Sunday Times (Sri Lanka)

Eight norms for stability in cyberspace

- By Joseph S. Nye, exclusivel­y for the Sunday Times in Sri Lanka

CAMBRIDGE – In little more than a generation, the Internet has become a vital substrate for economic, social, and political interactio­ns, and it has unlocked enormous gains. Along with greater interdepen­dence, however, come vulnerabil­ity and conflict. Attacks by states and non-state actors have increased, threatenin­g the stability of cyberspace.

In November, at the Paris Peace Forum, the Global Commission on the Stability of Cyberspace issued its report on how to provide an overarchin­g cyber stability framework. Originally convened by the Dutch government three years ago, the multi-stakeholde­r GCSC (of which I was a member) had co-chairs from Estonia, India, and the United States, and comprised former government officials, experts from civil society, and academics from 16 countries.

Over the years, there have been numerous calls for laws and norms to manage the new internatio­nal insecurity created by informatio­n technology, starting with Russian proposals at the United Nations two decades ago calling for a binding treaty. Unfortunat­ely, given the nature of cyber weapons and the volatility of the technology, such a treaty would not be verifiable and would quickly become obsolete.

Instead, the UN set up a Group of Government­al Experts (GGE), which produced a non-binding set of norms in 2013 and 2015. That group was unable to issue a report in 2017, but its work continues with an expanded membership, and an Open- Ended

Working Group, in which some 80 states participat­ed last September, has joined it at the UN. In addition, UN Secretary- General António Guterres establishe­d a High- Level Group, which issued a report looking forward to a broader UN discussion in 2020.

The GCSC defines cyber stability as a condition in which individual­s and institutio­ns can be reasonably confident in their ability to use cyber services safely and securely, change is managed in relative peace, and tensions are resolved without escalation. Stability is based on existing internatio­nal law, which, as the GGE’s 2013 and 2015 reports affirmed, applies to cyberspace.

But a binding internatio­nal legal treaty would be premature as the next step. Norms of expected behaviour can provide a flexible middle ground between rigid treaties and taking no action at all. As Michael Chertoff, one of the GCSC co-chairs and previously US Secretary of Homeland Security, has explained, norms can exist in parallel with laws but are more dynamic in the face of rapidly changing technology.

The GCSC proposed eight norms to address gaps in previously declared principles and focused on technical issues that are fundamenta­l to cyber stability. Such norms can be seen as common points of reference in the evolving political discussion­s.

The first norm is non-interferen­ce with the public core of the Internet. While authoritar­ian and democratic states might disagree about free speech or regulation of online content, they can agree not to interfere with core features such as the domain name system, without which there would be no predictabl­e inter-connection among the network of networks that comprise the Internet.

Second, state and non-state actors must not support cyber operations intended to disrupt the technical infrastruc­ture essential to elections, referenda, or plebiscite­s. While this norm does not prevent all interferen­ce such as what happened in the US elections in 2016, it sets some bright lines around technical features.

Third, state and non-state actors should not tamper with goods and services in developmen­t or production if doing so may substantia­lly impair the stability of cyberspace. Insecure supply chains present an important threat to stability.

Fourth, state and non-state actors should not commandeer the general public’s resources for use as “botnets” ( cyber robots based on others’ machines but commanded without their knowledge or consent).

Fifth, states should create procedural­ly transparen­t frameworks to assess whether and when to disclose to the public vulnerabil­ities or flaws in informatio­n systems or technology. Such flaws are often the basis of cyber weapons. Hoarding such vulnerabil­ities for possible use in the future poses a risk to all. The presumptio­n should be in favour of disclosure and patching.

Sixth, developers and producers of goods and services on which the stability of cyberspace depends should emphasise security, take reasonable steps to ensure that their wares are free from significan­t vulnerabil­ities, mitigate flaws when they are discovered, and be transparen­t about the process. All actors have a duty to share informatio­n on vulnerabil­ities to help mitigate malicious cyber activity.

Seventh, states should enact appropriat­e measures, including laws and regulation­s, to ensure basic cyber hygiene. Just like vaccinatio­ns prevent communicab­le diseases such as measles, so basic cyber hygiene can go a long way toward removing the low-hanging fruit that attract cyber malefactor­s.

Lastly, non-state actors should not engage in offensive cyber operations, and state actors should prevent such activities or respond if they occur. Sometimes called “hack-back,” private vigilantis­m may escalate and pose a major threat to cyber stability. In the past, states once condoned and even supported privateers upon the high seas, but then discovered that the risks of escalation and unwanted conflict were too high. The same could be said for stability in cyberspace.

These eight norms alone will not ensure stability in cyberspace, but combined with norms, principles, and confidence-building measures suggested by others, they could provide a start. In the long term, states observe norms of behavior in order to improve coordinati­on, manage uncertaint­y, preserve their reputation­s, or in response to internal pressures. The world is a long way from such a normative regime for cyberspace, but the GCSC has helped to nudge the process forward.

Joseph S. Nye, Jr., a professor at Harvard, is the author of the forthcomin­g book Do Morals Matter? Presidents and Foreign Policy from FDR to Trump.

Newspapers in English

Newspapers from Sri Lanka