Session 6-4 Transcript
(OEWG 2021-25)

Home » Resources » UN Open-ended Working Group (OEWG) transcripts » Session 6-4 Transcript(OEWG 2021-25)
Ambassador Gafoor

Distinguished delegates, the fourth meeting of the sixth substantive session of the Open-Ended Working Group is now called to order. And I do want to begin with an apology for beginning a little later than I had anticipated. Such is the life of diplomats in the building that there are sometimes multiple meetings happening at the same time, and one is sometimes obliged to be at two places at the same time. So, my apologies for being absent, but I’d like to resume in earnest the work that we had left off just prior to lunch, which was the discussion on the cluster under rules, norms, and principles, on which we have a list of speakers. And we’ll resume with that speakers list, and as I was entering the room, I saw that there was an assembly of people near the podium. I thought it was perhaps an attempt to take over the podium, hostile or otherwise. I want to assure you that if there is ever any intention to take over the podium, I guarantee you there will be no resistance. You will become the owner of a podium, and you can do what you wish with that. Now, let’s begin with the speakers list that we left off from this afternoon, and I’d like to start with Brazil, followed by Italy. Brazil, you have the floor, please.

Brazil

Thank you very much, Mr. Chair. Brazil appreciates the work you and your team have done so far in incrementally advancing our debate on rules, norms, and principles, building upon the important acquis from previous UN processes, particularly the GGE’s 2015 and 2021 reports, which respectively adopted 11 norms of responsible state behavior and further developed our understanding of those norms, as well as the recommendations contained in the first OEWG report. Brazil is a staunch supporter of the norms of responsible state behavior and has been guided by them in the establishing of our national norms on the matter and in securing our critical infrastructures and critical information infrastructures, which is currently undergoing a review process that will result, hopefully in the near future, in a more robust legal and institutional framework to tackle this issue. In this regard, we recognize the importance of international cooperation efforts in promoting the national implementation of those norms. We have greatly benefited from the national experiences of other countries and therefore fully welcome continued knowledge sharing in this area, including through the submission of written contributions through the report of the Secretary-General on developments in the field of ICTs, as well as the national survey of implementation as contained in the recommendation of the 2021 OEWG report and as stated in paragraph 23i of our second APR. Regional cooperation has been particularly relevant in this area. Brazil has been engaged in multiple initiatives in this regard, such as OAS CERT Americas, which has been instrumental in advancing norms related to information sharing and threats and vulnerabilities. Mercosur, with its Cybersecurity Commission, has also fostered national implementation of those norms through information exchange on cybersecurity, institutional and legal frameworks, and the ongoing development of a common regional terminology. Capacity building, targeted at the specific needs of recipient states, is particularly important in promoting the universal observance of those norms. We welcome initiatives implemented so far and are also hopeful that the capacity building mapping exercise currently being undertaken within the OEWG will contribute to further enhancing their effectiveness. We likewise support the development of a guiding checklist, as mentioned in the second APR, as another important tool to facilitate the implementation of the norms. Finally, I would like to stress that our support for the 11 norms of responsible state behavior and other voluntary norms and principles is not contradictory to discussing the possibility of adopting specifically legally binding norms in this area, and therefore reject the idea that there is a dichotomy opposing both perspectives. We are open, as our debates evolve, to considering the adoption both of additional voluntary norms and of legally binding ones, which we see as playing complementary roles in the promotion of a peaceful cyberspace. We look forward to developing our views on international law later on. Thank you very much.

Ambassador Gafoor

Thank you very much, Brazil, for your statement. Italy, to be followed by Mauritius. Italy, please.

Italy

Thank you, Mr. Chair, for giving me the floor. We fully align ourselves with the statement delivered by the European Union. We agree that existing UN norms represent a sufficient and adequate framework to guide member states to ensure responsible state behavior in cyberspace. Their implementation, however, requires continued effort from all international communities. This is one of the main reasons why we prefer to continue to work on existing norms rather than developing new ones that would necessarily build on the existing, yet unevenly applied ones. We welcome the approach followed by the Chair to focus some guiding questions on norms that strengthen the protection and resilience of critical infrastructure, and we are glad to share our national experience in the spirit of cooperation that underpins our participation in the group. At the outset and regarding norm 13f, a state should not conduct or support activities contrary to its obligations under international law. I would like to recall that the Italian constitution contains an automatic reference to existing international law that it recognizes as immediately applicable. The main measures Italy adopted to implement the new norms on the protection of critical infrastructure from the cyber security standpoint can be found in the legislation establishing a national security perimeter for cyber. The latter guarantees the security of networks, information systems, and information services of public administrations, public and private entities, and operators which are considered as an essential function of the state. Entities which are included in such a national security perimeter for cyber must identify, adopt specific security measures, and review their ICT assets, including their dependencies on external services. Provisions of the perimeter are addressed to the relevant private sector too. Adopting a national cyber security strategy and a dedicated implementation plan with specific references to the implementation measures is also good practice. For each measure, the plan identifies the responsible entity actors, the timeline for their implementation, and the required resources. Out of 82 measures, several ones respond to the implementation of UN norms, including the reference to vulnerability disclosures as well as to international cooperation and capacity building activities. The latter would be one of the priorities of the future POA that Italy fully supports and promotes. Mr. Chair, distinguished delegates, supply chain security is also a fundamental yet complex principle. The international community and major stakeholders have developed many measures and best practices to help in the task of achieving the highest security level during the whole supply chain process. In this context, we believe it is important to quote at least UNIDIR guidelines on supply chain security in the cyber age sector and ISO/IEC standards. The alignment and adoption from all relevant actors of such standards and best practices might be an important step towards a stronger security of global supply chains. Establishing national evaluation and certification schemes and centers, adopting cyber security certification schemes, and strengthening the national technological screening system to support the security of the supply chain of specific categories of assets can also represent an important measure which goes in the same direction of security. Coming to guiding questions about additional guidance on the implementation of norms, we see a lot of merit in the proposal of Singapore. In our opinion, possible guidance checklists would include publication of position on international law, national cyber security architecture and legal framework, national strategy and implementation, membership and work within a regional organization, ratification of relevant treaties, modality of cooperation with the private sector, records of incidents and related cooperation, and vulnerability disclosures legislation. Finally, and recalling the recent anniversary of the Universal Declaration of Human Rights, I would like to mention the GGE norm 13e on the promotion and enjoyment of human rights on the internet. This norm deserves additional attention. The respect of human rights is a cross-cutting requirement and the proposed guidance or checklist should include a reference on how the respect of human rights is mainstreamed both in national and international measures taken to ensure a secure use of ICT. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you very much, Italy. Mauritius to be followed by Kenya. Mauritius, please.

