Mission News

STATEMENT : SECOND SUBSTANTIVE SESSION OF OEWG ON SECURITY OF AND IN THE USE OF INFORMATION AND COMMUNICATIONS TECHNOLOGIES 2021-2025, 29 MARCH 2022

30 March 2022 1 views

STATEMENT BY

MS. SHARIFFAH RASHIDAH BINTI SYED OTHMAN

DELEGATE

PERMANENT MISSION OF MALAYSIA

ON

“EXISITING AND POTENTIAL THREATS IN THE SPHERE OF INFORMATION

SECURITY, INTER ALIA, DATA SECURITY, AND POSSIBLE COOPERATIVE

MEASURES TO PREVENT AND COUNTER SUCH THREATS”

 

AT THE SECOND SUBSTANTIVE SESSION OF THE OPEN-ENDED WORKING

GROUP ON SECURITY OF AND IN THE USE OF INFORMATION AND

COMMUNICATIONS TECHNOLOGIES 2021-2025

 

NEW YORK, 29 MARCH 2022

 

Distinguished Chair, Delegates, Ladies and Gentlemen,

 

1.       I will start by expressing my delegation’s appreciation to you, Mr Chair, for your continued support in ensuring progress in the substantive work of the OEWG. Malaysia shares your assessment that this Open-Ended Working Group is a valuable Confidence Building Measure (CBM) and that this process has the potential to produce constructive outcomes. Malaysia is with you, Mr Chair, to protect and nurture this process, and will focus on the mandate of this Open-Ended Working Group.

 

2.       Malaysia shares your assessment and fully supports the need for us to move from broad to specific proposals. Under-Secretary-General and High Representative for Disarmament Affairs Izumi Nakamitsu, in her opening statement yesterday, stressed that it is now more important than ever for us to demonstrate the critical 2 importance of common norms, rules and principles, and why we must continue our efforts to ensure their effective implementation and further elaboration. In responding to your guiding questions regarding existing and potential threats, the elements of norms, confidence building measures, capacity building and international law are encapsulated together.

 

Mr Chair,

 

3.       With regard to your question on what preventive and response measures States can consider implementing in relation to the potential threats identified in the first substantive session, Malaysia will start by indicating that, although managing cybersecurity (or security of and in the use of ICTs) may appear difficult, there are already helpful established methodologies and approaches to cyber security - one of them is the ‘cybersecurity baseline’. Off-the-shelf systems and solutions that have the capability to connect to the Internet/network are vulnerable in their default state. Security baselining enables the hardening of these systems/platforms; it also enables secure enrolment of these devices to the network in a proper authentication.

 

4.       Secondly, we should embed cybersecurity requirements at the early stage of any system/solution development. Designing security is not an option but a critical requirement. The reality is that security technologies become difficult due to the lack of proper governance and strategy. Often, cyber incidents happen as a result of unresolved or ineffective security controls which need to be managed. To implement effective security controls in a cost-effective manner is always a challenge. However, if states clearly align their cybersecurity strategy and digital development strategy with a common goal to ensure resilience and reduce operational risks, this will justify the investments that need to be made by all stakeholders in the cyber environment. Aligning cybersecurity strategy and digital development strategy is in line with norm (a) recommended in the 2015 Report of the UN GGE.

 

5.       I now move to your second question, Mr Chair, on how states can enhance protection of critical infrastructure from existing and potential threats. Here, clear strategies/directives/capacity requirements, and to some extent specific legislation, need to be introduced or strengthened at the national level. Also, critical infrastructure owners should have proper control measures by:

I.       Periodically performing proper risk assessments, including identification of the dependency of critical infrastructure, especially in the growing field of hybrid infrastructure, to identify the right security controls.

II.      Having in place appropriate security controls, comprising both conventional cyber security protections and credential protections. Conventional cyber security protections are still relevant as cyber space inherits ‘legacy vulnerabilities’, but, as more and more organisations move to clouds, access credentials become soft targets for more complex attacks, including ransomware attacks. Thus, access controls need to be reconsidered and reinforced with least privilege and multi-factor authentication, among others. Enforcement of end-point protection is also crucial and needs to be pursued strategically.

