Proposed activity X (also referred to as CBM#1): Points of Contact
ASEAN Regional Forum
Measure
Establishment of ARF Points of Contact (POC) Directory on Security of and in the Use of ICTs
Background: This measure seeks to strengthen real-time communication among ARF participating states to help prevent tensions and reduce the risk of conflict stemming from the misinterpretation of ICT security incidents. Its purpose is to establish clear coordination mechanisms within the ARF so that states know exactly whom to contact when concerns arise. To accommodate the diverse institutional frameworks of ARF members, the directory allows states to nominate a single coordination PoC or multiple PoCs across different levels - such as diplomatic (e.g., MFA), technical (e.g., CERT/CSIRT), law enforcement, or national security and policy coordination (e.g., ministries of interior or home affairs). This measure is considered fundamental, as it enables more effective communication and connectivity between technical and policy/diplomatic levels - something unprecedented in the ARF’s work on ICT security. It also serves as a cornerstone for the implementation of other CBMs.
Practice: The measure is co-sponsored by Malaysia and Australia, who first introduced the idea through a concept paper, building on the outcomes of their joint ARF Workshop on Cyber Confidence-Building Measures in 2014. That workshop, along with related exercises, including a tabletop simulation, demonstrated the practical utility of such a directory. The process of achieving consensus was neither quick nor simple, but once approved, it has been widely implemented and steadily advanced by the co-sponsors since 2018. By 2020, roughly half of ARF members had nominated PoCs; by 2024, that number had grown to 20 states. A standardized template guides nominations, requiring information such as the type of PoC (diplomatic, technical, etc.), seniority level (with senior officials to be contacted only in situations of regional security significance), institutional affiliation, as well as personal details such as name, title, contact information, spoken languages, and availability. Access to the Directory is restricted exclusively to ARF members. Over time, additional procedures were developed to facilitate use of the Directory.
Participation remains entirely voluntary: each state independently decides how to respond to incoming communications and what information to share. For example, states may choose to initiate consultations via diplomatic channels in response to an incident, mutually agreeing on the format, timing, location, and cost-sharing arrangements, and may even involve a third-party mediator if desired. States are encouraged to maintain records of all exchanges.
To ensure the Directory remains functional, its entries are validated, updated, and recirculated at every Study Group meeting, as it is not hosted on a live web platform but distributed as a digital list. Ping tests - carried out periodically by Malaysia and Australia - serve to verify communication channels at both strategic and working levels. In 2024, the first dedicated meeting of PoCs was convened, and it was also announced that future ping tests will be extended to senior-level officials.
Key Implementation Activities and Resources
ARF participating states have nominated national points of contact regularly update the information to facilitate communication.
Implementation is supported by a standardised nomination template, periodic ping tests, and regular validation of directory entries – maintained by Australia and Malaysia, the sponsoring states.