A/68/156/Add.1
Germany outlined possible elements of such a code of conduct on international
norms at the Organization for Security and Cooperation in Europe (OSCE)
conference on cyber security, held on 9 and 10 May 2011, as follows:
(a) Confirmation of the general principles of availability, confidentiality,
competitiveness, integrity and authenticity of data and networks, privacy and
protection of intellectual property rights;
(b)
Respect for the obligation to protect critical infrastructures;
(c) Enhanced cooperation aimed at confidence-building, risk reducing
measures, transparency and stability through:
(i) Exchanges of national strategies, best practices and national perceptions
referring to the international regulation of cyberspace;
(ii) Exchange of national views on international legal norms pertaining to the
use of cyberspace;
(iii) Establishment and notification of points of contact;
(iv) Establishment of early warning mechanisms and enhancement of
cooperation between computer emergency response teams;
(v) Upgrading of crisis communication links to encompass cyber incidents,
support for the development of technical recommendations that advance robust
and secure global cyber infrastructures;
(vi) Responsibility to combat terrorism comprising the exchange of practices
and enhanced cooperation to address non-State actors;
(vii) Support for cyber security capacity-building in developing countries, and
the development of voluntary measures for cyber security support to largescale events.
Along these lines, Germany submitted a position paper to the United Nations
Group of Governmental Experts in July 2012. We strongly welcome the
recommendations of the Experts on norms, rules or principles of responsible
behaviour of States and confidence-building measures in cyberspace, as well as the
emphasis the Experts placed on a multi-stakeholder approach to cyber security.
In 2011 and 2012, Germany supported projects on international cyber security
and confidence- and security-building measures being carried out by the United
Nations Institute for Disarmament Research (UNIDIR) and the Institute for Peace
Research and Security Policy at the University of Hamburg. The first Berlin Cyber
Conference, held in December 2011, provided a platform for international
discussion on risks, strategies and confidence-building in international cyber
security. The second Berlin Cyber Conference, held in September 2012, focused on
the Internet and human rights. A main conclusion was that security, freedom and
privacy online are complementary concepts. Germany also supported the 2012
UNIDIR Cyber Security Conference, held in Geneva on 8 and 9 November 2012,
with a focus on confidence-building measures in assuring cyber stability.
Moreover, we see the necessity to start a debate on international cooperation in
the framework of attribution of cyber attacks, which are usually very difficult to
trace, State responsibility for cyber attacks launched from their territory when States
do nothing to end such attacks, despite being informed about them, and the
8/24
13-47545