding of a member State’s CI’s dependencies on national and international critical service providers. Switzerland has established such an information exchange platform or network, and we are happy to share our experience with other States. Mr. Chair, in connection with the implementation of the norms on supply chain security and ICT vulnerabilities, I would like to inform this group about the launch of the Geneva Manual that took place in Geneva last week. I would like to take this opportunity to thank you, Mr. Chair, for your opening remarks at the launch. The Geneva Manual was developed in the framework of the Geneva Dialogue on Responsible Behaviour in Cyberspace, which was established by the Swiss Federal Department of Foreign Affairs in 2018. The Dialogue analyzes and maps the roles and responsibilities of various actors in ensuring the security and stability of cyberspace. Fifty representatives and independent experts from the private sector, academia, civil society, and technical community contributed to the drafting of the Geneva Manual. In this context, the Dialogue stems from the principle of shared responsibility and particularly asks how existing cyber norms might be best implemented by relevant stakeholders. The inaugural edition of the Manual focuses on the two norms related to supply chain security and reporting of ICT vulnerabilities, as I mentioned before. The Geneva Dialogue builds on the work and achievements made earlier, discussions on the role of industry, and the output report with good practices by the private sector to secure designs of digital products and reduce vulnerabilities in them. The Manual highlights the diverse perspectives of non-state stakeholders, emphasizing the importance of multistakeholder participation in the implementation of norms. The Manual offers an action-oriented approach to cyber stability. It explores the roles (who), the responsibilities and actions (what), the incentives (why), and challenges for stakeholders to implement or help to implement existing norms. A Geneva Manual in the spirit of Dialogue remains open to comments and suggestions at GenevaDialogue.ch and will be continuously updated to reflect the changes driven by the rapid development of technologies. We think the Manual can make an important contribution to the work of the Open-Ended Working Group. The Manual can also provide ideas and guidelines to competent national authorities of UN member states and their partners in the private sector and civil society on how to practically and jointly approach the implementation of the agreed cyber norms. Thank you.
Ambassador Gafoor
Thank you very much. Switzerland. Australia, to be followed by Ukraine. Australia, please.
Australia
Thank you very much, Chair. Australia welcomes the focus in this group on the implementation of the agreed norms of responsible state behavior, and today I’d like to provide some thoughts on a way forward on additional checklists, guidance, and self-assessment for the implementation of the norms. Then, I will speak to some specific examples of norms that might be worthwhile focusing on early in this process to build upon your other questions and the discussion we’ve had to date. Because it’s clear that it is only when the norms are implemented and adhered to that the international community can reap the benefits of the norms. The norms themselves are not revolutionary in content; they’re things that most countries are already doing to some extent. If we look around, I’m pretty sure that we can see that every country in this room has to some extent implemented some of the norms, and that’s because the norms themselves were developed from the bottom up. The 2015 GGE report looked at what states were already doing to promote peace and stability in cyberspace and collected this together into best practice and into the norms. As in everything, in developing this norms guidance checklist or a self-assessment tool or guidance, this OEWG would not be starting from scratch. I joined several others; I think the US, India, and China all have said today that we should be looking at the consensus agreed and General Assembly endorsed 2021 Group of Governmental Experts report, which provides depth to the agreed norms and includes additional explanation to interpret the norms and also some examples of how states may choose to implement each of the norms. We should also look to the 2021 OEWG and GGE endorsed survey of national implementation, which is hosted on the UNIDIR cyber policy portal. There’s also been some wonderful work done by stakeholders and civil society and others at UNIDIR, ASPE, and the Cyber Peace Institute, who have collected together examples of implementation, whether they are foundational or best practice, and also provide existing methodologies to collect, interpret, and assess this information. Work at the regional level can also be useful in developing this proposal further, and the example from Singapore on ASEAN is a fantastic one for us to look to as well. A core part of implementing the norms is not only sharing understandings on how to implement these recommendations but also to self-assess the actions each of us have taken towards implementation and what actions are still required to implement them fully. We suggest that the purpose of any checklist or guidance that we decide to develop and the methodology for its use are very clearly set out. Some proposed purposes could be to help each state determine for ourselves how we implement the