6. Undertake a proper threat assessment and develop recovery plans A threat assessment considers possible weaknesses, such as outdated infrastructure, that make the country more vulnerable to attack. Once threats have been assessed, this helps allocate limited resources to tackling the most acute threats. CSIRTs can help in making these assessments. TWO ACTIONS TO AVOID THAT DECREASE CYBER SECURITY Certain activities do not enhance cyber security, and may decrease it: 1. Do not spend time and resources on developing offensive powers As more daily transactions shift to online – from mobile banking to e-commerce – threats from cyber crime to the economy and national security will increase. Myanmar has limited resources and expertise to address cyber security. The resources it has should be invested in defensive capabilities to detect and manage threats in order to build trust in business and government services. Investing limited resources in offensive powers such as monitoring and surveillance equipment, rather than defensive capabilities, leaves the cyber security of individuals, devices and networks at risk. 2. Do not shroud cyber security in secrecy A clear, accessible and comprehensive cyber security policy and law(s) should be established and debated through public consultations. Developing Myanmar’s approach and its implementation in secret leaves the public and businesses at a disadvantage as they are not aware of the real threats and how they can protect themselves. Such an approach is the opposite of cyber security. HOW SHOULD CYBER CRIME BE ADDRESSED? While cyber security is concerned with technically securing systems, cyber crime is about deterring and punishing crimes involving computers. As cyber crime knows no borders, cross border cooperation is often required to address the crimes. A list of precisely defined cyber crimes can help, since cross-border cooperation may first require both the States to agree that the action is a crime. There is no globally accepted definition of cyber crimes. They are generally considered to include two groups of crimes that are different and therefore should be addressed separately in policy and law. Cyber dependent crimes: These are criminal actions which can only be committed using a computer or device. They are directed against the confidentiality, integrity and availability of computer systems and networks and the data stored and processed on them. The core principle should be to punish unauthorized access with criminal intent. Examples include:  breaking into the computer systems with the intention of harming or shutting it down  “phishing” (fake emails that try to gain access to peoples’ passwords and details)  spreading viruses and trojans  initiating a distributed denial of service (“DDOS”) attack which can disable websites  distributing malware which can, for example, record key strokes and steal passwords Cyber enabled crimes: This includes a far broader list of established crimes where technology allows them to be committed in a new way. Essentially these are crimes that could be committed online or offline. Examples include:  fraud using emails  distribution of child abuse images  distributing intimate images without consent (known as “revenge porn”). There are increasing concerns that some governments are seeking to identify behaviour as a ‘cyber crime’ just because it is carried out over the internet, even though it is not and should not be criminalized. This includes broadly worded, imprecise actions (“spreading information that offends the nation”, “insulting family values,” “frequently sending a large number of emails”), with or without additional requirements around criminal intent. These vaguely worded provisions can violate international human rights law because they can be misused to criminalise political opponents and 3

Select target paragraph3