international positions and treaty obligations undermine our credibility and effectiveness in our
pursuit of international order in this area. With that in mind, ‘practice what you preach’, too,
should serve as a point of departure for domestic policy. Obviously, the Netherlands is only
obliged to abide by international rules once international consensus exists and the Netherlands
has consented to assume the relevant obligations.
6. The internet’s transnational nature means that any challenges and threats that may arise with
regard to security must be dealt with in an international forum. Given that the international
legal order is based on the principle of sovereignty, national governments can only address
security challenges in cyberspace to a limited degree. This is an issue that requires
international cooperation in accordance with an integrated approach.
3. Approach
The government takes an integrated approach to international cooperation on cyber policy. This
extends to a variety of areas, which are discussed below. This section also looks at prospects for
further policy development.
3.1
International cooperation, diplomacy and strengthening international legal
frameworks
At both the domestic and international level, effective cooperation on cyber policy is a joint effort
requiring the input of policymakers and the implementing bodies involved in the operational side of
the equation. In keeping with this principle the Dutch government pursues its policy through a
variety of channels (outlined below).
A. In order to promote the Netherlands’ domestic and foreign interests, the government forges
broad coalitions and partnerships, both bilaterally and multilaterally, in international
organisations like the United Nations (UN), the European Union (EU), the North Atlantic Treaty
Organization (NATO), the Council of Europe, the Organisation for Economic Co-operation and
Development (OECD) and the Organization for Security and Co-operation in Europe (OSCE).
The private sector, the technology community, academia and the non-governmental sector are
involved by means of multi-stakeholder and public-private platforms such as the Internet
Governance Forum (IGF), the Internet Corporation for Assigned Names and Numbers (ICANN),
the Contractual Public-Private Partnership (cPPP) on cybersecurity, launched by the EU in July,
and the European Information Sharing and Analysis Centres (ISACs).
B. A wide range of operational partnerships have been based on these bodies and coalitions,
particularly in the realm of security. This is done through platforms like the Forum of Incident
Response and Security Teams (FIRST), the Task Force on Computer Security Incident
Response Teams (TF CSIRT), the Malware Information Sharing Platform (MISP) and the
European CSIRT network, the last of which includes the participation of national bodies like the
National Cybersecurity Centre (NCSC) and the Computer Emergency Response Team of the
Ministry of Defence (DEFCERT).
Throughout the whole cybersecurity system and within every element of the law enforcement
process – from prevention to detection and from the initial response to investigation and
prosecution – the Netherlands works with international partners. This includes providing
mutual legal assistance in criminal cases. The majority of the organisations concerned have
their own networks for that purpose. In the event of large-scale crises and incidents, the
Netherlands can deploy its standard diplomatic instruments, complementary to regular and
existing crisis structures, such as those associated with NATO and the EU Integrated Political
Crisis Response (ICPR), in addition to the national handbook on decision-making in crises.
C. The Netherlands is committed to building and promoting an international legal and normative
framework for cyberspace. Various ministries are focusing on this in international forums
where international norms and standards are discussed. These norms and standards, which
AVT17/BZ122203
6