norms with examples about how this might be achieved, to collate and collect national take-up of the norms, to share information, to share best practices, and share our priorities for norms implementation, and also to identify challenges that inhibit implementation of the norms. For example, political barriers like government priorities, structural or organizational barriers, barriers to personnel and resources, knowledge barriers, or financial barriers. Identifying these sorts of barriers can assist in developing targeted capacity building programs to assess implementation gaps in capacity and provide an evidence base, which has been provided by the state itself if it’s a self-assessment tool of the particular needs of that state when developing these capacity building programs. We also know that a tool that is buried in a document in the depths of a UN website, with no offense to the UN document system, is unlikely to garner uptake and day-to-day use, which is required for practical value and usefulness for this checklist. So we’d suggest considering incorporating this checklist or this product, this guidance, once developed and agreed by consensus within existing mechanisms or portals. For example, the annual report of the Secretary-General on national views and assessments of peace and security in cyberspace or the UNIDIR cyber policy portal, both of these are well established, and there are other examples as well that have been mentioned today. To make this work achievable, we’d also suggest taking small bites at this. Given the strong focus on critical infrastructure over the past two years, we would suggest first focusing on developing guidance for the three critical infrastructure norms, norms F, G, and H. Others this morning, the US, Argentina, Costa Rica, Czechia, Japan, Netherlands, and most recently Switzerland, have provided examples of implementation of these norms domestically, regionally, and internationally. We find this really valuable and would consider definitely continuing this conversation. It also seems like it is the season for cyber security strategies. Like Costa Rica, Chile, and Ecuador, Australia has recently published a new cyber security strategy, and we’ve elevated the protection of critical infrastructure to one of our six national priorities under our new strategy. And giving a national example here, we propose to uplift critical infrastructure protection through four actions: clarifying the scope of critical infrastructure regulation, strengthening the cyber security obligations and compliance for critical infrastructure owners and providers, leading by example by uplifting the cyber security across our government systems, and also pressure testing our critical infrastructure to identify vulnerabilities. Finally, Chair, given the threats discussion that we had yesterday, Australia would also like to briefly address the norms on preventing the proliferation of malicious cyber tools and techniques and encouraging responsible reporting of cyber vulnerabilities. These are norms I and J. We heard yesterday that the Syrian Arab Republic spoke about the proliferation of cyber tools in dark web marketplaces. Bangladesh spoke about developing responsible vulnerability reporting practices. Singapore also spoke about this this morning in relation to IoT devices. Mauritius raised the threat of increased availability of low-skill cyber tools, and Ireland also raised the threat of cyber crime as a service. And we’ve also heard the UK and France speak about the commercial availability of intrusive spyware tools this morning. We see these tools and techniques reshaping the threat landscape. Hacking as a service, zero-day exploit, and vulnerability marketplaces provide state actors with the ability to obfuscate activity by hiding in the noise and the changing tactics and tools and techniques which are quick and cost-effective. We’re concerned that this obfuscation can blur the line between state-linked operations and non-state actors. Understanding the specifics and vectors of commercial cyber tools and techniques and the evolution of this marketplace is essential for our ability to address and to mitigate these threats, including through implementing and adhering to our norms. These are really complex issues, and they deserve our attention and our consideration. In particular, I’d like to speak to vulnerability reporting because this does not come without its own risks. Vulnerability reporting is a two-way street. Vulnerabilities can be detected by the private sector or cyber security researchers outside of government and reported to cyber security agencies. Conversely, cyber security agencies may discover weaknesses or vulnerabilities in technologies that are unknown to the vendor and report these to the vendor so that they can patch or otherwise mitigate the threats to their systems and their customers. Trust, responsibility, and partnership between public and private sectors are absolutely key for this vulnerability reporting and mitigation effort to be effective and should always come down to a single objective, which is ensuring safety and security. Given the rapid evolution of these threats, we would really welcome further discussion on these norms and sharing expertise and measures to mitigate, and we would suggest that these two might serve as the second bite-sized piece for us to focus on in checklists. Thank you, Chair.
Ambassador Gafoor
Thank you very much. Australia, for the statement. Ukraine, please.