Mauritius

Thank you, Chair. Mauritius firmly believes that the National Survey of Implementation is a self-explanatory document that, to a large extent, helps recognize the stand of States as concerns the rules, norms, and principles of responsible behavior in the use of ICTs. Mauritius aligns itself with a statement made by the European Union in connection with the classification of incidents involving critical information infrastructure and the consideration for a risk management exercise. I would like to underscore that we, as a small State, are ourselves in the process of formally identifying national political sectors. With the promulgation of the Cybersecurity and Cybercrime Act in late 2021, Mauritius shall now abide by the provisions stipulated, particularly in regard to the protection of critical information infrastructure. Allow me to highlight that the law specifies that offenses relating to critical infrastructure bear significantly higher penalties as compared to other offenses, thus deterring cybercrime targeting such infrastructures. Critical sector organizations in Mauritius also now have an obligation to report security incidents to a national cybersecurity committee and undergo an independent IT security audit at regular intervals to ensure compliance with international standards. Coming back to the identification of critical sectors, Mauritius has implemented a national framework with a view to establishing proper governance for information security risk management at the national level and developing capabilities for responding to incidents impacting critical information infrastructure. We have developed a survey for critical sectors that aims to shed light on areas such as the dependency of services driven by ICTs, critical applications that can impact citizen-centric services, mechanisms established to address downtime, and measures in place to mitigate the greatest risk. We believe that such a survey can serve as a good starting point for identifying national CI and CII for developing countries and small states. In addition, we are of the opinion that cyber exercises remain one of the vital capacity-building initiatives that bring together public and private sectors to simulate the discovery of and response to a significant cyber incident impacting a nation. As regards the security of the ICT supply chain, there are existing standards, for example, the Cyber and Supply Chain Security Standard or SCS 9001, which could be promoted through national cybersecurity strategies and adopted by suppliers and vendors. Before ending, let me point out that we welcome further discussions on this topic. I thank you, Chair.

Ambassador Gafoor

Thank you very much, Mauritius, for your statement. Kenya to be followed by Bangladesh. Kenya, please.

Kenya

I thank you, Chair. I would like to make additional remarks from a national capacity. The rules, norms, and principles of responsible state behaviour are the basis of our dialogue at this OEWG and continue to guide member states on responsible state behaviour in cyberspace. Kenya continues in its efforts to domesticate rules, norms, and principles of responsible state behaviour in cyberspace. This has been done through national legislation, for instance, the Critical Infrastructure Drive Policy and Bill, which are a work in progress, and the National Cyber Security Strategy to enhance security, protect users, the privacy of citizens, critical infrastructure, and information systems. On the Chair’s question on additional norms that could complement existing norms, recognition of the harm to women and minorities that result from attacks on CI and CII will complement and further expound norm number 5 on human rights and elaborate the expectation of states in norm number 7 on protection of critical infrastructure. On the question of best practices to protect CI and CII, our experience is that clear definition and designation of CI and CII while establishing laid mechanisms on how to handle such infrastructure is essential. Further to this, establishment of institutions charged with securing infrastructure may also serve as a focal point for international cooperation in case of attacks and is critical in protecting CI and CII. Chair, further inclusion of multistakeholders in the OEWG discussions is an example of a good policy that will hopefully promote good practices. By suppliers and vendors, their participation and presence in the room will hopefully help them appreciate the critical role they play in ensuring a secure cyberspace. I thank you, Chair.

Ambassador Gafoor

Thank you very much, Kenya. Bangladesh to be followed by Ghana. Bangladesh, please.

Bangladesh

Thank you, Mr. Chair. Bangladesh emphasizes the shared responsibility of all nations in maintaining international peace and security within the cyber domain. As the use of new and emerging technologies continues to increase, so do the vulnerabilities. In this context, establishing clear and agreed-upon norms serves as a crucial normative framework for ensuring sustainability and security in the utilization of ICTs. We believe that states should prioritize the implementation of the existing 11 rules, norms, and principles as the fundamental foundation for responsible state behavior in cyberspace. The most effective approach to translating these norms into concrete action lies in collective efforts between states. These collaborative endeavors should focus on providing guidance on the interpretation and implementation of these principles, ensuring their effective application in the evolving cyber landscape. To that end, Bangladesh emphasizes that all states should have a common and comprehensive understanding of these norms. In pursuit of this shared understanding, we need to address the skill gap as a matter of priority. To answer your guiding questions on additional norms, my delegation underscores the importance of implementing existing norms and stresses that these norms, rules, and principles should be regarded as an ongoing process requiring continuous evaluation, updating, and recalibration rather than a one-time endeavor. We are of the view that the rapid advancement of AI and other emerging technologies introduces new complexities for responsible state behavior in ICTs. Norms in this domain are still evolving and require further definition. Thus, the Open-Ended Working Group (OEWG) may wish to articulate clear principles for their responsible use, encompassing transparency, accountability, safety, and non-discrimination. Simultaneously, establishing a robust framework for attributing cyber attacks remains a challenge. International consensus on criteria for evidence, information-sharing protocols, and mechanisms for state accountability is crucial. The current lack of transparency in attribution undermines confidence-building, risking miscalculation and escalation. Both aspects underscore the need for comprehensive norms in cyberspace. Mr. Chair, in addressing the question of support for developing and small states to enhance the protection of critical infrastructure and critical information infrastructure from ICT threats, Bangladesh underscores the significance of fundamental yet practical measures. These include fostering information sharing and facilitating the exchange of knowledge, experience, and expertise. These actions are deemed basic, yet their simplicity and effectiveness make them readily implementable and valuable in strengthening cyber security capabilities for nations in need. Mr. Chair, my delegation highlighted yesterday that supply chain attacks are becoming increasingly common, targeting critical infrastructure through vulnerabilities in software and hardware. Therefore, we reiterate that the Open-Ended Working Group (OEWG) should consider potential strategies for enhancing software supply chain security and promoting responsible vulnerability disclosure practices. Many delegations echoed the same this morning. Mr. Chair, to conclude, I am happy to share that, like a few other countries, Bangladesh too enacted its new Cyber Security Act 2023 in September, replacing its Digital Security Act 2018. I thank you.

Ambassador Gafoor

Thank you, Bangladesh. Ghana to be followed by Israel. Ghana, please.

