🇨🇴⚖️ La Rama Judicial valida a Ariel en prueba de concepto de IA. Conoce los resultados aquí

OEA - CICTE - Resolución CICTE GT MFCC DOC 21

OEA - Organización de Estados Americanos

Icono de documento PDF

Descargar PDF

Disponible

Detalles

Título
OEA - CICTE - Resolución CICTE GT MFCC DOC 21
Autor
OEA - Organización de Estados Americanos
Categoría
Infralegal
Área del derecho
Internacional_Publico
Año

INTER-AMERICAN COMMITTEE AGAINST TERRORISM (CICTE)

SIXTH MEETING OF THE WORKING GROUP OAS/Ser.L/X.5

ON COOPERATION AND CONFIDENCE-BUILDING CICTE/GT/MFCC/doc.21/25

MEASURES IN CYBERSPACE 26 February 2026

November 17-18, 2025 Original: English Santo Domingo, Dominican Republic REPORT OF THE SIXTH MEETING OF THE WORKING GROUP ON COOPERATION AND

CONFIDENCE-BUILDING MEASURES IN CYBERSPACE

(Prepared by the CICTE Secretariat)REPORT OF THE SIXTH MEETING OF THE WORKING GROUP ON COOPERATION AND

CONFIDENCE-BUILDING MEASURES IN CYBERSPACE

(Prepared by the CICTE Secretariat) Introduction The Sixth Meeting of the Working Group on Cooperation and Confidence-Building Measures in Cyberspace (“Sixth CBMs WG Meeting”) was held in Santo Domingo, Dominican Republic on November 17-18, 2025. Member States participating in the meeting were as follows: Argentina, Barbados, Belize, Brazil, Canada, Chile, Colombia, Costa Rica, Dominica, Dominican Republic, Ecuador, El Salvador, Grenada, Guyana, Honduras, Jamaica, Mexico, Panama, Peru, Saint Lucia, Suriname, The Bahamas, Trinidad and Tobago, United States of America, Uruguay. The meeting documents are available at the following link: VI Working Group Meeting. The speeches delivered by delegations which were forwarded to the CICTE Secretariat were circulated as documents CICTE/INF. 6/25 Opening Session The meeting was opened by Anselmo Muñiz, Director of Strategic Studies and Analysis, Ministry of Foreign Affairs, Dominican Republic. Mr. Muñiz underscored the strategic importance of sustained regional cooperation in addressing an increasingly complex cyber threat landscape. He emphasized that

the inherently borderless nature of cyberspace requires coordinated action among States, highlighting cyber confidence-building measures as a critical instrument for fostering trust, enhancing transparency, and enabling timely communication and cooperation. He further noted that these measures not only strengthen regional stability and predictability and support effective incident prevention and response but also encourage the adoption of international standards and normative frameworks that underpin a secure and resilient cyberspace. Ms. Kelly Anderson, Director of International Cyber Policy at Global Affairs Canada, stressed that this Working Group is not only important—it is essential to Canada’s vision for shared security, prosperity, and trust in the digital domain. She emphasized that its value extends beyond technical measures, reflecting a deeper commitment to diplomacy, confidence-building, and shared responsibility. For Canada, the Working Group reflects three core priorities: first, fostering trust and transparency by sharing national policies, points of contact, and incident response capabilities; second, strengthening regional cooperation, recognizing that cybersecurity challenges cannot be addressed in isolation; and third, advancing norms that promote stability and responsible state behavior in cyberspace, as the Working Group complements global efforts and ensures that our region speaks with a unified voice on the importance of stability and security online. Guillermo Moncayo, Acting Executive Secretary of the Inter-American Committee against Terrorism (CICTE) of the Organization of American States, also delivered opening remarks. He underscored the central role of the Working Group as the hemispheric space for advancing cooperation and trust in the cyber domain, recalling that its mandate aligns to the outcomes of the United Nations Groups of2Governmental Experts (UN GGE) and the Open-ended Working Group on cybersecurity (OEWG). He noted that, while differing views remain on certain sensitive issues, the Working Group has effectively supported OAS Member States’ engagement in both UN processes through dialogue, capacitybuilding, and practical cooperation. Considering the decision to establish a United Nations Permanent

Mechanism on ICT security, Mr. Moncayo emphasized that the Working Group is uniquely positioned to serve as a bridge between global cyber governance and regional implementation, translating multilateral commitments into tangible national action across the Americas. The speeches of the opening ceremony were distributed to delegations as document CICTE/INF.6/25.

