A/66/152
each of these threat actors are likely visible only in their effects. Thus, highconfidence attribution of identity to perpetrators cannot be achieved in a timely
manner, if ever, and success often depends on a high degree of transnational
cooperation. The increasing role of proxies further complicates the process of
attribution, as an affected party must identify not only the perpetrator but also the
sponsor, promising to make this challenge even more troublesome in the future.
Such challenges require that national Governments organize and lead domestic
efforts to develop and deploy resilient, layered defences for communications and
information infrastructures, regardless of the source of the threat. At the same time,
the complex transnational nature of these threats requires international collaboration
on strategies to address risks on a global basis.
III.
A.
Principles, rules and norms of behaviour
Responsibilities of States in assuring cybersecurity
Over the past decade, Member States have recognized their national
responsibility to take systematic domestic steps to defend themselves from
cybersecurity threats and have affirmed the need for international cooperation. Five
General Assembly resolutions have drawn attention to essential defensive measures
that Governments can perform to reduce risks to their security. While intended to
raise awareness, these resolutions nonetheless advance some useful norms for
individual and State behaviour in the interest of cybersecurity:
(a) Resolution 55/63 on combating the criminal misuse of information
technologies, in which the General Assembly underscores the need to have modern
effective national laws to adequately prosecute cybercrime and facilitate timely
transnational investigative cooperation;
(b) Resolution 56/21, in which the General Assembly specifically notes the
work of international and regional organizations in combating high-technology
crime, including the work of the Council of Europe in elaborating the Convention
on Cybercrime:
There has been intensive activity by the United Nations and other
organizations in this area. United Nations organizations that principally focus
on criminal misuse of the Internet include the United Nations Office on Drugs
and Crime, the Commission on Crime Prevention and Criminal Justice, the
United Nations Congress on Crime Prevention and Criminal Justice, the
International Telecommunication Union and others;
(c) Resolution 57/239, in which the General Assembly affirms the need for
the creation of a global culture of cybersecurity, recognizes the responsibility of
Governments to lead all elements of society to understand their roles and
responsibilities with regard to cybersecurity, and highlights complementary
elements that all participants in the information society must address;
(d) Resolution 58/199, in which the General Assembly focuses in particular
on actions that Member States should consider in their efforts to create a global
culture of cybersecurity and to protect critical information infrastructures. These too
can be considered a set of norms to which Governments should ascribe, and they
provide an essential basis or precursor in order to facilitate international
collaboration on risk reduction;
11-41691
17