4
4.5
support local industry associations or other initiatives to improve protection among
local businesses. It should be possible to detect an attack quickly and respond to
secure data and minimise damage. If companies do not do all they can to keep
services available, maintain the integrity of their systems, and protect the
confidentiality of user data they could suffer a loss of trust from users, impose costs
and liabilities on users and potentially on themselves.
Clearly communicate to customers or users what data is being collected and
why: Field research findings demonstrate that few companies in Myanmar have
privacy policies or communicate their policies to users (See Chapter 4.3 on Privacy).
Conduct on-going vulnerability assessments and penetration tests: It is critical
that businesses are aware of potential vulnerabilities in their internal systems. This
involves ensuring that all “information assets” (servers, applications, databases, paper
files) are protected from unauthorised access. Using licensed software means that
companies will have access to the latest available version from the developer and
fixes for security vulnerabilities through software updates.
Particularly protect vulnerable users: Civil society groups are often the target of
cyberattacks, either to disrupt the spread of information or gain confidential
information, such as journalist sources, from email accounts and servers. (See
Chapter 4.8 on Groups at Risk). Companies could open a channel of communication
with Myanmar’s civil society groups so they can quickly be notified if such events
occur. In the event of a data breach, companies should notify users if there has been
a data breach or if they suspect a state-sponsored attack has taken place on their
email accounts. 436 This enables users to take action to secure information or warn
others. In 2013, a number of journalists covering issues in Myanmar received these
warnings. 437
D. Relevant International Standards on Cyber Security
Relevant International Standards:
Council of Europe, Convention on Cybercrime (Budapest Convention)
Relevant Guidance:
Council on Cyber Security, “The Critical Security Controls for Effective Cyber
Security Defense, version 5.1”
Australian Department of Defense, “Strategies to Mitigate Cyber Intrusion”
Council of Europe, “Global Alliance on Cyber Crime – GLACY”
436
Google Online Security Blog, “Security Warnings for Suspected State-Sponsored Attacks“ (5 June 2012).
John Ribeiro, “Google Warns Reporters Covering Myanmar of ‘State-Sponsored’ Attacks on Gmail
Accounts” (11 February 2013).
437
188
PAGE
CHAPTER 4.5: CYBER-SECURITY