A/68/156/Add.1
signed in 2001. Also known as the Budapest Convention, this document serves as a
guideline for developing comprehensive national legislation against cyber crime and
as a framework for international cooperation between States.
Germany
[Original: English]
[25 June 2013]
General appreciation of the issues of information security
The digitalization of economic, administrative and private interactions is not
only ongoing, but also accelerating. This offers unprecedented opportunities both
for industrialized and developing countries. At the same time, increasing
dependency on information and communications technologies creates vulnerabilities
and systemic weaknesses. There is also a new interconnectedness on the part of all
actors, from the private user to businesses and Government organizations. The trend
regarding cyber attacks is clearly towards more sophisticated malicious activities
such as Advanced Persistent Threats or highly sophisticated malware going after
high-value targets. These activities are driven by interest in profit or information on,
respectively, the control of critical assets, systems and infrastructures with severe
consequences for Governments, numerous enterprises and organizations, including
providers of critical infrastructure services. Sophisticated malicious activities are
notoriously hard to detect. The speed of innovation routinely outpaces attempts to
secure existing technologies. The fact that malicious tools and methods can be
obtained relatively easily, being commercially available on an unregulated or black
market, exacerbates the risks. Our current information technology environments
cannot be secured against them solely through conventional information technology
security approaches.
Highly professional attackers are dedicating considerable technical and
financial means to detecting weaknesses in information and communications
technology systems and making use of these for their own purposes. The difficulty
of reliable attribution and the resulting opportunities for “false flag attacks” pose
additional risks to national and international security, in particular through
misunderstanding and miscalculation. Intrusions aimed at collecting information
often initially look no different from those with a destructive aim. This further
increases the risk of misperceptions about incoming attacks and their possible
breach of the prohibition of the use of force in international relations.
Prevailing ambiguity about what norms apply in cyberspace creates additional
unpredictability. Process control systems for critical infrastructures have proven
particularly vulnerable to malicious information and communications technology
operations. The risks of uncontrollable collateral damage on a global scale are high,
including the infection of industrial control systems with potentially physical
destructive effects. A single cyber attack against core telecommunication
infrastructure could cause more global disruption than a single physical attack.
Irrespective of varying degrees of information and communications technology
capacity and security of different States, concrete steps to enhance resilience are
often being deferred or even left off the agenda entirely as a result of the uncertainty
surrounding risks to cyber security and how to address them effectively, the
13-47545
5/24