Papua New Guinea Cybercrime Policy 2014
implementing
the
objectives
of
Policy.
The
strategies
envisaged
under
the
Policy
to
address
Cybercrime
are
–
(a) The
adoption
of
criminal
laws
against
attacks
on
the
security
and
integrity
of
computer
systems
and
information,
thereby
criminalizing
hacking,
illegal
interception
and
interference
with
availability
of
computer
subsystems.
(b) To
have
clear
procedures
meeting
international
standards
for
government
access
to
communications
and
stored
data
when
required
for
criminal
investigations.
Such
procedures
will
allow
government
to
carry
out
their
investigations,
but
will
also
assure
businesses
and
consumers
that
there
cannot
be
any
unjustified
monitoring
of
all
types
of
communications.
(c) To
put
in
place
procedures
and
laws
facilitating
the
use
of
credit
cards
and
electronic
forms
of
payment,
in
a
legal
framework
ensuring
consumers
and
business
proprietors
who
transact
business
online
have
recourse
if
the
transaction
does
not
go
through
or
if
the
product
or
services
purchased
are
unsatisfactory.
It
will
also
ensure
that
consumer
data
provided
to
merchants
will
not
be
misused.
(d) To
review
the
existing
intellectual
property
laws
to
ensure
that
there
is
adequate
protection
in
the
digital
setting.
(e) To
have
procedures
and
processes
in
place
to
take
all
critical
systems
offline
in
the
event
of
war,
disaster
or
civil
unrest,
which
otherwise
could
jeopardize
or
place
such
systems
at
risk.
Based
on
the
above,
the
Policy
alludes
to
certain
recommendations
as
a
way
forward.
Despite
these
recommendations,
there
has
not
been
any
real
progress
until
now.
6.
Challenges
in
Determining
the
Threat
Level
When
developing
policies
and
strategies
in
the
field
of
criminal
justice
and
crime
prevention,
very
often
crime
statistics
are
used
as
an
indicator
for
the
seriousness
of
a
subject
matter
and
the
need
for
the
Government
to
respond.
Consequently
crime
statistics
are
used
by
policy-‐makers
to
support
the
decision-‐making
processes.6
However,
it
is
difficult
to
quantify
the
impact
of
Cybercrime
solely
on
the
basis
of
the
number
of
offences
carried
out
within
a
given
time-‐frame7
because
Cybercrime
victims
very
often
fail
to
report
incidents.8
This
could
be
due
to
the
lack
of
knowledge
and
or
awareness
and
the
absence
of
appropriate
reporting
facilities.
For
example,
in
a
recent
national
survey
undertaken
in
preparation
of
this
Policy
9
,
answers
generated
from
questions
relating
to
people’s
understanding
of
Cybercrime
and
incidences
of
Cybercrime
showed
that
appropriate
awareness
is
lacking.
A
notable
percentage
(almost
50%)
of
those
surveyed
did
not
have
knowledge
of
or
were
unsure
of
what
Cybercrime
is
or
the
types
of
offences
that
constitute
such
crime.
6
Collier/Spaul,
Problems
in
Policing
Computer
Crime,
Policing
and
Society,
1992,
Vol.2,
page,
308.
7
Walden,
Computer
Crimes
and
Digital
Investigations,
2006,
Chapter
1.29.
8
Understanding
Cybercrime,
3rd
Edition,
ITU,
2012,
Chapter
4.2.
This
survey
was
widely
circulated
through
the
media
covering
most
of
the
country.
However,
only
314
questionnaires
were
completed
and
returned
albeit
covering
a
decent
cross
section
of
society.
9
P|9