Recognizing that a tight, globally-accepted definition of cybercrime does not exist,5
this section (I) explores ways in which cybercrime has been understood, then goes
through both (II) existing definitions of cybercrime as well as (III) grouping activities
constituting cybercrime and (IV) finishes by proposing a working definition of
“cybercrime” that will be used in the Toolkit. Discussion focuses on various approaches
used by various institutions and organizations with an yet to looking to lessons learned
from existing knowledge.
I. Defining Cybercrime
Different definitions of cybercrime, of varying breadth and depth, have been put forward by
experts, industry and academia, some of which have been used by governments.6 Under rule
of law principles, it is understood that laws must clearly define prohibited behavior7 and should
be construed narrowly8; such tenets, or so-called canons of construction, are particularly true
of criminal laws, where the consequences of misbehavior have significantly greater costs for
perpetrators.
In order to define “cybercrime”, it is helpful to begin (A) by defining a few key terms, before
moving on (B) to consider technology’s place in this evolving term and space and (C) to understand
where cybercrime actually takes place. The subsection goes on to explore both (D) broad and
narrow understandings of cybercrime before concluding with (E) a discussion of how and why
national and international approaches differ.
A. Key Terms
Before further examining different definitions of “cybercrime”, it is useful to describe some
key elements central to construing cyberspace, namely “computer” (and “ICT”), “data” and
“systems”.9 For the purposes of this Toolkit, these terms are understood as follows:
Computer
”Computer” is understood as an electronic device for storing and processing
data. While those processes are typically in binary form, according to
instructions given to it in a variable program,10 it is expected that, in the not-sodistant future, devices may operate in quantum form using what are known as
“quibits” (as opposed to “bits”), which, in essence, take the operating of binary
form to a multidimensional level (see section 1 C, box 1.3, above). Relatedly,
“information and communications technology” (ICT) is a broader term, which,
though less commonly used to define cybercrime, emphasizes the place of
Page 66 | Chapter 2 | § A. Working Definition of Cybercrime
Table of Contents