A/66/152 politically binding norms of State behaviour in cyberspace. They should be acceptable to a large part of the international community and should include measures to build trust and increase security. Confidence and security-building measures in cyberspace Cyberspace is a public good and a public space. As such we have to consider cyberspace security in terms of the resilience of infrastructure as well as the integrity and failure safety of systems and data. Being a public space, States have to promote security in cyberspace, particularly regarding security against crime and malicious activities, by protecting those who choose to use authenticity tools against identity theft and securing the integrity and confidentiality of data and networks. Cyberspace is global by nature. Ensuring cybersecurity, enforcing rights and protecting critical information infrastructures require major efforts by the State both at the national level and in cooperation with international partners. Against this backdrop, Germany is ready to work on a set of behavioural norms addressing State-to-State behaviour in cyberspace, including, in particular, confidence, transparency- and security-building measures, to be signed by as many countries as possible. Germany outlined possible elements of such a code of conduct on international norms recently at the Organization for Security and Cooperation in Europe (OSCE) conference on cybersecurity, held on 9 and 10 May 2011, as follows: (a) Confirm the general principles of availability, confidentiality, competitiveness, integrity and authenticity of data and networks, privacy and protection of intellectual property rights; (b) Respect the obligation to protect critical infrastructures; (c) Enhance cooperation aiming at confidence-building, risk reducing measures, transparency and stability by: • Exchanges of national strategies, best practices and national perceptions referring to the international regulation of cyberspace; • The exchange of national views of international legal norms pertaining to the use of cyberspace; • The setup and notification of points of contact; • The setup of early warning mechanisms and the enhancement of cooperation between computer emergency response teams; • The upgrade of crisis communication links to encompass cyberincidents, the support of the development of technical recommendations that advance robust and secure global cyberinfrastructures; • The responsibility to combat terrorism comprising the exchange of practices and enhanced cooperation to address non-State actors; • The support of cybersecurity capacity-building in developing countries, and the development of voluntary measures for cybersecurity support to large-scale events (e.g. the Olympic Games). 11-41691 9

Select target paragraph3