38.
The voluntary sharing of information on various aspects of national and transnational
threats and vulnerabilities, as well as best practices for ICT security, are powerful
tools that should be utilized, as appropriate, in a more systematic and harmonized
manner in the context of a multilateral inclusive specialized forum.
39.
The provision by States of their national views on categories of infrastructure that
they consider critical and national efforts to protect them, including information on
national laws and policies for the protection of data and ICT-enabled infrastructure,
could represent an important step forward.
40.
At the national level, the establishment of national emergency response mechanisms
is an important measure. States should support and facilitate the functioning of and
cooperation among such national response entities. Such cooperation should include,
as appropriate, addressing requests from other States to investigate ICT-related
incidents or to mitigate malicious ICT activity emanating from their territory, while
taking into account the possible limitations on the technical capacities of developing
countries to address such requests.
41.
Nevertheless, voluntary measures at the national level may no longer be sufficient to
address the rapidly widening scope of the global threats of the malicious use of ICTs.
VII. Capacity-Building:
42.
In an increasingly connected world, any international regime on cyber-security will
be only as strong as its weakest link.
43.
While States bear primary responsibility for national security and the safety of their
citizens, some States may lack sufficient capacity to protect their ICT networks, or to
assist other States to do so, which may represent a global threat taking into account
the possible cross-border spillovers of major ICT incidents.
44.
International cooperation and assistance play an essential role in enabling States to
secure ICTs and ensure their peaceful use. Providing assistance for capacity-building
in the area of ICT security is also essential for international security, by improving
the capacity of States for cooperation and collective action.
45.
The 2010, 2013 and 2015 GGE reports rightly recommended that the international
community should provide assistance to improve the security of critical ICT
infrastructure; develop technical skills and appropriate legislation, strategies and
regulatory frameworks to fulfil their responsibilities; and bridge the divide in the
security of ICTs and their use.
46.
These reports also stressed that capacity-building involves more than a transfer of
knowledge and skills from developed to developing States, as all States can learn from
each other about the threats that they face and effective responses to those threats.
47.
The relevant General Assembly resolutions have highlighted that States should
consider a variety of measures to provide technical and other assistance to build
capacity in securing ICTs in developing countries requesting assistance, including
training, exchange of legal and administrative best practices, and access to
technologies deemed essential for ICT security.
Page 6 of 7