LawyersForPeace.Online

a curated map of the law of peace in the cyber & information sphere

User Tools

Site Tools


glossary

This is an old revision of the document!


Glossary

As of 30 September 2026.

Short explanations of terms used on this site, in alphabetical order. Where a term has no agreed definition, or its meaning is disputed, this is indicated. Links lead to the entry in which the term is most relevant.

Act of aggression – Under Art. 8 bis(2) of the Rome Statute, the use of armed force by a State against the sovereignty, territorial integrity or political independence of another State, or in any other manner inconsistent with the UN Charter, with a list of acts drawn from General Assembly resolution 3314 (XXIX). Whether a cyber operation can be such a use of armed force is discussed. See Rome Statute: crime of aggression.

Armed attack – The trigger for the right of individual or collective self-defence under Art. 51 UN Charter. The ICJ distinguished armed attacks as the “most grave forms” of the use of force; many national positions assess cyber operations against this threshold by their “scale and effects”. See ICJ, Nicaragua v. United States (1986).

Attribution – Used in two senses: the legal attribution of conduct to a State under the rules of State responsibility, and the political or technical act of publicly identifying the author of a cyber operation. The standards of proof and the degree of State control required over non-State actors are discussed. See UN framework of responsible State behaviour in cyberspace.

Coercion – The element that, according to the ICJ in Nicaragua, makes interference in another State's internal or external affairs a prohibited intervention. States differ on whether coercion requires compelling a specific outcome or can include depriving a State of control over a choice, and on whether disinformation campaigns can be coercive. See ICJ, Nicaragua v. United States (1986).

Countermeasures – Otherwise unlawful acts that an injured State may take against a responsible State to induce it to comply with its international obligations, subject to conditions such as proportionality and respect for fundamental human rights. Whether States not directly injured may take “collective” countermeasures is contested; Estonia has expressed support, France has rejected them. See National positions on international law in cyberspace.

Critical infrastructure – Facilities and systems providing essential services to the public, such as energy, water, transport, health and communications. There is no universally agreed definition; UN norm 13(f) leaves it to States, and EU law uses its own sector lists. See EU NIS2 and CER Directives (2022).

Cyber operation – A general term for the use of computer capabilities to achieve effects in or through cyberspace, including access to, disruption of or manipulation of systems and data. It has no treaty definition; its legal characterisation depends on the effects and the applicable body of law. See Tallinn Manual 2.0 (2017).

Deep fake – Under Art. 3(60) of the EU AI Act, AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic. Art. 50(4) requires deployers to disclose such content. See EU Artificial Intelligence Act (2024).

Digital emblem – A proposed technical means of identifying, in digital form, the data and systems of medical services and humanitarian organisations protected under IHL. The ICRC is consulting States on it and a working group of the Internet Engineering Task Force is addressing technical standards. See Additional Protocol I to the Geneva Conventions (1977).

Disinformation / misinformation – There is no universally accepted definition. UN usage distinguishes disinformation, which is inaccurate and spread with intent to deceive and cause serious harm, from misinformation, the accidental spread of inaccurate information. See UN resolutions on countering disinformation.

Dual use – Describes goods, software and technologies that can be used for both civilian and military purposes, such as surveillance tools, encryption or AI models. The concept matters for export controls and for the scope of civilian AI instruments, which largely exclude military uses. See EU Artificial Intelligence Act (2024).

Due diligence – The expectation that a State does not knowingly allow its territory to be used for acts contrary to the rights of other States. Some States, such as Germany, regard it as a binding obligation in cyberspace; others treat it only as the voluntary norm 13© of the 2015 GGE report. See Germany: constitutional peace provisions and cyber position.

Effective control / overall control – Two tests for attributing the conduct of non-State groups to a State. The ICJ required “effective control” of the specific operations in Nicaragua (1986); the ICTY Appeals Chamber applied “overall control” in Tadić (1999) for classifying a conflict. Which test applies to cyber operations by proxies is discussed. See ICJ, Nicaragua v. United States (1986).

Entanglement – In nuclear policy literature, the interconnection of nuclear and non-nuclear command, control and communications systems, which may lead an operation against conventional capabilities to be perceived as an attack on nuclear forces. The term is associated with work by James M. Acton (Carnegie Endowment, 2018). See Gap: protection of nuclear command, control and communications.

Foreign information manipulation and interference (FIMI) – A term used by the European External Action Service for a largely non-illegal pattern of manipulative, intentional and coordinated behaviour by State or non-State actors that threatens or may negatively affect values, procedures and political processes. It is a policy concept, not a legal category. See EU Digital Services Act (2022).

