A/68/156/Add.1
responsibility of States not to facilitate areas of lawlessness in cyberspace, for
example, by knowingly tolerating the storage of illegally collected personal data on
their territory.
On 27 and 28 June 2013, the third Berlin Cyber Conference, held on the theme
“Securing the Freedom and Stability of Cyberspace: The Role and Relevance of
International Law”, and organized by the Federal Foreign Office in close
cooperation with the University of Potsdam, endeavoured to provide international
legal assessments of cyber operations not transgressing the threshold of armed
attack and thus not engaging the law of armed conflict. Consistent with existing
international norms and principles, States are responsible for the actions of those
within their sphere of control that affect the security and stability of information and
communications technology. Every State should consider how to minimize or end
malicious cyber activity originating from within its sphere of control or travelling
over its networks. States bear responsibility for internationally wrongful cyber
activity attributable to them, including the internationally wrongful activity in
cyberspace of any State-backed proxies acting on the State’s instructions or under its
direction or control, in accordance with existing norms of State responsibility under
customary international law. States should take all necessary measures to ensure that
their territories are not used by other States or by non-State actors for purposes of
unlawful use of information and communications technology against other States
and their interests. These necessary measures should include appropriate national
legislative and regulatory frameworks needed to meet international responsibilities.
Internationally wrongful cyber activity can affect States in three main ways: (1) as
countries of origin of malicious cyber activity with possibly damaging effects; (2) as
transit countries, whose information and communications technology infrastructures
are instrumentalized for malicious cyber activity; and (3) as target countries, where
damage caused by malicious cyber activity occurs. In all these scenarios, States are
obliged to exercise due diligence, which can be of both material and procedural in
nature and can range from prevention, i.e., the period preceding potential harm, to
containment, i.e., the onset of the actual, ongoing detrimental cyber activity, to
follow-up, i.e., the period after malicious cyber activity has been pursued.
Cyber security in the Organization for Security and Cooperation in Europe
The Organization for Security and Cooperation in Europe has been discussing
cyber security issues for several years. At the OSCE summit held in Astana in 2010,
the Heads of State and Government of the 56 participating States of OSCE
underlined that ‘‘greater unity of purpose and action in facing emerging
transnational threats” must be achieved. The Astana Commemorative Declaration
mentioned cyber threats as one of these emerging transnational threats.
Germany actively participated in the OSCE conference held in Vienna in 2011,
held on the theme “Exploring the future OSCE role”, on a comprehensive approach
to cyber security. In the course of the conference, concrete recommendations for
OSCE follow-up activities were discussed. In May 2012, an informal working group
was established by Permanent Council Decision 1039 (PC.DEC/1039) and tasked to
elaborate a set of draft confidence-building measures to enhance interstate
cooperation, transparency, predictability and stability, and to reduce the risks of
misperception, escalation and conflict that may stem from the use of information
and communication technologies. Germany submitted a non-paper to the group in
June 2012 containing German suggestions for a first set of confidence-building
13-47545
9/24