A/68/156 This Directive also calls for participation in the promotion of comprehensive cybersecurity management within the framework of the relevant principles of the national cybersecurity strategy. The Defence Policy Directive, adopted in 2012, also refers to the emergence of cyberspace as a new field of international relations and identifies as a defence priority the strengthening of information- and intelligence-gathering systems in order to support operations such as command and control systems with a view to reducing the risk of cyberattacks. In January 2011, the Head of the Chiefs of Defence Staff issued a vision of military cyberdefence, which provides guidance for the planning, development and use of the military capacities needed in order to ensure the effective use of cyberspace during military operations. 4. Possible measures that could be taken by the international community to strengthen information security at the global level Increased dependence on information systems and increased connectivity of critical infrastructures have made cyberspace security essential to the functioning of a modern State. For this reason, cybersecurity should be an intrinsic part of national security planning. At present, the protection of an international legal framework to meet cybersecurity threats is lacking. Therefore, without prejudice to States’ sovereignty in matters related to cybersecurity, there is a need for multilateral cooperation agreements in this area (analogous or similar to the International Convention for the Safety of Life at Sea (SOLAS)) whereby States would undertake to harmonize their legislation with a view to the prosecution of Internet crimes while attempting to ensure, to the extent possible, that anonymity, the absence of legislation and economic interests do not make the Internet the ideal breeding ground for crime and terrorism. The private sector, and particularly Internet service providers, must be involved in the effort to combat cybercrime. The cooperation of the private sector is essential since most Internet services are in the hands of private companies. The private sector has long dealt with Internet-related threats and its knowledge and experience in this area could be very valuable. CERTS play a key role in cybersecurity. The establishment of specialized teams and the ongoing training of their members are the first steps that Governments should take in order to ensure cybersecurity. It is also important to establish law enforcement units that specialize in the investigation of crimes committed via the Internet. Because cybersecurity is a global challenge, international cooperation in improving it is essential and should be strengthened at the policy and operational levels. There should be constant communication between the CERTS of different countries in order to facilitate the sharing of information on attacks within a short response time. Lessons learned and best national and international practices should also be shared. 8 13-39735

Select target paragraph3