4 both bilaterally and multilaterally, to help maintain international peace and security in cyberspace. We also contribute to setting international standards for new technologies, which can help prevent ICT practices that are harmful. On behalf of the UK, Jeremy Wright QC MP, the then Attorney General, set out the UK’s position on the application of international law in cyberspace in a speech at Chatham House on 23 May 2018. The UK first published a National Cyber Strategy in 2011. In October 2016, a second edition issued, supported by funding of £1.9bn, outlining UK goals for the continued shaping and investment in cyber security over another five-year term. The current strategy defines our vision and ambition to be secure and resilient to cyber threats as well as prosperous and confident in a digital world. We will continue to pursue economic and social value from cyberspace where our actions, guided by our core values, will enhance prosperity, national security and a strong society. The strategy contains three main pillars, which the whole of our society has a role in helping to deliver:  Defend our people, businesses and assets across the public and private sectors;  Deter and disrupt our adversaries: states, criminals and hacktivists;  Develop our critical capabilities and grow our cyber security sector. We also look to develop industry standards on security of technology, which help build cyber resilience globally. We continue to be active in the international standards space, as in order for this issue to be resolved, we know that there will need to be alignment at an international level. For example, in February 2019 the first globally applicable technical standard for Internet of Things security was released, based on the Code of Practice for Consumer Internet of Things Security 2, which we published in October 2018. We are now working to transpose this into a European Standard (EN), and we encourage ETSI members to play an active role in shaping this before then. Norm 2 (UNGGE 2015 report, paragraph 13b) – In case of ICT incidents, States should consider all relevant information, including, inter alia, the larger context of the event, the challenges of attribution in the ICT environment, and the nature and extent of the consequences The United Kingdom, through its National Cyber Security Centre (NCSC) has developed an integrated approach to national incident management in the public and private sectors. This has brought together several approaches that existed for different sectors and, in doing so, has simplified the process. The new incident management approach has been operating since mid-2016. Since it became fully 2 https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/77 3867/Code_of_Practice_for_Consumer_IoT_Security_October_2018.pdf

Select target paragraph3