- development and effective implementation is seen as a crucial and useful step to ensure coherent effort and increased security; The continued development of industry standards on security of technology, which help to build cyber resilience globally and seek alignment at an international level. Norm 2 – In case of ICT incidents, States should consider all relevant information, including, inter alia, the larger context of the event, the challenges of attribution in the ICT environment, and the nature and extent of the consequences. G7 States have developed crisis-management procedures to deal with ICT incidents at the national level: - - These generally include, under different forms, regular information-sharing and enhanced cooperation between relevant administrations and agencies; After an attack has been detected, technical agencies have the responsibility to come up with an assessment of the nature of the incident which then paves the way for a whole-of-government response, if required; G7 countries consider that attribution is sovereign political decision, taken on a caseby-case basis with due consideration for all relevant information; Some G7 countries have found it useful to establish incident categorization frameworks to help officials and decision-makers in their analysis and action. Norm 3 – States should not knowingly allow their territory to be used for internationally wrongful acts using ICTs. In order to ensure their territory is not used to commit internationally wrongful acts, G7 countries have: - - Increased the resources and capabilities of their respective national cybersecurity agencies; Strengthened cooperation with the private sector to promote effective cybersecurity standards, frameworks, and processes including on incident-reporting and the security of IoT devices (Internet of Things), to increase information-sharing on threats and to conduct cyber-awareness raising campaigns; Taken active measures to prevent and discourage cybercriminals from operating on their territories or through their digital infrastructures – including through the criminalization of wrongful acts using ICTs, such as unauthorized intrusions in information security systems of third parties. Page 2 out of 5 For Official Use Only

Select target paragraph3