Ghana

Thank you for giving me the floor, Mr. Chair. So, Mr. Chair, in outlining best practices for safeguarding critical infrastructure and critical information infrastructure against threats, especially for developing countries, my delegation would like to emphasize the significance of implementing measures to designate and protect CII. In 2021, Ghana, through the Cybersecurity Authority, as mandated by the Cybersecurity Act, Act 1038, has designated 13 CII sectors and enacted a directive establishing cybersecurity requirements, audit processes, and incident reporting protocols. In response to your question on how developing countries and small states can be supported in identifying national CII and CII, international cooperation and bilateral engagement are essential. Ghana, for instance, has signed a number of MOUs with other countries facilitating cooperation on CII protection, including the development and implementation of best practices in designation, classification, and registration of CIIs. These engagements make it possible to learn from each other and share best practices. Mr. Chair, considering your question on additional guidance and checklists for non-implementation, my delegation proposes incorporating agreed-upon norms into existing national cybersecurity policies and strategies and outlining concrete implementation steps at a national level through the implementation of the norms checklist. Like Australia mentioned, many countries are already implementing existing norms to a larger extent. Hence, it will be useful to put in place more intentional measures to further build on what countries are already doing and explore areas that require more improvement. To effectively do this, there’s a need for more capacity building. This can be done through needs-based training programs as a useful way to equip member states with the tools needed to implement existing norms. International cooperation, joint exercises, and transparency and accountability with reporting mechanisms for norms implementation evaluation at a national level could also be an integral component in the checklist. I thank you, Mr. Chair.

Ambassador Gafoor

Thank you very much, Ghana. Israel, followed by Sri Lanka. Israel, please.

Israel

Thank you, Mr. Chair. Thank you for giving us the floor to comment on the important issue of norms, rules, and principles. I’ll do my best to be very concise. Answering your guiding question, at this point in time, there is no need, in our opinion, to develop or elaborate any new norms, nor do we see a need for developing any legally binding instrument. Israel believes that a more cautious approach with respect to norms is required. As things currently stand, there is still a lack of certainty as to the manner in which existing norms and rules are being implemented and interpreted by States. Let us recall that the 2015 GGE norms are voluntary and non-binding in nature and do not detract from or extend beyond international law. Thus, norms are intended to signal expectations of the international community regarding appropriate State behavior, and from what we have seen thus far, their implementation has been at best deficient and uneven. Mr. Chair, before embarking on any process of updating the existing norms or developing new norms, it would be more appropriate, in Israel’s view, to focus on those norms that currently exist, assessing whether and how they are being understood and applied, ensuring that there exists a common language and understanding when referring to these norms. Once this is done, we, as a community, can begin to consider where the need is more acutely felt, whether it is an issue with the current norm, lack of clarity, or whether the original norm itself should be reconsidered. Informed by this approach, only then, in our view, can we assess whether there exists a need for additional norms. I thank you, Mr. Chair.

Ambassador Gafoor

Thank you, Israel, for your statement. Sri Lanka, followed by Poland. Sri Lanka, please. Yeah, perhaps we’ll give Poland a chance to go first. Poland, if you are ready.

Poland

My computer died. I will raise my hand when I am ready.

Ambassador Gafoor

Okay, so, right, Sri Lanka, back to you then. I hope your computer is alive. Over to you, Sri Lanka.

Sri Lanka

Thank you very much, Mr. Chairman, for your patience, and thank you very much for giving me the floor to make this very brief intervention on behalf of my delegation. Mr. Chairman, it has been accepted without demur that responsible state behavior requires cooperation with other nations to address shared cybersecurity challenges. No doubt international collaboration can lead to the development of norms and agreements that promote a safe and secure cyberspace environment for everyone. Be that as it may, Member States must be obliged to collaborate with other nations to share best practices, intelligence, and strategies for addressing violations effectively on a global scale. How do we do it? If we just take the example of combating the abuse of free speech in cyberspace, it is crucial for responsible states to strike a balance between the freedom of expression and protecting the right to express opinions and engage in open debates. This is essential, but it should not be used as a cover for promoting hate, inciting violence, or targeting vulnerable communities. To achieve this objective, Sri Lanka has acknowledged the 11 voluntary non-binding norms of the United Nations, which reflect the expectations that the broader international community has of each state and regional organization. Sri Lanka CERT has included these 11 norms in the National Cybersecurity Strategy for 2024-2029 as one thrust area to show commitment to adhering to the rules, norms, and principles of responsible state behavior. Another aspect is the need to bridge the trust deficit in technology, which is a fundamental aspect of building confidence in an interconnected, digitalized world. In the absence of an internationally legally binding instrument that governs the digital space, the development of rules, norms, and principles of responsible state behavior will surely have the potential for such norms to be observed in the breach and interpreted at the whims and fancies of the parties. Now, Mr. Chairman, this is very much a work in progress, and there is no one-size-fits-all. Communication, transparency, and ready information sharing regarding national views on specific norms, rules, and principles is the way forward. Such open discussions should aim at developing a joint understanding of these norms and at protecting international peace and security. Inter-state exchange and the sharing of best practices in preventing the misuse of ICTs should be encouraged. However, while the development of rules, norms, and principles of responsible behavior in this sector may be a positive step, Sri Lanka’s position has remained steadfast that it cannot be a replacement for working towards a legally binding instrument. This must be pursued, we say, with the same vigor as we attribute to other aspects of regulating the use or preventing the misuse of the information and communication technology sphere. The imposition of obligations and violations that may be adjudicated upon is important internationally as well as domestically. In conclusion, with the adoption of the Data Protection Act in 2022 in Sri Lanka and the Cyber Security Bill being in the final stages of its process, Sri Lanka is focusing on creating a rules-based order and setting minimum-based standards to protect our digital infrastructure and cyber use and engagement. In doing so, we are also protecting the freedoms of expression, innovation, and development in this field. The national information and cybersecurity strategy is to be updated to accommodate new developments. In this regard, as a starting point, I say, regional partnerships can widen understanding and become trust-building measures. ICT policy dialogue and research with partner countries may be, I say, the way to build effective partnerships and collaboration between industrial professionals and policymakers. I thank you, Mr. Chairman.

Ambassador Gafoor

Thank you very much, Ambassador. Sri Lanka, for your statement. Poland to be followed by Guatemala. Poland, please.

