A/68/156 up the necessary understanding and trust among signatories and to ensure that they can be reliably held to account for their adherence to their commitments. Experience in concluding these agreements on other subjects shows that they can be meaningful and effective only as the culmination of diplomatic attempts to develop shared understandings and approaches, not as their starting point. The United Kingdom believes that the efforts of the international community should be focused on developing common understandings on international law and norms rather than negotiating binding instruments that would only lead to the partial and premature imposition of an approach to a domain that is currently too immature to support it. Possible measures that could be taken by the international community to strengthen information security at the global level The borderless nature of cyberspace provides a particular imperative for States to enhance bilateral, regional and multilateral cooperation to develop common responses to common threats. In the view of the United Kingdom, the measures that could make the most significant contribution at this stage are: (a) Continuing discussions among States to develop a normative framework of acceptable State behaviour based on existing principles of international law and customary international norms; (b) The development of confidence building measures for cyberspace aimed at increasing the transparency and predictability of State behaviour, thus reducing the risk of misperception or unintended escalation of incidents; (c) The establishment of computer emergency response teams by States as a focus for incident-handling and information-sharing, supplemented by notification of key points of contact and reliable crisis communications mechanisms; (d) The development of joint exercises to test joint incident-handling and communications procedures; (e) The development of harmonized legal approaches to tackle cybercrime; (f) Enhanced dialogue with business and civil society representatives to ensure coordinated and prioritized approaches in a domain that is largely owned and operated by the private sector; (g) Commitments by States with more mature cybersecurity capabilities to support capacity-building for other States. 13-39735 19

Select target paragraph3