Ukraine
Thank you, Mr. Chair. Ukraine aligns itself with the statement delivered by the European Union, and now our delegation would like to make additional remarks in our national capacity. Before presenting Ukraine’s views on norms, rules, and principles of responsible state behavior in cyberspace, our delegation takes this opportunity to inform UN member states briefly, with full respect to the timing of our deliberations, on the matter which directly falls within the OEWG’s mandate. This morning, one of Ukraine’s largest national mobile operators, Kyivstar, became the target of a powerful cyber attack. According to the official statement of Kyivstar, the attack caused a technical failure which temporarily made mobile communication and Internet access services unavailable. Personal data of customers has not been compromised. The incident and consequences of unlawful interference with the network are being documented by the relevant authorities. According to the press service, the Security Service of Ukraine has announced the opening of a criminal case under eight articles of the Criminal Code of Ukraine on today’s cyber attack on Kyivstar. An investigation is currently ongoing. One of the versions currently being investigated by Security Service of Ukraine investigators is that the Russian special services may be behind this cyber attack. Mr. Chair, norms, rules, and principles of responsible state behavior are crucial elements of the normative framework for responsible state behavior and complementary to international law. In the 2015 GGE report, states agreed by consensus on a level of voluntary non-binding norms of responsible state behavior in cyberspace. The 2021 GGE report provided additional understanding and clarification on these norms. Ukraine reiterates the importance of advancing the implementation of these norms that will allow us to assess the activities of states in cyberspace in order to prevent conflict and increase stability, security, and resilience. At the same time, we strongly believe that we should focus on deepening our understanding and promotion of the existing 11 norms rather than developing new ones. It is important to stress that among all the agreed norms, seven pertain specifically to critical infrastructure protection. In particular, norm G encourages states to take measures to protect their critical infrastructure. As we have stated earlier, attacks on critical infrastructure by malicious states and non-state actors have significantly increased in recent years. In the countries that are facing severe large-scale cyberattacks carried out by Russia, the protection of critical infrastructure and critical information infrastructure remains one of the key cybersecurity priorities for Ukraine. In the context of strengthening our critical infrastructure, Ukraine has adopted a comprehensive national cybersecurity strategy and a number of laws and other decisions related to the protection of critical infrastructure. Ukraine’s authorities also make regular recommendations for private and public entities who are potential targets of cyberattacks in order to strengthen their cyber resilience. In this regard, we understand that timely monitoring and analysis of information, security of state information resources, and critical information infrastructure is a guarantee of their stable functioning in case of the need to ensure a prompt response to cyber threats. Mr. Chair, it is worth recalling that norm 13c of the UNGGE 2015 report provides that states should not knowingly allow their territory to be used for internationally wrongful acts using ICTs. Therefore, states should act strictly in line with their obligations under international law and perform due diligence, including by preventing their territory from being used by cyber criminals as well as prosecuting them. Russia has not only violated international law in the context of the current war against Ukraine but also the specific UN norms on the protection of critical infrastructure. In this regard, we would like to recall that among those who are engaged in malicious cyber activities against Ukraine are groups associated with the government or special services of the Russian Federation. In order to ensure that OEWG is fit for purpose, it should provide additional guidance and discuss more broadly this important topic. Thank you, Mr. Chair.
Ambassador Gafoor
Thank you very much, Ukraine, for the statement. It’s almost one, in fact, it’s a few minutes past one, and I wanted to make some announcements. We have about 10 to 12 speakers, so we will take them in the afternoon. There’s been a good discussion, so thank you all for that. Second, I wanted to say that this afternoon I intend to make some slight adjustments to the provisional program of work, which was adopted on the understanding that it will be applied in a flexible way, so I seek your kind understanding. So this afternoon we will meet at 4 p.m. instead of 3 p.m., because I have to attend to an urgent meeting, and therefore we will start at 4 p.m. instead of 3 p.m. And tomorrow, in the afternoon, the dedicated stakeholder session is scheduled from 3 to 6 p.m. It’s my intention to have the dedicated stakeholder session from 3 to 4 p.m. I understand there are about 15 stakeholders who have inscribed. We will give all of them a chance. We will hear them very carefully. This is part of our mandate. And then after that, immediately, we will proceed from 4 to 6 p.m. to the rest of the substantive work under agenda item 5. So starting later this afternoon, we can catch up by the end of tomorrow. And I seek your kind understanding for this slight adjustment to the provisional work program. So we will continue with the speaker’s list at 4 p.m. this afternoon, and the meeting is adjourned. Thank you very much.
Leave a Reply