Status of governance mechanisms for cybercrime
Combatting cybercrime involves diverse and elaborate mechanisms. According to the
UNODC Report Comprehensive Study on Cybercrime, 82 countries have signed and/or
ratified legally binding cybercrime conventions (Figure 3). The Council of Europe’s
Budapest Cybercrime Convention (2001) is the oldest cybercrime legal instrument, and it has
inspired many other regional and national regulations on cybercrime worldwide. Other
regional legal instruments include: the League of Arab States Convention on Combating IT
Offences (2010), the Shanghai Cooperation Organisation Agreement on Cooperation in the
Field of International Information Security, and the African Union Convention on the
Confidence and Security in Cyberspace (2014).
On the global level, the UNODC is the leading organisation, with a set of international
instruments to fight cybercrime. Since cybercrime often involves an organised approach, the
UNODC’s Convention against Transnational Organised Crime could be used in the fight
against cybercrime. Interpol facilitates a global network of 190 national police organisations,
which plays a key role in the cross-border investigation of cybercrime. The ITU hosts the
World Summit on the Information Society (WSIS) implementation process in cybersecurity,
labelled the ITU Global Security Agenda.
The Group of Eight (G8) has been addressing cybercrime since 1997 when it established the
Subcommittee on High-tech Crimes. One of the committee’s main achievements was the
establishment of an international 24/7 network of contacts for dealing with cybercrime issues.
FIRST coordinates network of CERTs. FIRST is the main forum in the technical community
for addressing cybersecurity and cybercrime issues. It functions as a network of CERTs, the
main bodies for addressing cybersecurity issues at national level.
Many regions have been developing programmes against cybercrime: Asia (Asia-Pacific
Economic cooperation), Africa (African Union and UN Economic Commission for Africa),
Americas (Organisation of American States), Asia (Shanghai Cooperation Organisation), etc.
The Anti-Phising Working group (APWG) acts as a worldwide coalition unifying the global
response to cybercrime across industry, government and law-enforcement sectors.
Cybercrime is most directly related to the following Internet policy issues: technical
standards, cybersecurity, child safety, encryption, freedom of expression, privacy and data
protection, jurisdiction, intermediary responsibility, e-commerce, e-money, access, cloud
computing, and content policy.
Possible gaps in dealing with cybercrime
Most gaps are caused by the predominantly transborder nature of cybercrime and the limited
international mechanisms available to fight it.
19