Poland

Thank you very much. I’m sorry for my computer; I talked to him. Poland aligns itself with the statement delivered by the European Union, not surprisingly, and in my national capacity, I would like to share shortly a few remarks, but I promise to be brief. Poland attaches great importance to the implementation of both international law and the 11 voluntary norms of responsible state behavior in cyberspace. Without their true and honest implementation, we will never reach a state of relative safety and security in cyberspace on an international level. Therefore, we believe we should focus our efforts on identifying the necessary conditions, suitable tools, and best practices for implementing the existing and agreed norms, rather than opening lengthy discussions on which other norms we can develop. Effective implementation of norms depends on several factors: political will to do so, legal framework to do so, and instruments, resources, and capacities to do so. Since the 11 norms were adopted by the United Nations, we should assume that political will to observe them in this place among states present in this room is observed. This, however, is not the case. The representative of Ukraine informed us before lunch about massive attacks on the major telecommunication provider in his country, which provides fundamental services to all institutions and citizens, including all critical infrastructure systems. I’m afraid this is not the last example of violating these 11 agreed norms, and perhaps tomorrow will bring us another sad proof of that pessimism. But there is not much we can do about the political will of countries which are not our country. Therefore, I believe we should focus on the tools, best practices, and capacity building in providing the conditions to implement these norms for those countries who want to observe them. Experiences of the COVID pandemic or unjustified Russian attacks on Ukraine highlight in different ways the particular importance of protecting critical infrastructure, providing services to the public, ensuring the integrity of supply chains, and securing the operation of telecommunication systems, especially as they are expressed in norms F, G, H, or I. Many delegates before me have talked about what tools we can use to help each other implement these norms in practice. I want to praise Singapore’s efforts and the way you work with the ASEAN countries. When you have specific exercises, guidelines, you offer the checklist and protocols on how to implement the norms. I want to refer to my friend and colleague from Switzerland bringing the OSCE experiences. OSCE focused some of the confidence-building measures there on providing security and safety of critical infrastructure. And along these activities within the OSCE, we try to bring more mutual trust and understanding among states on how to observe. In fact, these 11 norms were adopted in the United Nations framework in practice. A number of countries undertook a lot of efforts to provide this and listed by different delegations tools, manuals, and practices. I’m not going to repeat them, but I think in principle and in general, we should focus on identifying which of these manuals, which of these practices, which of these training programs are the best tools to help the implementation of the norms to these countries who are willing to do so in true political will but may be lacking capacities to do so. And in general, this is what I wanted to share in my intervention. Thank you, sir.

Ambassador Gafoor

Thank you very much, Poland, for your statement. Guatemala, to be followed by Honduras, please.

Guatemala

Thank you, Chairman. With regard to the questions, with regard to rules, norms, and principles, my country does recognize the importance of bringing up methods to avoid the ill-use of this technology. We are, however, aware of the challenges with regard to achieving political agreement at the international level. My delegation would like to highlight the fact that the application of international law to states in cyberspace in a non-mandatory way and the behavior of states in peacetime, in order to create trust between countries, continues to be important. Also, the current gaps between countries in terms of cyber security and defense, we believe, give particular importance to capacity building to ensure that we have a more fair approach to these issues. For that reason, for Guatemala, the voluntary norms of responsible behavior in cyberspace are important, and they should meet the expectations of the international community. Mr. Chair, Guatemala currently has a national cyber security strategy. Its main aim is to enhance the capacities of our country, establishing the environment and the necessary conditions to ensure the participation, development, and the enjoyment of rights of people in cyberspace. Beyond this, last year Guatemala has made considerable progress in terms of cyber security. We have clearly defined the areas for action and defined what are crimes in this area. We have promoted due process, and we have protocols to ensure the proper use of digital evidence. Now, all this is in line with the framework of states’ responsible behavior in cyber security. So, we have a question in this area with regard to norms, and we’d like to share the following areas of work. First, establishing the minimum safety and security requirements and ensuring that the systems are created in a proper way, and establishing policies in the use of these technologies to ensure that we meet regulations in terms of security and the necessary laws that apply to promote transparency. We aim to establish requirements for critical information infrastructure to reduce the risks of negative impact from a cyber security attack on this infrastructure and to encourage a culture of cyber security by establishing greater awareness of these problems and the proper use of emerging technology to deal with the threats to this technology and to use them to enhance the current security system. Finally, Chairman, we do recall the importance for my country of cooperation in the area of capacity building. We must promote information and communication technology to ensure advances in our scientific and technical development. Thank you very much.

Ambassador Gafoor

Thank you very much, Guatemala. Honduras, to be followed by Malaysia.

Honduras

Mr. Chair, for developing states, and in particular for my country on the item before us, it is essential to approach this section in the light of critical infrastructure as part of any framework for cooperation in the application and adoption of cybersecurity norms recognized at national and international levels in order to improve the resilience of critical infrastructure and help them to reduce vulnerabilities and to effectively manage risks in the cybersecurity domain. This cooperation and the framework of responsible behavior norms must place at the center fundamental values of protecting, in particular, the privacy, the security, equality, and human dignity, and the rule of law, and an open internet. All of them are essential elements to achieve a human society, economy, industry, and digital. And this is indicated in the UN Charter. My delegation believes that the group should continue to help promote the existing norms of responsible behavior for states and underscore the applicability of international law to the way in which member states use ICTs when identifying and condemning behavior which is against or illegal, promoting positive actions and stability in cyberspace. For my country, the report of the group should consider that the norms we already have complement international law. We must promote capacities implementing data and analytical technologies which promote machine learning and artificial intelligence to improve detection and to generate cooperation to counter cyber risk as new threats emerge. The group could also move toward prospective work on new threats and needs while suggesting investing in knowledge and knowledge taking into account that the new types of malicious behavior evolve more rapidly than existing laws. The group must move toward a formal mechanism which includes, inter alia, crisis management and which builds resilience capabilities. In our view, building a crisis management model for cyber attacks requires the cooperation of the international community and an inter-institutional commitment with regard to agreed norms, their use and assessment, including the challenges which hamper their implementation.

Ambassador Gafoor

Thank you very much, Honduras. Malaysia, to be followed by the Russian Federation, also on the same topic: rules, norms, okay.