First plenary session: Consideration and approval of the draft Agenda and draft Schedule Ambassador Claudio Peguero, Advisor on Cyber-Matters of the Ministry of Foreign Affairs, Dominican Republic, chaired the Working Group meeting.

The first plenary session was held on November 17. During the session, delegations considered the following points:

1. Consideration and approval of the draft agenda for the Sixth Working Group Meeting The Working Group Chair presented the draft agenda to delegations for approval.

The agenda approved was distributed as document CICTE/GT/MFCC/doc.16/25 rev.3.

2. Consideration and approval of the draft schedule for the Sixth Working Group Meeting The Working Group BMs Chair presented the draft schedule to delegations for approval.

The schedule approved was distributed as document CICTE/GT/MFCC/doc.17/25 rev. 4.

Second plenary session: Introduction and Progress Report of the Working Group Carlos Leonardo, Executive Director of the National Cybersecurity Center of the Dominican Republic, delivered the progress report on behalf of the Chair, outlining the key advances made during the Dominican Republic’s chairmanship of the Working Group for the 2024–2025 period. Mr. Leonardo recalled that the mandate of the Working Group is grounded in advancing international stability in cyberspace, aligned with the UN framework on responsible State behavior in the use of ICTs.

Guided by this mandate, the 2024-2025 workplan was structured around three core pillars: the practical implementation of the eleven adopted confidence-building and cooperation measures in cybersecurity; the enhancement and interoperability of Points of Contact directories at both the regional and UN levels; and the promotion of active engagement by Member States in relevant multilateral cybersecurity processes.- 3In support of this latter objective, Mr. Leonardo highlighted the regional dialogues that took place in

the enhancement and interoperability of Points of Contact directories at both the regional and UN levels; and the promotion of active engagement by Member States in relevant multilateral cybersecurity processes.- 3In support of this latter objective, Mr. Leonardo highlighted the regional dialogues that took place in the margins of multilateral processes, more specifically, the two “Working Breakfast Discussion” informal meetings that were championed by the Chair in collaboration with the Secretariat within the margins of the UN OEWG. These informal sessions provided a valuable platform for exchanging views, sharing regional perspectives, and reinforcing the role of the Americas in shaping global cyber norms discussions. He concluded by emphasizing that the progress made under the Dominican Republic’s leadership was the result of close coordination between the Chair, the Vice-Chair, the CICTE Secretariat, and the collective commitment of OAS Member States. Mariana Jaramillo, Cybersecurity Section Officer of the CICTE Secretariat, presented the main outcomes of the 2024–2025 Work Plan, first introduced during the fifth meeting of the Working Group. She highlighted its strategic focus on translating the eleven adopted confidence-building measures into concrete action through capacity building, dialogue, and sustained information exchange. A key component of this effort has been the implementation of the “National Dialogue on the Application of International Law in Cyberspace” initiative, supporting CBM 8. Delivered in Brazil, Chile, and Mexico, these dialogues were tailored to national contexts and designed to strengthen their capabilities in international law and have the tools to enable to develop coherent and informed legal approaches, bridging the gap between legal frameworks and operational realities, from a multistakeholder approach. Complementing these efforts, Ms. Jaramillo underscored the expansion of the OAS Cyber Diplomacy Training Program, which grown to include specialized modules on international law in cyberspace,

