relevant regional and international organizations, such as the OSCE, the EU CSIRT network or the parties to the Budapest Convention. Norm 9 – States should take reasonable steps to ensure the integrity of the supply chain, so end users can have confidence in the security of ICT products. States should seek to prevent the proliferation of malicious ICT tools and techniques and the use of harmful hidden functions. G7 countries have taken a series of steps to ensure the integrity of the supply chain and to prevent the proliferation of malicious ICT tools and techniques and the use of harmful hidden functions, such as: - - Developing and promoting frameworks, recommendations, codes of conduct, norms and standards for industry, to improve awareness of supply chain security and help companies establish effective control and oversight of their supply chain – these can also include labelling, evaluation and certification schemes; Establishing procedures to ensure ICT procurement by the public sector helps drive improvements in security and resilience; Supporting the proper and effective use of export-control regimes to prevent the proliferation of malicious ICT tools and techniques. Norm 10 – States should encourage responsible reporting of ICT vulnerabilities and share related information on available remedies to such vulnerabilities, in order to limit and possibly eliminate potential threats to ICTs and ICT-dependent infrastructure. G7 countries have established procedures, mechanisms and sometimes legal frameworks that facilitate and encourage responsible disclosure of vulnerabilities by and to their national cybersecurity agencies. They have increased cooperation with public and private partners to better share information on vulnerabilities, mitigation and recovery measures and developed programmes to assist partners in creating vulnerability disclosure processes. Norm 11 – States should not conduct or knowingly support activity to harm the information systems of another State’s authorized emergency response teams (sometimes known as CERTS or CSIRTS). A State should not use authorized emergency response teams to engage in malicious international activity. As a principle, and as responsible States, all G7 countries have strongly reaffirmed that they will not conduct or knowingly support activity to harm another State’s CERT, nor use their own CERT to engage in malicious international activities./. Page 5 out of 5 For Official Use Only

Select target paragraph3