A/76/136
A key part of the mandate of the GGE – including through these annexed
national contributions – is to continue to study how international law applies to the
use of ICTs by States. This question is a subject of ongoing consideration by States
individually and collectively through the UN and other multilateral forums.
Deepening our understanding of how international law applies is an iterative process,
involving States forming national views and exchanging positions. Through internal
consideration and international exchanges, States are building a deeper, clearer and
more practical understanding of how international law applies to State behaviour in
cyberspace. Even where views differ, developing understandings of respective States’
positions may increase predictability and reduce the risk of miscalculation, which can
lead to escalation in State conduct. The contributions of States represented through
experts as part of this GGE are an important part of this process and will be a valuable
resource for the international community on key questions of how international law
applies in cyberspace.
In 2020, Australia also submitted a non-paper to the UN OEWG on Cyber
containing a series of case studies on the application of international law in
cyberspace.
The case studies seek to demonstrate that existing treaties and customary
international law provide a comprehensive and robust framework to address the
threats posed by state-generated or sponsored malicious cyber activity. In particular,
international law provides victim States with a ‘tool kit’ to identify breaches of
international legal obligations, attribute those acts to the responsible State, seek
peaceful resolution of disputes and, where the victim State deems appropriate, take
lawful measures in response. In this way, the application of existing international law
to cyberspace can enhance international peace and security by increasing the
predictability of State behaviour, reducing the possibility of conflict, minimising
escalation and preventing misattribution. The case studies are annexed to this
submission and should be read in conjunction with it.
It is important to recognise that international law is most effective when States
implement and adhere to their international legal obligations and, where necessary,
cooperate to uphold international law and ensure accountability for violations.
In the cyber context, international law is one element in the ‘framework for
responsible State behaviour in cyberspace’. The other elements are: voluntary, nonbinding norms (‘norms’); confidence building measures; and capacity building. The
2015 GGE elaborated 11 norms, which were endorsed by consensus in UN General
Assembly Resolution 70/237 (2015), as well as in the report of the 2021 OEWG which
was itself endorsed by consensus in UN General Assembly Decision 75/816. The
norms reflect the expectations and standards of the international community regarding
responsible State behaviour in cyberspace, but they do not replace or alter States’
binding obligations or rights under international law. Accordingly, the norms provide
specific guidance, additional to international law, on what constitutes responsible
State behaviour in the use of ICTs. This understanding of the relationship between
international law and norms was affirmed by the OEWG in its 2021 report.
1.
The United Nations Charter, the law on the use of force (jus ad bellum) and the
principle of non-intervention
The United Nations Charter (UN Charter) and associated rules of customary
international law apply to activities conducted in cyberspace. Article 2(3) of the UN
Charter requires States to seek the peaceful settlement of disputes and Article 2(4)
prohibits the threat or use of force by a State against the territorial integrity or political
independence of another State, or in any manner inconsistent with the purposes of the
4/142
21-09670