Where ICTs are used as a tool to commit a traditional offence, there may be a need to
amend existing criminal provisions to reflect the use of such technologies. Under the
Council of Europe Cybercrime Convention (2001), offences in relation to fraud
forgery, infringements of intellectual property rights and child pornography are all
recast to take into account the use of ICTs in their commission.
The Task Force recommends that the impact of ICTs on criminal conduct be
given due consideration whenever a Partner State engages in a review or
examination of its criminal code in the course of a reform initiative (R.16).
In terms of offences targeting the confidentiality, integrity and availability of
computer or information systems and the data they process, there is broad consensus
around the types of conduct that should be criminalised:
•
•
•
•
Unauthorised access to the system
Unauthorised interference or modification of the system or the data
processed on the system
Unauthorised interception of communications between or within systems;
Misuse of devices, including the supply or possession of tools such as
password cracking or virus writing software.
Measures designed to tackle cyber-terrorist or cyber-warfare conduct are based
around the motivation of the offender rather than his conduct, which will generally
fall within one of the four categories above. Similarly, spamming, the mass sending of
unsolicited emails, is not itself an offence in most jurisdictions, although it will often
involve the commission of computer integrity offences in the course of its
commission, such as creating a ‘zombie’ computer from which to send the messages.
The jurisdictional scope of these offences will generally be extended to capture both
conduct carried out in the territory, where the harm or victim resides in another
jurisdiction; as well as when the victim or harm occurs within the territory.
Consideration may also be given to whether extra-territorial jurisdiction should be
provided for, where the conduct, victim and harm occur outside of the territory, but
the perpetrator is a national of the jurisdiction.
2.3.2
Criminal procedure
While the impetus for reform of criminal procedure and the powers of law
enforcement agencies may be driven by concerns about cybercrime, it must be borne
in mind that the reformed regime will generally be applicable across all forms of
criminality. As such, new powers that may be seen as desirable to tackle a particular
instance of cyber-criminality may appear excessive in a broader context of criminal
investigation.
It is often necessary that measures be taken to address the abilities and capabilities of
law enforcement agencies to obtain and access forensic data when being stored on a
system or device and when being transmitted between devices. In the former situation,
this will include amending the concept of search and seizure, particularly where the
evidence is held remotely but within the same jurisdiction. Obtaining access to data
protected through encryption or other techniques may also require specific legislative
15