E. Confidence-building Measures
Confidence-building measures (CBMs), which comprise transparency, cooperative and stability measures,
can contribute to preventing conflicts, avoiding misperception and misunderstandings, and providing a
“safety valve” for the reduction of tensions. CBMs can strengthen the overall security and resilience of the
ICT environment. CBMs can support implementation of norms of responsible State behaviour, in that they
foster trust and ensure greater clarity, predictability and stability in the use of ICTs by States. They can also
help build common understandings among States, thereby contributing to a more peaceful international
environment in the longer term.
In addition to the recommendations on CBMs contained in the consensus GGE reports, the OEWG
recognized that regional organizations have developed or adapted CBMs to address specific priorities of
their members. The 1988 Guidelines for Confidence-building Measures developed by the UN Disarmament
Commission and endorsed by the General Assembly in consensus resolution 43/78 (H) also contain
principles, objectives and characteristics for CBMs that remain relevant today.
41. In their discussions at the OEWG, States highlighted the need to translate confidence-building
measures into concrete actions that are implementable by all States.
42. States noted the continuing relevance of the CBMs recommended in the consensus GGE reports.
Measures highlighted for priority attention included regular dialogue and voluntary information
exchanges on existing and emerging threats, national policy or doctrine, national views on how
international law applies to State use of ICTs, and national approaches to defining critical
infrastructure or categorizing ICT-related incidents. Other such measures included developing
guidance, training for diplomats, exchanging lessons on establishing and exercising secure crisis
communication channels, and operational exercises at the technical level between Computer
Emergency Response Teams (CERTs) or Computer Security Incident Response Teams (CSIRTs).
43. States highlighted that the dialogue within the Open-ended Working Group was in itself a CBM, as it
stimulates an open and transparent exchange of views on perceptions of threats and vulnerabilities,
responsible behaviour of States and other actors and good practices, thereby ultimately supporting
the collective development of the normative framework that guides the use of ICTs by States.
44. In particular, States stressed that establishing national Points of Contact (PoC) constitutes a
prerequisite for the implementation of many CBMs, and is invaluable in times of crisis. States may
find it useful to have PoCs for, inter alia, diplomatic, policy, legal and technical exchanges, as well as
incident reporting and response. It was suggested that a global directory of Points of Contact would
be useful. At the same time, it was noted that the security of such a directory as well as its operational
modalities would be crucial to its success. The value of regularly conducting exercises among a
network of PoCs was also emphasized, as it can help to maintain readiness and ensure that PoC
directories remain updated.
45. As CBMs can be developed at the bilateral, regional or global level, States proposed the establishment
of a global repository of CBMs, with the objective of sharing policy, good practice, experiences with
CBM implementation and encouraging peer learning. Such a repository could also assist States to
identify additional CBMs appropriate to their national and regional contexts.
8