Cyber Confidence-Building Measures

CBM 4: Open, interoperable, secure, and reliable Internet

Organization for Security and Co-operation in Europe

OSCEPartially implemented2013

Measure

CBM 4 (2013): Participating States will voluntarily share information on measures that they have taken to ensure an open, interoperable, secure, and reliable Internet.

Background: This CBM invites OSCE participating states to voluntarily share information on national efforts to ensure an open, secure, interoperable, and reliable internet - an essential foundation for global connectivity, economic growth, and stability. While these terms are not always precisely defined, they generally refer to enabling users to access and exchange information freely, ensuring the internet functions as a neutral conduit for data, maintaining compatibility across systems, safeguarding data and infrastructure through strong security measures, and preserving functionality even amid disruptions. By exchanging such information states enhance transparency while strengthening collective cyber resilience and readiness.

Practice: Compared to other cyber CBMs, this measure is broadly formulated and best understood as both a commitment to the overarching objective and a framework for exchanging information and sharing best practices. A wide range of actions, which are regularly implemented by the participating states, can support this goal, including advocating for it in multilateral fora, integrating it into national cybersecurity strategies, enacting legal frameworks to protect digital rights, investing in secure infrastructure, or advancing efforts to counter cybercrime. In the OSCE’s e-learning course on CBMs, Canada - one of the adopters alongside Kazakhstan - showcased its Digital Charter and National Cyber Security Strategy as examples of transparent governance. Such measures illustrate the CBM’s purpose: to facilitate the exchange of lessons learned, policy updates, and relevant developments, rather than to prescribe explicit measurable activities. The IWG meetings provide a venue for such reporting.

This CBM is closely connected to CBM 2 and CBM 6, as the OSCE regularly organizes regional and subregional cybersecurity exercises under these frameworks to test national response capabilities, identify gaps, and foster continuous improvement. Given the wide disparities in cyber maturity among participating states, the measure provides important opportunities for CCB and peer learning. To advance implementation, Canada and Kazakhstan developed a non-paper outlining steps to strengthen cyber cooperation. In 2024, they also circulated a questionnaire to participating states to gather information on national efforts to promote an open, secure, interoperable, and reliable internet, with results expected to be shared in the IWG. While there are activities explicit implementation efforts remain limited, thus, the CBM is implemented, but not widely.

Key Implementation Activities and Resources

  • This CBM can be understood as a commitment to upholding this objective. It is implemented by sharing national policies, strategies, legal frameworks, and experiences related to maintaining an open, secure, interoperable, and reliable internet.