critical infrastructure protection, and artificial intelligence, reflecting emerging priorities and Member State needs. Furthermore, the CICTE Secretariat facilitated two interregional dialogues between OAS and EU Member States, in partnership with the EU Institute for Security Studies (EUISS). These dialogues, held in February (in-person, on the margins of the 10th UN OEWG session) and June 2025 (virtual), brought together over 18 countries to exchange views for the future UN Permanent Mechanism on ICT security. These exchanges provided an opportunity for mutual understanding, and enhanced coordination, strengthening the region’s ability to contribute constructively to global negotiations. Pursuant to the agreed workplan, the Secretariat launched the “Cyber CBMs Webinar Series”, an informal space to share national practices and raise awareness on agreed CBMs. Two sessions were held, the first session focused on Points of Contact (CBMs 2 and 3), and the second session focused on capacity building (CBMs 4 and 5). To further support the effectiveness of the Points of Contact network, the Secretariat developed a Guide for Updating Points of Contact, outlining a clear, structured process for verifying contact information, designating new representatives, and preparing for upcoming “ping tests” to assess coordination capacity during cyber incidents. Currently, 29 OAS Member States have designated Points of Contact. The CICTE Secretariat’s presentation concluded with the intervention of Nelson Guanilo, Cybersecurity Section Officer, who presented an overview of the enhancements made to of the Working Group’s digital platform. He traced the portal’s development from a basic Excel-based list of Points of Contact in 2017 to the launch of a dedicated web portal in 2021. As part of the 2024–2025 Work Plan presented during the fifth meeting of the Working Group, the Secretariat proposed4enhancements to both the external and internal portals. Improvements to the external portal have already been implemented, and these were presented, streamlining access and usability for Member States. Meanwhile, the internal portal has undergone the integration of new features, most notably the “Cyber Threat Landscape” section, developed in coordination with the CSIRTAmericas Network. This

already been implemented, and these were presented, streamlining access and usability for Member States. Meanwhile, the internal portal has undergone the integration of new features, most notably the “Cyber Threat Landscape” section, developed in coordination with the CSIRTAmericas Network. This capability will provide real-time visibility into cyber incidents and threat trends across the region. Mr. Guanilo noted that the official launch of the upgraded internal portal is scheduled for the first quarter of 2026, at which point it will become fully available to the Points of Contact designated by OAS Member States. These enhancements were designed to enhance rapid coordination, information exchange, and trust among Member States in response to growing cyber challenges. Member States were then invited to take the floor, and seven delegations provided their perspectives on the work of the Technical Secretariat, offering comments and/or thanks to the Secretariat. Statements made during the second plenary meeting, which were forwarded to the CICTE Secretariat, are available in document CICTE/INF. 6/25.

Third Plenary Session: Presentation by Member States on CBMs Implementation Under Agenda Item three (3), Member States were invited to share national updates on cybersecurity policies, recent experiences, and lessons learned in cyber capacity building. Fifteen delegations— Argentina, The Bahamas, Brazil, Canada, Chile, Colombia, Ecuador, El Salvador, Grenada, Guyana, Jamaica, Mexico, Saint Lucia, Trinidad and Tobago, and the United States—took the floor to present substantive interventions.

Delegations provided concrete examples of national progress, including the development and revision of cybersecurity strategies, the strengthening of institutional frameworks, the protection of critical infrastructure, and the enhancement of incident response capabilities. Many highlighted the evolving threat landscape and emphasized the need for resilience, whole-of-government approaches, and deeper international collaboration. Several interventions underscored the role of capacity building in

advancing national efforts, with particular attention to emerging technologies such as artificial intelligence, gender-responsive approaches, and the value of regional exercises in strengthening preparedness. The interventions reflected the growing maturity of cybersecurity governance across the region and reaffirmed the importance of continued cooperation under the framework of the Working Group. Statements made during the third plenary meeting, which were forwarded to the CICTE Secretariat, are available in document CICTE/INF. 6/25.

Fourth plenary session: Panel Discussion - From Critical Infrastructure to Critical Functions: A Confidence-Building Approach5During the fourth plenary session, a panel titled “From Critical Infrastructure to Critical Functions: A Confidence-Building Approach” examined how States can enhance national and regional resilience by transitioning from a sector-based framework to one centered on the protection of critical functions. The discussion highlighted the role of Confidence-Building Measures, particularly those related to communication and information exchange, as essential tools for fostering trust and bridging the gap between technical and policy communities. These measures were recognized for their potential to enable coordinated responses to complex, cascading cyber incidents and to support proactive, preventive strategies to prevent disruptions and strengthen systemic resilience.

