A/69/112 The first targets of cyberattacks in 2008 were Government and news media websites. Later, the attacks were expanded to include many more Government websites, Georgian financial institutions, business associations, educational institutions, more news media websites and a Georgian hacking forum. These cyberattacks were intended to interrupt normal business operations. Apart from the two big banks, the business-related targets were primarily organizations that could have been used to communicate and coordinate responses among different businesses. The above-described experience demonstrates that cyberattacks on the critical infrastructure of Georgia by State and private actors can cause serious physical damage as well as significant financial damage to the public and priv ate sectors. Therefore, the Government of Georgia considers cybersecurity to be part of the general security policy of the country, especially in the view of its increased reliance on IT as a vehicle for the delivery of Government services. Voicing these concerns, the National Security Council and a special working group comprised of different Government agencies developed the national Cybersecurity Strategy of Georgia throughout 2011, as a part of the National Security Review. The Cybersecurity Strategy and the action plan for its implementation were presented to the public for discussion in March 2012 and finally adopted in January 2013. A further step was the establishment of the Data Exchange Agency of the Ministry of Justice of Georgia in 2010 as a central Government entity responsible for the development and implementation of e-governance policies and solutions. An important part of the Agency’s mandate is information security for the public sector and private entities as follows: • Adoption and implementation of information security policies and standards in public sector and critical infrastructure • Providing consultancy services in the field of information security and performing information security audits • Awareness-raising activities about information security issues in the public as well as the civil sector • Cybersecurity mandate through the national computer emergency response team. The full text of Georgia’s submission can be found at http://www.un.org/ disarmament/topics/informationsecurity/. Germany [Original: English] [30 May 2014] Executive summary Information and communication technologies (ICTs) offer unprecedented opportunities for industrialized and developing countries alike. At the same time, vulnerabilities and systemic weaknesses exist. 10/18 14-56479

Select target paragraph3