Cyber Confidence-Building Measures

CBM 9: Promote norms implementation

Organization of American States

OASPartially implemented2022

Measure

CBM 9 (2022): Promote the implementation of the 11 voluntary, non-binding norms on responsible State behavior in cyberspace adopted by resolution 70/237 of the General Assembly of the United Nations and promote reporting on these efforts taking into account the national implementation survey.

Background: This CBM encourages member states to adopt and implement the 11 voluntary, non-binding UN norms of responsible state behavior in cyberspace, first developed by the GGE and further advanced through the OEWG. These norms guide states in promoting peace, security, and stability online, including commitments such as refraining from harming critical infrastructure, cooperating on the investigation of malicious cyber activity, and strengthening supply chain security. The CBM also calls on states to report national implementation efforts - using tools like the UNIDIR implementation survey - to enhance transparency, build trust, and identify regional capacity-building needs. In doing so, it aligns OAS efforts with global UN processes while translating them into concrete regional action.

Practice: Within the framework of the OAS CBMs, the cyber diplomacy training program - through its masterclasses and webinars - plays a key role in supporting implementation by helping to interpret and contextualize these global norms for regional actors, providing for limited implementation. Implicit implementation also occurs through participation of member states in the OEWG. For states with limited resources to engage directly in UN processes, the OAS Working Group provides a crucial platform to receive updates, coordinate positions, and prepare joint statements, thereby strengthening regional coherence and visibility in global cyber diplomacy.

The CBM also mandates the CICTE Secretariat to assist states in implementing the 11 voluntary norms endorsed by the UN GGE and OEWG. In practice, many OAS CCB activities contribute implicitly to this effort. More specifically, the PoC Directory (CBM 2 and CBM 3), for example, makes a particular contribution to the implementation of norm a (interstate cooperation on security), norm b (consider all relevant information), norm c (prevent misuse of ICTs in your territory), and norm h (respond to requests for assistance). Moreover, the CBM refers to the National Survey of Implementation of United Nations Recommendations on the Responsible Use of ICTs by States in the Context of International Security. This survey tracks national implementation, but it also asks to identify challenges to implementation and/or specific gaps in capacity limiting implementation. It thereby serves as a baseline assessment tool, allowing UN member states to conduct regular self-assessments of national implementation of the recommendations and to track their progress. The shared results of the survey flow into the national profiles on UNIDIR’s Cyber Policy Portal, thus fostering transparency.

Overall, the CBM is implemented, but not widely when it comes to explicit activities in this regard. However, this CBM is better understood as reflecting a broad commitment by member states to implement these norms. Even though the absence of a universally agreed definition of “implementation” yet leaves each state to interpret and apply the norms through diverse and often complex national processes. This lack of a common framework makes it especially challenging to assess the extent of implementation.

Key Implementation Activities and Resources

  • OAS member states promote awareness and implementation of the UN norms for responsible state behaviour through training activities, regional coordination, and participation in UN cyber diplomacy processes.

  • Resources supporting implementation implicitly via enhancing knowledge and awareness include the Cyber Diplomacy Training Program, the UNIDIR implementation survey is supposed to be used as a national implementation reporting mechanism.