CBM 3: National strategies, policies and programs
United Nations
Measure
Background: This CBM was first articulated in its current form in the second APR in 2023. Building on earlier reports, this CBM is designed to foster transparency and predictability among UN member states. It encourages states to openly share their strategic objectives, priorities, governance structures, and national cybersecurity policies - for example, through concept papers, national strategies, laws, and programs, as well as information on ICT institutions with relevance to international security. By doing so, states can anticipate each other’s actions and policies in the cyber domain, reducing the risk of misperceptions and helping organizations and agencies make effective risk management decisions.
Practice: This CBM is deliberately broad, allowing states to pursue multiple avenues for information-sharing. One channel is the submission of reports to the UN Secretary-General, which may include national assessments, lessons learned, good practices on CBMs, or broader developments in ICTs in the context of international security. Another option states may use is the UNIDIR Cyber Policy Portal (CPP), launched in 2019. The Portal maps the cyber policy landscape of all 193 UN member states, alongside major intergovernmental organizations and multistakeholder initiatives. By the end of 2023 the portal included more than 1,500 documents, either submitted directly by states or collected by UNIDIR from official public sources. Initially conceived as an information hub, the CPP has since evolved into a confidence-building tool, supporting implementation of this CBM by enabling transparency and comparability. The CPP also integrates data from the National Survey of Implementation of United Nations Recommendations on the Responsible Use of ICTs by States in the Context of International Security. This survey tracks state implementation of recommendations from the 2015 GGE report (and later OEWG/GGE outputs), while also identifying challenges and capacity gaps. Results feed into the CPP as a baseline assessment tool (also referenced in regional CBMs, such as OAS CBM 9). While states may choose to publicize their survey results, to date only two have done so (Czech Republic and Canada). It should be noted that the CPP predates this CBM’s formal adoption, but now serves as a central instrument for its implementation.
In addition, the OEWG has become a venue where states share their cybersecurity objectives, priorities, and governance structures. For example, Australia, as part of the “Confidence Builders” group, contributed a joint working paper showcasing national strategies, white papers, and progress reports as practical inputs to this CBM’s implementation. Such examples illustrate that, even without formalized requirements, the CBM is already being - implicitly - widely implemented.
Member states have also recognized that many states require capacity-building support to develop national policies, strategies, and laws that underpin a secure ICT environment. In response, initiatives such as UNIDIR’s annual Cyber Stability Conference, as well as workshops and training programs facilitated by the ITU and other organizations, have been highlighted as key enablers. These efforts reinforce the linkages between this CBM and CBM 5 and CBM 6.
Key Implementation Activities and Resources
States voluntarily share national cybersecurity strategies, policies, legislation, and implementation experiences through UN processes and related initiatives.
Resources which implicitly drive the implementation of this CBM forward include the UNIDIR Cyber Policy Portal, national implementation surveys, and capacity-building activities supporting the development of national cyber policies and frameworks.