A/68/156/Add.1 signed in 2001. Also known as the Budapest Convention, this document serves as a guideline for developing comprehensive national legislation against cyber crime and as a framework for international cooperation between States. Germany [Original: English] [25 June 2013] General appreciation of the issues of information security The digitalization of economic, administrative and private interactions is not only ongoing, but also accelerating. This offers unprecedented opportunities both for industrialized and developing countries. At the same time, increasing dependency on information and communications technologies creates vulnerabilities and systemic weaknesses. There is also a new interconnectedness on the part of all actors, from the private user to businesses and Government organizations. The trend regarding cyber attacks is clearly towards more sophisticated malicious activities such as Advanced Persistent Threats or highly sophisticated malware going after high-value targets. These activities are driven by interest in profit or information on, respectively, the control of critical assets, systems and infrastructures with severe consequences for Governments, numerous enterprises and organizations, including providers of critical infrastructure services. Sophisticated malicious activities are notoriously hard to detect. The speed of innovation routinely outpaces attempts to secure existing technologies. The fact that malicious tools and methods can be obtained relatively easily, being commercially available on an unregulated or black market, exacerbates the risks. Our current information technology environments cannot be secured against them solely through conventional information technology security approaches. Highly professional attackers are dedicating considerable technical and financial means to detecting weaknesses in information and communications technology systems and making use of these for their own purposes. The difficulty of reliable attribution and the resulting opportunities for “false flag attacks” pose additional risks to national and international security, in particular through misunderstanding and miscalculation. Intrusions aimed at collecting information often initially look no different from those with a destructive aim. This further increases the risk of misperceptions about incoming attacks and their possible breach of the prohibition of the use of force in international relations. Prevailing ambiguity about what norms apply in cyberspace creates additional unpredictability. Process control systems for critical infrastructures have proven particularly vulnerable to malicious information and communications technology operations. The risks of uncontrollable collateral damage on a global scale are high, including the infection of industrial control systems with potentially physical destructive effects. A single cyber attack against core telecommunication infrastructure could cause more global disruption than a single physical attack. Irrespective of varying degrees of information and communications technology capacity and security of different States, concrete steps to enhance resilience are often being deferred or even left off the agenda entirely as a result of the uncertainty surrounding risks to cyber security and how to address them effectively, the 13-47545 5/24

Select target paragraph3