INTERNATIONAL LEGAL BASIS FOR ENSURING INFORMATION SECURITY
Abstract
Abstract In this article, the author examines the issues of international legal framework for regulation in the field of information security. Currently, informatization not only contributes to the rapid progress of mankind, but also causes new threats to national, regional and global security, and accordingly, information security is one of the most important components of the general concept of security. According to the author, the main components of information security are the security of the information space, the security of the information infrastructure and ensuring such properties of information as availability, integrity and confidentiality.
Full text
Danish Scientific Journal No102, 2025 23 JURISPRUDENCE INTERNATIONAL LEGAL BASIS FOR ENSURING INFORMATION SECURITY Nugmanov N. DSc, Professor University of World Economy and Diplomacy 54, Mustakillik Ave., Tashkent, 100007, Uzbekistan https://doi.org/10.5281/zenodo.17740980 Abstract In this article, the author examines the issues of international legal framework for regulation in the field of information security. Currently, informatization not only contributes to the rapid progress of mankind, but also causes new threats to national, regional and global security, and accordingly, information security is one of the most important components of the general concept of security. According to the author, the main components of information security are the security of the information space, the security of the information infrastructure and ensuring such properties of information as availability, integrity and confidentiality. Keywords: international information security, international legal regulation of information security, international cooperation in the field of information security, security of the information space, security of the information infrastructure, information. The international legal framework for ensuring information security (IS) is a dynamically developing but still fragmented system of norms, principles and institutions. In today’s interconnected digital landscape, cybersecurity and data protection have become critical concerns for individuals, businesses, and governments worldwide. The rise of sophisticated cyber threats and increasing data privacy issues have led many countries to develop legal frameworks aimed at safeguarding data and securing cyberspace [1]. The modern development of the concept of information security is linked to the global information revolution, in the process of which the number of modern information and communication technologies (ICT) and the scale of dissemination of these technologies are constantly and dynamically growing. At the same time, it is very likely that the successful results of the global information revolution will be used for destructive purposes, for example, for the purpose of interference by one State in the internal affairs of another or for other purposes contrary to generally recognized principles of international law. That is, the issues of ensuring the information security of the state are the subject not only of cooperation between states, but also of rivalry in political, economic and other spheres. The formation of a completely new area of international counteraction to them, which concerns not only the interests of national security, but, also the global system of international security, determines the increasing role and importance of the problem of ensuring the information security [2]. Today, the problem of information security has moved from the field of technological categories to the field of social development management [3]. First and foremost, in the field of international legal regulation of international information security, it is necessary to consider such a fundamental document as the UN Charter. The principles of sovereign equality of states (Article 2(1)), non-use of force or threat of force (Article 2(4)), and non-interference in internal affairs (Article 2(7)) are cornerstones for application in cyberspace. Article 51 on the right to self-defense is also discussed in relation to large-scale cyber-attacks. The UN General Assembly has adopted a series of resolutions on achievements in the field of information and telecommunications in the context of international security: Since 1998 (first resolution A/RES/53/70), these annual resolutions have laid the foundation for discussions. They recognize that ICTs can pose threats to international peace and security and call on states to cooperate, develop norms of behavior and build trust. The UN General Assembly resolution of 23 December 1999, A/CE8/54/49, expresses concern that the spread and use of modern information technologies and means could potentially be used for purposes incompatible with the objectives of international stability and security. United Nations Groups of Governmental Experts (UNGEGEs): established by mandate of the UN General Assembly. Their reports (e.g., 2010, 2013, 2015, 2021) carry enormous weight. They have formulated key norms, rules and principles of responsible behavior by states in cyberspace, including issues such as: The application of international law (especially the UN Charter) in cyberspace; The sovereignty of states over their national ICT infrastructure; The obligation of states not to use ICT to violate international peace and security; The obligation of states to combat cybercrime and malicious activity from their territory; The importance of cooperation, trust and confidence-building measures (CBMs); The principle of humanitarian law (distinction, proportionality, precaution). The Open Working Group (UN OWG) established in 2020 emerged as a more inclusive alternative to the GPE. Its final report (2021) confirmed and developed many of the GPE's norms, emphasizing the applicability of international humanitarian law and human rights in cyberspace. The United Nations Convention against Transnational Organized Crime (Palermo Convention, 2000) also serves as a basis for cooperation in the fight against
