LawyersForPeace.Online

a curated map of the law of peace in the cyber & information sphere

User Tools

Site Tools


law:un:ict_norms

This is an old revision of the document!


UN framework of responsible State behaviour in the use of ICTs

Draft – editorial review pending. As of 27 September 2026.

Type Consensus reports of UN Groups of Governmental Experts and Open-ended Working Groups, endorsed by UN General Assembly resolutions (soft law; voluntary, non-binding norms alongside applicable international law)
Adopted by UN Groups of Governmental Experts (GGE); Open-ended Working Groups (OEWG); UN General Assembly
Adopted Principal texts: GGE report A/70/174 (22 July 2015); OEWG report A/75/816 (March 2021); GGE report A/76/135 (14 July 2021); OEWG 2021–2025 final report (11 July 2025, A/80/257, Annex I), endorsed by GA resolution 80/16 (1 December 2025)
Legal status Norms are voluntary and non-binding; the reports state that existing international law, in particular the UN Charter, applies to the use of ICTs by States. Follow-up: permanent Global Mechanism on developments in the field of ICTs in the context of international security, operational since March 2026
Official text UN Doc. A/70/174 (GGE 2015) · UN Doc. A/80/257 (OEWG 2021–2025 final report)
Subject area UN processes and institutions; Cybersecurity, cybercrime and critical infrastructure

Overview

The “framework of responsible State behaviour in the use of ICTs” is the term used in UN documents for a set of consensus outcomes developed since 2010 in the UN First Committee track. It consists of four elements: the applicability of international law, voluntary non-binding norms of responsible State behaviour, confidence-building measures, and capacity-building. The eleven norms in paragraph 13 of the 2015 GGE report (A/70/174) are its core; the General Assembly called upon Member States to be guided by that report in resolution 70/237. The framework was reaffirmed and elaborated by the 2021 OEWG and GGE reports and by the final report of the OEWG 2021–2025. It is referred to in debates on the protection of critical infrastructure, attribution of cyber incidents and the limits of State cyber operations in peacetime.

Provisions relevant to the cyber and information sphere

  • A/70/174, para. 13(a)–(k) – Eleven voluntary norms, including: cooperation to increase stability and security (a); considering all relevant information in the event of ICT incidents (b); not knowingly allowing one's territory to be used for internationally wrongful acts using ICTs ©; respect for human rights, including the right to privacy (e); protection of critical infrastructure (g); responding to requests for assistance (h); supply-chain integrity and preventing the proliferation of malicious ICT tools (i); responsible reporting of vulnerabilities (j); not harming the information systems of authorised emergency response teams (k).
  • A/70/174, para. 13(f) – A State should not conduct or knowingly support ICT activity contrary to its obligations under international law that intentionally damages critical infrastructure or otherwise impairs the use and operation of critical infrastructure to provide services to the public.
  • A/70/174, para. 28 – Lists how international law applies, including State sovereignty, peaceful settlement of disputes, non-intervention, and the principles of humanity, necessity, proportionality and distinction.
  • A/76/135 (2021) – Adds an agreed understanding of each of the eleven norms and notes that international humanitarian law applies only in situations of armed conflict.
  • OEWG final report 2025 (A/80/257, Annex I) – Reaffirms the framework and sets out the elements of the permanent Global Mechanism; the Global Points of Contact Directory and related communication template are among the confidence-building measures referred to in the report.

Application to cyber and information operations

The norms are cited by States in public attributions of cyber operations, in particular norm 13(f) on critical infrastructure. States disagree on several points: some States, including the Russian Federation and others, have proposed a legally binding instrument on international information security; many other States hold that existing international law, complemented by voluntary norms, is sufficient. How international humanitarian law applies to ICT operations in armed conflict and how rules on State responsibility and attribution apply remain under discussion. National positions on international law are compiled in UN Doc. A/76/136. The Global Mechanism operates by consensus.

Recent developments

  • 2025-07-11: The OEWG 2021–2025 adopted its final report by consensus, including the establishment of a permanent Global Mechanism with annual substantive plenary sessions, two dedicated thematic groups (one on norms, threats and international law-related topics, one on capacity-building) and periodic review conferences (first review conference timing [to be verified]) (A/80/257, Annex I).
  • 2025-12-01: GA resolution 80/16 endorsed the final report, requested the Secretary-General to support the Global Mechanism commencing in 2026 and to support a Global ICT Security Cooperation and Capacity-Building Portal (A/RES/80/16).
  • 2026-03-30/31: Organizational session of the Global Mechanism in New York; Ambassador Egriselda López (El Salvador) elected Chair (Ministry of Foreign Affairs of Japan; UNODA).
  • 2026-07-20/24: First substantive plenary session of the Global Mechanism (UNODA).
  • 2026-12-07/11: Meetings of the dedicated thematic groups scheduled (hybrid format) (Letter from the Chair-designate, 19 March 2026).

Sources

Change log

  • 2026-09-27: Entry created (draft).
law/un/ict_norms.1790536039.txt.gz · Last modified: by lfpo