6
Improving Transparency:
International Law and State Cyber Operations
Fifth Report
d. to afford the OAS and its Member States an appropriate voice in global
conversations about international law’s application.
done so as well.3 To date, however, efforts to delineate how States understand
international law’s application to cyberspace have had limited success.
At the same time, it is important to reiterate what this project is not designed
to do. It does not aim to codify or progressively develop international law (nor
even to identify best practices or general guidance). Nor does it aim to offer
a comprehensive or overarching perspective on international legal issues in
the cyber context.
4. Part of the problem in applying international law to cyberspace derives
from the lack of tailor-made rules or standards. When it comes to international peace and security, for example, there are no cyber-specific treaties. And
those conventions that deal with cybercrime – the Budapest Convention
and (if it ever enters into force) the African Union Convention – only target,
by definition, non-State actor behavior with support from a minority of nation States.4 Thus, international law’s application to cyberspace depends on
analogizing to more general multilateral treaties (e.g., the U.N. Charter) or
customary international law.
2. Rather, this project is intended—and should be read—as a modest, first
step. The Juridical Committee (and the OAS more broadly) may use the materials provided here to evaluate what, if any, further activities might be pursued
to add more transparency to how international law applies to States in the
region, their cyber-operations, and their reactions to cyber threats by others.
The Committee might also consider ramping up existing capacity building
efforts to improve the knowledge and experience of relevant officials on the
questions of international law’s application to cyberspace. This may involve
gathering (and publicizing) additional national views and/or establishing platforms or other processes for information sharing and dialogue on international
law’s relationship to cyberspace and the information and communication
technologies (ICTs) from which it derives.
3. My first report highlighted international law’s limited visibility in regulating
State cyber operations despite the increasing number of such operations and
their economic, humanitarian, and national security implications.1 It is true
that many States have confirmed the applicability of international law to their
behavior in cyberspace.2 And, although the OAS has not, other international
organizations—ASEAN, the European Union, and the United Nations—have
1
See Duncan B. Hollis, International Law and State Cyber Operations: Improving Transparency,
OEA/Ser.Q, CJI/doc 570/18 (August 9, 2018) (“Hollis, First Report”), at http://www.oas.org/
en/sla/iajc/docs/CJI_doc_570- 18.pdf.
2
See U.N. Secretary-General, Report of the Group of Governmental Experts on Developments
in the Field of Information and Telecommunications in the Context of International Security, 19,
U.N. Doc. A/68/98 (June 24, 2013) (“[i]nternational law, and in particular the Charter of the
United Nations, is applicable” to cyberspace); see also U.N. Secretary-General, Report of the
Group of Governmental Experts on Developments in the Field of Information and Telecommunications in the Context of International Security, 24, U.N. Doc. A/70/174 (July 22, 2015).
Inter-American Juridical Committee
5. However, as my second report highlighted, at the global level there is no
universal consensus among States on what existing general international
laws apply to cyber operations, let alone how they do so.5 For various international legal regimes (e.g., self-defense, international humanitarian law,
countermeasures, sovereignty (as a standalone rule), and due diligence) one
or more States contest their application in toto to cyberspace, while others
3
See UNGA Res. 266, U.N. Doc. A/RES/73/266 (Jan. 2, 2019); ASEAN-United States Leaders’ Statement on Cybersecurity Cooperation (Nov. 18, 2018), at https://asean.org/storage/2018/11/ASEAN-US-Leaders-Statement- on-Cybersecurity-Cooperation-Final.pdf ; EU
Statement – United Nations 1st Committee, Thematic Discussion on Other Disarmament
Measures and International Security (Oct. 26, 2018) (“EU Statement”), at https://eeas.europa.
eu/delegations/un-new-york/52894/eu-statement-%E2%80%93-united-nations-1st-committee- thematic-discussion-other-disarmament-measures-and_en. Both the G7 and G20
have made similar affirmations. See, e.g., G7 Declaration on Responsible States Behavior in
Cyberspace (April 11, 2017) at https://www.mofa.go.jp/files/000246367.pdf; G20 Antalya
Summit Leader’s Communique (Nov. 15-16, 2015) 26, at http://www.gpfi.org/sites/gpfi/
files/documents/G20-Antalya-Leaders-Summit-Communiqu--.pdf.
4
Council of Europe, Convention on Cybercrime (Budapest, 23 Nov 2001) CETS No 185;
AU Convention on Cyber Security & Personal Data Protection, June 27, 2014, AU Doc. EX.
CL/846(XXV). The Budapest Convention now has 65 parties, although several other States
view it with some hostility. See Convention on Cybercrime, at http://conventions.coe.int/
Treaty/Commun/ChercheSig.asp?NT=185&CL=ENG.
5
Duncan B. Hollis, International Law and State Cyber Operations: Improving Transparency,
OEA/Ser.Q, CJI/doc 578/19 (Jan. 21, 2019) (“Hollis, Second Report”), at http://www.oas.org/
en/sla/iajc/docs/CJI_doc_578-19.pdf.
International Law and State Cyber Operations
7