A/66/152
politically binding norms of State behaviour in cyberspace. They should be
acceptable to a large part of the international community and should include
measures to build trust and increase security.
Confidence and security-building measures in cyberspace
Cyberspace is a public good and a public space. As such we have to consider
cyberspace security in terms of the resilience of infrastructure as well as the
integrity and failure safety of systems and data. Being a public space, States have to
promote security in cyberspace, particularly regarding security against crime and
malicious activities, by protecting those who choose to use authenticity tools against
identity theft and securing the integrity and confidentiality of data and networks.
Cyberspace is global by nature. Ensuring cybersecurity, enforcing rights and
protecting critical information infrastructures require major efforts by the State both
at the national level and in cooperation with international partners.
Against this backdrop, Germany is ready to work on a set of behavioural
norms addressing State-to-State behaviour in cyberspace, including, in particular,
confidence, transparency- and security-building measures, to be signed by as many
countries as possible.
Germany outlined possible elements of such a code of conduct on international
norms recently at the Organization for Security and Cooperation in Europe (OSCE)
conference on cybersecurity, held on 9 and 10 May 2011, as follows:
(a) Confirm the general principles of availability, confidentiality,
competitiveness, integrity and authenticity of data and networks, privacy and
protection of intellectual property rights;
(b)
Respect the obligation to protect critical infrastructures;
(c) Enhance cooperation aiming at confidence-building, risk reducing
measures, transparency and stability by:
• Exchanges of national strategies, best practices and national perceptions
referring to the international regulation of cyberspace;
• The exchange of national views of international legal norms pertaining to the
use of cyberspace;
• The setup and notification of points of contact;
• The setup of early warning mechanisms and the enhancement of cooperation
between computer emergency response teams;
• The upgrade of crisis communication links to encompass cyberincidents, the
support of the development of technical recommendations that advance robust
and secure global cyberinfrastructures;
• The responsibility to combat terrorism comprising the exchange of practices
and enhanced cooperation to address non-State actors;
• The support of cybersecurity capacity-building in developing countries, and
the development of voluntary measures for cybersecurity support to large-scale
events (e.g. the Olympic Games).
11-41691
9