A/66/152
Moreover we see the necessity to start a debate on an international cooperation
in the framework of attribution of cyberattacks, which are usually very difficult to
trace, State responsibility for cyberattacks launched from their territory when States
do nothing to end such attacks despite being informed about them and States’
responsibility not to facilitate areas of lawlessness in cyberspace, for example by
knowingly tolerating the storage of illegally collected personal data on their
territory.
Military aspects of cybersecurity
As military forces increasingly rely on information technology to master ever
more complex scenarios at all levels of command, the protection of the information
and the means to process it has become a first order task.
However, in military thinking, information security is challenged not only by a
potential adversary, in an operational understanding, using weaponry for the
physical destruction of information infrastructure, but also by irresponsible users,
malfunctioning technology, criminals or simply accidents.
Hence, the efforts to be undertaken range from awareness-raising of each
single user and securing the trustworthiness of the supply chain for information
technology, to responsive defences to fend off cyberattacks and an overall resilient
information technology architecture.
In essence, a comprehensive risk management is required, with measures to
strengthen information security on a national and global scale.
At an early stage, the German armed forces (Bundeswehr) established resilient
command and control architectures, security techniques and procedures as well as
an information technology-security organization, encompassing all branches of the
armed forces, and including an independent computer emergency response team
with the capacity to intervene in case of critical disruptions to the operations of
information technology. Adapting personal and technical abilities to the continually
increasing level of threat is a perpetual task.
The German armed forces are collaborating closely with the Federal German
Ministry of the Interior in its efforts and strongly support the strengthening of
information security in the North Atlantic Treaty Organization (NATO) and the EU
and the formation of policies and capacities to this end. Furthermore, the armed
forces hold regular exchanges with a number of countries in the context of
information security, both at the policy and working levels.
The German armed forces welcome initiatives and work together with other
departments of the Federal German Government on international motions to further
protect the utility of worldwide information networks, for example, the development
of a voluntary international code of conduct in cyberspace.
Cyberdefence in NATO
Cybersecurity has been identified by NATO as one of the key emerging
security challenges. The Strategic Concept adopted by Heads of State and
Government at the NATO Summit, held in November 2010, in Lisbon, states that
“cyber attacks ... can reach a threshold that threatens national and Euro-Atlantic
prosperity, security and stability”.
10
11-41691