key policy areas: action at the domain level, dealing with offensive content and ensuring appropriate law enforcement access to data. The I&J Network last met in Berlin in June 2019, where discussions were based on operational approaches to all three areas, with norms, criteria and mechanisms. The I&J Network has also undertaken the creation of a Global Status Report on the state of jurisdiction on the Internet, drawing on the expertise of more than 100 members of the I&J Policy Network. D) Canada’s work with regional organizations on disseminating cyber CBMs Canada believes that cyber Confidence Building Measures (CBMs) are an important tool to promote stability and security in cyberspace and address cyber incidents by preventing miscalculations and conflict. Canada has been working closely with regional organizations such as the ASEAN Regional Forum (ARF), the Organization of American States (OAS), and the Organization for Security and Co-operation in Europe (OSCE) to disseminate and implement cyber CBMs. For example, Canada has contributed to the ARF’s efforts to implement cyberrelated CBMs in ASEAN countries by jointly organising a workshop with Singapore in June 2019 on National Strategies on Security in the Use of ICTs. Canada has also recently announced that we will lead efforts to implement OSCE cyber CBM 4, “Participating States [to] voluntarily share information on measures that they have taken to ensure an open, interoperable, secure, and reliable Internet.” Canada will indicate to other OSCE participating States how we are implementing this CBM, and provide guidance and best practices on its implementation. E) Cyber capacity building Canada’s Anti-Crime Capacity Building Program (ACCBP) helps support global efforts to combat cybercrime and threats to cyber security. These projects form a critical part of Canada’s engagement strategy to influence countries to share our vision of preserving an open, secure and multistakeholder-led Internet. The Program also enhances the capacities of national authorities to deter, respond to, and investigate cyber threats, including criminal exploitation of ICTs. Since 2015, the ACCBP has contributed over $9M to cyber capacity building, primarily in the Americas. Canada currently programs through international organizations such as the UNODC, OAS and INTERPOL. ACCBP cyber programing also assists nations develop their national cyber strategies, which includes developing standards on how to increase security of ICTs, while at the same time ensuring human rights and privacy are protected for all citizens. Norm 2 – In case of ICT incidents, States should consider all relevant information, including, inter alia, the larger context of the event, the challenges of attribution in the ICT environment, and the nature and extent of the consequences. A) Canada’s 2018 National Cyber Security Strategy created a streamlined response process to ICT incidents: Until recently, the government of Canada’s cyber security operational capabilities were distributed across different departments and agencies. Though measures were in place to ensure good communication and coordination, ambiguity concerning roles and responsibilities and the inherent difficulty in coordinating multiple decision makers was a barrier to the quick, effective, clear, and trusted technical guidance that Canadians have come to expect from their government. To address this gap, the Government of Canada established the new Canadian Centre for Cyber Security within the CSE in October 2018. The Cyber Centre leads Canada’s response to cyber security events as the country’s National Computer Emergency Response Team (CERT) and the Government of Canada’s Computer Incident Response Team (CIRT). The Cyber Centre provides a single point of contact for critical infrastructure owners and operators for advice and guidance in the event of a cyber incident. The 2018 National Cyber Security Strategy also included funding for the new National Cybercrime Coordination Unit (NC3). While managed by the Royal Canadian Mounted Police (RCMP), the NC3 will serve all Canadian police agencies and will work with public and private sector partners. The NC3 will coordinate and de-conflict cybercrime investigations targeting multiple jurisdictions in Canada and internationally, and will implement a new public reporting system to make it easier for Canadian victims to report cybercrime incidents to law enforcement. The NC3 will work closely with the Cyber Centre to address cyber threats. The NC3 will have initial operating capability by April 2020, and the new public reporting system is planned for 2022.

Select target paragraph3