38. The voluntary sharing of information on various aspects of national and transnational threats and vulnerabilities, as well as best practices for ICT security, are powerful tools that should be utilized, as appropriate, in a more systematic and harmonized manner in the context of a multilateral inclusive specialized forum. 39. The provision by States of their national views on categories of infrastructure that they consider critical and national efforts to protect them, including information on national laws and policies for the protection of data and ICT-enabled infrastructure, could represent an important step forward. 40. At the national level, the establishment of national emergency response mechanisms is an important measure. States should support and facilitate the functioning of and cooperation among such national response entities. Such cooperation should include, as appropriate, addressing requests from other States to investigate ICT-related incidents or to mitigate malicious ICT activity emanating from their territory, while taking into account the possible limitations on the technical capacities of developing countries to address such requests. 41. Nevertheless, voluntary measures at the national level may no longer be sufficient to address the rapidly widening scope of the global threats of the malicious use of ICTs. VII. Capacity-Building: 42. In an increasingly connected world, any international regime on cyber-security will be only as strong as its weakest link. 43. While States bear primary responsibility for national security and the safety of their citizens, some States may lack sufficient capacity to protect their ICT networks, or to assist other States to do so, which may represent a global threat taking into account the possible cross-border spillovers of major ICT incidents. 44. International cooperation and assistance play an essential role in enabling States to secure ICTs and ensure their peaceful use. Providing assistance for capacity-building in the area of ICT security is also essential for international security, by improving the capacity of States for cooperation and collective action. 45. The 2010, 2013 and 2015 GGE reports rightly recommended that the international community should provide assistance to improve the security of critical ICT infrastructure; develop technical skills and appropriate legislation, strategies and regulatory frameworks to fulfil their responsibilities; and bridge the divide in the security of ICTs and their use. 46. These reports also stressed that capacity-building involves more than a transfer of knowledge and skills from developed to developing States, as all States can learn from each other about the threats that they face and effective responses to those threats. 47. The relevant General Assembly resolutions have highlighted that States should consider a variety of measures to provide technical and other assistance to build capacity in securing ICTs in developing countries requesting assistance, including training, exchange of legal and administrative best practices, and access to technologies deemed essential for ICT security. Page 6 of 7

Select target paragraph3