The panel was moderated by Ms. Pamela Polanco, Counselor at the Permanent Mission of the Dominican Republic to the OAS, and featured expert interventions from Mr. Benjamín Iturra, Incident Response Officer at Chile’s National Cybersecurity Agency; Ms. Fabiana Santellán, Information Security Management and Audit Manager at Uruguay’s Agency for Electronic Government and Information and Knowledge Society (AGESIC); and Mr. Harom Ramos, Chief Information Security Officer at EGE Haina, a Dominican power generation company. Panelists shared practical experiences on identifying and protecting critical functions, enhancing public-private collaboration and information exchange, and operationalizing CBMs as enablers of cooperation and trust-building.

The discussion emphasized the importance of developing a common language for critical infrastructure and critical functions protection, as a foundation for cross-border collaboration. It also underscored the need to integrate technical and diplomatic communities, particularly in the context of incident response, emerging technologies such as AI, and the establishment of minimum cybersecurity baselines. Following the panel, several delegations took the floor to reflect on the presentations, share national insights, and underscore the value of inclusive, cross-sector dialogue in addressing fast-evolving threats and advancing coordinated, strategic action across the region.

Fifth plenary session: Presentation on Non-Paper on Cyber Incident Severity Schema During this agenda item, Mr. Carlos Leonardo, Executive Director of the National Cybersecurity Center of the Dominican Republic, presented the “Non-paper on a Cyber Incident Severity Schema” “Practical Guide to Classifying Incidents and Severity Levels” submitted by the Government of the Dominican Republic distributed as document CICTE/GT/MFCC/doc.19/25. which was circulated on October 28, 2025, prior to the meeting. This non-paper was introduced to support the advancement of CBM 11, regarding developing national incident severity frameworks and sharing related information.

As part of its chairmanship of the Working Group, the Dominican Republic proposed this Practical Guide for Establishing a National Cyber Incident Severity Scheme as a non-binding reference tool to assist OAS Member States in developing their own classification systems. The presentation by Mr. Leonardo highlighted a proposed matrix to support the consistent evaluation of incident severity levels, a glossary of key terms, and an illustrative diagram outlining how the various components of the guide interrelate. Its purpose is to foster harmonization, strengthen communication between CSIRTs, and support a shared regional understanding of cyber incidents. The presentation emphasized the importance of having common terminology, severity categories, and incident definitions to enhance transparency, coordination, and response effectiveness—especially in6cross-border scenarios. The guide was presented as a flexible and adaptable tool, allowing States to tailor implementation to their national contexts and maturity levels. Following the presentation, five delegations—Brazil, Chile, Mexico, Saint Lucia, and Uruguay, Chile, and Saint Lucia—provided feedback. While recognizing the initiative’s value and its alignment with regional confidence-building efforts, several countries noted that their national internal technical reviews are ongoing. Some comments provided on the floor included the need for a clearer definition of what constitutes a cyber incident, questions on whether the matrix captures all relevant incident types and calls to ensure the severity schema guide can be realistically applied across States with varying levels of institutional maturity. Acknowledgment was also made of earlier contributions from Ecuador and the CSIRTAmericas Network, reinforcing the importance of continuing consultation to refine the proposal and ensure broad regional utility. Statements made during the fifth plenary session—both preceding and following the presentation of the non-paper on the Cyber Incident Severity Schema—and submitted to the CICTE Secretariat, are available in document CICTE/INF.6/25. Sixth plenary session - Presentation: OAS Cybersecurity Mandates and Confidence-Building Measures: Reporting and Implementation As part of the fifth plenary session under Agenda Item six (6), Ms. Stephanie Pasternak, representing the Department of Public Security of the OAS, delivered a presentation on the OAS Consolidated List of Confidenceand Security-Building Measures (CSBMs), adopted by the General Assembly. She outlined the evolution of this list, which has been updated on four occasions—twice by the Committee on Hemispheric Security (CSH) and twice through General Assembly resolutions—underscoring its role as a foundational instrument for enhancing transparency, cooperation, and trust across the Hemisphere. Additionally, Ms. Pasternak highlighted the structure of the CSBMs list, which is organized into

