OPEN-ENDED WORKING GROUP ON SECURITY OF AND IN THE USE OF INFORMATION AND COMMUNICATIONS TECHNOLOGIES 2012-2025 (OEWG)
SECOND SUBSTANTIVE SESSION
28 March to 01 April 2022
Statement on ‘Existing and potential threats’ Cluster
Mr. Chair,
India takes this opportunity to thank you for your able-leadership and sincere efforts to take forward the mandate of this Working Group. India appreciates the initiative that the Chair has been undertaking in resolving modalities of the non-governmental organizations participation in the Open Ended Working Group.
2. The range of threats in the sphere of information security are constantly in a flux with multiple threat vectors emerging wherein the actors are exploiting vulnerabilities in ICT infrastructure and develop new methods for infiltration. With an increasing dependence of Member States on ICT products and systems for essential social and economic activities, the potential loss in case of cyber incidents is going to be at an unprecedented level. Potential threats to ICT environment in the context of multiplicity of threat actors operating to infiltrate critical information infrastructure may severely impair economic development, social harmony and peace and security of the Member States. During the First Substantive Session, Member States highlighted threats posed by ransomware, misinformation, data security and mismatch in cyber capabilities between Member States.
Mr. Chair,
3. With an increase in the use of ICTs, the threats to the security of ICTs continue to evolve with more complexity and scale. India believes that identifying and exchanging Point-of-Contacts (PoCs) of national Computer Emergency Response Teams (CERTs) and Cybersecurity Incident Response Teams (CSIRTS) is a first step in preventing and responding to potential threats. To discourage potential threats from becoming threats of large-scale implications, it is important to exchange information on discovered vulnerabilities and emerging threat scenarios to ICT environment through a 24*7 contact points.
4. Facilitating regular interaction between competent authorities or PoCs to share the methods of response to a particular potential cyber incident along with established cyber hygiene practices would assist Member States to work together and share best practices.
5. Protection of critical information infrastructure is of vital importance in ensuring international security, peace and stability. The OEWG may explore inviting Member States to voluntarily share information on their national organization, policies and programs including initiatives that involve non-governmental organizations that they are employing to ensure integrity and safety of critical information infrastructure.
Mr. Chair,
6. Encouraging reporting of latest vulnerabilities discovered in ICT environment that are of consequential importance in ensuring critical infrastructure, in particular critical information infrastructure, would effectively build an international cooperative framework for Member States to prevent potential threats and ensure security of ICT environment. Promoting public-private partnerships and develop practical mechanisms to exchange best practices and new information may play an importance role in responding to existing and potential threats.
7. As the nature of threats continues to change, CERTs/CSIRTs with diverse capabilities and expertise in incident response would be needed to effectively identify and respond to threats. Capacity building initiatives would need to expand to new areas such as law, policy and government, and international relations to operate effectively in the emerging cyber threat landscape.
Thank you.
****
Statement on ‘’Rules, norms and principles’ cluster
Mr. Chair,
The 11-voluntary, non-binding norms of responsible State behaviour can reduce risks to international peace, security and stability and play an important role in increasing predictability and reducing risks of misconceptions, thus contributing to the prevention of conflict. With an increasing number of threats to critical infrastructure emanating from the use of disruptive ICT tools and ICT vulnerabilities, the norms provide guiding path in ensuring stability and security in the use of ICTs.
2. The norms in the existing form needs complementary framework to outline the mechanisms of cooperation, information exchange, trust building initiatives, sharing best practices to protect critical infrastructure and protect the CI from malicious ICT activity. The use of ICTs by non-state actors for terrorist and criminal purposes needs to be reported to the State that malicious activity is directed to in order to take appropriate measures.
3. OEWG may further discuss the deep interconnected nature of the norms to build a comprehensive understanding of the essential cooperation elements between Member States. Cooperation between Member States in areas of sharing latest vulnerabilities and their remedies in ICT-dependent infrastructure. The integrity of supply chain is of utmost importance to build trust and confidence at the end user level in the ICT environment.
