CHAPTER ONE: CONNECTIVITY AND CYBERCRIME example of this approach is found in the Commonwealth of Independent States Agreement, which describes an ‘offence relating to computer information’ as a ‘criminal act of which the target is computer information.’86 The Shanghai Cooperation Organization Agreement (more broadly) describes ‘information offences’ as ‘the use of information resources and (or) the impact on them in the informational sphere for illegal purposes.’ The Council of Europe Cybercrime Convention – although not by way of defined terms – uses broad criminalization headings, including ‘offences against the confidentiality, integrity and availability of computer data and systems,’ ‘computer-related offences’ and ‘content-related offences.’87 The Draft African Union Convention similarly uses criminalization chapter headings that make a distinction between ‘offences specific to information and communication technologies’ and ‘adapting certain offences to information and communication technologies.’88 It is clear from these approaches that a number of general features could be used to describe cybercrime acts. One approach is to focus on the material offence object – that is, on the person, thing, or value against which the offence is directed.89 This approach is seen in the Commonwealth of Independent States Agreement (where the offence object is computer information) and also in Title One of the substantive criminal law chapter of the Council of Europe Cybercrime Convention (where the objects are computer data or computer systems). Another approach is to consider whether computer systems or information systems form an integral part of the modus operandi of the offence.90 This approach is also seen in Titles Two, Three and Four of the substantive criminal law chapter of the Council of Europe Cybercrime Convention, as well as in the Shanghai Cooperation Organization Agreement, and the Draft African Union Convention. Identifying possible cybercrime offence objects and modus operandi does not describe cybercrime acts in their entirety, but it can provide a number of useful general categories into which acts may be broadly classified. Some international or regional instruments concern cybercrime only in the narrower conception of the computer system or data as the offence object.91 Others address a broader range of offences, including acts where the offence object is a person or value, rather than a computer system or data – but where a computer system or information system is nonetheless an integral part of the modus operandi of the offence.92 Chapter Four (Criminalization) examines the specific acts criminalized by such instruments in detail. While not all international or regional instruments use a broad conception of cybercrime, the approach taken by this Study aims to be as comprehensive as possible. It thus makes use of a wide list of cybercrime act descriptions, broadly organized in three categories based on the offence object and modus operandi. Due to the use of two methods of classification, some degree of overlap may exist between the categories. 86 87 88 89 90 91 92 Commonwealth of Independent States Agreement, Art. 1(a). Council of Europe Cybercrime Convention, Titles 1, 2, and 3. Draft African Union Convention, Part III, Chapter V, Section II, Chapters 1 and 2. Those comprise offences against the confidentiality, integrity and availability of data and computer systems. See Calderoni, F., 2010. The European legal framework on cybercrime: striving for an effective implementation. Crime, Law, and Social Change, 54(5):339-357. Podgor, E.S., 2002. International computer fraud: A paradigm for limiting national jurisdiction. U.C. Davis Law Review, 35(2):267317, 273 et seq. EU Decision on Attacks against Information Systems and Commonwealth of Independent States Agreement. For instance, ECOWAS Draft Directive, Art. 17 (Facilitation of access of minors to child pornography, documents, sound or pornographic representation). See also Pocar, F., 2004. New challenges for international rules against cyber-crime. European Journal on Criminal Policy and Research, 10(1):27-37. 15

Select target paragraph3