[Link].T.
Unit 4: Cybercrimes and cybersecurity: the Legal Perspective
Prof: Thorat.T.M
Introduction:
Cyberspace is the computer-generated world of the internet.
Cyberspace refers to the virtual computer world, and more specifically, an electronic medium
that is used to facilitate online communication.
Cyberlaw is a branch of law that deals with legal issues arising from the usage of
interconnected information technology. In a nutshell, cyberlaw governs computers and
the internet.
Recent high-profile security incidents show that no organization or corporation is
immune to cyber attack. Like the White House's email system was partially shut down
after a cyber attack in 2014 and as part of the 2014 Sony hack, confidential movie
scripts and emails about employees and movie stars were made public.
The term "cybercrime" is well-known nowadays and requires no explanation.
Cybercrime is the misuse of information technology for unauthorized or unlawful
access. Like electronic fraud, and other crimes such as data deletion, alteration,
interception, concealment, forging, and so on.
Cybercrime and the Legal Landscape around the World:
Computer crimes, internet crimes, information crimes, communications crimes, and
technology crimes are all covered by cybercrime law.
Cybercrime laws establish the definitions and penalties for cybercrime.
Cybercrime is becoming a greater concern for countries at all stages of development, affecting
both customers and sellers.
While 154 countries (79 per cent) have enacted cybercrime legislation, the pattern varies
by region: Europe has the highest adoption rate (93 per cent) and Asia and the Pacific the
lowest (55 per cent).
Legal actions are essential in preventing and combating cybercrime.
The following are some of the existing laws in place to combat cybercrime:
1. Data Protection Act:
[Link].T.M
The United Kingdom Parliament has passed the Data Protection Act 1998 (DPA).
This is intended to safeguard information kept on computers.
The goal is to manage and control information, as well as to provide legal rights to
individuals who have kept data and how it can be used.
The Act established a fundamental framework, including standards that persons and
businesses can follow when storing personal information.
The act regulates how personal data can be utilized by businesses, organizations, and the
government. And they want everyone who uses data to be held accountable for
adhering to stringent data privacy and security regulations.
Information must be used fairly and lawfully, be confined to particular, clearly stated
goals, be accurate, not kept longer than necessary, and be safe and secure. Also,
sensitive reports such as political, religious, health, and criminal reports are legally
protected
2. The Computer Misuse Act (1990):
The United Kingdom Parliament passed this Act to prevent certain illegal actions such
as hacking, software misuse, or someone assisting another in gaining access to protected
files on another's computer system.
To address cybercrime, the UK Computer Misuse Act established three kinds of
offence. These are the following:
a. Looking into someone else's files on a computer without their permission.
There must be an intention to access a computer program or data, and the person must be aware
that such access is not permitted.
This is why many login screens include a statement stating that access is restricted to authorized
users
This offence carries a penalty of six months in prison or £5000 in fines.
b. Without permission, accessing computer material with the goal to commit
additional criminal offences, such as obtaining personal data or company
documents in order to perpetrate fraud or blackmail
This is punishable by six months in prison or 5 years or maximum fine.
c. Changing (modifying) computer data without authorization, such as by creating a virus
to destroy someone else's data or changing the money in a bank account. This offence is also classified
as a section 2 offence.
[Link].T.M
3. Copyright Law:
The Copyright, Design and Patents Acts of 1998 were passed in the United Kingdom
The Acts prevent software piracy by granting the right to control, sell, and distribute
one's work in a secure manner.
This Act prohibits the publication of books, videos, and computer software.
For the purposes of the law, it is prohibited for people who purchase software to-
1) Provide a copy to their friends
2) manufacture a software copy and sell
According to copyright law, software companies have the right to prevent piracy by a variety of
measures, including a license agreement covering copyright between the company that
developed the software and the user.
Companies supply a unique key license to the software and input to confirm the license right
during installation and/or program application executes if machine is connected to the internet
after user installs supporting files of the software.
