35. States, bearing in mind General Assembly resolution 73/27, also reaffirmed the voluntary, nonbinding norms of responsible State behaviour of the 2015 GGE report, 5 recalling that consensus
resolution 70/237 calls upon States to be guided in their use of ICTs by the 2015 GGE report, which
includes the 11 voluntary, non-binding norms.
36. Attention was drawn to the international code of conduct for information security tabled in 2015.6
States also recalled General Assembly resolutions 2131 (XX), 1965 entitled “Declaration on the
Inadmissibility of Intervention in the Domestic Affairs of States and the Protection of their
Independence and Sovereignty” and 58/199 entitled “Creation of a global culture of cybersecurity and
the protection of critical information infrastructures”.
37. States stressed the need to promote awareness of the existing norms and support their
operationalization. While these norms articulate what actions States should or should not take, States
underscored the need for guidance on how to operationalize them. In this regard, States called for
the sharing and dissemination of good practices and lessons on norm implementation. Different
cooperative approaches were also proposed, such as developing a roadmap to assist States in their
implementation efforts.
38. States, during discussions and through written submissions, also proposed suggestions for the
“upgrading” as well as further elaboration of norms. Proposals included, inter alia, that States should
affirm their commitment to international peace and security in the use of ICTs; that it should be
reaffirmed that States hold the primary responsibility for maintaining a secure, safe and trustable ICT
environment; that the general availability or integrity of the public core of the Internet should be
protected; and that States should not conduct ICT operations intended to disrupt the infrastructure
essential to political processes or harm medical facilities. States also proposed the need to further
ensure the integrity of the ICT supply chain, expressing concern over the creation of harmful hidden
functions in ICT products, and the responsibility to notify users when significant vulnerabilities are
identified. States also highlighted that supranational critical information infrastructure could be
considered a special category of critical infrastructure, and that its protection was the shared
responsibility of all States.
39. [placeholder: additional proposals by Member States for new norms could be introduced here]
40. The need to encourage partnerships and joint efforts with the private sector and other stakeholders
on the implementation of norms was highlighted, including with regard to ensuring sustainable
capacity-building efforts. It was noted that all stakeholders had responsibilities in their use of ICTs.
5
6
A/70/174, paragraph 13.
A/69/723.
7