Chapter 4.5 4 Cybersecurity 4.5 In this Section: A. Context • Cybersecurity • Cybersecurity in the Myanmar Context B. Field Assessment Findings C. Recommendations for ICT Companies D. Relevant International Standards for Cybersecurity A. Context Cybersecurity A safe and secure Internet is a global Internet governance priority. There are many threats that can undermine the security and stability of cyberspace, impacting governments, business, civil society groups and individual users. Cyber-attacks, or cybercrime, can come in many forms, resulting in loss of services or loss of control over services, stolen personal information (such as credit card details), fraud and identity theft and receiving a high volume of spam messages. A range of actors execute cyber-attacks, including: national governments, criminals, business, hacker groups or individual hackers 404 . Attacks can be carried out by spreading computer viruses, denial of service attacks (DDoS)405, phishing406, or hacking. Governments, business, civil society groups and individual users can all be victims of cyber-attacks, and there have been some high profile examples in recent years. Estonia suffered a three-week long cyber-attack in 2007 that disabled banks, companies, government ministries and newspapers. Experts from the North Atlantic Treaty Organisation (NATO) had to be called in to help the country defend and rebuild its cyber capabilities. 407 In 2014, Sony Pictures systems were hacked, reportedly by North Korea, resulting in a leak of employee details, employee emails and yet-to-be-released films. 408 Encryption 409 is the technique by which data (when in transit or when at rest on devices) is scrambled to make it unreadable without using specific passwords or keys. It is important to keep personal data safe from criminals and therefore extremely important for the 404 A hacker is someone who seeks and exploits weaknesses in a computer system or computer network. Sometimes this can be for malicious intent (known as ‘black hat’ hackers) or it can be dome for ethical reasons, such as helping make services more secure (known as ‘white hat’ hackers) 405 A Distributed Denial of Service (DDoS) attack is an attempt to make an online service unavailable by overwhelming it with traffic from multiple sources. 406 Phishing is the act of sending an email to a user falsely claiming to be an established legitimate enterprise in an attempt to scam the user into surrendering private information that will be used for identity theft. 407 Ian Traynor, “Russia accused of unleashing cyberwar to disable Estonia“ The Guardian (17 May 2007). 408 Vlad Savov, “Sony Pictures Hacked: The Full Story“ The Verge (8 December 2014). 409 A recent report by the UN Special Rapporteur on Freedom of Expression, David Kaye, defines encryption using the SANS Institute definition from the Sans Institute, “History of Encryption” (2001), a mathematical “process of converting messages, information, or data into a form unreadable by anyone except the intended recipient”. CHAPTER 4.5: CYBER-SECURITY 181

Select target paragraph3