Best Practices in Legal Preparedness :
1. Businesses are legally required to have "appropriate security measures" in place from a
technical standpoint. The relevant industry technical standards should be taken into
account. The steps that have been done must be familiar to senior management.
2. Employees should be provided with appropriate levels of training.
3. Employees should be able to easily get information on how to keep data safe and what to do in
case of a cyber attack in the form of a documented cyber policy.
4. Businesses must ensure that mobile device rules (including bring-your-own-device) improve
rather than impede the security of company data.
5. Keep a written record of the above, as well as any other efforts you've made to prepare your
company for a cyber attack. This will be crucial for any future regulatory investigations,
among other reasons.
[Link].T.M
Why Do We Need Cyberlaws: The Indian Context:
Cyber-law is important in a country like India where the internet is used to a large extent.
The law is enacted to save people and organizations from cybercrime and other internet-related
crimes.
It protects the privacy of every individual and organization
Before the enactment of Cyber-law, no specific law existed in India to deal with cybercrime. As
per rules and regulations of the Cyber-law, a person who commits cybercrime is liable to get
punishment. If anyone violates and breaks the provisions of the law, then it allows another
person or organization to take legal action against that person.
Cyberlaw may be required in the following situations:
1. The majority of Indian businesses retain their formal records on computers. A
corporation may require the help of this law to prevent the misuse of such data
2. Because of the rapid advancement of technology, many government forms, such as ITR
returns and service tax returns, are now completed electronically. Anyone can simply
misuse the forms by hacking into government portal sites. Only under cyberlaw will you
be able to seek justice for this form of fraud.
3. Credit cards and debit cards are widely used for shopping. Some internet fraudsters, on
the other hand, clone those credit and debit cards. Card cloning is a way in which
someone obtains your credit card information through the internet. You can readily track
down such criminals using cyberlaw.
4. The most frequent ways of transacting business are digital signatures and e-contracts.
Anyone who works with digital signatures and e-contracts has the potential to commit
fraud by misusing them. You are protected from this form of scam under cyberlaw.
[Cyber Law also called IT Law is the law regarding Information-technology including computers and
internet. It is related to legal informatics and supervises the digital circulation of information,
software, information security and ecommerce]
The Indian IT Act :
The Information Technology Act, 2000 (also known as ITA-2000, or the IT Act) is an Act of the
Indian Parliament (No 21 of 2000) notified on17th October 2000.
It is India's primary law governing cybercrime and electronic commerce.
The major goal of this act is to carry out legal and reliable electronic, digital, and online
transactions, as well as to prevent or eliminate cybercrime
There are 13 chapters and 90 sections in the IT Act.
There are two schedules in the IT Act of 2000:
[Link].T.M
First Schedule: The first schedule deals with papers that are exempt from the Act's
provisions.
Second Schedule: The second schedule is concerned with the use of an electronic signature
or authentication mechanism.
In the wake of the recent Indo-China border clash, the Government of India banned various
Chinese apps under the Information Technology Act. Example. tiktok and other Chinese app
Key Features of IT Act :
It goes into detail about offences, penalties, and violations.
All electronic contracts created through secure electronic channels were legally valid.
In a new clause, the term "cyber café" is defined as "any facility from which any person
in the regular course of business provides access to the internet to members of the
public."
The Cyber Regulations Advisory Committee will be formed as a result of this law.
It's based on the Indian Penal Code of 1860, the Indian Evidence Act of 1872, the
Bankers' Books Evidence Act of 1891, and the Reserve Bank of India Act of 1934, etc.
It amends Section 81 to include a provision that specifies that the Act's provisions take
precedence. The provision states that nothing contained in the Act shall prevent any
person from exercising any right granted under the Copyright Act of 1957.
Scheme of IT Act:
The Information Technology Act is divided into 13 chapters and 90 sections.
The IT Act 2000's last four parts, namely sections 91 to 94, deal with amendments to the
Indian Penal Code 1860, Indian Evidence Act 1872, Bankers' Books Evidence Act 1891,
and Reserve Bank of India Act 1934.
It begins with the Preliminary Aspect in Chapter 1, which covers the Act's title, scope,
commencement, and application in Section 1. The second section contains a definition.