Mr. Chair,
4. Confidence Building Measures (CBMs) and Capacity Building are the two key areas that can encourage Member States to cooperate with each other in practical ways. OEWG can discuss the initiatives to enhance capacities of the Member States that enable them to be prepared for taking ‘appropriate measures’ whenever information of malicious activity or ICT supply chain vulnerabilities are reported.
5. This OEWG must consider building an additional layer of understanding on the existing norms, rules and principles that form the basis for responsible behaviour of States and may develop additional norms, rules and principles on need basis. For adoption of a normative framework, it is necessary for OEWG to discuss the basic mechanisms for information exchange, sharing best practices and enhancement of capabilities computer emergency response teams at national level.
Mr. Chair,
6. In the GGE and OEWG final reports, it was mentioned that States were called upon to avoid and refrain from the use of ICTs not in line with the norms of responsible State behavior. While the use of ICTs by non-state actors for terrorist and criminal purposes itself is a threat that can result in significant risks to critical infrastructure, the states use of harmful ICT activities may pose significant risks to international security, peace and stability. The use of cloud ICT infrastructure for such harmful practices by a Member State targeting other Member State causes transnational conflicts undermining international peace and security, trust and stability between States, and may increase the likelihood of future conflicts between States.
7. OEWG need to discuss the fine elements incorporated in each of the 11 voluntary, non-binding norms for realizing the potential they offer to Member States, through cooperation and dialogue, in ensuring stability of ICT dependent-infrastructure.
Thank you.
*****
Statement on ‘International Law and ICT’ cluster
Mr. Chair,
The UN Group of Governmental Experts (UN GGE) reports in 2013, 2015 and 2021 and the final report of the UN Open Ended Working Group (UN OEWG) in 2021 mentioned that international law is the basis for States’ shared commitment to preventing conflict and maintaining international peace and security and is a key to enhancing confidence among States. The work by previous GGEs and OEWG that international law, and in particular the Charter of the United Nations is applicable and essential to maintaining peace and stability and for promoting an open, secure, stable, accessible and peaceful ICT environment. These assessments and recommendations, in conjunction with other substantive elements of previous reports, emphasize that adherence by States to international law, in particular their Charter obligations, is an essential framework for their actions in their use of ICTs.
2. We believe that international law is a vital deterrent in preventing conflicts and maintaining international peace and security. The principles of sovereign equality of States, non-use of force and threat of force, settlement of international disputes by peaceful means, non-interference into internal affairs of States are the foundational elements to take forward the discussion on international law to the use of ICTs during the mandate of the OEWG. It was recommended that additional neutral and objective efforts were needed to build capacity in the areas of international law, national legislation and policy matters and thereby building further common understandings on how international law applies to State use of ICTs.
3. Application of how international law applies to the use of ICTs by States needs to be discussed in the OEWG further with primary focus on how specific aspects of the existing international law apply to the ICT, with an objective of developing a common understanding for the Member States under the UN auspices. Exploring new areas in the application of international law to the use of ICTs by States would bring in diverse opinions from Member States. The OEWG needs to build on such discussions to form a matrix of areas of convergence and areas of divergence to consolidate our understanding on the subject.
Mr. Chair,
4. Violations of state sovereignty by another state through use of ICTs, constitute an internationally wrongful act and entail an international responsibility of the State. Similarly, cyber operations against information systems located in another state’s territory or causing extra-territorial effects might also constitute a breach of sovereignty. A State enjoys the right to exercise sovereignty over objects and activities within its territory. It has the corresponding responsibility to ensure that those objects and activities are not used to harm other States. In this context, a State which is aware of an internationally wrongful act originating from or routed through its territory, and having the ability to put an end to the harmful activity, that State should take reasonable steps to do so consistent with international law.
5. There is a need to further develop a common understanding by the OEWG for Member States on attribution in case of harmful ICT activity of serious nature. A relative mechanism to evaluate the large-scale implications emanating from such ICT activity and the options to be exercised by a Member State to protect its sovereignty and take appropriate measures to protect its critical infrastructure.
