6. Undertake a proper threat assessment and develop recovery plans
A threat assessment considers possible weaknesses, such as outdated infrastructure, that make the
country more vulnerable to attack. Once threats have been assessed, this helps allocate limited
resources to tackling the most acute threats. CSIRTs can help in making these assessments.
TWO ACTIONS TO AVOID THAT DECREASE CYBER SECURITY
Certain activities do not enhance cyber security, and may decrease it:
1. Do not spend time and resources on developing offensive powers
As more daily transactions shift to online – from mobile banking to e-commerce – threats from cyber
crime to the economy and national security will increase. Myanmar has limited resources and
expertise to address cyber security. The resources it has should be invested in defensive capabilities
to detect and manage threats in order to build trust in business and government services. Investing
limited resources in offensive powers such as monitoring and surveillance equipment, rather than
defensive capabilities, leaves the cyber security of individuals, devices and networks at risk.
2. Do not shroud cyber security in secrecy
A clear, accessible and comprehensive cyber security policy and law(s) should be established and
debated through public consultations. Developing Myanmar’s approach and its implementation in
secret leaves the public and businesses at a disadvantage as they are not aware of the real threats
and how they can protect themselves. Such an approach is the opposite of cyber security.
HOW SHOULD CYBER CRIME BE ADDRESSED?
While cyber security is concerned with technically securing systems, cyber crime is about deterring
and punishing crimes involving computers. As cyber crime knows no borders, cross border cooperation is often required to address the crimes. A list of precisely defined cyber crimes can help,
since cross-border cooperation may first require both the States to agree that the action is a crime.
There is no globally accepted definition of cyber crimes. They are generally considered to include two
groups of crimes that are different and therefore should be addressed separately in policy and law.
Cyber dependent crimes: These are criminal actions which can only be committed using a computer
or device. They are directed against the confidentiality, integrity and availability of computer systems
and networks and the data stored and processed on them. The core principle should be to punish
unauthorized access with criminal intent. Examples include:
breaking into the computer systems with the intention of harming or shutting it down
“phishing” (fake emails that try to gain access to peoples’ passwords and details)
spreading viruses and trojans
initiating a distributed denial of service (“DDOS”) attack which can disable websites
distributing malware which can, for example, record key strokes and steal passwords
Cyber enabled crimes: This includes a far broader list of established crimes where technology allows
them to be committed in a new way. Essentially these are crimes that could be committed online or
offline. Examples include:
fraud using emails
distribution of child abuse images
distributing intimate images without consent (known as “revenge porn”).
There are increasing concerns that some governments are seeking to identify behaviour as a ‘cyber
crime’ just because it is carried out over the internet, even though it is not and should not be
criminalized. This includes broadly worded, imprecise actions (“spreading information that offends
the nation”, “insulting family values,” “frequently sending a large number of emails”), with or without
additional requirements around criminal intent. These vaguely worded provisions can violate
international human rights law because they can be misused to criminalise political opponents and
3