Malaysia

Mr. Chair, Malaysia shares your views that we need to intensify our efforts to implement the agreed norms of responsible state behavior in cyberspace. The agreed norms are central to the cumulative and evolving framework and will continue to contribute to international peace and security. Full and effective implementation of these norms is therefore imperative. As indicated in the second APR, the norms reflect the expectations and standards of the international community regarding the behavior of states in the use of ICTs and enable the international community to assess the activities of states in cyberspace. The key words here are expectation and standards. Many delegations have rightly underlined the importance of protections of critical infrastructure and critical information infrastructure. Malaysia appreciates the comments made by the United States on the linkage between Norms 13F, G, and H and how these connect and support other norms. We also support statements made by El Salvador, Costa Rica, South Africa, Argentina, and others in this regard. We further support South Africa’s proposal on information sharing and expertise exchange as low-hanging fruit to be pursued together with existing guidelines that have been adopted and implemented by others for protections of CI and CII. Echoing Canada, the topic of protections of CI and CII is also close to our heart. Malaysia is currently in the process of presenting our cybersecurity bill to Parliament, and this is scheduled to be considered in the first quarter of next year. Although we already have national directives and a strategy on cybersecurity, we currently do not have specific legislation which regulates cybersecurity and mandates the maintenance of cyber hygiene standards at the national level for CII. This often resulted in a legal approach which views cyber attacks only as cybercrime without fully reflecting the potentially devastating impact of security threats to CII. The new legislation will be proactive with mandatory legal norms for CII applicable to relevant organizations in Malaysia. The legislation shall be read together with any other written laws relating to cybersecurity activities, including those relating to communications and multimedia and personal data protection. We agree with the Netherlands on the need to not only consider the direct impact of cyber incidents on CII but also the wider cascading impact of such incidents. Malaysia thanks Costa Rica for sharing the elements of their national cybersecurity strategy and how it links with the implementations of norms. With regards to Norm I on ensuring supply chain security, Malaysia welcomes the comments of Qatar and Chechnya on measures for service providers and supply chain suppliers. Malaysia further concurs with the United Kingdom on the need for oversight vis-à-vis the development, facilitation, and usage of intrusive cyber capability. Finally, Malaysia agrees with Singapore’s statement on the rule of norms implementation checklist, which could assist member states in identifying capacity building needs for states so as to ensure the effective implementations of norms. In this connection, we will continue working closely with Singapore and other ASEAN colleagues on the development of a norm checklist, taking into account experience at the national and regional levels. Thank you, Mr. Chair.

Ambassador Gafoor

Thank you very much, Minister. Russian Federation, I believe this is your second intervention. Thank you.

Russia

Mr. Chairman, we once again need to take the floor because of the anti-Russian statements made by a number of delegations. First of all, as was said in our statement, the statement made by the Arab states, as was stressed also by the chairman of the Working Group when we completed the agenda item on threats, this is no place for politicizing the discussion. This draws the attention of the members of the Working Group from fulfilling their mandate, and developing countries, particularly small states in the global south, do not have the possibility of expressing their views with regards to international information security within the Working Group. This is categorically not acceptable to push forward by states accusations about illegal actions in the use of ICT on the basis that their governments have certain doubts with regard to this, but there is no evidence to support it. Our assessment of such statements in the Open-Ended Working Group was laid out yesterday during the right to reply, and we set out the information there with regard to recognition by the Ukrainian government of facts of computer attacks and information resources in the government structures of the Russian Federation. You can find this statement on the website of the Open-Ended Working Group. Thank you.

Ambassador Gafoor

Thank you very much, Russian Federation. I understand that you would have to say what you have just said. I think that once again I appeal to all delegations to focus on what’s on our mandate, and if delegations feel the need to come back and clarify, may I appeal that we do it at the end of the day rather than after each agenda item or discussion, because then I think we end up taking a little more time than necessary. But having said that, this is the United Nations where each one of you are representatives of your country and sitting here as sovereign equals, so if you ask for the floor, I will give it to you. But let’s also have some understanding, let’s also have enough confidence and trust among ourselves that, first of all, you will all do your best to focus on the agenda item, and I can sense that that’s what you want to do. And second, if you need to say what you have to say and there are others who also need to respond in a way that they have to respond, let’s see if we can keep those comments in a succinct way and hopefully address them towards the end of the day. I will give time for that. I have one last speaker under this item, but before that, I see the delegation of Ukraine asking for the floor. But before I give the floor to Ukraine, I mean this is precisely the point, I recognize Ukraine, your right to take the floor, and I will give it to you shortly. But this is precisely the point that I’m making, that perhaps we can have an understanding that we will come to these comments towards the end of the day and each one of you can say what you wish based on what you have heard. So you will have that opportunity. But if we are in a situation where the compulsion to respond immediately keeps coming, then we are going to be in a situation where there will be responses and counter-responses, and that dynamic may take us in a different direction. So that is the point that I want to make. So Ukraine, you have the floor.

Ukraine

Thank you, Mr. Chair. Our delegation would like to make a very short comment with regard to the statement just made by the Russian Federation. We just would like to say that perhaps the Russian Federation could exercise the right of reply and not waste the time of this important body. If the Russian Federation is concerned about the time not being used efficiently, perhaps they could fully exercise the available means provided by the rules of procedure of the main committees of the UN General Assembly and make a statement in exercise of the right of reply instead of making another intervention within this agenda item. Thank you.

Ambassador Gafoor

Thank you very much, Ukraine. I’ve got one last speaker from an accredited NGO, the Organization of American States (OAS). You have the floor for a brief statement.

Organization of American States

Thank you, Mr. Speaker. Thank you, Chair. First of all, thank you for the opportunity to address you for the first time during this sixth substantive session, and on behalf of the General Secretariat of the OAS, we appreciate being included in these crucial discussions. Chair, I would like to just reflect on the guiding questions related to critical infrastructure and CII and its protection against ICT threats. I would like to highlight that the OAS member states, at the level of the General Assembly, approved in June of this year a confidence-building measure where member states agreed to promote the implementation of the 11 voluntary non-binding norms in response to state behavior. Member states also agreed in that resolution to foster synergies with other multilateral cybersecurity processes, including analysis of existing and potential threats, international law, international humanitarian law, norms, rules, and principles of response to state behavior, CBMs, and the gender perspective. In this regard, member states mandated CICTE to convene a hemispheric meeting of high-level authorities in 2024 on cybersecurity in order to reflect on the current cyber threat landscape in the region and develop a regional agenda on cybersecurity and critical infrastructure protection. Chair, I cite these references as congruence at the regional level among OAS member states to move not just from their acknowledgment of the norms to promoting implementation, which is in and of itself confidence. Chair, as it relates to critical infrastructure and in recognizing the vital importance that critical infrastructure plays for a nation’s social and economic well-being, member states have begun to pursue this objective, understanding that the establishment of a national strategy for critical infrastructure protection and resilience will help to sustain essential services and advance economic growth. Some of our member states have already started their national efforts in the identification and protection of critical infrastructure, but at the regional level, Chair, we would like to share that in accordance with the OAS General Assembly mandate last year, a model national strategy on the protection of critical infrastructure for all hazards is being developed at the regional level within the OAS member states. As a part of that, a comprehensive strategy will be approved by our member states later this year after consultations over the past two years. This initiative, we believe, will inform established processes and practices of our member states, and we have been receiving technical support from CISA, an agency of the United States government. The finalized outcome document, we believe, Chair, is an example of the type of tools that can be provided to member states to help in their protection of critical infrastructure. Finally, in relation to cross-regional cooperation, as it relates to critical infrastructure, the OAS CICTE has been working with the EU CyberNet Project. EU experts have supported OAS member states upon request to be able to do not just national risk assessments, but we’ve also received support in the identification of critical infrastructure with a view of actually having protection measures put in place. We believe, Chair, that sharing these examples will demonstrate to member states ways in which they can actually implement the norms, including the protection of critical infrastructure. Thank you, Chair.

