relevant regional and international organizations, such as the OSCE, the EU CSIRT network
or the parties to the Budapest Convention.
Norm 9 – States should take reasonable steps to ensure the integrity of the supply chain,
so end users can have confidence in the security of ICT products. States should seek to
prevent the proliferation of malicious ICT tools and techniques and the use of harmful
hidden functions.
G7 countries have taken a series of steps to ensure the integrity of the supply chain and
to prevent the proliferation of malicious ICT tools and techniques and the use of
harmful hidden functions, such as:
-
-
Developing and promoting frameworks, recommendations, codes of conduct, norms
and standards for industry, to improve awareness of supply chain security and help
companies establish effective control and oversight of their supply chain – these can
also include labelling, evaluation and certification schemes;
Establishing procedures to ensure ICT procurement by the public sector helps drive
improvements in security and resilience;
Supporting the proper and effective use of export-control regimes to prevent the
proliferation of malicious ICT tools and techniques.
Norm 10 – States should encourage responsible reporting of ICT vulnerabilities and
share related information on available remedies to such vulnerabilities, in order to limit
and possibly eliminate potential threats to ICTs and ICT-dependent infrastructure.
G7 countries have established procedures, mechanisms and sometimes legal frameworks
that facilitate and encourage responsible disclosure of vulnerabilities by and to their
national cybersecurity agencies. They have increased cooperation with public and private
partners to better share information on vulnerabilities, mitigation and recovery measures and
developed programmes to assist partners in creating vulnerability disclosure processes.
Norm 11 – States should not conduct or knowingly support activity to harm the
information systems of another State’s authorized emergency response teams
(sometimes known as CERTS or CSIRTS). A State should not use authorized emergency
response teams to engage in malicious international activity.
As a principle, and as responsible States, all G7 countries have strongly reaffirmed that
they will not conduct or knowingly support activity to harm another State’s CERT, nor
use their own CERT to engage in malicious international activities./.
Page 5 out of 5
For Official Use Only