Recognizing that a tight, globally-accepted definition of cybercrime does not exist,5 this section (I) explores ways in which cybercrime has been understood, then goes through both (II) existing definitions of cybercrime as well as (III) grouping activities constituting cybercrime and (IV) finishes by proposing a working definition of “cybercrime” that will be used in the Toolkit. Discussion focuses on various approaches used by various institutions and organizations with an yet to looking to lessons learned from existing knowledge. I. Defining Cybercrime Different definitions of cybercrime, of varying breadth and depth, have been put forward by experts, industry and academia, some of which have been used by governments.6 Under rule of law principles, it is understood that laws must clearly define prohibited behavior7 and should be construed narrowly8; such tenets, or so-called canons of construction, are particularly true of criminal laws, where the consequences of misbehavior have significantly greater costs for perpetrators. In order to define “cybercrime”, it is helpful to begin (A) by defining a few key terms, before moving on (B) to consider technology’s place in this evolving term and space and (C) to understand where cybercrime actually takes place. The subsection goes on to explore both (D) broad and narrow understandings of cybercrime before concluding with (E) a discussion of how and why national and international approaches differ. A. Key Terms Before further examining different definitions of “cybercrime”, it is useful to describe some key elements central to construing cyberspace, namely “computer” (and “ICT”), “data” and “systems”.9 For the purposes of this Toolkit, these terms are understood as follows: Computer ”Computer” is understood as an electronic device for storing and processing data. While those processes are typically in binary form, according to instructions given to it in a variable program,10 it is expected that, in the not-sodistant future, devices may operate in quantum form using what are known as “quibits” (as opposed to “bits”), which, in essence, take the operating of binary form to a multidimensional level (see section 1 C, box 1.3, above). Relatedly, “information and communications technology” (ICT) is a broader term, which, though less commonly used to define cybercrime, emphasizes the place of Page 66 | Chapter 2 | § A. Working Definition of Cybercrime Table of Contents

Select target paragraph3