The main knowledge gap is related to a shortage of reliable statistics and data on cybercrime that should trigger, inform, and shape cybercrime policy actions. Policy gaps start with the lack of common or widely accepted definition of cybercrime. In addition, there are no sustainable and effective mechanisms to ensure that policy response to cybercrime follows technological development effectively. Implementation gaps include the insufficient use of international instruments in criminal matters (mutual assistance agreements, regional, and global arrangements) in cyber matters. Regional and global harmonisation of national cybercrime legislations is lacking as effective mechanisms for cooperation in cybercrime investigation (electronic evidence and cyber forensic). Institutional and individual capacities in cybercrime field (juridical, law enforcement) are needed in order to reduce the number of ‘safe havens’ for cybercrime attacks, as is an intersectoral approach for cybercrime activities, including the following aspects: human rights (privacy protection, freedom of expression), and economic (trustworthy environment for e-commerce). 3.3 Critical information infrastructure The Internet is a critical information infrastructure (CII) in two main aspects. First, the Internet is a communication, economic, and information platform for almost 3 billion Internet users. Second, it provides communication supports for vital systems of modern society, including energy network, water supply, and financial systems, among others. The IETF defines a CII as ‘systems that are so vital to a nation that their incapacity or destruction would have a debilitating effect on national security, the economy, or public health and safety.’ As a CII, the Internet must be accessible, secure, and reliable. Status of governance mechanisms for critical information infrastructure The CII requires a systematic national approach with enhanced regional and international cooperation networks for information sharing. Its governance involves a wide range of private and public organisations. With more than 80% of the CII owned and/or operated by the private sector, effective governance mechanisms should inter alia involve public-private partnerships. Among international organisations, the ITU has many initiatives related to the CII. This issue is increasingly addressed by various regional organisations (OSCE, ASEAN, Shanghai Cooperation Organisation, OAS, APEC). CERTs are also important governance mechanisms. Technical infrastructure and cloud servers are essential for the functioning of the Internet as a CII. For example, many businesses and individual users depend on the services provided from the cloud servers, including Facebook and Twitter. 20

Select target paragraph3