A/66/152 each of these threat actors are likely visible only in their effects. Thus, highconfidence attribution of identity to perpetrators cannot be achieved in a timely manner, if ever, and success often depends on a high degree of transnational cooperation. The increasing role of proxies further complicates the process of attribution, as an affected party must identify not only the perpetrator but also the sponsor, promising to make this challenge even more troublesome in the future. Such challenges require that national Governments organize and lead domestic efforts to develop and deploy resilient, layered defences for communications and information infrastructures, regardless of the source of the threat. At the same time, the complex transnational nature of these threats requires international collaboration on strategies to address risks on a global basis. III. A. Principles, rules and norms of behaviour Responsibilities of States in assuring cybersecurity Over the past decade, Member States have recognized their national responsibility to take systematic domestic steps to defend themselves from cybersecurity threats and have affirmed the need for international cooperation. Five General Assembly resolutions have drawn attention to essential defensive measures that Governments can perform to reduce risks to their security. While intended to raise awareness, these resolutions nonetheless advance some useful norms for individual and State behaviour in the interest of cybersecurity: (a) Resolution 55/63 on combating the criminal misuse of information technologies, in which the General Assembly underscores the need to have modern effective national laws to adequately prosecute cybercrime and facilitate timely transnational investigative cooperation; (b) Resolution 56/21, in which the General Assembly specifically notes the work of international and regional organizations in combating high-technology crime, including the work of the Council of Europe in elaborating the Convention on Cybercrime: There has been intensive activity by the United Nations and other organizations in this area. United Nations organizations that principally focus on criminal misuse of the Internet include the United Nations Office on Drugs and Crime, the Commission on Crime Prevention and Criminal Justice, the United Nations Congress on Crime Prevention and Criminal Justice, the International Telecommunication Union and others; (c) Resolution 57/239, in which the General Assembly affirms the need for the creation of a global culture of cybersecurity, recognizes the responsibility of Governments to lead all elements of society to understand their roles and responsibilities with regard to cybersecurity, and highlights complementary elements that all participants in the information society must address; (d) Resolution 58/199, in which the General Assembly focuses in particular on actions that Member States should consider in their efforts to create a global culture of cybersecurity and to protect critical information infrastructures. These too can be considered a set of norms to which Governments should ascribe, and they provide an essential basis or precursor in order to facilitate international collaboration on risk reduction; 11-41691 17

Select target paragraph3