A/69/112 There is a trend towards hard-to-detect, sophisticated and malicious activities, targeting high-value objectives. Severe consequences may result. A cyberattack against key infrastructures could cause more disruption than an isol ated physical attack, sometimes with unpredictable consequences for other networked entities. Despite such risks, an all-out “cyberwar” seems unrealistic for the time being. A more likely scenario may be the limited use of cybercapabilities as part of a larger war-fighting effort. Finally, there is the danger that cyberincidents may escalate into “real-life” conflict. In this situation, increasing cyberresilience, agreeing on laws and rules that apply to the use of ICTs and engaging in confidence-building measures become ever more important. There has been welcome progress in 2013: The last report of the Group of Governmental Experts on Developments in the Field of Information and Telecommunications in the Context of International Security made clear th at international law is applicable to cyberspace. The Group also found that State sovereignty and international norms and principles that flow from sovereignty apply to State conduct of ICT-related activities and to its jurisdiction over ICT infrastructure within its territory. Germany is looking forward to seeing how the new Group of Governmental Experts will take this further. Concerning confidence-building measures, OSCE made important progress with the adoption of a first set of steps to increase inte r-State cooperation, transparency, predictability and stability, with a view to reducing the risks of misperception, escalation and conflict that may stem from the use of information and communication technologies. This OSCE agreement might be useful as a model for other regional organizations. Germany’s Cybersecurity Strategy (2011) proceeds from the assertion that the availability of cyberspace and the integrity, authenticity and confidentiality of data in cyberspace have become of vital importance. Ensuring cybersecurity has turned into a central challenge for the State, business and society. All need to act together, both at the national level and in cooperation with international partners. Germany ’s Cybersecurity Strategy sets out the following objectives and measures: • Protecting critical information infrastructures • Securing IT systems • Strengthening IT security in public administration • Running a national cyberresponse centre • Establishing a national Cybersecurity Council • Effective crime control in cyberspace • Effective coordinated action to ensure cybersecurity in Europe and worldwide • Using reliable and trustworthy information technology • Personnel development among federal authorities • Tools to respond to cyberattacks. 14-56479 11/18

Select target paragraph3