Chapter 4.5
4
Cybersecurity
4.5
In this Section:
A. Context
• Cybersecurity
• Cybersecurity in the Myanmar Context
B. Field Assessment Findings
C. Recommendations for ICT Companies
D. Relevant International Standards for Cybersecurity
A. Context
Cybersecurity
A safe and secure Internet is a global Internet governance priority. There are many threats
that can undermine the security and stability of cyberspace, impacting governments,
business, civil society groups and individual users. Cyber-attacks, or cybercrime, can
come in many forms, resulting in loss of services or loss of control over services, stolen
personal information (such as credit card details), fraud and identity theft and receiving a
high volume of spam messages. A range of actors execute cyber-attacks, including:
national governments, criminals, business, hacker groups or individual hackers 404 .
Attacks can be carried out by spreading computer viruses, denial of service attacks
(DDoS)405, phishing406, or hacking.
Governments, business, civil society groups and individual users can all be victims of
cyber-attacks, and there have been some high profile examples in recent years. Estonia
suffered a three-week long cyber-attack in 2007 that disabled banks, companies,
government ministries and newspapers. Experts from the North Atlantic Treaty
Organisation (NATO) had to be called in to help the country defend and rebuild its cyber
capabilities. 407 In 2014, Sony Pictures systems were hacked, reportedly by North Korea,
resulting in a leak of employee details, employee emails and yet-to-be-released films. 408
Encryption 409 is the technique by which data (when in transit or when at rest on devices) is
scrambled to make it unreadable without using specific passwords or keys. It is important
to keep personal data safe from criminals and therefore extremely important for the
404
A hacker is someone who seeks and exploits weaknesses in a computer system or computer network.
Sometimes this can be for malicious intent (known as ‘black hat’ hackers) or it can be dome for ethical
reasons, such as helping make services more secure (known as ‘white hat’ hackers)
405 A Distributed Denial of Service (DDoS) attack is an attempt to make an online service unavailable by
overwhelming it with traffic from multiple sources.
406 Phishing is the act of sending an email to a user falsely claiming to be an established legitimate enterprise
in an attempt to scam the user into surrendering private information that will be used for identity theft.
407 Ian Traynor, “Russia accused of unleashing cyberwar to disable Estonia“ The Guardian (17 May 2007).
408 Vlad Savov, “Sony Pictures Hacked: The Full Story“ The Verge (8 December 2014).
409 A recent report by the UN Special Rapporteur on Freedom of Expression, David Kaye, defines encryption
using the SANS Institute definition from the Sans Institute, “History of Encryption” (2001), a mathematical
“process of converting messages, information, or data into a form unreadable by anyone except the intended
recipient”.
CHAPTER 4.5: CYBER-SECURITY
181