Proposed activity XI (also referred to as CBM#3): Critical infrastructure protection
ASEAN Regional Forum
Measure
Protection of critical infrastructures and consultations mechanism
Background: This measure supports the priority area of “critical information infrastructure protection frameworks and mechanisms” by emphasizing cooperation and information sharing. Its purpose is to reduce the risk of conflict arising from ICT use by strengthening awareness and building capacity around critical infrastructure (CI) protection. By fostering voluntary cooperation through preventive and consultative frameworks, the measure aims to prevent misunderstandings that could escalate into political or military tensions. It is not designed to resolve ongoing conflicts but rather to mitigate risks before they emerge, offering a practical avenue for collaboration. In cases where conflict has already occurred, other tools may be more suitable.
Practice: The measure was introduced in 2018 through a concept paper by Singapore and the EU, which outlined two complementary dimensions: the “preventive side of the coin” and the “cooperative side of the coin.” On the preventive side, states are encouraged to take national steps such as defining baseline security requirements, establishing incident notification frameworks, and designating competent national authorities. For example, Singapore and the Netherlands shared their joint 2017 initiative to develop baseline IoT security standards, illustrating how such practices could inform regional discussions. The measure also links to activity I, as information exchanged under that framework can help shape national and regional CI protection efforts. In practice, some states have shared how they classify CI during annual meetings. Additionally, ASEAN’s 2019 regional framework for identifying and protecting CI - though not formally part of this CBM - can be seen as implicitly relevant, offering methodologies, best practices, and strategic recommendations. The concept paper also proposed regular working group meetings of CI operators from ARF states, but these have not yet materialized.
On the cooperative side, the co-sponsors proposed a consultation mechanism designed to defuse risks of misperception or escalation stemming from malicious ICT activity against CI. Under this mechanism, if one ARF member (the requesting party) experiences such an incident and suspects another ARF member (the requested party) may be involved, it can issue a notification via the PoCs established under activity X. This notification is intended to initiate dialogue without implying blame. The requested party is expected to acknowledge receipt promptly - ideally within 48 hours - and provide a timeline for response. The states may then pursue consultations through diplomatic channels, deciding by mutual agreement on the format, location, timing, and cost-sharing. Third-party mediation or observers may also be included. Consultations can be ended at any point by mutual consent, and unresolved cases may be escalated to the UN Security Council. To date, there is no record of it having been used.
Despite limited formal uptake, progress has been made through workshops: Singapore and the EU co-hosted a virtual event in 2021 on protecting ICT-enabled CI (due to the COVID-19 pandemic) and a follow-up workshop in 2024 on strengthening CI security and resilience. Both workshops were well attended and contributed to sustaining momentum around this measure. Thus, the measure is implemented, but not widely.
Key Implementation Activities and Resources
Participating states exchange experiences on critical infrastructure protection, including approaches to risk management, incident notification, and the identification of critical infrastructure sectors via workshops.