A/70/172
against highly visible targets, such as media outlets. Attacks against critical
infrastructures, in particular, could have severe consequences.
An all-out “cyberwar” seems unlikely at present. However, the limited use of
cybercapabilities as part of a larger war-fighting effort, including in the context of
hybrid conflicts, has become a reality. In addition, incidents in cyberspace may
escalate into real-world conflict.
Germany advocates a three-pronged approach to manoeuvre in that
environment: agreeing rules of responsible State behaviour in cyberspace, engaging
in confidence-building and increasing cyberresilience.
The United Nations is the crucial forum for establishing the rules of
responsible State behaviour in cyberspace. An important starting point is the
consensus of the Group of Governmental Experts on Developments in the Field of
Information and Telecommunications in the Context of International Security of
2012-2013 that international law, particularly the Charter of the United Nations, is
applicable in cyberspace. The Group of Governmental Experts of 2014 -2015, in
which Germany has once again been actively engaged, has built on this.
A shared understanding of the rules, norms and principles of responsible State
behaviour in cyberspace could enhance international transparency and predictability,
thereby contributing to peace and stability. It would be useful, for example, to have
a better common understanding of how the law on armed conflict applies to the use
of those military cybercapabilities that more and more States are developing.
Concerning confidence-building, Germany attaches the utmost importance to
regional organizations. In 2013, the Organization for Security and Cooperation in
Europe agreed on an initial set of cyberconfidence-building measures.
Implementation is proceeding well and negotiations are under way for a second set,
which would address trust-building and cooperation. As part of its upcoming
chairmanship of the organization, Germany plans to prioritize cybersecurity.
Germany is working on an information technology security act to increase
cyberresilience at the national level. The draft text of that act defines minimum
requirements for the information technology security of critical infrastructures. It
establishes an obligation to report significant incidents with a view to improving the
overall security of systems and public protection in general. Germany also offers
support to other States in increasing their capacity to manage cybersecurity risks.
The full text of the submission by Germany
www.un.org/disarmament/topics/informationsecurity/.
can
be
found
at
Netherlands
[Original: English]
[29 May 2015]
The international community has a shared interest and responsibility to ensure
that cyberspace remains open, free and secure. In the view of the Netherlands,
security would be served by the broad acceptance of and adherence to a set of norms
of responsible behaviour of States. Much work has been done already by the Group
of Governmental Experts on Developments in the Field of Information and
Telecommunications in the Context of International Security. However, the
15-12333
7/14