international positions and treaty obligations undermine our credibility and effectiveness in our pursuit of international order in this area. With that in mind, ‘practice what you preach’, too, should serve as a point of departure for domestic policy. Obviously, the Netherlands is only obliged to abide by international rules once international consensus exists and the Netherlands has consented to assume the relevant obligations. 6. The internet’s transnational nature means that any challenges and threats that may arise with regard to security must be dealt with in an international forum. Given that the international legal order is based on the principle of sovereignty, national governments can only address security challenges in cyberspace to a limited degree. This is an issue that requires international cooperation in accordance with an integrated approach. 3. Approach The government takes an integrated approach to international cooperation on cyber policy. This extends to a variety of areas, which are discussed below. This section also looks at prospects for further policy development. 3.1 International cooperation, diplomacy and strengthening international legal frameworks At both the domestic and international level, effective cooperation on cyber policy is a joint effort requiring the input of policymakers and the implementing bodies involved in the operational side of the equation. In keeping with this principle the Dutch government pursues its policy through a variety of channels (outlined below). A. In order to promote the Netherlands’ domestic and foreign interests, the government forges broad coalitions and partnerships, both bilaterally and multilaterally, in international organisations like the United Nations (UN), the European Union (EU), the North Atlantic Treaty Organization (NATO), the Council of Europe, the Organisation for Economic Co-operation and Development (OECD) and the Organization for Security and Co-operation in Europe (OSCE). The private sector, the technology community, academia and the non-governmental sector are involved by means of multi-stakeholder and public-private platforms such as the Internet Governance Forum (IGF), the Internet Corporation for Assigned Names and Numbers (ICANN), the Contractual Public-Private Partnership (cPPP) on cybersecurity, launched by the EU in July, and the European Information Sharing and Analysis Centres (ISACs). B. A wide range of operational partnerships have been based on these bodies and coalitions, particularly in the realm of security. This is done through platforms like the Forum of Incident Response and Security Teams (FIRST), the Task Force on Computer Security Incident Response Teams (TF CSIRT), the Malware Information Sharing Platform (MISP) and the European CSIRT network, the last of which includes the participation of national bodies like the National Cybersecurity Centre (NCSC) and the Computer Emergency Response Team of the Ministry of Defence (DEFCERT). Throughout the whole cybersecurity system and within every element of the law enforcement process – from prevention to detection and from the initial response to investigation and prosecution – the Netherlands works with international partners. This includes providing mutual legal assistance in criminal cases. The majority of the organisations concerned have their own networks for that purpose. In the event of large-scale crises and incidents, the Netherlands can deploy its standard diplomatic instruments, complementary to regular and existing crisis structures, such as those associated with NATO and the EU Integrated Political Crisis Response (ICPR), in addition to the national handbook on decision-making in crises. C. The Netherlands is committed to building and promoting an international legal and normative framework for cyberspace. Various ministries are focusing on this in international forums where international norms and standards are discussed. These norms and standards, which AVT17/BZ122203 6

Select target paragraph3