10 Overview Of Existing Confidence Building Measures As Applied To Cyberspace Global Forum on Cyber Expertise Global Forum on Cyber Expertise Overview Of Existing Confidence Building Measures As Applied To Cyberspace Encouraging, on a voluntary basis, transparency at the bilateral, subregional, regional and multilateral levels, as appropriate, to increase confidence and inform future work. This could include the voluntary 2015 sharing of national views and information on various aspects of national and transnational threats to and national organizations, strategies, policies and programmes relevant to ICT security Regional Organisations’ efforts on cyber/ICT CBMs The voluntary provision by States of their national views of categories of infrastructure that they consider As highlighted above, the UNGGE in its 2015 report in particular provided the groundwork for increased critical and national efforts to protect them, including information on national laws and policies for involvement of regional organizations in this space. They have set an initial set of CBMs; however what has the protection of data and ICT-enabled infrastructure. States should seek to facilitate cross-border become clear since was that regional organizations are uniquely equipped to develop, and in particular co-operation to address critical infrastructure vulnerabilities that transcend national borders. These implement CBMs. It is easier for them to focus on practical approaches, amongst countries that have measures could include: (i) A repository of national laws and policies for the protection of data and common historical and cultural ties, thereby developing the foundational groundwork for enhanced ICT-enabled infrastructure and the publication of materials deemed appropriate for distribution on these communication, transparency and collaboration. Recent years have seen efforts to do just that at the national laws and policies; (ii) The development of mechanisms and processes for bilateral, subregional, Organization of American States (OAS), Organization for Security and Co-operation in Europe (OSCE), and regional and multilateral consultations on the protection of ICT-enabled critical infrastructure; (iii) the Association of South East Asian Nations (ASEAN). in the use of ICTs; vulnerabilities and identified harmful hidden functions in ICT products; best practices for ICT security; confidence-building measures developed in regional and multilateral forums; and 2015 The development on a bilateral, subregional, regional and multilateral basis of technical, legal and diplomatic mechanisms to address ICT-related requests; (iv) The adoption of voluntary national Organization for Security and Co-operation in Europe (OSCE) arrangements to classify ICT incidents in terms of the scale and seriousness of the incident, for the purpose of facilitating the exchange of information on incidents. Building on its previous success in developing CBMs in the conventional weapons area, the OSCE worked on and adopted two sets of cyber-related confidence-building measures since 2012, when the organization first 2015 2015 Strengthen co-operative mechanisms between relevant agencies to address ICT security incidents and decided to establish an informal working group to explore a possible OSCE role in strengthening develop additional technical, legal and diplomatic mechanisms to address ICT infrastructure-related cybersecurity. 7 The latter provided a platform to engage in structured, but still informal, discussions on requests, including the consideration of exchanges of personnel in areas such as incident response CBMs. The first set of OSCE CBMs (2013) established official Points of Contact (PoC) and communication and law enforcement, as appropriate, and encouraging exchanges between research and academic lines to prevent possible tensions resulting from cyber activities. 8 The second set (2016) focused on further institutions. enhancing co-operation between OSCE participating states: including, for example, effective mitigation of Enhance co-operation, including the development of focal points for the exchange of information on cyberattacks on critical infrastructure. 9 malicious ICT use and the provision of assistance in investigations, Establish a national computer emergency response team and/or cybersecurity incident response team 2015 or officially designate an organization to fulfil this role. States may wish to consider such bodies within their definition of critical infrastructure. States should support and facilitate the functioning of and cooperation among such national response teams and other authorized bodies, Expand and support practices in computer emergency response team and cybersecurity incident response team co-operation, as appropriate, such as information exchange about vulnerabilities, 2015 attack patterns and best practices for mitigating attacks, including coordinating responses, organizing PC.DEC/1039 (2012) Establishment of the informal Working Group PC.DEC/1106 (2013) Initial Set of OSCE CBMs to reduce the risks of conflict stemming from the use of ICTs PC.DEC/1202 (2016) SecondSet of OSCE CBMs to reduce the risks of conflict stemming from the use of ICTs MC.DEC/5/16 (2016) First Ministerial endorsement of agreed upon CBMs FSC.DEC/5/17 (2017) Approval to use the OSCE Communications Network for crisis cyber/ICT security communication MC.DEC/5/17 (2017) Ministerial endorsement and commitment to implement exercises, supporting the handling of ICT-related incidents and enhancing regional and sector based cooperation Cooperate, in a manner consistent with national and international law, with requests from other States in 2015 investigating ICT-related crime or the use of ICTs for terrorist purposes or to mitigate malicious ICT activity emanating from their territory. Chart 1: Overview of OSCE CBM-related decisions from 2012 to 2017. 10 7 8 9 10 OSCE, Permanent Council Decision No. 1039 in 2012, available at: https://www.osce.org/pc/90169 OSCE, Permanent Council Decision No. 1106 in 2013, available at: https://www.osce.org/pc/109168 OSCE, Permanent Council Decision No. 1202 in 2016, available at: https://www.osce.org/pc/227281 “The Role of OSCE Confidence-Building Measures in addressing cyber/ICT security challenges”, Nikolas Ott, Central Asian Internet Governance Forum 2019, Plenary session: Using the Internet to strengthen the resilience of the region, Tashkent, Uzbekistan.” 11

Select target paragraph3