24 Danish Scientific Journal No102, 2025 cybercrime, especially when it involves organized groups. In addition, the Organization for Economic Cooperation and Development, the International Organization for Standardization, and the International Telecommunication Union deal with issues of information security. At the regional level, within the framework of the Council of Europe, the source of international legal regulation of various aspects of international information security is the Convention on Cybercrime (Budapest Convention, 2001). This agreement is a key international legal instrument in the fight against cybercrime. It establishes standards for national legislation, investigation procedures and mechanisms for international cooperation (extradition, mutual legal assistance). It has an Additional Protocol on the criminalization of acts of a racist and xenophobic nature committed through computer systems (2003). Within the framework of the SCO, an Agreement on Cooperation in the Field of International Information Security was adopted (2009, entered into force in 2011). This agreement emphasizes the principles of sovereignty, non-interference, and combating the use of ICT for terrorist, extremist and criminal purposes. ASEAN, OAS. The African Union and other international organizations are also developing regional approaches and cooperation in the field of information security and the fight against cybercrime. At the national level, many states also have regulatory legal acts in place to ensure information security. What are the key issues and trends in the field of international legal regulation of international information security? Firstly, there is the problem of fragmentation, i.e. the lack of a single, comprehensive treaty. Existing norms are mainly based on ‘soft law’ (resolutions, reports of the GPE/OVRG) and regional instruments (the Budapest Convention). Secondly, there are disagreements between states, as there are currently different approaches to ensuring international information security. Some countries believe that cybersecurity is primarily about protecting systems and data and regulating issues related to cybercrime. Other countries believe that ensuring international information security is primarily about preventing interference in internal affairs (‘information weapons’, ‘color revolutions’). Thirdly, there is hyper-dynamic technological development, meaning that international law cannot keep pace with technology, especially in areas such as AI, quantum computing and the Internet of Things. Fourthly, there is the role of non-state actors, i.e. the difficulty of controlling at the state level the growing threat posed by the international activities of criminal groups and terrorists. It is clear that the international legal framework for information security is still being developed. It is based on the principles of the UN Charter, norms of responsible behavior by states (developed by the UN Working Group on Disarmament Matters and the UN Working Group on Disarmament Questions), regional treaties (especially the Budapest Convention) and confidence-building measures. However, key challenges – fragmentation, political disagreements between states on fundamental issues and the speed of technological change – are still hindering the creation of a unified, universal and effective system of international legal regulation of information security. Development is moving in the direction of strengthening cooperation, developing specific norms and trust, but the path to a comprehensive convention remains difficult. Undoubtedly, cyberterrorism poses a threat of attack on so-called critical information infrastructures that allow critically important objects (or processes) to function. These include national telecommunications systems, airfields, gas pipelines, etc. As a result of destructive impact on such infrastructures, the probability of a catastrophic situation caused by disruption of their information systems and fraught with enormous negative consequences on a national scale increases many times over [4]. The interconnectedness of digital infrastructure allows cyber threats to easily cross borders, causing widespread damage. A data breach in one country can impact international markets, highlighting the economic risks of weak cybersecurity [5]. Attacks on critical infrastructure, like energy grids and healthcare systems, pose national security risks [6]. As Cybersecurity Ventures reports, global spending on cybersecurity is expected to exceed $1.75 trillion from 2021 to 2025 [7]. It should be noted that the problem of ensuring information security is complex in nature and includes two main aspects. The first aspect concerns issues related to the content of information, namely the compliance of the information disseminated with certain standards, including generally accepted principles of international law. The second aspect concerns issues related to various means of information processing. These means include various technical means for collecting, accumulating, storing and transmitting information, including information and telecommunications networks and computers. It should be noted that issues related to ensuring the operation of information processing tools include not only technical aspects, since ensuring information security for various government organizations includes such properties of information related to its processing as integrity, confidentiality and accessibility, and this already requires appropriate legal regulation. The division of information security into the two aspects mentioned above reflects the need to reflect that they relate to two different spheres of public relations and are therefore regulated by different legal regimes. This understanding of the division of the concept of information security into two aspects contributes to the correct legal regulation of information security issues. It should be noted that interstate relations in the field of information exchange are subject to the norms and principles of international law, which regulate various aspects of the dissemination of information at the international level [8]. At the same time, it should be noted that informatization is not just a local sphere of public life; in essence,
