development and hamper the efforts, particularly of developing countries, in realizing their sustainable development goals. 28. The elaboration of binding norms would help in strengthening cooperation and trust between governments, as well as between governments and the private sector. Such norms and rules must also set standards for stakeholders and entities from the private sector. Confidence Building Measures 29. Previous GGE reports have recognized that CBMs strengthen international peace and security and that they can increase interstate cooperation, transparency, predictability and stability. 30. Reports of previous GGEs include valuable recommendations that can enhance confidence among States in the ICT environment. These include: identification of points of contact to address serious ICT incidents; development of mechanisms and processes for bilateral, regional, subregional and multilateral consultations to reduce the risk of misperception, escalation and conflict from ICT incidents; and encouraging transparency on a voluntary basis to increase confidence. 31. Voluntary sharing of information regarding infrastructure that they consider critical and national efforts to protect them, including national laws and policies for the protection of data and ICT-enabled infrastructure, also represents a useful measure. 32. Establishment of computer emergency response team at the national level and promoting cooperation among such bodies represents a useful measure. Such cooperation could include, where appropriate, addressing requests from other States to investigate ICT-related incidents or to mitigate malicious ICT activity emanating from their territory, while taking into account the possible limitations on the technical capacities of developing countries to address such requests. Capacity-building 33. States bear primary responsibility for national security and the safety of their citizens, including in the ICT environment. However, some States may lack sufficient capacity to protect their ICT networks. 34. In a highly interconnected world, lack of capacity for ICT security among States may present a serious threat to security and stability in the global ICT environment. Towards this end, international cooperation and assistance to enhance States’ capacity can play an essential role in enabling them to secure ICTs, ensure their peaceful use and strengthen international security. 35. Previous GGE reports have recommended a number of measures to develop capacity of States. These include assistance in strengthening cooperative mechanisms with national computer emergency response teams; providing assistance and training to developing countries to improve security in the use of ICTs, including critical infrastructure, and exchanging best practices; providing access to technologies deemed essential for ICT security. 36. The 2015 GGE report has emphasized that capacity-building involves more than a transfer of knowledge and skills from developed to developing States, as all States can learn from each other about the threats that they face and effective responses to those threats. 37. Varying levels of capacity among States underscores their ‘common but differentiated responsibility’ in making the global ICT network safe and secure. Developed countries have a special responsibility in bridging the digital divide, securing the global ICT environment and achieving the development goals though international cooperation and assistance. 38. Capacity-building must be seen as a trust-building measure, requiring steps to ensure that capacity-building remains politically neutral, with the objective of bridging inequalities caused by the “digital divide”. 4/5

Select target paragraph3