B) The development of our cyber capacities to better defend ourselves and prevent malicious cyber
activities, in a fully transparent manner.
In implementing Canada’s 2018 National Cyber Security Strategy, Canada created the Canadian Centre for
Cyber Security, which consolidated the cyber security operational units of the Government of Canada into one
public-facing organization. The Cyber Centre is a single unified source of expert advice, guidance, services and
support on cyber security for government, critical infrastructure owners and operations, the private sector
and the Canadian public. Specifically, the Cyber Centre enables faster, better-coordinated, and more focused
Government responses to cyber threats. It provides quicker, more effective information flow between the
Government and private sector partners. The Cyber Centre provides a clear national point of contact for
authoritative cyber security advice and assistance. The Cyber Centre also aims to provide enhanced public
awareness and education about cyber security, improve cyber security skills sharing and information, and
provide more regular cyber threat assessments to better inform decision-making and inform federal policy on
cyber security. As an outward-facing organization, the Cyber Centre welcomes collaborative partnerships and
projects with the Canadian cyber security sector.
Canada’s Defence Policy, released on June 7, 2017, recognized the growing threat posed by malicious actors in
cyberspace. To help protect and defend Canada, our Defence Policy stated that the Canadian Armed Forces
are developing the capability to conduct active cyber operations focused on external threats to Canada in the
context of government-authorized military missions. All our missions are subject to all applicable domestic
and international law. The 2017 Defence Policy also announced the creation of the cyber occupation in the
military to increase the Canadian Armed Forces capacity in this domain.
In June 2019, the Communications Security Establishment Act (CSE Act) received Royal Assent. It gave the
Communications Security Establishment, Canada’s signals intelligence agency, the authority to undertake
active and defensive cyber operations for the first time. These authorities are needed to allow Canada to
better defend against foreign cyber threats before they can damage Canadian systems or information
holdings. The legislation also included clear requirements for and restrictions on the exercise of this authority.
Other partners and allies have been similarly transparent about their capabilities and the conditions under
which they might be used. Like others, we see this transparency as an important step to avoid misperceptions,
reduce uncertainties and foster trust in cyberspace.
C) The promotion, at the international level, of the applicability of international law and of norms of
responsible behavior applicable to the conduct of different actors in cyberspace.
To counter cyber threats, Canada has supported the recognition of the applicability of international law in
cyberspace, the adoption of voluntary norms for responsible State behaviour, and the development of
confidence-building measures. The 2013 and 2015 UN GGE reports recognized the applicability of
international law and the 2015 GGE report outlined voluntary norms for State behaviour in cyberspace. These
norms were subsequently endorsed in a wide range of international forums, including by the UN General
Assembly, the G20 and various regional organizations. Canada has endorsed these norms and is actively
working to promote their implementation. One way we have done this is by organizing workshops to help
countries better understand the norms and what can be done to implement them. We co-hosted a workshop
with Mexico and the OAS on May 30, 2019 that targeted OAS countries, and we organized a similar one
targeting Francophonie countries on September 6, 2019.
In our annual submissions to the UN, such as our 2016 submission, and elsewhere, Canada has stated that we
believe that existing international law is applicable to the use of ICTs by States, and is essential to maintaining
peace and stability and to promoting an open, secure, peaceful and accessible ICT environment. The
international law relevant to cyberspace includes the UN Charter, the law on State Responsibility, including
countermeasures, International Human Rights Law and International Humanitarian Law, where applicable.
Canada has also participated in the work of the Internet & Jurisdiction (I&J) Policy Network. Founded in 2012,
the I&J has brought together international stakeholders from academia, industry (Internet companies,
technical operators), governments, international organizations and civil society groups with over 200 key
organizations as members from more than 40 countries. The goal of the I&J Network is to look at developing
consensus-based approaches to the challenges created by the cross-border nature of the Internet, in three