Cyber Confidence-Building Measures

Proposed activity I (also referred to as CBM#2): National strategies, policies and programs

ASEAN Regional Forum

ARFStatus unspecified2018

Measure

Sharing of Information on Domestic Laws, National Policies, Best Practices and Strategies as well as Rules and Regulations

Background: This measure is designed to enhance transparency through information sharing - for example, by providing updates on national postures, systems, and policies - thereby supporting the overall objectives of the ARF Work Plan. It falls under the priority area of “awareness building and exchange of best practices.”

Practice: The measure was introduced in 2018 through a concept paper by co-facilitators Japan and the Philippines. Since then, it has been implemented regularly: at each Study Group and ISM meeting, ARF participants share information on domestic laws, policies, best practices, strategies, and regulations related to ICT security, along with the procedures governing their application. In addition, Japan and the Philippines host annual workshops dedicated to information exchange, featuring presentations and roundtable discussions. While not all states participate consistently, those that do generally provide updates, and the resulting workshop reports are circulated to all ARF members.

Information sharing also extends to the ARF Annual Security Outlook (ASO), published since 2000. The ASO offers an overview of the Asia-Pacific security environment, with each member state contributing its perspectives and reporting national initiatives. In recent years, many submissions have begun to include cybersecurity-related content, such as new legislation, strategies, or capacity-building programs. Although not originally tied to this activity, these contributions have nonetheless supported its implementation by fostering confidence, transparency, and mutual understanding.

In 2020, Malaysia and New Zealand proposed the development of an online resource - a dedicated repository for ARF documents, reports, draft proposals, and workshop presentations - to further strengthen transparency and information sharing. While the ARF already maintains a portal, the proposal suggested either expanding it or establishing a standalone platform. To date, however, no decision has been made in this regard.

Key Implementation Activities and Resources

  • ARF members agreed to share information on national cybersecurity laws, policies, strategies, and regulations through Study Group and Inter-Sessional Meetings.