18. States noted significant technological trends, including progress in machine learning, encryption, and
quantum computing; the ubiquity of connected devices (”Internet of Things“); new ways to store and
access data through distributed ledgers and cloud computing; and the expansion of big data, including
digitized personal data. While recognizing the substantial beneficial applications of these innovations,
States cautioned that technological advances and new applications may also expand attack surfaces,
amplify vulnerabilities in the ICT environment or facilitate novel malicious activities. At the same time,
there was broad agreement that measures to promote responsible State behaviour should remain
technology-neutral.
19. While States observed that critical infrastructure is defined differently in accordance with national
prerogatives and priorities, they emphasized the severity of threats to particular categories of
infrastructure, including for instance the health and financial sectors and electoral infrastructure.
Transborder and transnational critical infrastructure was highlighted as at risk as was supranational
critical information infrastructure, notably those global systems upon which public or financial
services rely. In this regard, States underscored that attacks on critical infrastructure pose not only a
threat to security, but also to economic development and people’s livelihoods.
20. In light of the increasingly concerning digital threat landscape, and recognizing that no State is
sheltered from these threats, the OEWG underscored the urgent need for States to further develop,
through multilateral forums, cooperative measures to address such threats. It was affirmed that
acting together and inclusively would produce more effective and far-reaching results. The positive
contributions of the private sector, civil society and academia were also emphasized in this regard.
21. The following sections reflect the OEWG’s discussions of how the international community might
actively strengthen its collective resolve to address these threats. The concluding section contains the
OEWG’s recommendations.
C. International Law
Existing obligations under international law, in particular the Charter of the United Nations, are applicable
to State use of ICTs. Furthering shared understandings among States on how international law applies to
the use of ICTs is fundamental for international security and stability. Such shared understandings can be
fostered by encouraging exchange of views on the issue among States and by identifying specific topics of
international law for more in-depth discussion.
22. In their discussions at the OEWG, States reaffirmed that international law, and in particular the
Charter of the United Nations, is applicable and essential to maintaining peace and stability and
promoting an open, secure, stable, accessible and peaceful ICT environment.
23. Specific principles of the UN Charter highlighted include sovereign equality; the settlement of
international disputes by peaceful means in such a manner that international peace and security and
justice are not endangered; refraining in their international relations from the threat or use of force
against the territorial integrity or political independence of any State, or in any other manner
inconsistent with the purposes of the United Nations; respect for human rights and fundamental
freedoms; and non-intervention in the internal affairs of other States.
4