B) Canada has participated in public attributions of activities that it deems to be unacceptable State
behaviour. In undertaking its attribution process, Canada considers the larger context of the event, the
challenges of attribution in the ICT environment, relevant international law and voluntary norms, and the
nature and extent of the consequences of the incident.
C) Through international cyber capacity building Canada has assisted countries implement or improve their
Computer Security Incident Response Teams (CSIRTs), which allow for real time information sharing between
nations on cyber incidents, including the misuse of ICTs. Canada also works with police forces and judiciary
systems of foreign nations to increase their capacity of cyber forensics and investigation, attribution, and
prosecution of those who use ICTs for criminal or exploitative purposes.
Norm 3 – States should not knowingly allow their territory to be used for internationally wrongful acts
using ICTs.
Canada considers that States have a responsibility to ensure that their territory is not used in a way that
harms the rights of other States. If Canada is contacted about incidents on our territory, we will take
appropriate action to contain the harmful behaviour. Furthermore, in order to ensure that our territory is not
used to commit internationally wrongful acts, Canada has:
A) Developed legislation to prosecute cyber criminals: Canada’s Criminal Code includes a number of offences
that can apply to the actions of cyber criminals, as well as investigative tools that may be relevant to
investigate these activities. This includes production orders, and preservation demands and orders, which are
used to ensure evidence is not deleted prior to obtaining authority for access by investigators. A key offence
in this regard is found in section 342.1, the offence of unauthorized use of a computer, which provides:
“Everyone is guilty of an indictable offence and liable to imprisonment for a term of not more than 10 years,
or is guilty of an offence punishable on summary conviction who, fraudulently and without colour of right,
(a) obtains, directly or indirectly, any computer service;
(b) by means of an electro-magnetic, acoustic, mechanical or other device, intercepts or causes to be
intercepted, directly or indirectly, any function of a computer system;
(c) uses or causes to be used, directly or indirectly, a computer system with intent to commit an offence
under paragraph (a) or (b) or under section 430 in relation to computer data or a computer system; or
(d) uses, possesses, traffics in or permits another person to have access to a computer password that
would enable a person to commit an offence under paragraph (a), (b) or (c).”
Possession of a device to obtain unauthorized use of a computer system or commit mischief is also
criminalized, under section 342.2.
Another relevant offence in this context is section 430(1.1), mischief in relation to computer data, which
provides:
“Everyone commits mischief who wilfully
(a)
(b)
(c)
(d)
destroys or alters computer data;
renders computer data meaningless, useless or ineffective;
obstructs, interrupts or interferes with the lawful use of computer data; or
obstructs, interrupts or interferes with a person in the lawful use of computer data or denies access to
computer data to a person who is entitled to access to it.”
The punishment for this offence is found at section 430(5) and (5.1), which state:
“(5) Everyone who commits mischief in relation to computer data
(a) is guilty of an indictable offence and liable to imprisonment for a term not exceeding ten years; or
(b) is guilty of an offence punishable on summary conviction.
(5.1) Everyone who wilfully does an act or wilfully omits to do an act that it is their duty to do, if that act or
omission is likely to constitute mischief causing actual danger to life, or to constitute mischief in relation to
property or computer data,