traditional and non-traditional measures, noting that cybersecurity-related CBMs fall within the nontraditional category, reflecting the growing recognition of cyber threats as integral to regional security. Her presentation encouraged Member States to make annual voluntary submissions on the measures they are implementing and emphasized the value of reporting as a means to strengthen mutual confidence, assess progress, and inform future collective action. The session reaffirmed the importance of aligning political commitments with operational practice and leveraging the CSBM framework to address evolving security challenges in the Americas, including those in cyberspace. Furthermore, the intervention underscored the need for a better understanding of the OAS institutional landscape to enhance coordination, avoid duplication, and make use of existing mandates and mechanisms. In doing so, Member States can more effectively leverage the CSBM framework to address evolving security challenges in the Americas, including those in cyberspace— while advancing collective resilience and strategic alignment across the region. In the continuation of the fifth plenary session, Ms. Kerry-Ann Barrett, Cybersecurity Section Chief at the OAS/CICTE Secretariat, presented the findings of a study titled “Cybersecurity Strategies,- 7Resolutions, and Initiatives within the Inter-American System.” The study was conducted to assess regional progress in the two decades since the adoption of the 2004 Comprehensive Inter-American Cybersecurity Strategy through OAS General Assembly resolution AG/RES. 2004 (XXXIV-O/04). That strategy called for a multidimensional and multidisciplinary approach to promoting a culture of cybersecurity in the Americas. The reference paper presented by Ms. Barrett highlighted that the study examined more than 100 instruments adopted between 1997 and 2025 by various OAS bodies, with the aim of mapping the institutional evolution of cybersecurity and identifying areas for strengthened coordination and future strategic alignment. The document provides Member States with a consolidated institutional lens through which to

understand how cybersecurity has increasingly intersected with broader hemispheric priorities, including digital rights, democratic governance, international law, supply chain security, and critical infrastructure protection. It underscores the value of aligning political mandates with operational efforts and fostering greater coherence across the Organization’s workstreams related to cyber and digital policy. Ms. Barrett highlighted three main findings drawn from this assessment paper: first, while the regional cyber ecosystem within the OAS has grown substantially, coordination across bodies remains a persistent challenge; second, although cybersecurity has emerged as a cross-cutting priority, progress has been uneven across thematic areas; and third, the region’s increasing ambition in this space requires forward-looking approaches that reflect the complexities of today’s geopolitical and technological landscape. The presentation of the study concluded with a set of forward-looking suggestions for the consideration of OAS Member States. These included the potential institutionalization of risk and vulnerability assessments, the consolidation of a strategic cyber agenda within the OAS, and the possible development of a future-oriented cybersecurity strategy—building on the accomplishments of the 2004 Comprehensive Inter-American Cybersecurity Strategy (AG/RES. 2004 (XXXIV-O/04)). The study reaffirms cybersecurity as a key pillar of hemispheric security, and the presentation invited Member States to consider coordinated, inclusive, and sustainable approaches to bolster regional resilience and align future efforts with emerging digital challenges. Statements made during the second plenary meeting, which were forwarded to the CICTE Secretariat, are available in document CICTE/INF. 6/25. Seventh plenary session - Panel Discussion: Regional Considerations on the United Nations Global Mechanism on developments in the field of ICTs in the context of international security and advancing responsible State behavior in the use of ICTs The second day of the Working Group meeting, held on the morning of November 18, 2025, opened with the panel discussion titled “Regional Considerations on the United Nations Global Mechanism on Developments in the Field of ICTs in the Context of International Security and the Promotion of Responsible State Behavior.” The session was moderated by Ms. Kelly Anderson, Director of International Cyber Policy at Global Affairs Canada, and featured government representatives from8with the panel discussion titled “Regional Considerations on the United Nations Global Mechanism on Developments in the Field of ICTs in the Context of International Security and the Promotion of Responsible State Behavior.” The session was moderated by Ms. Kelly Anderson, Director of International Cyber Policy at Global Affairs Canada, and featured government representatives from8countries that have been actively engaged in the UN Open-Ended Working Group (OEWG) process: Ms. Estefanía Porta, First Secretary at the Ministry of Foreign Affairs, International Trade and Worship of Argentina; Ms. Larissa Schneider Calza, Head of the Cyber Defense and Security Division at the Ministry of Foreign Affairs of Brazil; and Ms. Catalina Vera, Alternate Representative of Chile to the OAS, Ministry of Foreign Affairs of Chile. The discussion provided OAS Member States with an opportunity to reflect on lessons learned from the OEWG and to consider the region’s role in shaping the forthcoming United Nations Permanent Global Mechanism on ICT Security. Panelists emphasized that the new mechanism should build upon key elements that proved effective in the previous OEWG processes, inclusive formats for stakeholder engagement, and practical, action-oriented dialogue. The importance of ensuring the participation of small and developing states was noted, alongside the value of gender diversity—particularly in cyber diplomacy and capacity-building efforts. The discussion also addressed the emerging role of thematic working groups under the new mechanism, highlighting the opportunity to foster integrated approaches that bridge diplomatic, technical, and capacity-building efforts. The panel further explored how the OAS can serve as a strategic enabler in this new global framework by facilitating coordination among Member States, promoting shared regional perspectives, and offering platforms to showcase practical initiatives such as the Confidence-Building Measures Working Group. The contributions of the various OAS Member States , particularly its paper on capacity-building submitted ahead of the final OEWG session, were recognized as an important

