recover from an attack without loss of data or permanent damage to a system. SIX ACTIONS TO INCREASE CYBER SECURITY 1. Establish a cyber security framework rather than one law in isolation Cyber security is made up of different, complementary initiatives and approaches. Laws are just one element. Other, non-legal mechanisms include minimum standards of security, investment in security research, and security audits of key industries and public bodies. Clear and consistent frameworks, strategies and policies – such as a National Cyber Security Strategy – can set out standards of security while at the same time ensuring that human rights are protected. 2. Prioritise protecting and defending individuals, devices, and networks as the core objective of any cyber security strategy / policy Good cyber security policies and practices put people and their rights at the centre and seek to strengthen and protect human rights as a core objective of the strategy. o Protecting Individuals: Cyber security frameworks must include data protection laws which safeguard against the exploitation of personal data collected by companies and public bodies. o Protecting Devices: Securing devices (such as routers, webcams and other household objects connected to the internet -- known as the “Internet of Things” (IoT)) should be a key cyber security objective. These devices are a risk to privacy because they generate, collect and transmit personal data that should be protected. If they are integrated into a network they are also a risk to security as they are often the weakest link in network security protection. o Protecting Networks: Good network security means reducing the attack surface and allowing only the right people through the right devices to access the right services on a network -- and then keeping everyone and everything else out. 3. Adopt and implement a comprehensive data protection law There must be legal obligations on companies and public bodies to protect personal data from: abuse, being excessively collected, poorly secured or at risk of being stolen. Myanmar currently lacks a data protection law.4 4. Identify and prioritise the security of the country’s critical infrastructure Critical infrastructure is largely defined as essential systems whose damage or loss would have a significant impact on the functioning of the State and the safety of the people. Each government must decide what it considers “critical”, but such designated infrastructure often includes energy (electricity, oil, gas), transport (air, rail, water, road), banking & financial market infrastructure, digital infrastructure, chemicals, food, health, water, and emergency services. 5. Establish incident response teams These teams of experts are the frontline when a security incident happens. They mostly deal with compromised devices or services that are enabling cyber attacks. Ideally, they should be independent of government departments. The most common is a Cyber Security Incident Response Team (CSIRT) which handles security incidents that involve ICT infrastructure. 5 Myanmar has the Myanmar Computer Emergency Response Team (mmCERT), a non-profit organization, for dealing with cyber security incidents.6 4 See MCRB’s companion Policy Brief on Privacy and Data Protection. FIRST, the global forum of incident response and security teams, conduct training workshops and have a lot of resources available on how to set up a CSIRT See https://www.first.org/ and slides on how to set up a CSIRT www.first.org/education/trainings 6 https://www.mmcert.org.mm/ 5 2

Select target paragraph3