STATEMENT BY MALAYSIA AT
THE SIXTH SUBSTANTIVE SESSION OF THE
OPEN-ENDED WORKING GROUP ON SECURITY OF AND IN THE USE OF INFORMATION AND COMMUNICATIONS TECHNOLOGIES 2021-2025
ON
FURTHER DEVELOPING THE RULES, NORMS AND PRINCIPLES OF RESPONSIBLE BEHAVIOUR OF STATES AND THE WAYS FOR THEIR IMPLEMENTATION AND, IF NECESSARY TO INTRODUCE CHANGES TO THEM OR ELOBORATE ADDITIONAL RULES OF BEHAVIOUR
[FROM PARA 1, GA RESOLUTION 75/240]
12 DECEMBER 2023
NEW YORK
Mr. Chair,
1. Malaysia shares your view that we need to intensify our efforts to implement the agreed norms of responsible State behaviour in cyberspace. The agreed norms are central to the cumulative and evolving framework and will continue to contribute to international peace and security. Full and effective implementation of these norms is therefore imperative.
2. As indicated in the 2nd APR, the norms reflect the expectations and standards of the international community regarding behaviour of States in the use of ICTs and enable the international community to assess the activities of States in cyberspace. The key words here are expectations and standards.
3. Many delegations have rightly underlined the importance of protection of Critical Infrastructure and Critical Information Infrastructure. Malaysia appreciates the comments made by the United States on the linkage between norms 13 (f), (g), and (h), and how these connect with and support other norms. We also support statements made by El Salvador, Costa Rica, South Africa, Argentina, and others in this regard. We further support South Africa’s proposal on information sharing and expertise exchange as “low-hanging fruit” to be pursued together with existing guidelines that have been adopted and implemented by others for protection of CI and CII.
4. Echoing Canada, the topic of protection of CI and CII is also close to ourheart. Malaysia is currently in the process of presenting our cyber security bill to Parliament, and this is scheduled to be considered in the first quarter of next year. Although we already have national directives and a strategy on cyber security, we currently do not have specific legislation which regulates cyber security and mandates the maintenance of cyber hygiene standards at the national level for CII. This has often resulted in a legal approach which views cyber-attacks only as cybercrime, without fully reflecting the potentially devastating impact of security threats to CII. The new legislation will be proactive, with mandatory legal norms for CII applicable to relevant organisations in Malaysia. We agree with the Netherlands on the need to not only consider the direct impact of cyber incidents on CII, but also the wider “cascading impact” of such incidents.
5. Malaysia thanks Costa Rica for sharing elements of their national cybersecurity strategy and how it links with the implementation of norms.
6. With regard to norm (i) on ensuring supply chain security, Malaysia welcomes the comments of Qatar and Czechia on measures for service providers and supply chain suppliers. Malaysia further concurs with the United Kingdom on the need for oversight vis-à-vis the development, facilitation, and usage of intrusive cyber capabilities.
7. Finally, Malaysia agrees with Singapore’s statement on the role of norms implementation checklists, which could assist Member States in identifying capacity-building needs for States so as to ensure the effective implementation of norms. In this connection, we will continue working closely with Singapore and other ASEAN colleagues on the development of a norms checklist, taking into account experience at the national and regional levels.
Thank you, Mr Chair.