46. Drawing from the lessons and practices shared at the OEWG, States emphasized that the prior
existence of national and regional mechanisms and structures, as well as adequate resources and
capacities, are essential to ensuring that CBMs serve their intended purpose. In this regard, States
underscored the significant efforts of regional and sub-regional bodies in developing CBMs, adapting
them to their specific contexts, as well as the crucial awareness raising and information sharing role
that cross-regional or inter-organizational exchanges have served. It was noted that, as not all States
are members of a regional organization and not all regional organizations have CBMs in place, it is
important that other fora are used to promote CBMs as well. States also proposed that some CBMs
developed at the regional level could be universalized.
47. States drew attention to the roles and responsibilities of other actors, including the private sector,
academia and civil society, in contributing to building trust and confidence in the use of ICTs at
national, regional and global levels. States noted the variety of multi-stakeholder initiatives that have,
through the development of principles and commitments, established new networks for exchange,
collaboration and cooperation. In a similar vein, sector- or domain-specific initiatives have
demonstrated the growing awareness of the roles and responsibilities of other actors and the unique
contributions that they can make to ICT security through voluntary commitments, professional codes
and standards.
F. Capacity-building
Capacity-building helps to develop the skills, define the policies and build the institutions that increase the
resilience and security of States so they can fully enjoy the benefits of digital technologies. The
international community’s ability to prevent or mitigate the impacts of malicious ICT activity depends on
the capacity of each State to prepare and respond. Capacity-building can also support adherence to
binding or voluntary commitments. In a digitally interdependent world, the benefits of capacity-building
“spill over” national borders and thereby contribute to a more secure and stable ICT environment for all.
48. In their discussions at the OEWG, States reiterated the recommendations on international
cooperation and capacity-building in the consensus GGE reports. They emphasized the critical
function that capacity-building can play with regard to empowering all States and other relevant
actors to fully participate in the global normative framework, while also contributing to shared
commitments such as the 2030 Sustainable Development Agenda. In addition, capacity-building plays
an important enabling function for promoting adherence to international law and the implementation
of the voluntary, non-binding norms of responsible State behaviour and the CBMs recommended by
the previous GGEs, while also offering important opportunities for building understanding between
and within States.
49. States noted that capacity-building helps to address the systemic and transnational risks arising from
a lack of ICT security, disconnected technical and policy capacities at the national level, and the related
challenges of inequalities and digital divides. Capacity-building aimed at enabling States to identify
and protect national critical infrastructure and to cooperatively safeguard supranational critical
information infrastructure was deemed to be of particular importance.
50. There was a general acknowledgement that in addition to technical skills, there is a pressing need for
building expertise across a range of diplomatic, policy, legislative and regulatory areas.
9