14
MEANS – ACTIONS
The Means flow from the Ways. The means describe the resources available to achieve
the stated ends. The actions we present are not prescriptive. Local conditions should
determine the type and order of actions you choose from this list. One should feel free to
create new actions. The only condition, of course, is that one does not lose track of the
GCA association. National administrations may also use the section to review or improve
existing institutions, policies, and relationships addressing cybersecurity issues.
15
PRIORITY 1 – LEGAL
MEASURES
Actions under this priority focus on the establishment and modernisation of criminal law,
procedures, and policy to prevent, deter, respond to, and prosecute cybercrime.
15.1
ACTION 1: LEGAL MEASURES STRATEGY
We advise that nations adopt a legal measures strategy to provide common direction
and obtain the commitment of all stakeholders. The strategy would allocate resources,
coordinate and control all activities aimed at enacting and enforcing a comprehensive set
of laws relating to cybersecurity. The strategy also identifies the roles and responsibilities
in the creation and modernisation of criminal law, procedures, and policy to prevent,
deter, respond to, and prosecute cybercrime.
15.2
ACTION 2: REVIEW ADEQUACY OF
LEGISLATION
Statutes define roles of parties that fight cybercrime. Thus, countries should establish
whether national statutes related to cybercrime, privacy, data protection, commercial law,
digital signatures and encryption are adequate. The review should involve as many
stakeholders as possible. Typical participants include government departments,
intelligence and law enforcement, private firms, civil society, academics and citizens. We
recommend that you involve regional and international partners, where practical,
because international cooperation is pivotal to confronting the global issue:
15.2.1
Model Cybercrime Legislation
If relevant experts and stakeholders determine no sufficient legislation exists, then the
country should draft and/or adopt cybercrime legislation. We recommend that you adopt
harmonised legislation that is compatible with regional and cybercrime legislation. For
example, the ITU Toolkit for Cybercrime Legislation contains sample language that
72