Is cyberwar lawful?
Network World - The answer is probably not -- at least an unprovoked attack -- based on extensive new legal research appearing in an upcoming issue of the British journal INFO.
The research describes a 150-year-old series of Geneva Conventions relating to cyberwar. However, a precise answer to the question is impossible because no one has actually defined the term "cyberwar" and reaching broad agreement on a definition seems problematic at best.
Quiz: Separate cyber security fact from fiction
Both "cyber" and "war" have remained elusive abstractions over many years. In addition, once attacked, all nations typically assert a right to proportional responsive measures, and during war, all means of attack are usually employed.
The topic of cyberwar is much discussed worldwide. What is not well known, however, is that two key provisions were added in the 1990s to an international treaty signed and ratified by almost every country that constrain the conditions under which a nation could adversely affect the networks, services and equipment in another nation.
The provisions were added after major cyber security incidents and obligate every nation:
1) Not to cause "technical harm … to the operation of … telecommunication services of other … States."
2) "Recognize the necessity of taking practical measures to prevent … disrupting the operation of telecommunication installations within the jurisdiction of other Member States."
The term "telecommunication" here includes essentially every kind of service, signal or communicated intelligence via any medium. There is so little wiggle room here that a "defensive measures" clause may emerge the next time this treaty is reviewed.
From the first time the states agreed to interconnect their networks in 1850 or enable worldwide wireless in 1906, the potential for information and communication technology (ICT) cyber incidents and adverse actions during conflicts were on the table. Many decades of experience refined relevant treaty provisions -- which were further enhanced more than a decade ago following early Internet incidents.
In addition to obligations concerning other countries, all states recognize a broad "stoppage" right to cut off any communications within their jurisdiction that "may appear dangerous to the security of the State or contrary to its laws, to public order or to decency."
The next steps to pave the way for implementing these "ICT security" provisions now appear to be moving forward under a U.N. Experts Group agreement reached by 15 of the world’s major powers on July 15.
While no one may be able to define "cyberwar," it appears that nations want to avoid any approximation by cooperating to diminish threats, risks and vulnerabilities through a broad array of different forums and means.
So it appears that cyberspace is emulating the real world, and countries are finding common ground in taking steps to implement existing treaty provisions and avoiding the escalation of cyber conflict even if they cannot define cyberwar.
Rutkowski is a well-known expert in international telecommunication law. He currently serves as the international cybersecurity rapporteur in the Geneva-based ITU-T and is a senior fellow in the Georgia Tech's Sam Nunn School.
Read more about wide area network in Network World's Wide Area Network section.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make...
- CA Technology Brief: CA Point of View: Content Aware Identity & Access Management
- This paper explores the concept of content-aware IAM, describes the integrated architecture for this new approach, and highlights the benefits that this approach...
- Google: Security for Google Apps Messaging & Collaboration
- Content provided by Google
Find out about how Google creates a security-based platform for Google Apps, covering topics like information security, physical security, and... - An Interactive Guide: Bring Your Own Device
- BYOD presents significant security and management challenges to IT departments who want to take advantage of the trend, but still protect corporate assets....
- Fundamental Principles of Network Security
- This paper covers the fundamentals of secure networking systems, including firewalls, network topology and secure protocols. Best practices are also given that introduce... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts