The main knowledge gap is related to a shortage of reliable statistics and data on cybercrime
that should trigger, inform, and shape cybercrime policy actions. Policy gaps start with the
lack of common or widely accepted definition of cybercrime. In addition, there are no
sustainable and effective mechanisms to ensure that policy response to cybercrime follows
technological development effectively.
Implementation gaps include the insufficient use of international instruments in criminal
matters (mutual assistance agreements, regional, and global arrangements) in cyber matters.
Regional and global harmonisation of national cybercrime legislations is lacking as effective
mechanisms for cooperation in cybercrime investigation (electronic evidence and cyber
forensic).
Institutional and individual capacities in cybercrime field (juridical, law enforcement) are
needed in order to reduce the number of ‘safe havens’ for cybercrime attacks, as is an
intersectoral approach for cybercrime activities, including the following aspects: human
rights (privacy protection, freedom of expression), and economic (trustworthy environment
for e-commerce).
3.3 Critical information infrastructure
The Internet is a critical information infrastructure (CII) in two main aspects. First, the
Internet is a communication, economic, and information platform for almost 3 billion Internet
users. Second, it provides communication supports for vital systems of modern society,
including energy network, water supply, and financial systems, among others. The IETF
defines a CII as ‘systems that are so vital to a nation that their incapacity or destruction would
have a debilitating effect on national security, the economy, or public health and safety.’ As a
CII, the Internet must be accessible, secure, and reliable.
Status of governance mechanisms for critical information infrastructure
The CII requires a systematic national approach with enhanced regional and international
cooperation networks for information sharing. Its governance involves a wide range of
private and public organisations. With more than 80% of the CII owned and/or operated by
the private sector, effective governance mechanisms should inter alia involve public-private
partnerships. Among international organisations, the ITU has many initiatives related to the
CII. This issue is increasingly addressed by various regional organisations (OSCE, ASEAN,
Shanghai Cooperation Organisation, OAS, APEC). CERTs are also important governance
mechanisms.
Technical infrastructure and cloud servers are essential for the functioning of the Internet as a
CII. For example, many businesses and individual users depend on the services provided
from the cloud servers, including Facebook and Twitter.
20