A/68/156/Add.1 responsibility of States not to facilitate areas of lawlessness in cyberspace, for example, by knowingly tolerating the storage of illegally collected personal data on their territory. On 27 and 28 June 2013, the third Berlin Cyber Conference, held on the theme “Securing the Freedom and Stability of Cyberspace: The Role and Relevance of International Law”, and organized by the Federal Foreign Office in close cooperation with the University of Potsdam, endeavoured to provide international legal assessments of cyber operations not transgressing the threshold of armed attack and thus not engaging the law of armed conflict. Consistent with existing international norms and principles, States are responsible for the actions of those within their sphere of control that affect the security and stability of information and communications technology. Every State should consider how to minimize or end malicious cyber activity originating from within its sphere of control or travelling over its networks. States bear responsibility for internationally wrongful cyber activity attributable to them, including the internationally wrongful activity in cyberspace of any State-backed proxies acting on the State’s instructions or under its direction or control, in accordance with existing norms of State responsibility under customary international law. States should take all necessary measures to ensure that their territories are not used by other States or by non-State actors for purposes of unlawful use of information and communications technology against other States and their interests. These necessary measures should include appropriate national legislative and regulatory frameworks needed to meet international responsibilities. Internationally wrongful cyber activity can affect States in three main ways: (1) as countries of origin of malicious cyber activity with possibly damaging effects; (2) as transit countries, whose information and communications technology infrastructures are instrumentalized for malicious cyber activity; and (3) as target countries, where damage caused by malicious cyber activity occurs. In all these scenarios, States are obliged to exercise due diligence, which can be of both material and procedural in nature and can range from prevention, i.e., the period preceding potential harm, to containment, i.e., the onset of the actual, ongoing detrimental cyber activity, to follow-up, i.e., the period after malicious cyber activity has been pursued. Cyber security in the Organization for Security and Cooperation in Europe The Organization for Security and Cooperation in Europe has been discussing cyber security issues for several years. At the OSCE summit held in Astana in 2010, the Heads of State and Government of the 56 participating States of OSCE underlined that ‘‘greater unity of purpose and action in facing emerging transnational threats” must be achieved. The Astana Commemorative Declaration mentioned cyber threats as one of these emerging transnational threats. Germany actively participated in the OSCE conference held in Vienna in 2011, held on the theme “Exploring the future OSCE role”, on a comprehensive approach to cyber security. In the course of the conference, concrete recommendations for OSCE follow-up activities were discussed. In May 2012, an informal working group was established by Permanent Council Decision 1039 (PC.DEC/1039) and tasked to elaborate a set of draft confidence-building measures to enhance interstate cooperation, transparency, predictability and stability, and to reduce the risks of misperception, escalation and conflict that may stem from the use of information and communication technologies. Germany submitted a non-paper to the group in June 2012 containing German suggestions for a first set of confidence-building 13-47545 9/24

Select target paragraph3