Danish Scientific Journal No102, 2025 25 it covers all areas of society, and its consequences deeply affect the lives of individuals, society and the state, and this influence is becoming increasingly significant [9]. Informatization is defined as ‘a new stage in the development of productive forces, in which the exchange of information, its rapid processing and effective application are the determining conditions for the comprehensive development of society [10]. In today's world, one of the features of information technology is its accessibility regardless of a person's level of training. This means that informatization processes contribute to the productive management of a wide variety of social processes. However, informatization not only contributes to the rapid progress of humanity, but also poses new threats to national, regional and global security. Therefore, information security is one of the most important components of the general concept of security. We agree with the opinion of Western researchers that security in the traditional sense is a state in which the vital interests of individuals, society, the state and the international system are protected from any internal or external threat [11]. For example, experts in the field of international information security A. V. Biryukov and M. B. Alborova define IIS as a state of the global information space in which the possibility of violating the rights of the individual, society and the state in the information and cyber sphere is excluded, as well as the likelihood of destructive and illegal impact on elements of the national critical information structure[12]. According to T.A. Meshkovaya, information security is defined as ‘a state of society in which reliable and comprehensive protection of individuals, society and the state in the information space is ensured against the impact of special types of threats in the form of organized or spontaneously arising information and communication flows [13]. Information security is understood as the state of protection of individuals, society and the state from information that is harmful or illegal, from information that has a negative impact on human consciousness and hinders the sustainable development of individuals, society and the state. Information security is also a state of protection of the information infrastructure, including computers and information and telecommunications infrastructure, and the information contained therein, which ensures sustainable development [14]. According to A.A. Streltsov, information security is dualistic in nature, being both the result of activities to ensure it and the state of protection of individuals, society and the state in the information sphere. This gives rise to the need for activities to counter threats to the security of individuals, society and the state in the information sphere, carried out using the forces and resources allocated for this purpose [15]. Today, it is technically difficult to track conflicts arising in the information space. Therefore, it is necessary to review the rules of inter-state relations in this sphere. It should be borne in mind that most of the most important resources of state governance in the modern world are in the hands of giant private technology companies. This is a prerequisite for the fact that the use of information technology can cause enormous damage to public administration [16]. We agree with the opinion that information security is the protection of information and its supporting infrastructure from accidental or deliberate natural or artificial influences that could cause damage to the owners or users of the information. The possibility of practical application of information technology in its finished form without understanding the essence of the processes gives rise, among other things, to a conflict over the status of participants and the possibilities for establishing the order of IT processes in society [17]. E.Yu. Mitrokhina believes that “a deep and comprehensive analysis of information impact and information security in modern conditions is becoming a vital need for society, which requires the creation of mechanisms to control a number of factors: the creation of information weapons and the waging of information wars; the expansion of information flows, which carry with them the possibility of increasing the scale of negative impact on social systems at various levels; the emergence of real opportunities and methods for manipulating mass and individual consciousness” [18]. The fundamental legal principles on which the system of legal support for information security is based must be enshrined in a single international treaty, which, firstly, will be the final stage in achieving consensual approaches between major entities of international legal relations, and secondly, will contribute to uniformity in the procedures and mechanisms for ensuring international information security. In this regard, one cannot but agree with the following statement by A.K. Duben: "the fundamental principles in the field of ensuring international information security require enshrining at the global level, since the supranational level of legal support on a regional scale, which involves the participation of several (or several dozen) states, cannot fully satisfy the needs of the world community in solving the problems of international information security" [19]. According to foreign researchers, information security is the main point of confrontation between the internal and international interests of states. Military state power in the information sphere is directly related to the economic and social potential of ICT. At the same time, in the modern world, the use of information technology for military purposes is an important component of ensuring state security [20]. Furthermore, it should be noted that the development of a global and secure information society is a complex process demanding continuous monitoring, analysis, and active international multilateral cooperation. Therefore, in light of the regrettably negative trends in the international information environment, it's imperative to not only promote positive developments within the international legal framework concerning information security but also to further enhance practical, compromise-driven inter-state collaboration on various aspects of international information security [21]. We agree with the opinion that in the global information society, the task of finding the necessary modern universal and complexly organized legal mecha-
