Draft for Myanmar Digital Rights Forum January 2019 POLICY BRIEF CYBER SECURITY AND CYBER CRIME: ISSUES FOR MYANMAR This Policy Brief1 provides an overview of terminology, concepts and good and bad practices in addressing cyber security and cyber crime. These terms are widely used but often poorly understood. The Brief aims to contribute to a more informed discussion in Myanmar on these topics. Attacks on networks and devices within Myanmar appear to be on the rise, as they are globally. However, Myanmar does not currently have in place an overall cyber security framework, nor specific laws for cyber crime or data protection. The Policy Brief aims to support the Myanmar Government, the private sector and civil society to fill the gaps in Myanmar’s policy and legal framework and establish cyber security framework(s) and cyber crime law(s) that protect both security and human rights. This is necessary for the digital ecosystem in Myanmar to thrive. Filling these legal gaps needs to be done in a way which protects human rights since this builds trust for users. As a recent World Bank Cyber Toolkit notes, “it is well understood that “trust” in the use of the internet and ICTs will engender use, and that part of building this trust environment in cyberspace involves striking a balance between establishing the security of networks, devices and data, and ensuring that fundamental rights such as privacy (including data protection) and freedom of expression are observed.”2 CYBER SECURITY OR CYBER CRIME? Cyber security and cyber crime are not the same. They therefore should be dealt with separately, using targeted approaches for each area, rather than trying to deal with all issues in one law.  Cyber security refers to a technical approach to securing computer systems from attack and failure. Computer systems are complex and are likely to contain flaws that affect the security of those systems. Good cyber security recognises that computer systems contain vulnerabilities and prioritises identification and fixing vulnerabilities.3  Cyber crime refers to a criminal law approach to punish unauthorised access to computer systems, carried out with criminal intent to damage or alter the systems or the data on it, and to punish specified criminal acts carried out using computer systems. Criminal law is used both to punish and to deter. AR TDIRENCES BETWEEN CYBER SECURITY AND CYME Cyber security should be treated as a public good. The Government’s approach to cyber security can be compared to its approach to public health: it is a collective responsibility that is for the benefit of everyone. The core obligation is on the Government to establish an appropriate cyber security framework and ensure it is implemented. It is impossible to prevent all cyber attacks. Systems are inherently vulnerable and it is likely that systems will suffer some degree of attack at some point. Preventing attacks as much as possible is important. But good cyber security also requires resilience. Resilience means being able to effectively 1 With thanks to Privacy International. This Briefing Paper draws on information featured in Privacy International’s : After the Gold Rush: Developing Cyber Security Frameworks and Cyber Crime Legislation to Safeguard Privacy and Security (September 2018) 2 World Bank and United Nations (2017). Combatting Cybercrime: Tools and Capacity Building for Emerging Economies, Washington, DC., p. 18 3 More resources from Privacy International on cyber security: https://privacyinternational.org/topics/cyber-security 1

Select target paragraph3