Mr. Chair,
6. The attribution of an internationally wrongful act, including an internationally wrongful harmful ICT activity to sovereignty, requires careful assessment of whether and how malicious activity conducted by a person, a group of persons or legal persons can be considered as the act of a State. OEWG should discuss the impact of harmful ICT activity on people, socio-economic conditions and economic development of a Member State and whether such activity cab be attributed to a State under international law wherein the activity was conducted by an organ of the State; by persons or entities exercising elements of governmental authority; or by non-State actors operating under the direction or control of the State.
7. Previous GGEs and OEWG final reports delivered an appreciative work in the area of how international law applies to use of ICTs by States. However, the new and emerging disruptive technologies, especially cloud-based ICT infrastructure for data processing and hosting malicious ICT activities of serious nature are posing challenges on the present understanding of international law. OEWG need to discuss it in the light of constantly emerging new disruptive ICT tools of exploitative nature that can be used against Member States.
Thank you Chair.
*****
Statement on ‘Regular Institutional Dialogue’ Cluster
Mr. Chair,
As we have seen in the last few sessions, the cyberspace and its associated key dimensions such as existing and potential threats; norms, principles and rules for responsible behaviour of States to cyberspace, application of international law to use of ICTs, CBMs and capacity building do not stand in isolation but are integrated as a homogenous entity that evolves continuously with emerging technologies and inventions in future.
2. Previous GGE and OEWG report of 2021 discussed these aspects in detail and the necessity of having a regular inter-governmental dialogue to discuss, plan, implement and review a list of effective and resilient mechanisms that ensure an open, secure, stable, accessible and peaceful ICT environment. We believe that a regular inter-governmental institutional dialogue would function as an open and inclusive platform for Member States to progress from policy-oriented discussions to action-oriented cooperation measures.
3. My delegation believes that a regular institutional dialogue under the UN supports the shared objectives of strengthening international peace, stability and prevention of conflicts in cyberspace. In the context of an increasing dependency on ICTs and the potential threats emanating from their malicious use, there is a need to continue to further develop common understanding for Member States, build confidence and strengthen international cooperation. An inter-governmental dialogue would enable capacity building for the Member States which in turn enable implementation of the normative framework. An important advantage of regular institutional dialogue under the UN would also result in building mutual confidence among Member States.
Mr Chair,
4. Any future regular institutional dialogue should not duplicate existing UN mandates, efforts and activities. A future dialogue on international cooperation on ICTs in the context of international security should integrate various key aspects of ICT environment such as raising awareness, building trust, confidence and encouraging deeper study and discussion on areas where no common understanding is yet to emerge.
I thank you, Mr. Chair.
*****
Statement on ‘Capacity Building’ cluster
Mr. Chairperson,
The role of capacity building is of vital importance in taking forward the mandate of the working group and in actually assisting the Member States in building a resilient ICT-based infrastructure. India would like to underline that capacity building is not just limited to respective national technical agencies but in reality transcends into policy level entities.
2. Capacity building is the common thread that connects focus areas of the working group such as promoting study and common understanding on existing and potential threats, implementation of normative framework for responsible behavior in cyberspace, application of international law to the use of ICTs and developing inclusive, transparent and action oriented Confidence Building Measures (CBMs). An inclusive, democratic, neutral and trust-based capacity building programs lay strong foundation in sustaining a regular institutional dialogue for Member States.
To that end, we would like to propose some of the following action items that the OEWG could work and deliver during its mandate:
I) OEWG may consider to form a forum of CERTs/CSIRTs at UN level and it can develop and execute specific capacity building programs to the smaller and under developed member states through this forum, in particular enough focus should be on protecting critical infrastructure of Member States.
II) Global cyber security mock drills/exercises under the UN forum on the latest threats will help the developing countries to check their preparedness against latest threats and attacks.
III) Att present, capacity building measures are well developed by relevant global forums by organizing security mock drills, exercises, conferences, working groups, training/workshop programs involving many member states. The same methodology may be considered by OEWG to help the smaller and under developed countries.
IV) The OEWG may involve in partnerships with the national CERTs which focus on the capacity building and security awareness activities in their constituencies and can help in improving the capacity building of the member states.