III.     Strengthening their threat visibilities by having security monitoring mechanisms, including tools and the right number of people, as the capability of detection depends on the level of the threats’ visibilities.

IV.     Ensuring protection measures are in place to respond effectively. Effective response can only be performed with proper control measures in place, including Computer Security Incidents Response Teams (CSIRT). With any automated detection and use of preventive technology, human intelligence remains crucial, especially to detect targeted incidents, and this includes targets of critical infrastructure.

 V.     Ensuring that, should there be any cyber security incident, recovery measures for services/data/systems are in place. Coming back to the specific matter of ransomware, with the right control measures, any incident should be addressed by an appropriate recovery plan of services/data/system. An additional step can be taken by emphasising the need to refrain from paying the ransom, in order to prevent financing of organised crime and terrorist activities. Implementation of these measures is in line with norms 13 (f),(g), and (h) recommended in the 2015 Report of the UN GGE, which relate specifically to critical infrastructure, and to some extent norm 13 (i) regarding reasonable steps to ensure the integrity of the supply chain.

 

Mr Chair,

 

6.       For states to work together to share new information on existing and potential threats in real-time, Malaysia would like to reiterate points that we had highlighted in the first substantive meeting of this OEWG, as well as our national statement in the first session of the Ad Hoc Committee to elaborate a comprehensive international convention on countering the use of ICTs for criminal purposes. Malaysia indicated that cybercrime cases are becoming more complex. There are multiple criminal actors involved in malware distribution, remote command and control, as well as financial transactions. And crime scenes are spread across multiple end users’ devices, as well as third party application and cloud services. Responses require speed and cooperation from the various parties involved. Cyber criminals are using advanced tools, partnerships and collaborations that mimic those of large organisations.

 

7.       However, enforcement at various entities is not moving at the speed of growing threats. In this regard, more concerted, swift, and effective measures should be taken by hosting providers and enforcement entities, Internet Service Providers, and Domain Registrars in blocking and taking down malicious sites at the level of hosting providers, especially those that affect Critical Information Infrastructure, 5 such as phishing and banking trojans targeting multiple banks, utilities, and the health sector. Norm 13 (d) of the GGE 2015 addresses the need for more concerted, swift and effective efforts to prosecute terrorist and criminal use of ICTs, and to consider whether new measures need to be developed in this respect. For states to share new information on existing and potential threats in real-time, states need to have threat visibilities which can support the formulation of policies that focus on investment in capacity- and capability-building. Specific legislation, clear structures, and mechanisms on technical, enforcement, legal and diplomatic matters are essential. Leveling up and raising the bar in increasing national cyber security situational awareness ties in with the exercise of operationalising the voluntarily non-binding norms.

 

Mr Chair,

 

8.       You also asked how can states work together to share best practises about critical infrastructure protection. We have various existing platforms at the bilateral, regional and global levels. The COVID-19 pandemic has also changed the way states interact, both with other states and with different stakeholders. Allowing hybrid access at the bilateral, regional, and global levels has stretched the horizon of outreach. But to ensure effective cooperative measures, it is imperative that all the stakeholders understand, share, and aim to achieve the same cybersecurity baselines. Best practises in the protection of critical infrastructure should always be based on approaches that recognise not only that there are unique stakeholders for each critical infrastructure sector all along the supply chain, but also that there are common and cross-sectoral stakeholders. Hence, in in aiming for safe and secure critical infrastructure, cross-sectoral and sector-specific best practises should be recognised, addressed, and applied.

 

9.       Multi-level cybersecurity protection measures need to be rethought in the growing hybrid infrastructure context, and suitable areas identified for investment in terms of establishing necessary security controls. Having common cybersecurity baselines that are capable of being understood by all stakeholders is crucial, so 6 that we can achieve a more accurate assessment of cyber maturity levels in striving for an open, secure, stable, accessible, and peaceful ICT environment.

 

Thank you.

 

Share:
Link copied to clipboard
Back