35. States, bearing in mind General Assembly resolution 73/27, also reaffirmed the voluntary, nonbinding norms of responsible State behaviour of the 2015 GGE report, 5 recalling that consensus resolution 70/237 calls upon States to be guided in their use of ICTs by the 2015 GGE report, which includes the 11 voluntary, non-binding norms. 36. Attention was drawn to the international code of conduct for information security tabled in 2015.6 States also recalled General Assembly resolutions 2131 (XX), 1965 entitled “Declaration on the Inadmissibility of Intervention in the Domestic Affairs of States and the Protection of their Independence and Sovereignty” and 58/199 entitled “Creation of a global culture of cybersecurity and the protection of critical information infrastructures”. 37. States stressed the need to promote awareness of the existing norms and support their operationalization. While these norms articulate what actions States should or should not take, States underscored the need for guidance on how to operationalize them. In this regard, States called for the sharing and dissemination of good practices and lessons on norm implementation. Different cooperative approaches were also proposed, such as developing a roadmap to assist States in their implementation efforts. 38. States, during discussions and through written submissions, also proposed suggestions for the “upgrading” as well as further elaboration of norms. Proposals included, inter alia, that States should affirm their commitment to international peace and security in the use of ICTs; that it should be reaffirmed that States hold the primary responsibility for maintaining a secure, safe and trustable ICT environment; that the general availability or integrity of the public core of the Internet should be protected; and that States should not conduct ICT operations intended to disrupt the infrastructure essential to political processes or harm medical facilities. States also proposed the need to further ensure the integrity of the ICT supply chain, expressing concern over the creation of harmful hidden functions in ICT products, and the responsibility to notify users when significant vulnerabilities are identified. States also highlighted that supranational critical information infrastructure could be considered a special category of critical infrastructure, and that its protection was the shared responsibility of all States. 39. [placeholder: additional proposals by Member States for new norms could be introduced here] 40. The need to encourage partnerships and joint efforts with the private sector and other stakeholders on the implementation of norms was highlighted, including with regard to ensuring sustainable capacity-building efforts. It was noted that all stakeholders had responsibilities in their use of ICTs. 5 6 A/70/174, paragraph 13. A/69/723. 7

Select target paragraph3