卡内基国际和平基金会-The-New-Norms-Global-Cyber-Security-Agreements-Face-Challenges_2页_116kb
报告摘要
2016: The New Norms in Cyber-Security
Core Content
2016 is expected to be a pivotal year for international cyber-security norms, following a year of diplomatic progress in 2015. Despite the increasing frequency and severity of cyber-attacks, such as the major power outage in Ukraine and the OPM data breach, 2015 was viewed as a positive year for global cyber diplomacy. The key focus of these efforts was to define and agree on international norms governing cyber activity.
Main Points
- Diplomatic Challenges in 2016: The diplomatic efforts in 2016 will be tested by the actual implementation of agreements made in 2015. The success of these efforts will depend on whether they lead to tangible actions.
- China's Role: China signed significant agreements with the US and other countries in 2015 to limit offensive cyber activity, but implementation remains uncertain. There are concerns about the Chinese government's commitment to these terms.
- Other Nations Outside Norms: Key states with active cyber programs, such as Iran and North Korea, are not participating in the international diplomatic efforts, which may undermine the effectiveness of global norms.
- GGE Report: The United Nations Group of Governmental Experts (GGE) report from 2015 outlines norms for cyber activity, emphasizing the protection of critical infrastructure and the prevention of non-state actors from using state territory for cyber-attacks.
- Legal Framework: A group of 15 international lawyers is working on the application of existing international law to cyber incidents, focusing on those below the threshold of use of force.
Key Agreements and Meetings Since 2010
| Date | Agreement or Meeting |
|---|---|
| 30 July 2010 | 2010 United Nations GGE consensus report on cyber-security (10 member states) |
| 17 June 2013 | US-Russian heads of state-level meeting with agreement on co-operation on ICT security |
| 24 June 2013 | 2013 GGE consensus report on cyber-security (15 states) |
| 3 December 2013 | OSCE agreement on cyber-security confidence-building measures |
| 9 January 2015 | SCO draft International Code of Conduct for Information Security |
| 22 July 2015 | 2015 GGE consensus report on cyber-security (20 states) |
| 25 September 2015 | US-China presidential meeting – fact sheets include sections on cyber-security and cyber-enabled theft of intellectual property |
| 22 October 2015 | UK-China Joint Statement including section on cyber-enabled theft of intellectual property |
| 16 November 2015 | G20 Leaders’ Communiqué – Antalya Summit (paragraph 26) |
Implementation Challenges
- Chinese Compliance: There are doubts about China's willingness to fully implement its agreements with the US. Cyber activity has not decreased, raising concerns about the effectiveness of the commitments.
- Internal Control: China's cyber activities may be driven by various entities, including the PLA, which may not fully comply with new norms. Political will and internal control will be critical to success.
- Sanctions Risk: The US may attempt to impose sanctions in 2016 if there is no visible progress in reducing cyber-attacks. However, China is unlikely to risk this due to economic and political considerations.
- Divided GGE: The GGE remains divided between those advocating for state control of the internet and those supporting a multi-stakeholder model. New entrants may align with either side or form a third faction calling for a demilitarised internet.
Outlook
- 2016 UN GGE: A new GGE will convene in the second half of 2016, expanding its membership to 25 states. This will be an opportunity to assess the progress made in previous years.
- Global Cyber Environment: The deteriorating cyber-security environment has increased awareness among decision-makers, leading to a push for more concrete actions and norms.
- Political Will: The effectiveness of these agreements ultimately depends on political will. While the norms are voluntary, their implementation will be crucial to addressing global cyber threats.
Conclusion
The year 2016 will be a critical test for the international community in terms of implementing cyber-security norms. Despite diplomatic progress in 2015, the lack of visible action and the absence of key players like Iran and North Korea pose significant challenges. The success of these efforts will depend on the commitment of states to enforce the agreed norms and the political will to do so.
试读结束,高清完整版pdf/doc/ppt,请点下载