Hack-and-leak – An operation in which information is obtained through unauthorised access to computer systems and then published, often selectively or altered, to influence public opinion, for example during elections. Legal assessment may involve sovereignty, non-intervention and criminal law. See National positions on international law in cyberspace.

ICTs – Information and communications technologies; the term used in UN documents instead of “cyber” or “cyberspace”. The Russian Federation and some other States refer to “international information security”, a concept which commentators describe as also covering information content. See UN framework of responsible State behaviour in cyberspace.

Incitement to genocide – “Direct and public incitement to commit genocide” is punishable under Art. III© of the Genocide Convention even if no genocide follows. International tribunals have applied it to radio and print media. See Genocide Convention (1948).

Information integrity – A term used in UN documents, including the Global Digital Compact and the UN Global Principles for Information Integrity launched by the Secretary-General on 24 June 2024, for an information ecosystem in which accurate and reliable information is accessible. It has no legal definition. See Global Digital Compact (2024).

Information operation – A general term for the coordinated use of information, including propaganda, disinformation and cyber means, to influence the perceptions and behaviour of a target audience. It has no agreed legal definition; its legal assessment depends on the rules engaged. See Friendly Relations Declaration (1970).

Lethal autonomous weapons systems (LAWS) – Weapons systems that, once activated, select and apply force to targets without further human intervention. There is no agreed definition; the 2026 rolling text of the CCW Group of Governmental Experts characterises them by their ability to identify, select and engage a target. See UN and CCW processes on autonomous weapons.

Legal review of new weapons – The obligation under Art. 36 of Additional Protocol I to determine whether a new weapon, means or method of warfare would be prohibited by international law. It is invoked in relation to cyber capabilities and autonomous weapons. See Additional Protocol I to the Geneva Conventions (1977).

Meaningful human control – A term used by civil society organisations since around 2013, and by some States, for the degree of human involvement required in the use of autonomous weapons. Its content is disputed, and some States have opposed it as a binding standard, preferring formulations such as “human judgement”. See Gap: treaty on autonomous weapons systems.

NC3 – Nuclear command, control and communications: the systems used to plan, warn of, authorise and execute the use of nuclear weapons. No international instrument specifically addresses cyber operations against them. See Gap: protection of nuclear command, control and communications.

Non-intervention – The customary rule prohibiting States from intervening, directly or indirectly, in matters that each State is entitled to decide freely, by coercive means. It is set out in the Friendly Relations Declaration and was confirmed by the ICJ. See Friendly Relations Declaration (1970).

Propaganda for war – Art. 20(1) ICCPR requires States to prohibit it by law; according to the Human Rights Committee it covers propaganda threatening or resulting in an act of aggression or breach of the peace contrary to the UN Charter. The Friendly Relations Declaration records a duty to refrain from propaganda for wars of aggression. See International Covenant on Civil and Political Rights (1966).

Scale and effects – A formula from the Nicaragua judgment (para. 195), used in many national positions to assess whether a cyber operation amounts to a use of force or an armed attack by comparison with kinetic operations. See ICJ, Nicaragua v. United States (1986).

Sovereignty (rule or principle) – Whether sovereignty is a primary rule that a cyber operation can violate in itself, or a principle from which other rules such as non-intervention derive, is contested. France (2019) and Germany (2021) treat it as a rule; the United Kingdom stated in 2018 that there is no such rule beyond the prohibition of intervention. See National positions on international law in cyberspace.

Systemic risk (DSA) – Under Art. 34 of the Digital Services Act, risks stemming from the design, functioning or use of very large online platforms and search engines, including actual or foreseeable negative effects on civic discourse, electoral processes and public security, which providers must assess and mitigate. See EU Digital Services Act (2022).

Use of force – Prohibited in international relations by Art. 2(4) UN Charter, subject to self-defence and Security Council authorisation. The ICJ stated in 1996 that the Charter rules apply regardless of the weapons employed; whether cyber operations without physical effects can amount to a use of force is not settled. See ICJ Advisory Opinion on Nuclear Weapons (1996).

Voluntary norms – The non-binding norms of responsible State behaviour in the use of ICTs, set out in para. 13 of the 2015 GGE report and endorsed by the General Assembly, which operate alongside binding international law. See UN framework of responsible State behaviour in cyberspace.

See also

glossary.1790789584.txt.gz · Last modified: by lfpo