3/4/22, 1:38 PM
Managing a digital revolution: cyber security capacity building in Myanmar - Routledge Companion to Global Cyber-Security Strategy
ministries of agencies and taking in very little input from private companies or
critical infrastructure owners. As a consequence, questions can be raised
regarding the applicability' of the strategy when it comes into force. The noninclusion of the very companies that will be tasked with providing cyber security in
developing the strategy can be seen as troubling.
The lack of an overarching strategy in turn fragments the approach by various
ministries and agencies, as a cross-sectorial issue is met by isolated initiatives. As
ministries and agencies operate within their respective silos when it comes to
detecting and responding to various risks and threats. As Myanmar has rapidly
digitalized, the frequency of cyber incidents is growing rapidly and the fragmented
approach is hampering the ability to manage it sufficiently. This is further
complicated by the byzantine bureaucratic processes and structures that define
much of the governmental work. For the issue of cyber security providing
meaningful legislation and regulations is for instance dependent on the
cooperation between the Ministry of Transport and Communication and the
Ministry of Planning and Finance, a cooperation which so far has been limited and
strained. Providing a clear overarching direction for these various approaches and
conflicts of interests necessitates a cyber strategy tailored to the situation in
Myanmar, providing clear incentives, benchmarks, and divisions of responsibility.
The lack of top-down political leadership is further reflected in the absence of
awareness about critical infrastructures and their importance for modern societies.
The very concept of critical infrastructures is not widely established, and
subsequently neither is the cyber security of said infrastructures. The lacking
mapping, categorization, and understanding of different infrastructures and the
role they play in society limits the ability to secure them in a sufficient manner. As
there does not exist any legal definition of what a critical infrastructure is, the
framework for mapping and categorizing them is non-existent. As a first step
creating a legal framework for what is considered critical infrastructure, as well as
giving the responsibility of protecting said infrastructures to an institution, would be
a starting point to improve critical infrastructure protection in Myanmar. The
i
i
b
f
b
i
id
t t
ti
i
tit ti
di f
https://ebrary.net/173520/political_science/managing_digital_revolution_cyber_security_capacity_building_myanmar#aftercont
t
t
th t
9/19