Ambassador Gafoor

Thank you very much, OAS, for your statement. Now, France, before we move on to the next cluster, which is international law, I don’t want to do a summary, certainly not an exhaustive one, but some scattered thoughts from the podium at this stage. Very, very encouraged by what I’ve heard earlier this morning and today, that there is a strong desire and appetite to get deeper into the norms implementation discussion, and we saw that here today. Also very heartened that many of you mentioned that you have already begun that process of implementation at the national level, at the regional level, and that many of you have also incorporated these norms adopted at the global level in your own strategies, national strategies, national cyber strategies, regional strategies, etc. So the rules, norms, and principles are being given shape and life through various actions already, and that’s very heartening. At the same time, many of you have also signaled that it is necessary to go deeper into clarifying the norms, including the idea of norms implementation checklists that many of you have referred to and expressed your support in various ways, and I think that’s very useful. There was also a lot of traction and appetite for a deeper discussion on what we can do with regard to the norms around critical infrastructure and critical information infrastructure. Many of you made some detailed remarks with regard to those three norms relating to CI and CII, as well as the supply chain integrity, which is also part of the framework of norms. So in this regard, I mean, I would very much welcome proposals and ideas and contributions that you have already or you would like to put together with groups of delegations, and if you’d like to convey them to the chair, I’ll be very happy to receive them. I think there were also some delegations who addressed some very specific proposals in terms of proposals for possible new norms and also possibilities for elaborating existing norms, and again, I would encourage delegations to work with each other, having heard each other today, you know, to work together to see if we can put your thoughts on a piece of paper, and whatever you can agree among yourselves in groups or smaller groups or cross-regional groups, even better, I’ll be also very happy to receive them. Now, going through my notes, yeah, I think those were some of the initial impressions that I wanted to share, and certainly, we are going to have a dedicated session as well in May, so that will give us an opportunity, but I think for the dedicated inter-sessional meeting to be meaningful, we must already have some concrete material for us to discuss and see if we can find some common ground. So between now and the inter-sessional in May, I think we have an opportunity to discuss some of the common ground. So between now and the inter-sessional in May, I think we have an opportunity to start discussing, and meanwhile, with regard to the norms implementation checklist that the chair is to put together, I will also give some thought, and if groups or cross-regional groups have ideas with that regard, I would also welcome that very much. So overall, guess what? I’m giving you another A-plus for responding to the guiding questions in a very detailed way, and therefore, I propose that we now move to the next cluster, agenda item five, how international law applies to the use of ICT. Now, before we begin the discussions, so please press your buttons if you’d like to intervene under this item, I’d like to invite UNIDIR, our colleagues from UNIDIR, you would be familiar with them, and they had organized a workshop recently in Geneva on international law and the behavior of states in the use of ICTs, challenges and opportunities, and they had invited me to this workshop in Geneva. I had planned to attend that, but unfortunately, I couldn’t because of work engagements in New York, and I think UNIDIR has also prepared some kind of report, so I thought that perhaps we could ask them to kick off the discussion by sharing with us some of the impressions from that workshop and to see whether that can feed into our discussion in one way or another. So, UNIDIR, you have the floor, and then we’ll go on to the speaker’s list after that. UNIDIR.

UNIDIR

Thank you, Mr. Chair. It is an honor to have the opportunity to take the floor and open the discussions on such an important topic that is international law. I will use the next few minutes to share some reflections on the recent event that you mentioned that we organized in Geneva on the topic of international law. We did release a preliminary summary report on Friday last week as a working paper that you can all consult on OEWG’s website, and soon we will publish the final version on UNIDIR’s website. I would like to start by acknowledging the co-sponsors of this workshop, as I believe that the diversity of this group is a very important first indicator of the appetite and willingness that exists to engage in substantive discussions on the topic of international law. In alphabetical order, this event was supported by the governments of China, Czech Republic, France, Germany, the Netherlands, the Russian Federation, Switzerland, and the United Kingdom. Apologies in advance because in a few minutes there is a very high risk that I will oversimplify the outcomes of what was a very fruitful full day of discussions, so please do not use what I’ll say against me later, but if you’re interested in knowing more, have a look at our summary paper or come to see me and I’ll be very happy to share more information. I’ll briefly cover what we did, why we did it, and what we would like to do next. Starting with the why, through our workshop, which was designed as an experiment, we really wanted to provide a platform for states to exchange substantive and expert views on how international law applies to the ICT environment, what are the potential challenges, and related solutions. Our goal was really to take the discussion away from the well-known political positions on international law and instead try to focus on substantive considerations on a range of very specific aspects related to international law. This first edition of the workshop involved 62 state representatives and legal experts from 23 states. We discussed a set of scenarios prepared by us, by UNIDIR, describing fictional ICT incidents that provided a context, or the way in which we like to call it a reality bubble, for deliberation on how international law might apply, as well as the potential associated challenges. In creating the scenarios, we played with several variables that we thought were important, ranging from the type of target, the type of malicious activity, the severity of the consequences, the number of states involved, the evidence available about perpetrators, and other factors. These workshop scenarios guided the participants to consider the international legal principles of sovereignty and of peaceful settlement of disputes, both of which are explicitly confirmed by the General Assembly as applicable to state behavior in the use of ICT. Within these principles, more detailed discussions took place on issues such as the obligation of non-intervention, the prohibitions of the threat or use of force, issues related to due diligence, and attribution. I will not provide now too many details, but the workshop did highlight that there are several areas of convergence upon which this group can build, and areas that could benefit from further exchanges. Now, rather than listing what these areas are, for which I recommend that you read the summary paper, I would like to highlight a few important key takeaways. First, it was clear that, it emerged clearly that while, you know, when the discussions remain at the very high level, at the political level, it is easier to identify clear schools of thought. When faced with scenarios that are simply tools that can bring the discussion closer to reality, then the discussions become much more nuanced, and interpretations of the details make a real difference. The workshop, we consider it to be a success, as it highlighted the benefit of coming together in person where possible, and where not, at least in hybrid format, to exchange views on simulated complex incidents, which in turn contributed to building a more robust mutual understanding of respective positions, again, going beyond the well-known political statements that we hear often in this forum. The workshop also demonstrated the overall value of using scenarios as tools to structure more substantive exchanges. Scenarios allowed experts to articulate their legal analysis against incidents that, while being fictional, were inspired by the real world. That gives us no shortage of examples of how malicious ICT activities can be conducted, and also provided a very concrete platform for exchanging views and interpretations and considerations. But based on this pilot exercise, we believe that the same approach can also be a very important and powerful tool for increasing awareness and building knowledge among those that may not have yet developed a very strong or elaborate national legal capacity that can address the challenges of the ICT domain. Building on this last point, I will conclude by saying that we will be building on the success of this workshop, which, again, was a pilot exercise. We thought we could pull it off, but we weren’t sure until we did it. And from next year, you can all expect to be invited at some point to take part in more of these activities that will be organized following two parallel tracks. One focused on exploring in-depth different situations and scenarios, and this track will be designed for those states which already have developed a clear position on international law that have legal expertise that they can share. And a second track designed more with knowledge and capacity building in mind. With this dual track, we hope to support the work of this group by both increasing the number of states that will take the floor and engage in the important discussions on international law, but also by providing all of you in this room with a more detailed and nuanced understanding of the specific issues that could benefit from a more detailed discussion in this forum. And with that, I thank you, Mr. Chair.

