3/4/22, 1:38 PM
Managing a digital revolution: cyber security capacity building in Myanmar - Routledge Companion to Global Cyber-Security Strategy
increasing number of cyber incidents targeting institutions and infrastructures that
are widely categorized as “critical” in other states, such as the central bank,
highlights the importance of improving on this issue.
Moving towards the regulatory regime, the state of Myanmar cyber security
legislation is also at an early stage, with large gaps and insufficient existing
frameworks. Some laws are in place that cover some aspects of cyber security,
notable examples being the Electronic Transactions Law (State Peace and
Development Council Law No 5/2004) covering some aspects of electronic data
and cybercrime. This law defines the distribution of information that causes harms
to minors (see, section 34(d)) via digital technology and networks as illegal, and it
also allows electronic evidence to be brought before the court. The
Telecommunications Law regulates access to and the use of telecommunication
services (Electronic Transactions Law, 2004). Legislation covering issues like
human rights, data protection, and child pornography is however not in place,
making the overall legislative framework highly insufficient for responding to
rapidly evolving digital threats. Beyond the actual legal framework, the
implementation of existing laws is also lacking, as there are limited resources,
competencies, and abilities to investigate and prosecute cybercrime both in the
police and the judiciary. Some initiatives have been taken, such as the Cybercrime
Division at the National Police Criminal Investigation Department, but also here,
the unit suffer from limited capacity. Very few cybercrime cases have been brought
to court. Prosecutors and judges need training on cybercrime and how to make
use of digital evidence.
One of the institutions that has been established is a national Computer
Emergency Response Team (CERT), with mmCERT (Myanmar Computer
Emergency Response Team) being established as early as 2004 by e-National
Task Force. The CERT’s mission is to do incident handling, public awareness in
security, to provide cyber security advice to Myanmar Internet users, and to
prevent cyberattacks. It is also nrmCERT’s responsibility to function as a
coordinator of incident responses with other teams, organizations, security
experts, and law enforcement agencies nationally and internationally. In 2010
CERT
d
th
ibilit
fM
’ Mi i t
https://ebrary.net/173520/political_science/managing_digital_revolution_cyber_security_capacity_building_myanmar#aftercont
fT
t
d
10/19