LawyersForPeace.Online

a curated map of the law of peace in the cyber & information sphere

User Tools

Site Tools


law:regional:sco_2009

This is an old revision of the document!


SCO Agreement on International Information Security (2009)

As of 30 September 2026.

Full title Agreement among the Governments of the Member States of the Shanghai Cooperation Organisation on Cooperation in the Field of Ensuring International Information Security
Type Treaty (intergovernmental agreement, regional)
Adopted by Governments of the member States of the Shanghai Cooperation Organisation (SCO)
Adopted Signed at Yekaterinburg on 16 June 2009
Legal status Binding on the Parties; enters into force 30 days after the depositary receives the fourth notification of completion of domestic procedures (Art. 12); of unlimited duration; open to accession; depositary: SCO Secretariat (Art. 11)
Official text Ministry of External Affairs of India – English text
Subject area Cybersecurity, cybercrime and critical infrastructure; Propaganda, disinformation and elections

Overview

The agreement was signed by the governments of the then six SCO member States (China, Kazakhstan, Kyrgyzstan, the Russian Federation, Tajikistan and Uzbekistan) at the SCO summit in Yekaterinburg. It establishes a framework for cooperation in “ensuring international information security”, identifies the main threats in this field and lists areas, principles and mechanisms of cooperation. The authentic languages are Russian and Chinese. Kazakhstan, for example, ratified the agreement by Law No. 286-IV of 1 June 2010. In a statement of 10 November 2020, the SCO Heads of State called for the comprehensive implementation of the agreement. The agreement is referred to in debates on differing conceptions of “information security” and “cybersecurity” and on the regulation of information content between States.

Provisions relevant to the cyber and information sphere

  • Art. 2 (main threats) – Lists six threats: (1) developing and using information weapons and preparing and conducting information war(fare); (2) information terrorism; (3) cybercrime; (4) use of a dominant position in the information space to the detriment of the interests and security of other States; (5) dissemination of information prejudicial to the socio-political and socio-economic systems and the spiritual, moral and cultural environment of other States; (6) threats to the secure and stable functioning of global and national information infrastructures. Annex 2 contains a “List of Basic Types, Sources, and Features of Threats in the Field of International Information Security”.
  • Art. 3 (areas of cooperation) – Includes coordination of joint measures, monitoring and response systems, development of international law, countering terrorist and criminal use of ICTs, Internet governance, protection of critical infrastructure, confidence-building measures and exchange of information and experience.
  • Art. 4 (principles) – Cooperation is to be conducted in accordance with, among others, the principles of peaceful settlement of disputes, non-use of force, non-interference in internal affairs and respect for human rights, and of non-interference in the information resources of the Parties.
  • Annex 1 (definitions) – “Information security” is defined as the state of protection of individuals, society and the State and their interests against threats and destructive and other negative impacts in the information space. “Information war” is defined as a confrontation between two or more States in the information space with the aim of damaging information systems, processes and resources and critically important structures, undermining political, economic and social systems, and psychologically manipulating the population to destabilise society and the State, and forcing a State to take decisions in the interests of the opposing party (summary of the English translation).

Application to cyber and information operations

Several SCO member States submitted a draft “International code of conduct for information security” to the UN General Assembly: China, the Russian Federation, Tajikistan and Uzbekistan by letter of 12 September 2011 (A/66/359), and China, Kazakhstan, Kyrgyzstan, the Russian Federation, Tajikistan and Uzbekistan a revised version by letter of 9 January 2015 (A/69/723). The draft code was not adopted by the General Assembly. According to the NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE), SCO member States regard information content as a potential security threat that should be regulated, whereas what the CCDCOE calls the “Western consensus” considers this level of content regulation a threat to fundamental human rights. The CCDCOE also notes that the 2015 revision of the code no longer contained the term “information weapons” and added language on human rights. At the United Nations the subject is dealt with under the General Assembly agenda item “Developments in the field of information and telecommunications in the context of international security” (see ict_norms).

Recent developments

  • 2020-11-10: Statement of the SCO Council of Heads of State on cooperation in the field of ensuring international information security (Moscow), calling for the comprehensive implementation of the 2009 agreement.

Sources

Change log

  • 2026-09-30: Entry created.
law/regional/sco_2009.1790789480.txt.gz · Last modified: by lfpo