The authentication of electronic records, digital signatures, electronic signatures, and
other topics are covered in Chapter 2.
Offenses and sanctions are discussed in Chapter 11. In this section of the Act, a number
of offences and penalties are listed.
After that, there are provisions about due diligence, the role of intermediaries, and some
other provisions.
Two schedules are included in the Act. The Act does not apply to certain documents or
transactions, according to the First Schedule. The electronic signature or electronic
authentication technique and procedure are covered in the Second Schedule.
[Link].T.M
The IT Act in Practice:
Nothing in this Act applies to the documents or transactions listed in the First Schedule,
according to Section 1 subclause (4). The following papers or transactions are not covered by the
Act:
1. Section 13 of the Negotiable Instruments Act, 1881, defines a negotiating instrument
(other than a cheque).
2. Section 1A of the Powers-of-Attorney Act of 1882 defines a power-of-attorney.
3. Section 3 of the Indian Trusts Act of 1882 defines a trust
4. A will as defined in clause (h) of section 2 of the Indian Succession Act of 1925
including any other testamentary disposition by whatever name called.
5. Any contract for the sale or conveyance of real estate, or any interest in such real estate.
6. Any class of documents or transactions that the Central Government may specify.
Challenges to Indian Law and Cybercrime Scenario in India :
1) Devices used for internet access are not uniform:
In India, not everyone can buy costly phones due to the wide range of income levels.
Apple's market share in the United States is over 44%. In India, however, iPhones are
only utilized by less than 1% of mobile subscribers due to its stricter security standards.
The rising security gap between the high- end iPhone and lower-cost smartphones makes
it nearly hard for regulators to create legal and technical data protection standards.
2) Cybersecurity architecture at the national level is lacking:
The military has its own firefighting agency, and critical infrastructure is owned by the
commercial sector. However, there is no national security architecture that integrates all of these
agencies' efforts in order to analyse the nature of any danger and properly respond to it. Although
the Prime Minister's Office has established a position dedicated to this cause, India still has a
long way to go until it has the essential infrastructure in place.
3) A lack of distinction:
Cyberspace, unlike countries or states, has no borders, banking functions, and other functions
vulnerable to cyber attacks from anywhere. This could lead to national security breaches,
resulting in the loss of money, property, or lives.
[Link].T.M
4) Lack of understanding:
There is a lack of awareness at both the corporate and individual levels because there is no
national regulatory framework in place for cybersecurity.
Cybercrime Scenario in India :
India is making every effort to fully implement the Digital India project. Maximum
connection with minimal cybersecurity threats will be critical to the success of the Digital
India project.
This is a dilemma for India, which has a bad track record when it comes to cybersecurity.
According to Home Ministry statistics, 71,780 cases of cyber fraud were registered in
2013, compared to 22,060 occurrences in 2012. Up until June 2014, there had been
62,189 occurrences of cyber fraud.
In the last two to three years, the number of cyber-crime cases registered in the country
has increased by more than 40% annually.
According to data collected by the Indian Computer Response Team (CERT-In), a total
of 308, 371 and 78 government websites were hacked in 2011, 2012, and 2013,
respectively, while 16,035 occurrences of spam, malware infection, and system break-in
were recorded in 2013.
Consequences of Not Addressing the Weakness in Information Technology Act:
Existing cyberlaws contain numerous flaws, and as a result of these flaws, suspects are
often released even after committing serious cybercrime.
If these flaws are not addressed in a timely manner, they will have severe consequences
In reality, new vulnerabilities are being discovered every day in the field of
cybersecurity. It must investigate and take actions in order to respond quickly to
cybercrime.
Digital Signatures and the Indian IT Act :
In India, the Information Technology (IT ACT 2000) gave digital signatures legal authority in the
year 2000.
It gave electronic signatures the same legal standing as handwritten signatures on
physical documents.
The Information Technology Act of 2000 covers the entire country and allows people to use digital
signatures in the same way they do traditional signatures.
