recover from an attack without loss of data or permanent damage to a system.
SIX ACTIONS TO INCREASE CYBER SECURITY
1. Establish a cyber security framework rather than one law in isolation
Cyber security is made up of different, complementary initiatives and approaches. Laws are just one
element. Other, non-legal mechanisms include minimum standards of security, investment in security
research, and security audits of key industries and public bodies. Clear and consistent frameworks,
strategies and policies – such as a National Cyber Security Strategy – can set out standards of security
while at the same time ensuring that human rights are protected.
2. Prioritise protecting and defending individuals, devices, and networks as the core objective
of any cyber security strategy / policy
Good cyber security policies and practices put people and their rights at the centre and seek to
strengthen and protect human rights as a core objective of the strategy.
o Protecting Individuals: Cyber security frameworks must include data protection laws
which safeguard against the exploitation of personal data collected by companies and
public bodies.
o Protecting Devices: Securing devices (such as routers, webcams and other household
objects connected to the internet -- known as the “Internet of Things” (IoT)) should be a
key cyber security objective. These devices are a risk to privacy because they generate,
collect and transmit personal data that should be protected. If they are integrated into a
network they are also a risk to security as they are often the weakest link in network
security protection.
o Protecting Networks: Good network security means reducing the attack surface and
allowing only the right people through the right devices to access the right services on a
network -- and then keeping everyone and everything else out.
3. Adopt and implement a comprehensive data protection law
There must be legal obligations on companies and public bodies to protect personal data from:
abuse, being excessively collected, poorly secured or at risk of being stolen. Myanmar currently lacks
a data protection law.4
4. Identify and prioritise the security of the country’s critical infrastructure
Critical infrastructure is largely defined as essential systems whose damage or loss would have a
significant impact on the functioning of the State and the safety of the people. Each government
must decide what it considers “critical”, but such designated infrastructure often includes energy
(electricity, oil, gas), transport (air, rail, water, road), banking & financial market infrastructure,
digital infrastructure, chemicals, food, health, water, and emergency services.
5. Establish incident response teams
These teams of experts are the frontline when a security incident happens. They mostly deal with
compromised devices or services that are enabling cyber attacks. Ideally, they should be
independent of government departments. The most common is a Cyber Security Incident Response
Team (CSIRT) which handles security incidents that involve ICT infrastructure. 5 Myanmar has the
Myanmar Computer Emergency Response Team (mmCERT), a non-profit organization, for dealing
with cyber security incidents.6
4
See MCRB’s companion Policy Brief on Privacy and Data Protection.
FIRST, the global forum of incident response and security teams, conduct training workshops and have a lot of resources
available on how to set up a CSIRT See https://www.first.org/ and slides on how to set up a CSIRT
www.first.org/education/trainings
6 https://www.mmcert.org.mm/
5
2