25.
States reaffirmed that norms do not replace or alter States’ obligations or rights under
international law, which are binding, but rather provide additional specific guidance on what
constitutes responsible State behaviour in the use of ICTs. Norms do not seek to limit or prohibit
action that is otherwise consistent with international law.
26. While agreeing on the need to protect all critical infrastructure (CI) and critical information
infrastructure (CII) supporting essential services to the public, along with endeavouring to ensure
the general availability and integrity of the Internet, States further concluded that the COVID19 pandemic has accentuated the importance of protecting healthcare infrastructure including
medical services and facilities through the implementation of norms addressing critical
infrastructure. such as those affirmed by consensus through UN General Assembly resolution
70/237.
27. States affirmed the importance of supporting and furthering efforts to implement norms by
which States have committed to be guided at the global, regional and national levels.
28. States, reaffirming General Assembly resolution 70/237 and acknowledging General
Assembly resolution 73/27, should: take reasonable steps to ensure the integrity of the supply
chain, including through the development of objective cooperative measures, so that end users
can have confidence in the security of ICT products; seek to prevent the proliferation of
malicious ICT tools and techniques and the use of harmful hidden functions; and encourage the
responsible reporting of vulnerabilities.
29. Given the unique attributes of ICTs, States reaffirmed that, taking into account the proposals
on norms made at the OEWG, additional norms could continue to be developed over time. States
also concluded that the further development of norms, and the implementation of existing norms
were not mutually exclusive but could take place in parallel.
The OEWG recommends that
30. States, on a voluntary basis, survey their national efforts to implement norms, develop and
share experience and good practice on norms implementation, and continue to inform the
Secretary-General of their national views and assessments in this regard.
31. States should not conduct or knowingly support ICT activity contrary to their obligations
under international law that intentionally damages critical infrastructure or otherwise impairs the
use and operation of critical infrastructure to provide services to the public. Furthermore, States
should continue to strengthen measures to protect of all critical infrastructure from ICT threats,
and increase exchanges on best practices with regard to critical infrastructure protection.
32. States, in partnership with relevant organizations including the United Nations, further
support the implementation and development of norms of responsible State behaviour by all
States. States in a position to contribute expertise or resources be encouraged to do so.
33. States, recalling General Assembly resolution 70/237 and acknowledging General Assembly
resolution 73/27 take note of proposals made by States on the elaboration of rules, norms and
principles of responsible behaviour of States in future discussions on ICTs within the United
Nations, noting that resolution 75/240 established an Open-ended Working Group on security of
and in the use of information and communications technologies 2021-2025.
International Law
34. Recognizing General Assembly Resolution 70/237, and also acknowledging General
Assembly resolution 73/27, which established the OEWG, States reaffirmed that international
law, and in particular the Charter of the United Nations, is applicable and essential to maintaining
peace and stability and promoting an open, secure, stable, accessible and peaceful ICT
5