Ambassador Gafoor

Thank you very much, UNIDIR, for that overview. And we also take note of your indication that you will invite people in the room, and I hope very much that the invitation will be extended to as many people as possible so that we get everyone involved in this conversation in order to build understanding using scenario-based exercises, as you put it, leading to convergence. So I hope that everyone would look at the report as well, which I think has been made available. Perhaps we can put it on the website. The Secretary will do that. So let’s go through the list of speakers, and then we’ll continue as much as possible this evening, and then we’ll continue tomorrow. So, Canada to be followed by the European Union. Canada, please.

Canada

Chair, it has been 10 years since UN Member States first agreed on the application of existing international law in cyberspace. Our Open-Ended Working Group, further to our mandate, is making steady progress in building common understandings on the application of international law. Our mandate is being advanced through a growing range of capacity-building activities focused on international law and cyber. Chair, we have, in a word, momentum. We are, in your words, gaining altitude. Whereas Canada has said before, we are advancing in building our birchbark canoe, joining together elements to make a boat that will float and paddle well in the waters of cyberspace in the future. Chair, Canada thanks you and your team for the guiding questions which are providing focus to our discussions. On your first question, on convergence of views on international law, Canada answers with an emphatic yes. There is growing convergence in two ways. First, with more Member States active in discussions, here at the OEWG and beyond, and secondly, in substantive areas of international law. On the latter, we would mention in particular the Charter of the United Nations, the Prohibition on the Threat or Use of Force, the Prohibition on Intervention, and the Obligation to Settle Disputes Peacefully. Continued discussions on these topics will deepen our common understandings. Further, we see a common ambition to clarify how international law addresses violations. This is evidenced in our discussions on the international law of state responsibility, which reveal broad agreement on its application and utility in cyberspace. We should keep discussing the law of state responsibility. Chair, this convergence did not happen by chance. It is resulting from our focused discussion on international law topics, targeted capacity-building activities, the development of national and regional statements, deliberations among states on hypothetical scenarios in events like the recent UNIDIR workshop, which was just reported on, and regional efforts such as those of the OAS and the African Union. All these efforts should continue for the life of our OEWG and beyond. Chair, on the second question, Canada has concluded that cyberspace is not unique such that it requires a distinction in how international law applies. Cyberspace clearly involves new technology, but this does not mean that established legal rules do not apply. These rules have been developed to govern state behavior generally in all realms, so logically they will apply to state behavior in cyberspace. Some states have expressed concern about their ability to meet their legal obligations in cyberspace and benefit from the rules of state responsibility. These are legitimate concerns that our OEWG should continue to address. However, these concerns at root seem to involve questions of capacity and resources not unique to cyberspace rather than the adequacy of the law. These concerns can be addressed, as our OEWG has recognized, by cooperation among states through capacity building or technical assistance, whether from other states, the private sector, UN bodies such as UNIDIR, or civil society. The Global Forum on Cyber Expertise has much to offer in this regard. Chair, on the third question, Canada sees gaps, but we see gaps in our shared efforts in interpreting how international law applies in cyberspace. The process of interpretation of applicable law is not unique to cyberspace. Rather, it is a classic task for international lawyers who, over time, have developed tools for interpretation. A growing number of Member States are publishing national or regional positions on how the law applies. Some of these statements identify not gaps, but topics for further clarification which can guide our ongoing work. Finally, question four on capacity building. Canada observes that Member States have identified two priority areas for capacity building on international law. First, national expertise to enable meaningful participation in substantive legal discussions in multilateral processes such as our OEWG. This need is being addressed through many initiatives, such as training courses by Cyber Law International that Canada and other states support. More than 250 government officials from 82 Member States have benefited from these Canadian-funded courses, and this is but one initiative. The second priority is expertise to develop national or regional positions. This is best achieved, in our view, through cooperation between Member States, including with regional peers, based on national requirements. A promising example is the African Union initiative to develop a common position, which includes training for African officials and consultations with African legal experts virtually and in Addis Ababa, New York, and Tunis in recent months. Canada stands ready to share our own experiences in developing a national statement. The recent Global Conference for Capacity Building, GC3B in Accra, Ghana, has provided an up-to-date set of capacity-building priorities relevant to international law, including a focus on the rule of law and respect for human rights. This can also guide our OEWG. In conclusion, Chair, to gain further altitude, we must continue to focus discussions on international law and cyber, and facilitate the participation of many more Member States in these discussions. We look forward to intersessional work on international law in 2020-24 and 2025, complemented by further UNIDIR and similar workshops, and targeted capacity building grounded in the needs of Member States. All of this will allow us to gain more altitude and to successfully land a plane in time for our APR in July and our final landing in 2025, and to complete the delicate but strong birchbark canoe we are building together in this OEWG for stability and security in cyberspace. Thank you.

Ambassador Gafoor

Thank you very much, Canada, for your statement. It’s clear that you and your delegation are deeply attached to the Birch Bark Canoe. We welcome that. Yeah, I think the aviation metaphor has also been used, so I’m figuring out how we gain altitude with a Birch Bark Canoe, and I hope we don’t have a water landing. But I think your point is well made. I think we need to gain altitude, we need to go deeper, and I think there are a lot of issues to unpack on the international law side. Thanks for responding to the questions. So let’s continue so that we all listen to each other to see how we can find common ground. EU followed by Cuba and then Thailand. EU, please. Thank you very much.

