卡内基国际和平基金会-Cyberspace-and-Geopolitics-Assessing-Global-Cybersecurity-Norm-Processes-at-a-Crossroads_32页_463kb
报告摘要
Cyberspace and Geopolitics: Assessing Global Cybersecurity Norm Processes at a Crossroads
Core Content
This document analyzes the current state and future prospects of global cybersecurity norm processes, highlighting the growing complexity and fragmentation of efforts to establish shared expectations of behavior in cyberspace. It presents an overview of key cyber norm initiatives, their structures, histories, and effectiveness, and offers recommendations for improving their impact.
Main Cyber Threats and Norms
Cybersecurity has become a global challenge with significant economic, humanitarian, and national security implications. Examples include:
- Economic Impact: The 2017 WannaCry ransomware attack caused up to $4 billion in losses, while NotPetya was estimated to cause $10 billion in damages.
- Humanitarian Impact: In 2019, 5,183 data breaches affected 7.9 billion records.
- National Security Impact: High-profile incidents such as Stuxnet, Russian election interference, and attacks on Indian nuclear infrastructure demonstrate the critical importance of cybersecurity in state operations.
In response, stakeholders have developed various "cyber norm" processes to promote responsible behavior in cyberspace, including multilateral, private, industry, and multistakeholder approaches.
Key Cyber Norm Processes
1. The UN Group of Governmental Experts (GGE)
- Structure: A small, exclusive group of 25 state representatives, including all five permanent members of the UN Security Council.
- Mandate: Focuses on the applicability of international law, nonbinding norms of state behavior, and confidence-building measures.
- History: The GGE has had notable successes in 2013 and 2015, producing a list of 11 voluntary norms. However, the 2017 iteration failed to produce an outcome report due to lack of consensus, geopolitical tensions, and reduced commitment to international law.
- Strengths:
- Credibility from its UN affiliation.
- A proven track record of producing concrete outputs.
- Inclusion of major cyber powers.
- Weaknesses:
- Limited transparency and openness.
- Exclusionary nature, potentially alienating nonstate actors.
- Voluntary norms may not be widely internalized by states.
2. The UN Open-Ended Working Group (OEWG)
- Structure: An open forum for all UN member states, with a broader mandate than the GGE.
- Mandate: Includes developing norms, studying institutional dialogue, and promoting common understandings of cybersecurity threats and cooperative measures.
- History: Established in response to the GGE's 2017 failure, the OEWG began in June 2019 with over 100 states participating. It held its first formal meeting in September 2019 and planned further sessions in 2020.
- Strengths:
- More inclusive and transparent than the GGE.
- Encourages multistakeholder participation.
- Weaknesses:
- Risk of competition or conflict with the GGE.
- Potential for divergent interpretations of norms.
- Concerns over expanding mandates to include issues like fake news and propaganda, which may conflict with free speech commitments.
3. The Global Commission on the Stability of Cyberspace
- Structure: A nonstate-led initiative composed of 26 experts from diverse backgrounds, including government, industry, academia, and civil society.
- Mandate: Develop and promote new cyber norms, with a focus on the "public core" of the internet and responsible state behavior.
- History: Launched in 2017 by the Dutch foreign minister, it built on earlier GGE reports and proposed eight norms, including the protection of the public core. Its final report was released in November 2019, emphasizing the need for better implementation.
- Strengths:
- Broad interdisciplinary expertise.
- Credibility from prior work and endorsements.
- Weaknesses:
- Funding from Western governments may lead to perceptions of bias.
- No formal authority to enforce norms.
- Limited influence as the focus shifts to implementation rather than norm creation.
4. The Paris Call for Trust and Security in Cyberspace
- Structure: A multistakeholder initiative led by France and supported by Microsoft.
- Mandate: Promotes nine voluntary principles, including the protection of individuals, critical infrastructure, and electoral processes.
- History: Launched in 2018, it has over 1,000 signatories, though major powers like the U.S., China, and Russia have not signed. It aims to strengthen existing norm processes rather than replace them.
- Strengths:
- Broad support from a variety of stakeholders.
- Focus on norm diffusion and conformance.
- Weaknesses:
- Limited impact without major power endorsements.
- Potential for norm dilution or conflict with other processes.
- Concerns about the inclusivity of signatory status.
Process Competition, Collaboration, and the Benefits of a Fragmented Norm Ecosystem
The workshop highlighted that the fragmentation of cyber norm processes is not inherently negative. It allows for a broader base of engagement and deeper understanding of normative expectations. However, it also raises challenges:
- Fragmentation Issues: Overlapping mandates and competing norms may lead to confusion and inefficiency.
- Geopolitical Tensions: The GGE and OEWG may be in tension, with Russia and the U.S. having different visions for cyber norms.
- Transparency and Incentives: A lack of transparency and clear incentives for norm adoption hampers effectiveness.
Key Takeaways and Policy Options
The document concludes with four recommendations to improve the effectiveness of cyber norm processes:
- Conduct focused research on specific norms to assess their alignment with actual behavior and identify gaps.
- Create a shared global database of cyber norm processes to enhance transparency and understanding of their interactions.
- Identify and research incentives for norm adoption and the consequences of nonconformance.
- Increase multistakeholder engagement with great powers to promote responsible behavior and cooperation.
Conclusion
The global cybersecurity norm ecosystem is at a critical juncture, with multiple processes vying for influence and effectiveness. While the UN GGE and OEWG represent state-driven efforts, the Global Commission and the Paris Call reflect nonstate and multistakeholder approaches. The success of these processes depends on overcoming inherent challenges such as transparency, inclusivity, and political will. The workshop suggests that a fragmented but diverse ecosystem can be a strength if managed effectively through research, collaboration, and shared goals.
About the Authors
- Christian Ruhl, Duncan Hollis, Wyatt Hoffman, and Tim Maurer are affiliated with the Carnegie Endowment for International Peace and the University of Pennsylvania.
Notes
The document is based on a workshop held at the University of Pennsylvania's Perry World House in October 2019, bringing together key stakeholders in the cyber norm discourse. It provides a critical assessment of the current state of global cybersecurity norms and outlines a path forward.
试读结束,高清完整版pdf/doc/ppt,请点下载