Where ICTs are used as a tool to commit a traditional offence, there may be a need to amend existing criminal provisions to reflect the use of such technologies. Under the Council of Europe Cybercrime Convention (2001), offences in relation to fraud forgery, infringements of intellectual property rights and child pornography are all recast to take into account the use of ICTs in their commission. The Task Force recommends that the impact of ICTs on criminal conduct be given due consideration whenever a Partner State engages in a review or examination of its criminal code in the course of a reform initiative (R.16). In terms of offences targeting the confidentiality, integrity and availability of computer or information systems and the data they process, there is broad consensus around the types of conduct that should be criminalised: • • • • Unauthorised access to the system Unauthorised interference or modification of the system or the data processed on the system Unauthorised interception of communications between or within systems; Misuse of devices, including the supply or possession of tools such as password cracking or virus writing software. Measures designed to tackle cyber-terrorist or cyber-warfare conduct are based around the motivation of the offender rather than his conduct, which will generally fall within one of the four categories above. Similarly, spamming, the mass sending of unsolicited emails, is not itself an offence in most jurisdictions, although it will often involve the commission of computer integrity offences in the course of its commission, such as creating a ‘zombie’ computer from which to send the messages. The jurisdictional scope of these offences will generally be extended to capture both conduct carried out in the territory, where the harm or victim resides in another jurisdiction; as well as when the victim or harm occurs within the territory. Consideration may also be given to whether extra-territorial jurisdiction should be provided for, where the conduct, victim and harm occur outside of the territory, but the perpetrator is a national of the jurisdiction. 2.3.2 Criminal procedure While the impetus for reform of criminal procedure and the powers of law enforcement agencies may be driven by concerns about cybercrime, it must be borne in mind that the reformed regime will generally be applicable across all forms of criminality. As such, new powers that may be seen as desirable to tackle a particular instance of cyber-criminality may appear excessive in a broader context of criminal investigation. It is often necessary that measures be taken to address the abilities and capabilities of law enforcement agencies to obtain and access forensic data when being stored on a system or device and when being transmitted between devices. In the former situation, this will include amending the concept of search and seizure, particularly where the evidence is held remotely but within the same jurisdiction. Obtaining access to data protected through encryption or other techniques may also require specific legislative 15

Select target paragraph3