foundation to guide future thematic discussions. The session concluded with the announcement by one Member State of its intention to chair one of the upcoming thematic groups under the Global Mechanism—demonstrating continued regional leadership and commitment to strengthening the international cyber stability agenda. Eight plenary session - Open Dialogue: Recommendations, Guidelines and Proposals The eighth plenary session featured an open dialogue offering OAS Member States a structured opportunity to share lessons learned and exchange perspectives on advancing the implementation of agreed Confidence-Building Measures in cyberspace. The discussion was guided by a series of questions circulated in advance by the Chair of the Working Group, developed by the Government of the Dominican Republic and shared as document CICTE/GT/MFCC/doc.20/25. The guiding questions were framed around topics included within the agenda of the Working Group meeting, the questions encouraged Member States to move beyond general reflections and instead offer concrete insights into national experiences, barriers, and needs. Several overarching themes emerged from the dialogue, including the need to address uneven CBM implementation across the region, the importance of fostering coordination between technical and diplomatic stakeholders, and the value of institutionalizing cooperation formats—such as thematic working groups, joint exercises, and targeted technical assistance. Delegations also discussed strategies for enhancing regional input into global cyber processes, such as the forthcoming UN Global Mechanism, and highlighted the potential of the OAS to serve as a platform for sharing good practices, aligning efforts, and building trust.- 9A summary of key points raised during the dialogue includes:  Some delegations emphasized the need to move from general incident reporting to structured critical infrastructure functions, with periodic reports, collaboration with portal administrators, and increased visibility of national cyber activity.  Several States pointed to limited personnel and insufficient training, as well as the need to strengthen cyber diplomacy skills, including international law, implementation of CBMs, and

technical capacities. Initiatives such as diplomatic academies and master classes were mentioned.  The implementation of some CBMs remains challenging due to operational dependencies, lack of real-time data, and the need to involve multiple agencies, internet providers, and regulators. Effective application requires clear legal frameworks, technical-strategic coordination, and shared responsibility.  Delegations highlighted the value of peer networks for day-to-day coordination, experiencesharing, and private sector engagement. Strengthening information-sharing platforms and multisectoral participation was deemed essential.  Building trust requires not only information-sharing but also conduct cyber incident exercises to test national and regional response mechanisms. States emphasized the need for clear and practical coordination frameworks. This was complemented by the suggestion that the OAS support the regular updating of Points of Contact assigned to the Working Group.  States stressed the need for more consistent and institutionalized communication mechanisms —such as regular consultations, updated contact lists, and shared email addresses—to address staff turnover and ensure continuous and reliable coordination. In relation to the non-paper on the Cyber Incident Severity Schema, Member States agreed to submit written comments to the CICTE Secretariat by January 30, 2026. The Secretariat will consolidate and circulate the feedback for continued consideration. Finally, the importance of regional dialogue was reaffirmed, with Member States emphasizing its value in fostering mutual understanding and identifying areas of convergence for future cooperation. Member States including Argentina, Canada

Consultar sobre este documento ...