10
Overview Of Existing Confidence Building Measures As Applied To Cyberspace
Global Forum on Cyber Expertise
Global Forum on Cyber Expertise
Overview Of Existing Confidence Building Measures As Applied To Cyberspace
Encouraging, on a voluntary basis, transparency at the bilateral, subregional, regional and multilateral
levels, as appropriate, to increase confidence and inform future work. This could include the voluntary
2015
sharing of national views and information on various aspects of national and transnational threats to and
national organizations, strategies, policies and programmes relevant to ICT security
Regional Organisations’ efforts
on cyber/ICT CBMs
The voluntary provision by States of their national views of categories of infrastructure that they consider
As highlighted above, the UNGGE in its 2015 report in particular provided the groundwork for increased
critical and national efforts to protect them, including information on national laws and policies for
involvement of regional organizations in this space. They have set an initial set of CBMs; however what has
the protection of data and ICT-enabled infrastructure. States should seek to facilitate cross-border
become clear since was that regional organizations are uniquely equipped to develop, and in particular
co-operation to address critical infrastructure vulnerabilities that transcend national borders. These
implement CBMs. It is easier for them to focus on practical approaches, amongst countries that have
measures could include: (i) A repository of national laws and policies for the protection of data and
common historical and cultural ties, thereby developing the foundational groundwork for enhanced
ICT-enabled infrastructure and the publication of materials deemed appropriate for distribution on these
communication, transparency and collaboration. Recent years have seen efforts to do just that at the
national laws and policies; (ii) The development of mechanisms and processes for bilateral, subregional,
Organization of American States (OAS), Organization for Security and Co-operation in Europe (OSCE), and
regional and multilateral consultations on the protection of ICT-enabled critical infrastructure; (iii)
the Association of South East Asian Nations (ASEAN).
in the use of ICTs; vulnerabilities and identified harmful hidden functions in ICT products; best practices
for ICT security; confidence-building measures developed in regional and multilateral forums; and
2015
The development on a bilateral, subregional, regional and multilateral basis of technical, legal and
diplomatic mechanisms to address ICT-related requests; (iv) The adoption of voluntary national
Organization for Security and Co-operation in Europe (OSCE)
arrangements to classify ICT incidents in terms of the scale and seriousness of the incident, for the
purpose of facilitating the exchange of information on incidents.
Building on its previous success in developing CBMs in the conventional weapons area, the OSCE worked on
and adopted two sets of cyber-related confidence-building measures since 2012, when the organization first
2015
2015
Strengthen co-operative mechanisms between relevant agencies to address ICT security incidents and
decided to establish an informal working group to explore a possible OSCE role in strengthening
develop additional technical, legal and diplomatic mechanisms to address ICT infrastructure-related
cybersecurity. 7 The latter provided a platform to engage in structured, but still informal, discussions on
requests, including the consideration of exchanges of personnel in areas such as incident response
CBMs. The first set of OSCE CBMs (2013) established official Points of Contact (PoC) and communication
and law enforcement, as appropriate, and encouraging exchanges between research and academic
lines to prevent possible tensions resulting from cyber activities. 8 The second set (2016) focused on further
institutions.
enhancing co-operation between OSCE participating states: including, for example, effective mitigation of
Enhance co-operation, including the development of focal points for the exchange of information on
cyberattacks on critical infrastructure. 9
malicious ICT use and the provision of assistance in investigations,
Establish a national computer emergency response team and/or cybersecurity incident response team
2015
or officially designate an organization to fulfil this role. States may wish to consider such bodies within
their definition of critical infrastructure. States should support and facilitate the functioning of and cooperation among such national response teams and other authorized bodies,
Expand and support practices in computer emergency response team and cybersecurity incident
response team co-operation, as appropriate, such as information exchange about vulnerabilities,
2015
attack patterns and best practices for mitigating attacks, including coordinating responses, organizing
PC.DEC/1039
(2012)
Establishment
of the informal
Working Group
PC.DEC/1106
(2013)
Initial Set of
OSCE CBMs to
reduce the risks
of conflict
stemming from
the use of ICTs
PC.DEC/1202
(2016)
SecondSet of
OSCE CBMs to
reduce the risks
of conflict
stemming from
the use of ICTs
MC.DEC/5/16
(2016)
First Ministerial
endorsement of
agreed upon
CBMs
FSC.DEC/5/17
(2017)
Approval to use
the OSCE
Communications
Network for crisis
cyber/ICT
security
communication
MC.DEC/5/17
(2017)
Ministerial
endorsement
and commitment
to implement
exercises, supporting the handling of ICT-related incidents and enhancing regional and sector based cooperation
Cooperate, in a manner consistent with national and international law, with requests from other States in
2015
investigating ICT-related crime or the use of ICTs for terrorist purposes or to mitigate malicious ICT activity
emanating from their territory.
Chart 1: Overview of OSCE CBM-related decisions from 2012 to 2017. 10
7
8
9
10
OSCE, Permanent Council Decision No. 1039 in 2012, available at: https://www.osce.org/pc/90169
OSCE, Permanent Council Decision No. 1106 in 2013, available at: https://www.osce.org/pc/109168
OSCE, Permanent Council Decision No. 1202 in 2016, available at: https://www.osce.org/pc/227281
“The Role of OSCE Confidence-Building Measures in addressing cyber/ICT security challenges”, Nikolas Ott, Central Asian Internet
Governance Forum 2019, Plenary session: Using the Internet to strengthen the resilience of the region, Tashkent, Uzbekistan.”
11