3/4/22, 1:38 PM Managing a digital revolution: cyber security capacity building in Myanmar - Routledge Companion to Global Cyber-Security Strategy increasing number of cyber incidents targeting institutions and infrastructures that are widely categorized as “critical” in other states, such as the central bank, highlights the importance of improving on this issue. Moving towards the regulatory regime, the state of Myanmar cyber security legislation is also at an early stage, with large gaps and insufficient existing frameworks. Some laws are in place that cover some aspects of cyber security, notable examples being the Electronic Transactions Law (State Peace and Development Council Law No 5/2004) covering some aspects of electronic data and cybercrime. This law defines the distribution of information that causes harms to minors (see, section 34(d)) via digital technology and networks as illegal, and it also allows electronic evidence to be brought before the court. The Telecommunications Law regulates access to and the use of telecommunication services (Electronic Transactions Law, 2004). Legislation covering issues like human rights, data protection, and child pornography is however not in place, making the overall legislative framework highly insufficient for responding to rapidly evolving digital threats. Beyond the actual legal framework, the implementation of existing laws is also lacking, as there are limited resources, competencies, and abilities to investigate and prosecute cybercrime both in the police and the judiciary. Some initiatives have been taken, such as the Cybercrime Division at the National Police Criminal Investigation Department, but also here, the unit suffer from limited capacity. Very few cybercrime cases have been brought to court. Prosecutors and judges need training on cybercrime and how to make use of digital evidence. One of the institutions that has been established is a national Computer Emergency Response Team (CERT), with mmCERT (Myanmar Computer Emergency Response Team) being established as early as 2004 by e-National Task Force. The CERT’s mission is to do incident handling, public awareness in security, to provide cyber security advice to Myanmar Internet users, and to prevent cyberattacks. It is also nrmCERT’s responsibility to function as a coordinator of incident responses with other teams, organizations, security experts, and law enforcement agencies nationally and internationally. In 2010 CERT d th ibilit fM ’ Mi i t https://ebrary.net/173520/political_science/managing_digital_revolution_cyber_security_capacity_building_myanmar#aftercont fT t d 10/19

Select target paragraph3