A/70/174
(c) States should not knowingly allow their territory to be used for
internationally wrongful acts using ICTs;
(d) States should consider how best to cooperate to exchange informatio n,
assist each other, prosecute terrorist and criminal use of ICTs and implement other
cooperative measures to address such threats. States may need to consider whether
new measures need to be developed in this respect;
(e) States, in ensuring the secure use of ICTs, should respect Human Rights
Council resolutions 20/8 and 26/13 on the promotion, protection and enjoyment of
human rights on the Internet, as well as General Assembly resolutions 68/167 and
69/166 on the right to privacy in the digital age, to guarantee full respect for human
rights, including the right to freedom of expression;
(f) A State should not conduct or knowingly support ICT activity contrary to
its obligations under international law that intentionally damages critical
infrastructure or otherwise impairs the use and operation of critical infrastructure to
provide services to the public;
(g) States should take appropriate measures to protect their critical
infrastructure from ICT threats, taking into account General Assembly resolution
58/199 on the creation of a global culture of cybersecurity and the protection of
critical information infrastructures, and other relevant resolutions;
(h) States should respond to appropriate requests for assistance by another
State whose critical infrastructure is subject to malicious ICT acts. States should
also respond to appropriate requests to mitigate malicious ICT activity aimed at the
critical infrastructure of another State emanating from their territory, taking into
account due regard for sovereignty;
(i) States should take reasonable steps to ensure the integrity of the supply
chain so that end users can have confidence in the security of ICT products. States
should seek to prevent the proliferation of malicious ICT tools and techniques and
the use of harmful hidden functions;
(j) States should encourage responsible reporting of ICT vulnerabilities and
share associated information on available remedies to such vulnerabilities to limit
and possibly eliminate potential threats to ICTs and ICT -dependent infrastructure;
(k) States should not conduct or knowingly support activity to harm the
information systems of the authorized emergency response teams (sometimes known
as computer emergency response teams or cybersecurity incident response teams) of
another State. A State should not use authorized emergency response teams to
engage in malicious international activity.
14. The Group observed that, while such measures may be essential to promote an
open, secure, stable, accessible and peaceful ICT environment, their implementation
may not immediately be possible, in particular for developing countries, until they
acquire adequate capacity.
15. Given the unique attributes of ICTs, additional norms could be developed
over time.
8/17
15-12404