Thank you, Chair, for giving me the floor. I have the honour to speak on behalf of the European Union and the 27 Member States. The candidate countries North Macedonia, Montenegro, Albania, Ukraine, the Republic of Moldova, and Bosnia and Herzegovina, the potential candidate country Georgia, and the EFTA countries Iceland and Norway, members of the European Economic Area, as well as San Marino, aligned themselves with this statement. The international community recognizes that existing international law, including the UN Charter in its entirety, is applicable in cyberspace and is essential for maintaining peace and stability and promoting an open, secure, peaceful, and accessible ICT environment. States have also recognized the applicability of the Law of State Responsibility, international human rights law, and in situations of armed conflict, international humanitarian law. This is reflected in the 2013, 2015, and 2021 reports of the UNGGE and the 2021 report of the UN Open-Ended Working Group on Cyber, all endorsed by all Member States in the UNGA, as well as the first and second annual progress reports of this Open-Ended Working Group. The 2021 Open-Ended Working Group report called upon States to avoid and refrain from taking any measures not in accordance with international law, and in particular the Charter of the United Nations. The report concluded that States continue to engage in focused discussions at the Open-Ended Working Group on how international law applies in the use of ICTs. This needs to be the departure point of our discussions. Elaborating how existing international law applies to state activity in cyberspace is necessary in order to build the practical understandings of States’ rights and obligations under international law in the cyber context, as well as on how to better implement the Law of State Responsibility when a State breaches its obligations through cyber means. This year, several States have shared their national perspectives on how existing international law applies in cyberspace, adding to the several dozen States which have done so previously. In doing so, they have contributed to further clarification of key legal roles and principles, such as the principle of state sovereignty, non-intervention, etc. We welcome the broadening of the debate with contributions from States that for the first time have outlined their views, as well as the increasingly higher level of details in national positions that have been adopted and shared. These developments have shown that there is broad agreement among States on key aspects of the application of international law to the cyber context, including the application of the UN Charter, the settlement of peaceful disputes, the Law of State Responsibility, as well as international human rights law and international humanitarian law. While substantial progress has been made, there remain areas for further convergence in States’ perspectives on how international law applies in the use of ICTs. And as we can see from many of the national positions so far, the primary issue does not appear to be the existence of gaps, but rather how to interpret existing rules of international law to address some specific issues in the cyber context. We are confident that as more States engage in this process of developing and sharing their national positions, it will contribute to developing a better common understanding on how international law applies in cyberspace and become even clearer that the existing international rules and principles provide a comprehensive legal framework to regulate State behavior in cyberspace. In light of that, needs-based capacity building has never been more important, not only in terms of scale, but also in terms of depth in accordance with agreed capacity building principles. The international community should seek to ensure that all States that express a need are able to benefit from capacity building initiatives designed to deepen the expertise regarding international law in cyberspace. For example, such capacity building could support States in forming their own national assessment and position on how international law applies to cyberspace. This primarily involves making professional educational programs available to governmental legal advisors, but also sensitizing other public officials involved in cyber affairs, diplomats, policymakers and advisors, cyber operators, decision makers, and law enforcement personnel, to the fact that the decisions they make, the advice they give, is guided by international law. It is only through engagement and targeted discussions, like the workshop provided by the UNIDIR, and others, that we can improve our collective understanding. The EU therefore welcomes the recommendations of the annual progress report to convene a dedicated international meeting on how international law applies to cyber operations. Such a meeting of several days should be well prepared by an expert paper identifying key issues to be discussed by legal advisors. Thank you.

Ambassador Gafoor

Thank you very much, EU. Cuba, please.

Cuba

Mr. Chair, we are grateful for the non-exhaustive list of questions to guide our debate. We hope to contribute to these deliberations, be it on the basis of those questions or by adding other elements and considerations. To address the question we are discussing today, we consider it essential to start with the fact that the security of cyberspace, although it may involve other actors, is a responsibility of states. After the debates in the framework of the Open-Ended Working Group in 2019-2021 and the current one, we agree with the validity of the principles of international law and the United Nations Charter in cyberspace. In particular, those of sovereignty and territorial integrity and non-interference in the internal affairs of states in using information and communications technologies. However, since cyberspace is an extremely dynamic environment and the nature of the events leading to disputes are different from those in other areas that impact international security, it is not possible to address and mitigate the growing threats associated with the malicious uses of ICTs by automatically applying the tools of existing international law. In this regard, a clear difficulty, for example, is determining the origin of incidents relating to the use of ICTs. Unilateral attributions can be questioned since there is no multilateral mechanism to determine impartially and unequivocally the origin of incidents, nor is there a common terminology to facilitate understanding among states on the matter. The concepts which try to equate a cyber attack to a traditional armed attack and trying to justify in the context of cybersecurity the presumed applicability of self-defense provided for in Article 51 of the UN Charter are not acceptable. Our delegation firmly opposes this approach. We also reject the attempts to base the concept of applicability of humanitarian international law to the use of ICTs in the context of international security. We recall that the conventions under international humanitarian law were agreed to apply to armed conflicts and they are only applicable in these cases. To assume that those norms apply to ICTs would imply tacitly applying the possibility of armed conflict in this area. It would contribute to the militarization of cyberspace. Mr. Chair, the debate on the way in which international law is to be applied to the use of ICTs strengthens its relevance. However, it cannot follow an approach in which certain topics having to do with international law prevail over others selectively, especially when they are not the object of consensus. Discussions in the framework of the group must strictly follow the mandate given to this group in Resolution 75/240. Capacity building, especially for developing countries, goes beyond matters relating to the application of international law. Developing countries require greater commitments on cooperation, technical assistance, and transfers of technology by developed countries, as well as the immediate elimination of unilateral restrictions which limit the access of many countries of the global south to that assistance. We need a legally binding instrument on ICTs in the context of international security which responds to the significant legal gaps in matters of security and which makes it possible to address duly the growing challenges and threats through international cooperation. This must be a multilaterally negotiated instrument in the framework of the United Nations. We can make use of the space provided by this group to begin these negotiations. Thank you.

Ambassador Gafoor

Thank you very much, Shubha. I’m conscious of the time, and Thailand, if you do not mind, perhaps we can take you tomorrow, so that way we do justice to your statement as well, and we don’t rush you, and we don’t keep the interpreters, who have been very kind to us, beyond the six o’clock time limit. So, France, another great start, and let’s continue the discussions tomorrow to look at the four guiding questions, and I hope to hear as many of you as possible tomorrow morning. The meeting is adjourned. Have a pleasant evening.

Leave a Reply

Your email address will not be published. Required fields are marked *