decision making involved in publicly or privately attributing malicious activity. These being
that a decision to attribute will be based on an objective technical assessment and
international law considerations. States will also want to take a national decision, based on
diplomatic considerations, about whether to make known the results of any attribution they
have conducted – publicly or privately.
Further proposals touching on principles of existing international law, such as that of the
principle of non-intervention,f may be better reflected in Section C. A final group of
proposals, whilst worthy of concerted international attention, address topics that the UK
considers to beyond the mandate of the OEWG for instance: data protection, internet
governance, national regulation, and free trade. We continue to actively support international
discussion of these topics in appropriate fora.
E. Confidence Building Measures
We welcome the focus placed on operationalisation of confidence building measures
(CBMs) (E41). It could be prefaced by a reference to the fact that States reaffirmed the value
of CBMs. Listing all those CBMs mentioned in discussion may be challenging (E42). It could
be better to note that there was detailed discussion of many existing, agreed CBMs, as well
as some new proposals. The pre-draft could then move onto specific CBMs such as the
Points of Contact (E44). On this issue, we note that Points of Contact are not just a
prerequisite to CBMs, but also a CBM in their own right.
We consider that the importance of national and regional structures being in place (E46)
cannot be underestimated. Such structures enable States to provide credible and wellexercised responses to incidents and require effort and resource to maintain. National
Computer Emergency Response Teams (CERTs) are particularly important in this regard
and should be highlighted. Equally important, but different, is the work regional organisations
do to develop and implement CBMs. We consider this element, including the need for
inclusion and possible universalisation could merit its own paragraph.
F. Capacity Building
The crucial nature of capacity building in supporting both the international cyberspace
stability framework and the Sustainable Development Goals is well captured (Chapeau,
F48). We fully support the references to two-way processes (F53) and the United Nations
Women, Peace and Security agenda (F56). We consider any mention of the concept of the
‘development of a global capacity-building agenda’ (F55) would benefit from some
clarification.
We suggest that additional text could be included in this section to note the richness of the
discussion on this topic, as well as strengthening the reference to the need for cyber
diplomats to participate in OEWG discussions (F50). We consider that this section of the
pre-draft must recognise that coordination is key (F55), but should also highlight the need for
all States and stakeholders to contribute to the mobilisation of funding and resource for
capacity building wherever possible, as this underpins our ability to implement the framework
and achieve the recommendations made in this pre-draft.
G. Regular Institutional Dialogue
We welcome the description of the history of the processes (G58) and the capturing of the
proposal for Regular Institutional Dialogue based on the existing process (G62). Efforts to
capture the proposals for Regular Institutional Dialogue based on new arrangements (G59,
G60, G61) must reflect the call from several Member States that is was important to start
from the purpose of any possible dialogue and how it would further international peace and