V) The OEWG needs to play a major role in the capacity building of smaller and under developed countries under the UN framework. These countries lack infrastructure and technology to mitigate and counter ICT related threats. Developing an International Counter Task Force by involving experts from the member states may be useful. Such Task Force may be used to provide the technical assistance to smaller, under developed and developing states in times of attacks targeting their critical infrastructure. They may also provide support in guiding the smaller states with the necessary infrastructure to protect their assets against attacks.
VI) We understand that cross-regional initiatives and regional organizations in their own unique way have an important role to play in enhancing capacities of the Member States.
Mr. Chairperson,
It needs to be noted that a large number of developing and small Member States have no readily available vibrant and functioning private sector, academia and civil society at national level. At the same time, their capacity building programs have unique priorities and interests.OEWG need to incorporate these fine elements in its proposed capacity building programs and initiatives.
OEWG could consider preparing capacity building calendar that includes events like conferences, security drills/exercises, workshops and training programs with hands-on sessions to smaller and under developed countries.
Thank you Chair.
*****
Statement on ‘Confidence Building Measures’ cluster
Mr. Chair,
Confidence-building measures (CBMs) when integrated with capacity building and normative framework for responsible state behaviour in cyberspace play a crucial role in building trust, cooperation, transparency and confidence for Member States. CBMs are a concrete expression of international cooperation and developing such CBMs will be a long-term and progressive commitment requiring the sustained engagement of States.
2. Sharing of Points of Contact (PoCs), exchange of information, workshops, conferences, table-top exercise, authorizing procedures to bring in national agencies in addition to CERT/CSIRTs, exchange of professionals for training purposes, familiarizing each other on latest developments in the use of ICTs through bilateral, regional and multilateral platforms, exchange of views on various latest issues pertaining to ICTs need to be part of CBMs.
3. OEWG offers an opportunity for a neutral and objective discussion on global ICT security threats that demand new, innovative, inclusive and universal approaches. Identification and exchange of appropriate Points of Contact (PoCs) at the policy and technical levels can facilitate secure and direct communication between States to help prevent and address serious ICT incidents and de-escalate tensions in situations of crisis. Communication between PoCs can help reduce tensions and prevent misunderstandings and misperceptions that may stem from ICT incidents, including those affecting critical infrastructure and that have national, regional or global impact. They can also increase information sharing and enable States to more effectively manage and resolve ICT incidents.
4. In the processes of developing and implementing CBMs, the role of multi-stakeholders is vital. A close public-private partnership is a foundational need for inclusive and universal CBMs. OEWG can discuss setting up a practical mechanism that involves private sector, academia, civil society and the technical community. It can have resilient mechanisms for cooperation so that the stakeholders can contribute significantly to facilitating such consultations and engagement.
5. The Member States could greatly benefit from identification of activities that can be carried out through mutual cooperation, timely exchange of Information on threats targeting infrastructure located in the international counterpart constituency and holding periodical consultations on the latest threats observed to enhance the mutual trust of international partners. To continue strengthening cooperative measures relevant to national computer emergency response teams and other authorized bodies, States could encourage the sharing and dissemination of information and good practices on establishing and sustaining national CERTs/CSIRTs and on incident management through existing regional and global emergency response organizations and networks.
6. In order to build a common understanding under the framework of OEWG, a framework for exchange of national views and practices on ICT security incidents would greatly benefit Member States in building lasting CBMs. Timely exchange of threat information, ICT security advice, guidance, data-based studies and availability of the same, to an extent in the public domain would help in building trust and predictability, reducing the possibility of misinterpretation and escalation, and helping organizations and agencies make good risk management decisions.
7. OEWG needs to give priority to practical areas of cooperation in CBMs such as exercises, training of ICT professionals, exchange of professionals and latest ICT tools and other need-based confidence building measures. OEWG may form a consensus-based list of CBMs with practical areas of cooperation that Member States can explore and prepare national, regional and other multilateral organizations to explore the same for building a universal approach to CBMs.
Thank you.
****