Status of governance mechanisms for cybercrime Combatting cybercrime involves diverse and elaborate mechanisms. According to the UNODC Report Comprehensive Study on Cybercrime, 82 countries have signed and/or ratified legally binding cybercrime conventions (Figure 3). The Council of Europe’s Budapest Cybercrime Convention (2001) is the oldest cybercrime legal instrument, and it has inspired many other regional and national regulations on cybercrime worldwide. Other regional legal instruments include: the League of Arab States Convention on Combating IT Offences (2010), the Shanghai Cooperation Organisation Agreement on Cooperation in the Field of International Information Security, and the African Union Convention on the Confidence and Security in Cyberspace (2014). On the global level, the UNODC is the leading organisation, with a set of international instruments to fight cybercrime. Since cybercrime often involves an organised approach, the UNODC’s Convention against Transnational Organised Crime could be used in the fight against cybercrime. Interpol facilitates a global network of 190 national police organisations, which plays a key role in the cross-border investigation of cybercrime. The ITU hosts the World Summit on the Information Society (WSIS) implementation process in cybersecurity, labelled the ITU Global Security Agenda. The Group of Eight (G8) has been addressing cybercrime since 1997 when it established the Subcommittee on High-tech Crimes. One of the committee’s main achievements was the establishment of an international 24/7 network of contacts for dealing with cybercrime issues. FIRST coordinates network of CERTs. FIRST is the main forum in the technical community for addressing cybersecurity and cybercrime issues. It functions as a network of CERTs, the main bodies for addressing cybersecurity issues at national level. Many regions have been developing programmes against cybercrime: Asia (Asia-Pacific Economic cooperation), Africa (African Union and UN Economic Commission for Africa), Americas (Organisation of American States), Asia (Shanghai Cooperation Organisation), etc. The Anti-Phising Working group (APWG) acts as a worldwide coalition unifying the global response to cybercrime across industry, government and law-enforcement sectors. Cybercrime is most directly related to the following Internet policy issues: technical standards, cybersecurity, child safety, encryption, freedom of expression, privacy and data protection, jurisdiction, intermediary responsibility, e-commerce, e-money, access, cloud computing, and content policy. Possible gaps in dealing with cybercrime Most gaps are caused by the predominantly transborder nature of cybercrime and the limited international mechanisms available to fight it. 19

Select target paragraph3