Cyber Confidence-Building Measures

CBM 9: ICT terminologies

Organization for Security and Co-operation in Europe

OSCEWidely implemented2013

Measure

CBM 9 (2013): In order to reduce the risk of misunderstandings in the absence of agreed terminology and to further a continuing dialogue, participating States will, as a first step, voluntarily provide a list of national terminology related to security of and in the use of ICTs accompanied by an explanation or definition of each term. Each participating State will voluntarily select those terms it deems most relevant for sharing. In the longer term, participating States will endeavour to produce a consensus glossary.

Background: This CBM seeks to reduce the risk of misunderstanding among participating states by fostering transparency around key cybersecurity-related terms. Since states often apply different definitions to relevant concepts, this measure encourages them to voluntarily share their national terminology and definitions. Doing so helps establish a clearer, common understanding - an especially critical asset during times of crisis. Over time, such exchanges are intended to contribute to the development of a shared, consensus-based glossary, thereby enabling more precise dialogue and more effective cooperation in the field of cybersecurity.

Practice: This CBM can be broken down into two phases: first, the creation of a shared glossary, and second, the agreement on common definitions. The first phase has been widely implemented under Serbia’s leadership as the adopter. In 2020, a dedicated website for the glossary was launched with the support of the Ministry of Interior of the Republic of Serbia and the University of Criminal Investigation and Police Studies. The glossary currently includes over 2000 terms and is supposed to be updated on a regular basis, at least once per year.

The starting point for this initiative was the OSCE’s POLIS platform, where in 2020 a team of university students reviewed all 225 available documents and identified more than 1,800 terms and definitions used by participating states, either in their national languages or in English. Implementation followed a structured process: defined terms were extracted from national legislation along with their original-language definitions. Where states had officially published legal acts in English, both the term and its definition were included; where no official translation existed, only the term was translated, while the definition remained in the original language. The compiled list was then made available on the POLIS platform, and participating states were invited to review, comment, and provide missing English translations of definitions. This process resulted in the development of a glossary containing all terms defined by participating states. The initiative built on earlier work funded by Switzerland, notably a 2014 research study by the New America Foundation supporting the implementation.

Regarding the second step, it has been decided that implementation is no longer a current objective. As the website notes: “[a]t this stage, we do not intend to undertake activities on producing a consensus glossary.” This position reflects broader international developments in cybersecurity, where it has become increasingly evident that agreeing on common definitions poses a major challenge given that divergent political and ideological perspectives are often embedded in the terminology itself.

Key Implementation Activities and Resources

  • Participating states contributed national cybersecurity terminology and definitions to create a shared glossary aimed at reducing misunderstandings and supporting common understanding.

  • Resources supporting implementation include the online glossary platform containing over 2,000 terms, contributions from national legislation.