[Link].T.M
The prime objective of a digital signature is the same as that of a traditional signature: to
authenticate the document, to identify the person signing it, and to bind the contents of
the document to the person signing it.
Though most electronic documents can be signed electronically, there are a few exclusions that
require handwritten signatures.
1) a negotiable document (such as a promissory note or a bill of exchange) as specified in section
13 of the Negotiable Instruments Act of 1881;
2) a power of attorney, as described in section 1A of the 1882 Powers-of-Attorney Act;
3) section 3 of the Indian Trusts Act of 1882 defines a trust deed;
4) a will, as specified in clause (h) of section 2 of the Indian Succession Act, 1925, as well
as any other testamentary disposition known by any other name
5) a contract for the sale or conveyance of real estate or other interest in real estate.
Definition :
The term "digital signature" is defined as follows under section 2(p) of the IT Act
2000: "Digital Signature" refers to a subscriber's authentication of any electronic
record using an electronic method.
The digital signature technology described in Section 3 is as follows:
1) Any subscriber may authenticate an electronic record by affixing his digital signature,
according to the provisions of this section
2) The authentication of the electronic record will be accomplished through the use of an
asymmetric crypto system (private and public keys) and a hash function that will
envelop and transform the original electronic record into another electronic record
3) The private key and public key are both unique to the subscriber and form a working key
pair.
[Link].T.M
Definition: Digital Signature Certificates (DSCs)
Digital signing is made possible by Digital Signature Certificates (DSCs), which contains
a unique private and public key pair that serves as the signer's identification.
Businesses in India have begun signing documents such as HR letters, reports, agreements, and other
documents with DSC-based digital signatures.
Amendments to the Indian IT Act:
Sections 91-94 of the IT Act amended four statutes. Schedules 1-4 have been updated to reflect these
changes.
1) The modifications to the Penal Code are listed in the first schedule. It has broadened the
definition of the term "document" to include electronic documents.
2) The modifications to the India Evidence Act are deal within the second schedule. It has to
do with electronic documents being included in the definition of evidence.
3) The Banker's Books Evidence Act is amended in the third schedule. The definition of
"banker's book" has been changed as a result of this revision. Printouts of data saved on a
floppy disc, a disc, a tape, or any other type of electromagnetic data storage device are
included.
4) The Reserve Bank of India Act is amended in the fourth schedule. It is concerned with
the regulation of electronic fund transfers between banks or between banks and other
financial institutions.
Intermediary Liability
When dealing with specific electronic records, an intermediary is a person who accepts, keeps, or
transmits that record on behalf of another person, or offers any service related to that record.
Providers of network services
Websites that accept payments online
Cyber cafes and online marketplaces
[Link].T.M
Key features of Amended Act :
The following are some of the features of the newly amended act:
i. It emphasizes privacy concerns as well as information security.
ii. Digital signature is explained in detail.
iii. It clarifies pragmatic corporate security practices.
iv. It is primarily concerned with the role of intermediaries.
V. New faces of cybercrime have been added.
Cybercrime and Punishment:
Section Offense Penalty
65 Tampering with source documents on a Upto three years in prison or/and a fine of
computer upto RS 200,000.
66 Computer system hacking. Upto three years in prison or/and a fine of
upto RS 500000
66A Punishment for sending offensive Upto three years in prison and a fine.
communications via a
communication service, and so on
66B Getting a hold of a stolen computer or Upto three years in prison or/and a fine of
phone. upto 100,000
66C Using another person's password. Upto three years in prison or/and a fine of
upto 100,000
66D Using a computer resource to cheat. Upto three years in prison or/and a fine of
upto 100,000
66F Cyber-terrorist acts Imprisonment for the rest of your life.
67C Failure to keep records. Upto three years in prison or/and a fine
72 Violation of privacy and Upto two years in prison or/and a fine of
confidentiality. upto 100,000.
73 Publishing electronic signature Up to two years in prison or/and a fine of
certificate false in certain particulars. upto 100,000.
74 Falsely published material. Up to two years in prison or/and a fine of
upto 100,000.