8
Overview Of Existing Confidence Building Measures As Applied To Cyberspace
Global Forum on Cyber Expertise
Overview of efforts to
establish confidence building
measures for cyberspace
Global Forum on Cyber Expertise
Confidence Building Measures at UN GGE
Year
2013
implementation of cybersecurity CBMs is relatively recent. More work
that they have already contributed to advancing the dialogue on cyber
resulted in the creation of important platforms that enable governments
practices, decision-making processes, relevant national organizations and measures to improve
international co-operation. The extent of such information will be determined by the providing states.
This information could be shared bilaterally, in regional groups or in other international forums.
will need to be done to encourage their wider implementation. Despite
stability. In addition, the discussions around CBMs adoption have
Measure
The exchange of views and information on a voluntary basis on national strategies and policies, best
Efforts to design effective CBMs for cyberspace have been undertaken at
both multilateral and bilateral levels. However, the development and
Overview Of Existing Confidence Building Measures As Applied To Cyberspace
The creation of bilateral, regional and multilateral consultative frameworks for confidence-building,
2013
to have a conversation around these important issues.
which could entail workshops, seminars and exercises to refine national deliberations on how to prevent
disruptive incidents arising from state use of ICTs and how these incidents might develop and be
managed.
It is worth highlighting that enabling these conversations can,
Enhanced sharing of information among states on ICT security incidents, involving the more effective
by facilitating an exchange on the subject between
use of existing channels or the development of appropriate new channels and mechanisms to receive,
governments, also be considered a confidence-building
measure in its own right.
2013
Groups of Governmental Experts (GGEs) since the early 2000s. In their 2010 report 4, the UN GGE on
development of early warning mechanisms.
Exchanges of information and communication between national Computer Emergency Response Teams
2013
recommended five actions for the development of confidence-building and other measures to reduce the
•
elaborating common terms and definitions necessary to advance dialogue in the information security field;
•
identifying measures to support capacity building in less developed countries; as well as
•
exchanging information on national legislation, information and communication technology (ICT)
(CERTs) bilaterally, within CERT communities, and in other forums, to support dialogue at political and
policy levels.
Developments in the Field of Information and Telecommunications in the Context of International Security
risk of misperception resulting from cyber disruptions. These actions included:
mitigation actions. States should consider exchanging information on national points of contact, in order
to expand and improve existing channels of communication for crisis management, and supporting the
UN Group of Governmental Experts
At the multilateral level, cyber stability has been firmly on the agenda of the United Nations (UN) and its
collect, analyze and share information related to ICT incidents, for timely response, recovery and
Increased co-operation to address incidents that could affect ICT or critical infrastructure that rely upon
2013
ICT-enabled industrial control systems. This could include guidelines and best practices among states
against disruptions perpetrated by non-state actors.
2013
Enhanced mechanisms for law enforcement co-operation to reduce incidents that could otherwise be
misinterpreted as hostile State actions would improve international security.
security strategies, policies and best practices.
Further to this, the UN GGE in 2013 and 2015 recommended states consider a range of confidence building
5
6
2015
The identification of appropriate points of contact at the policy and technical levels to address serious
ICT incidents and the creation of a directory of such contacts;
measures described in the following table.
The development of and support for mechanisms and processes for bilateral, regional, subregional and
4 https://undocs.org/en/A/65/201
5 http://www.unidir.org/files/medias/pdfs/developments-in-the-field-of-information-and-telecommunications-in-the-context-ofinternational-security-2012-2013-a-68-98-eng-0-518.pdf
6 http://www.un.org/ga/search/view_doc.asp?symbol=A/70/174
2015
multilateral consultations, as appropriate, to enhance inter-State confidence-building and to reduce the
risk of misperception, escalation and conflict that may stem from ICT incidents
9