UN Group of Governmental Experts Norms of Responsible State Behaviour in Cyberspace

InternationalGeneral Cybersecurity2015
ByDecipherU Editorial

The UN GGE established 11 voluntary, non-binding cybersecurity norms for responsible state behavior in cyberspace. These norms address protection of critical infrastructure, incident response cooperation, and responsible vulnerability disclosure by states. While not legally binding, they represent international consensus on how nations should behave in cyberspace.

Quick Reference

Enacted2015 (consensus report); reaffirmed 2021
Enforcement BodyNon-binding norms; no enforcement body (voluntary compliance by states)
PenaltiesNo formal penalties; diplomatic consequences for violations
Applicable ToNation-states participating in UN processes

Key Requirements

Norm 13(g)

States should take reasonable steps to ensure the integrity of the supply chain for ICT products and prevent the insertion of harmful hidden functions

Norm 13(i)

States should encourage responsible reporting of ICT vulnerabilities and share associated information on available remedies

Norm 13(f)

States should not conduct or knowingly support activity that intentionally damages critical infrastructure or impairs use of critical infrastructure to provide services to the public

How Does UN GGE Cyber Norms Affect Cybersecurity Careers?

Cybersecurity policy professionals working in government or international organizations reference UN GGE norms when developing national cybersecurity strategies. Threat intelligence analysts tracking state-sponsored operations assess activities against these norms. GRC professionals at critical infrastructure entities benefit from understanding the international norms framework.

Cybersecurity Roles That Work With UN GGE Cyber Norms

Related Cybersecurity Certifications

Related Cybersecurity Laws

Read the full text of UN GGE Cyber Norms at the official source: https://www.un.org/disarmament/group-of-governmental-experts/

Frequently Asked Questions

The UN GGE established 11 voluntary, non-binding cybersecurity norms for responsible state behavior in cyberspace. These norms address protection of critical infrastructure, incident response cooperation, and responsible vulnerability disclosure by states. While not legally binding, they represent international consensus on how nations should behave in cyberspace.

Cybersecurity policy professionals working in government or international organizations reference UN GGE norms when developing national cybersecurity strategies. Threat intelligence analysts tracking state-sponsored operations assess activities against these norms. GRC professionals at critical infrastructure entities benefit from understanding the international norms framework.

No formal penalties; diplomatic consequences for violations

Last verified: April 2026?Report an inaccuracy

Explore Related Cybersecurity Resources

Was this page helpful?