UN
United Nations
The United Nations (UN) plays a central role in shaping the global framework for responsible state behaviour in cyberspace. As the only universal international organisation, the UN provides a unique forum where states discuss cybersecurity, international security, and the management of cyber-related risks.
Over the past two decades, the UN has become the primary venue for developing a shared understanding of how states should behave in cyberspace. Through a series of dedicated processes, it has helped establish the foundations of today's international cyber diplomacy framework, including non-binding voluntary norms of responsible state behaviour, the applicability of international law, capacity-building initiatives, and cyber CBMs.
Timeline
GGE Reports lay out recommendations for cyber CBMs
States agreed on the Global PoC Directory (CBM 1) and layed the foundation for the continued UN cyber CBM process
CBM 2-4 adopted
Four additional UN cyber CBMs adopted
OEWG final report adopted and permanent global mechanism agreed which will further function as a forum of exchange and confidence-building
Permanent global mechanism continues work on international cyber stability and cyber CBMs focusing on implementation
UN Cyber CBMs
- 1CBM 1: Point of Contactsa) States agree to establish, building on work already done at the regional level, a global, inter-governmental, points of contact directory. At the fourth and…Widely implemented2022
- 2CBM 2: Hold consultationsa) States concluded that the dialogue within the Open-ended Working Group was in itself a CBM, as it stimulates an open and transparent exchange of views on per…Partially implemented2023
- 3CBM 3: National strategies, policies and programsa) States, on a voluntary basis, continue to inform the Secretary-General of their views and assessments and to include additional information on lessons learne…Widely implemented2023
- 4CBM 4: Strengthen (regional) CBM implementationa) States voluntarily identify and consider CBMs appropriate to their specific contexts, and cooperate with other States on their implementation. [2021 OEWG rep…Widely implemented2023
- 5CBM 5: Capacity building platformCapacity-building programmes are an important avenue of collaboration which could strengthen relationships as well as build trust and enhance confidence between…Widely implemented2024
- 6CBM 6: Best practice exchangeThe regular organization of seminars, workshops and training programmes on relevant issues related to ICT security with the inclusive representation of States c…Widely implemented2024
- 7CBM 7: Critical infrastructure protectionExchange of information and best practice on, inter alia, the protection of critical infrastructure (CI) and critical information infrastructure (CII), includin…Not implemented2023
- 8CBM 8: Public Private Partnerships (PPP’s)A range of technical capabilities and knowledge are required to detect, defend against and respond to and recover from ICT incidents. In this regard, public-pri…Partially implemented2024
Further Reading
Important Documents and Decisions
- ›UN Secretary-General (2013): Group of Governmental Experts on Developments in the Field of Information and Telecommunications in the Context of International Security (A/68/98).
- ›Group of Governmental Experts on Developments in the Field of Information and Telecommunications in the Context of International Security (A/70/174).
- ›UN General Assembly (2022): Developments in the field of information and telecommunications in the context of international security. (A/77/275).
- ›UN General Assembly (2023): Developments in the field of information and telecommunications in the context of international security. (A/78/265).
- ›UN General Assembly (2025): Draft Final Report (A/AC.292/2025/CRP.1).