3.
States should not knowingly allow their territory to be used for
internationally wrongful acts using ICTs;
4.
States should consider how best to cooperate to exchange information,
assist each other, prosecute terrorist and criminal use of ICTs and
implement other cooperative measures to address such threats. States
may need to consider whether new measures need to be developed in
this respect;
5.
States, in ensuring the secure use of ICTs, should respect Human Rights
Council resolutions 20/8 and 26/13 on the promotion, protection and
enjoyment of human rights on the Internet, as well as General Assembly
resolutions 68/167 and 69/166 on the right to privacy in the digital age,
to guarantee full respect for human rights, including the right to freedom
of expression;
6.
A State should not conduct or knowingly support ICT activity contrary
to its obligations under international law that intentionally damages
critical infrastructure or otherwise impairs the use and operation of
critical infrastructure to provide services to the public;
7.
States should take appropriate measures to protect their critical
infrastructure from ICT threats, taking into account General Assembly
resolution 58/199 on the creation of a global culture of cybersecurity and
the protection of critical information infrastructures, and other relevant
resolutions;
8.
States should respond to appropriate requests for assistance by another
State whose critical infrastructure is subject to malicious ICT acts. States
should also respond to appropriate requests to mitigate malicious ICT
activity aimed at the critical infrastructure of another State emanating
from their territory, taking into account due regard for sovereignty;
9.
States should take reasonable steps to ensure the integrity of the supply
chain so that end users can have confidence in the security of ICT
products. States should seek to prevent the proliferation of malicious ICT
tools and techniques and the use of harmful hidden functions;
10. States should encourage responsible reporting of ICT vulnerabilities and
share associated information on available remedies to such
vulnerabilities to limit and possibly eliminate potential threats to ICTs
and ICT-dependent infrastructure;
11. States should not conduct or knowingly support activity to harm the
information systems of the authorized emergency response teams
(sometimes known as computer emergency response teams or
cybersecurity incident response teams) of another State. A State should
4