26 Danish Scientific Journal No102, 2025 nisms for building a system of legal support for information security, taking into account the peculiarities of the transformation of law, the need for closer development of legal, technical, moral and corporate norms, as well as extrapolation of the methods of technical and natural sciences used in the study of technical regulation of information security, into the legal sphere for building a universal concept of legal regulation of ensuring information security, is especially urgent [22]. Based on the above, it can be concluded that the main components of ensuring information security are, first, the security of the information space, which is necessary for the use of information for peaceful purposes; secondly, the security of the information infrastructure, which is necessary to prevent the negative impact of information on the system being used; and thirdly, ensuring such properties of information as accessibility, integrity and confidentiality. References: 1. Cybersecurity Rules Saw Big Changes in 2024: Here’s What to Know, World Economic Forum (Oct. 17, 2024), https://www.weforum.org/stories/2024/10/cybersecurity-regulation-changes-nis2eu-2024/ 2. Nugmanov N.A. Information Security Concept Major Aspects and Specifics // International Affairs: Politics, Economics, Law. Volume number 1-2 / 2024. - P. 118-136. 3. Nugmanov N.A. Information Security Concept Major Aspects and Specifics // International Affairs: Politics, Economics, Law. Volume number 1-2 / 2024. - P. 118-136. 4. Nugmanov N.A. Problems of Formation of International Standards for the Implementation of a Unified Approach to Ensuring Information Security // International Relations: Politics, Economics, Law. – T., 2016. – No. 2. – P. 65 5. Keman Huang, Stuart Madnick & Fang Zhang, Navigating Cybersecurity Risks in International Trade, HARV. BUS. REV. (Dec. 2, 2021), https://hbr.org/2021/12/navigating-cybersecurityrisks-in-international-trade. 6. Gregg Lindemulder & Matt Kosinski, What Is Cybersecurity?, IBM, https://www.ibm.com/topics/cybersecurity (Aug. 12, 2024). 7. David Braue, Global Cybersecurity Spending To Exceed $1.75 Trillion From 2021-2025, Cybersecurity Ventures (Sept. 10, 2021), https://cybersecurityventures.com/cybersecurity-spending-2021-2025/. 8. Нугманов Нугман Абдуллаевич. Международно-правовое регулирование сотрудничества в области международного обмена информацией // Вестник ПАГС. 2015. №2 (47). URL: https://cyberleninka.ru/article/n/mezhdunarodno-pravovoe-regulirovanie-sotrudnichestva-v-oblasti-mezhdunarodnogoobmena-informatsiey. (Nugmanov N.A. International Law Regulation of Cooperation in the Sphere of International Information Exchange // Bulletin of the Volga Region Institute of Administration. Science journal №2 (47), 2015. Saratov. – P.40). 9. Dobrenkov V.I. Problems of building a strategic community based on the provisions of the Okinawa Charter // Global informatization and security of Russia: Materials of the round table "Global informatization and social and humanitarian problems of man, culture, society (Moscow State University, October 2000) / Ed. by prof. V.I. Dobrenkov. - M.: Publishing house of Moscow University, 2021. - P. 23. 10. Belov V.G. Paradigm of the information society and the formation of information law // Law and informatization of society: Collection of scientific papers / Ed. Bachilo I.L. – M.: INION RAS, 2022. – P. 36. 11. Segbers K., Imbusch K. The Globalization of Eastern Europe. Teaching International Relations Without Borders. – Hamburg, 2020. – P. 333. 12. Biryukov A. V., Alborova M. B. Social and humanitarian risks of the information society and international information security // Moscow State Institute of International Relations (University) of the Russian Foreign Ministry, Center for International Information Security and Scientific and Technological Policy, 2021. 13. Meshkova T.A. Security in the context of global informatization: new challenges and new opportunities: Abstract of Cand. of Political Sciences dissertation. – Moscow: Lomonosov Moscow State University, 2019. – P. 4-5. 14. T.V. Zakupen. The concept and essence of information security, and its place in the system of ensuring national security, 2019. P. 34. 15. Organizational and legal support for information security. Ed. by T.A. Polyakova, A.A. Streltsov, M., 2016. P. 15 16. Segal, Adam. The Hacked World Order: How Nations Fight, Trade, Maneuver, and Manipulate in the Digital Age. New York: PublicAffairs, 2016. – 125 р. 17. Zharova A.K. Law and information conflicts in the information and telecommunications sphere. – M.: Janus K. 2016. – 435 p. 18. Mitrokhina E.Yu. Information security as a sociological problem // Information collection "Security". - M.: National and International Security Fund, 1997. - No. 7-9. - P. 30. 19. Gorbunov I.A. Information security: international legal aspects of its provision // International law. 2024. No. 1. P. 38. 20. Tikk-Ringas, Eneken, ed. Evolution of the Cyber Domain: The Implications for National and Global Security. London: Routledge, 2015. – 35 р. 21. Nugmanov N.A. Some issues of the regulation of international relations in the sphere of information security //Thematics Journal of Law. Vol-5-Issue-6June-2021. – p.37. 22. Polyakova T.A. Actual problems of development of the system of legal support of information security // Bulletin of the O.E. Kutafin University (MSAL), 2019, P. 43.