6 Improving Transparency: International Law and State Cyber Operations Fifth Report d. to afford the OAS and its Member States an appropriate voice in global conversations about international law’s application. done so as well.3 To date, however, efforts to delineate how States understand international law’s application to cyberspace have had limited success. At the same time, it is important to reiterate what this project is not designed to do. It does not aim to codify or progressively develop international law (nor even to identify best practices or general guidance). Nor does it aim to offer a comprehensive or overarching perspective on international legal issues in the cyber context. 4. Part of the problem in applying international law to cyberspace derives from the lack of tailor-made rules or standards. When it comes to international peace and security, for example, there are no cyber-specific treaties. And those conventions that deal with cybercrime – the Budapest Convention and (if it ever enters into force) the African Union Convention – only target, by definition, non-State actor behavior with support from a minority of nation States.4 Thus, international law’s application to cyberspace depends on analogizing to more general multilateral treaties (e.g., the U.N. Charter) or customary international law. 2. Rather, this project is intended—and should be read—as a modest, first step. The Juridical Committee (and the OAS more broadly) may use the materials provided here to evaluate what, if any, further activities might be pursued to add more transparency to how international law applies to States in the region, their cyber-operations, and their reactions to cyber threats by others. The Committee might also consider ramping up existing capacity building efforts to improve the knowledge and experience of relevant officials on the questions of international law’s application to cyberspace. This may involve gathering (and publicizing) additional national views and/or establishing platforms or other processes for information sharing and dialogue on international law’s relationship to cyberspace and the information and communication technologies (ICTs) from which it derives. 3. My first report highlighted international law’s limited visibility in regulating State cyber operations despite the increasing number of such operations and their economic, humanitarian, and national security implications.1 It is true that many States have confirmed the applicability of international law to their behavior in cyberspace.2 And, although the OAS has not, other international organizations—ASEAN, the European Union, and the United Nations—have 1 See Duncan B. Hollis, International Law and State Cyber Operations: Improving Transparency, OEA/Ser.Q, CJI/doc 570/18 (August 9, 2018) (“Hollis, First Report”), at http://www.oas.org/ en/sla/iajc/docs/CJI_doc_570- 18.pdf. 2 See U.N. Secretary-General, Report of the Group of Governmental Experts on Developments in the Field of Information and Telecommunications in the Context of International Security, 19, U.N. Doc. A/68/98 (June 24, 2013) (“[i]nternational law, and in particular the Charter of the United Nations, is applicable” to cyberspace); see also U.N. Secretary-General, Report of the Group of Governmental Experts on Developments in the Field of Information and Telecommunications in the Context of International Security, 24, U.N. Doc. A/70/174 (July 22, 2015). Inter-American Juridical Committee 5. However, as my second report highlighted, at the global level there is no universal consensus among States on what existing general international laws apply to cyber operations, let alone how they do so.5 For various international legal regimes (e.g., self-defense, international humanitarian law, countermeasures, sovereignty (as a standalone rule), and due diligence) one or more States contest their application in toto to cyberspace, while others 3 See UNGA Res. 266, U.N. Doc. A/RES/73/266 (Jan. 2, 2019); ASEAN-United States Leaders’ Statement on Cybersecurity Cooperation (Nov. 18, 2018), at https://asean.org/storage/2018/11/ASEAN-US-Leaders-Statement- on-Cybersecurity-Cooperation-Final.pdf ; EU Statement – United Nations 1st Committee, Thematic Discussion on Other Disarmament Measures and International Security (Oct. 26, 2018) (“EU Statement”), at https://eeas.europa. eu/delegations/un-new-york/52894/eu-statement-%E2%80%93-united-nations-1st-committee- thematic-discussion-other-disarmament-measures-and_en. Both the G7 and G20 have made similar affirmations. See, e.g., G7 Declaration on Responsible States Behavior in Cyberspace (April 11, 2017) at https://www.mofa.go.jp/files/000246367.pdf; G20 Antalya Summit Leader’s Communique (Nov. 15-16, 2015) 26, at http://www.gpfi.org/sites/gpfi/ files/documents/G20-Antalya-Leaders-Summit-Communiqu--.pdf. 4 Council of Europe, Convention on Cybercrime (Budapest, 23 Nov 2001) CETS No 185; AU Convention on Cyber Security & Personal Data Protection, June 27, 2014, AU Doc. EX. CL/846(XXV). The Budapest Convention now has 65 parties, although several other States view it with some hostility. See Convention on Cybercrime, at http://conventions.coe.int/ Treaty/Commun/ChercheSig.asp?NT=185&CL=ENG. 5 Duncan B. Hollis, International Law and State Cyber Operations: Improving Transparency, OEA/Ser.Q, CJI/doc 578/19 (Jan. 21, 2019) (“Hollis, Second Report”), at http://www.oas.org/ en/sla/iajc/docs/CJI_doc_578-19.pdf. International Law and State Cyber Operations 7

Select target paragraph3