A/69/112
There
is a trend towards
hard-to-detect,
sophisticated
and malicious
activities,
targeting high-value objectives. Severe consequences may result. A cyberattack
against key infrastructures could cause more disruption than an isolated physical
attack, sometimes with unpredictable consequences for other networked entities.
Despite such risks, an all-out “cyberwar” seems unrealistic for the time being.
A more likely scenario may be the limited use of cybercapabilities as part of a larger
war-fighting effort. Finally, there is the danger that cyberincidents may escalate into
“real-life” conflict.
In this situation, increasing cyberresilience, agreeing on laws and rules that
apply to the use of ICTs and engaging in confidence-building measures become ever
more important.
There has been welcome progress in 2013: The last report of the Group of
Governmental
Experts
on Developments
in the Field of Information
and
Telecommunications in the Context of International Security made clear that
international law is applicable to cyberspace. The Group also found that State
sovereignty and international norms and principles that flow from sovereignty apply
to State conduct of ICT-related activities and to its jurisdiction over ICT
infrastructure within its territory. Germany is looking forward to seeing how the
new Group of Governmental Experts will take this further.
Concerning confidence-building measures, OSCE made important progress
with the adoption of a first set of steps to increase inter-State cooperation,
transparency, predictability and stability, with a view to reducing the risks of
misperception, escalation and conflict that may stem from the use of information
and communication technologies. This OSCE agreement might be useful as a model
for other regional organizations.
Germany’s Cybersecurity Strategy (2011) proceeds from the assertion that the
availability of cyberspace and the integrity, authenticity and confidentiality of data
in cyberspace have become of vital importance. Ensuring cybersecurity has turned
into a central challenge for the State, business and society. All need to act together,
both at the national level and in cooperation with international partners. Germany’s
Cybersecurity Strategy sets out the following objectives and measures:
¢ Protecting critical information infrastructures
* Securing IT systems
¢ Strengthening IT security in public administration
* Running a national cyberresponse centre
* Establishing a national Cybersecurity Council
¢ Effective crime control in cyberspace
¢ Effective coordinated action to ensure cybersecurity in Europe and worldwide
* Using reliable and trustworthy information technology
¢ Personnel development among federal authorities
¢ Tools to respond to cyberattacks.
14-56479
11/18