4 4.5    support local industry associations or other initiatives to improve protection among local businesses. It should be possible to detect an attack quickly and respond to secure data and minimise damage. If companies do not do all they can to keep services available, maintain the integrity of their systems, and protect the confidentiality of user data they could suffer a loss of trust from users, impose costs and liabilities on users and potentially on themselves. Clearly communicate to customers or users what data is being collected and why: Field research findings demonstrate that few companies in Myanmar have privacy policies or communicate their policies to users (See Chapter 4.3 on Privacy). Conduct on-going vulnerability assessments and penetration tests: It is critical that businesses are aware of potential vulnerabilities in their internal systems. This involves ensuring that all “information assets” (servers, applications, databases, paper files) are protected from unauthorised access. Using licensed software means that companies will have access to the latest available version from the developer and fixes for security vulnerabilities through software updates. Particularly protect vulnerable users: Civil society groups are often the target of cyberattacks, either to disrupt the spread of information or gain confidential information, such as journalist sources, from email accounts and servers. (See Chapter 4.8 on Groups at Risk). Companies could open a channel of communication with Myanmar’s civil society groups so they can quickly be notified if such events occur. In the event of a data breach, companies should notify users if there has been a data breach or if they suspect a state-sponsored attack has taken place on their email accounts. 436 This enables users to take action to secure information or warn others. In 2013, a number of journalists covering issues in Myanmar received these warnings. 437 D. Relevant International Standards on Cyber Security Relevant International Standards:  Council of Europe, Convention on Cybercrime (Budapest Convention) Relevant Guidance:  Council on Cyber Security, “The Critical Security Controls for Effective Cyber Security Defense, version 5.1”  Australian Department of Defense, “Strategies to Mitigate Cyber Intrusion”  Council of Europe, “Global Alliance on Cyber Crime – GLACY” 436 Google Online Security Blog, “Security Warnings for Suspected State-Sponsored Attacks“ (5 June 2012). John Ribeiro, “Google Warns Reporters Covering Myanmar of ‘State-Sponsored’ Attacks on Gmail Accounts” (11 February 2013). 437 188 PAGE CHAPTER 4.5: CYBER-SECURITY

Select target paragraph3