16 April 2020 with their obligations under international law to respect and protect human rights and fundamental freedoms (ref 28(b) 2015 GGE Report). X4. While the specific nature, scope and language would require further deliberation (and may not be the subject of consensus), certain proposals may more appropriately be considered in the context of providing guidance for implementation of norms articulated in para 13 of the 2015 GGE report (endorsed by consensus in A/Res/70/237), including:        China: dot points 1, 3-4 under heading ‘Critical infrastructure protection’ (ref paras. 13(f) and (g) of the 2015 GGE Report), noting dot point 2 under the same heading appears to duplicate para. 13(f) China: dot points 1-3 under heading ‘Supply Chain Security’ (ref para. 13(i) of the 2015 GGE Report), noting consensus might be found by comparing the current language with the Prague Proposals dated 3 May 2019 Croatia, Finland, France and Slovenia: dot point 2 (ref para. 13(c) of the 2015 GGE Report), noting dot point one appears to duplicate existing para. 13(c) and further noting that relevant language from the Paris Call and/or Global Commission on Stability in Cyberspace may provide a starting point for further consideration Cuba: dot point 2 (ref para. 13(b) of the 2015 GGE Report) Islamic Republic of Iran: dot point 5 (ref para. 13(c) of the 2015 UNGGE Report) Islamic Republic of Iran: dot point 6 (ref para. 13(i) or (j) of the 2015 UNGGE Report) Netherlands: dot points 1-2 (ref para. 13(f) of the 2015 GGE Report), noting that relevant language from the Paris Call and/or Global Commission on Stability in Cyberspace may provide a starting point for further consideration. X5. Welcome inclusion in the Report of a new stand-alone norm against cyber-enabled intellectual property theft for commercial gain (ref China: dot point 3, under heading ‘Data Security’) - provided that the language reflects the 2015 G20 Leaders’ Communique, which has subsequently been endorsed by many countries bilaterally, including by Australia and China (ref Joint Statement Australia-China High-Level Security Dialogue, Sydney, 2017). X6. While not diminishing their importance or gravity, other issues in the Non-paper (including: internet governance, data security and counter-terrorism) would be better addressed in other forums (see: UNODA Background Paper on existing UN bodies and processes related to the mandate, available on the OEWG’s website). Page 8 of 9 www.dfat.gov.au/cyberaffairs

Select target paragraph3