17.
States also concluded that any use of ICTs by States in a manner inconsistent with their
obligations under the framework, which includes voluntary norms, international law, and CBMs,
undermines international peace and security, trust and stability between States, and may increase
the likelihood of future conflicts between States.
18.
States concluded that there are potentially devastating security, economic, social and
humanitarian consequences of malicious ICT activities on critical infrastructure (CI) and critical
information infrastructure (CII) supporting essential services to the public. While it is each
State’s prerogative to determine which infrastructures it designates as critical, such infrastructure
may include medical facilities, financial services, energy, water, transportation and sanitation.
Malicious ICT activities against CI and CII that undermine trust and confidence in political and
electoral processes, public institutions, or that impact the general availability or integrity of the
Internet, are also a real and growing concern. Such infrastructure may be owned, managed or
operated by the private sector, may be shared or networked with another State or operated across
different States. As a result, inter-State or public-private cooperation may be necessary to protect
its integrity, functioning and availability.
19. States also concluded that ICT activity contrary to obligations under international law that
intentionally damages critical infrastructure or otherwise impairs the use and operation of critical
infrastructure to provide services to the public, could pose a threat not only to security but also
to State sovereignty, as well as economic development and livelihoods, and ultimately the safety
and wellbeing of individuals.
20. As all States are increasingly reliant on digital technologies, States concluded that a lack
of awareness and adequate capacities to detect, defend against or respond to malicious ICT
activities may make them more vulnerable. As witnessed during the current global health
emergency, existing vulnerabilities may be amplified in times of crisis.
21. States concluded that threats may be experienced differently by States according to their
levels of digitalization, capacity, ICT security and resilience, infrastructure and development.
Threats may also have a different impact on different groups and entities, including on youth, the
elderly, women and men, people who are vulnerable, particular professions, small and mediumsized enterprises, and others.
22. In light of the increasingly concerning digital threat landscape, and recognizing that no
State is sheltered from these threats, States underscored the urgency of implementing and further
developing cooperative measures to address such threats. It was affirmed that acting together and
inclusively whenever feasible would produce more effective and far-reaching results. The value
of further strengthening collaboration, when appropriate, with civil society, the private sector,
academia and the technical community, was also emphasized in this regard.
23. States emphasized the positive economic and social opportunities that can be derived from
ICTs and concluded that it is the misuse of such technologies, not the technologies themselves,
that is of concern.
Rules, Norms and Principles for Responsible State Behaviour
24. Voluntary, non-binding norms of responsible State behaviour can reduce risks to
international peace, security and stability and play an important role in increasing predictability
and reducing risks of misperceptions, thus contributing to the prevention of conflict. States
stressed that such norms reflect the expectations and standards of the international community
regarding the behaviour of States in their use of ICTs and allow the international community to
assess the activities of States. In accordance with General Assembly resolution 70/237, and
acknowledging General Assembly resolution 73/27 States were called upon to avoid and refrain from
use of ICTs not in line with the norms for responsible State behaviour.
4