CPE3208 – Cyber Security
Course Administration
Dr. Ann Move Oguti
School of Engineering and Technology
Department of Electronics and Computer Engineering
Soroti University
CPE3208 – Cyber Security
Ethics and Policy
Cyber Crime, Laws, and Ethics
Lecture 02
Cyber Law
Cyber law is the law governing cyber space (cyber space is a term used to refer to computers,
networks, software, data storage devices (such as hard disks, USB disks etc.), the internet,
websites, emails and even electronic devices such as cell phones, ATM machines etc.)
The essence is to prevent any person from violating the right of other persons in cyberspace.
Any kind of violation of cyber rights is considered to be a cyberspace violation and are deemed
punishable under cyber laws
Cyber law plays a crucial role in promoting trust, security, and legal certainty in cyberspace, while
also addressing the challenges and risks associated with digital technologies and online activities
It provides a framework for balancing innovation and technological advancement with the protection
of individual rights, privacy, and security in the digital age
Compliance with cyber law ensures that individuals, businesses, and governments operate ethically
and responsibly in the digital domain, fostering trust and confidence in electronic transactions and
communications
Cyber Law
Cyber law encompasses laws relating to
1) Cyber Crimes: Cyber law addresses offenses committed using computers,
networks, or digital devices. This includes unauthorized access to computer
systems (hacking), identity theft, online fraud, cyberbullying, phishing, malware
attacks, and other forms of illegal activities conducted in cyberspace
2) Electronic and Digital Signatures: Cyber law provides legal recognition and
regulatory frameworks for electronic and digital signatures. Electronic
signatures are used to authenticate electronic documents and transactions,
ensuring their integrity and non-repudiation. Digital signatures use
cryptographic techniques to provide stronger security and authentication for
electronic communications and transactions
Cyber Law
3) Intellectual Property: Cyber law protects intellectual property rights in
cyberspace, including copyrights, trademarks, patents, and trade secrets. It
addresses issues such as online piracy, digital rights management (DRM), domain
name disputes, cybersquatting, and unauthorized use or distribution of
copyrighted material on the internet
4) Data Protection and Privacy: Cyber law establishes rules and regulations for
the collection, storage, processing, and sharing of personal data and sensitive
information in cyberspace. It protects individuals' privacy rights and regulates the
handling of personal data by governments, businesses, and organizations. Data
protection laws govern issues such as consent, data breaches, data security, cross-
border data transfers, and the rights of data subjects
Limitations of Traditional Law and Need For a
Separate Law for Cyber Crime
1) Jurisdictional Challenges: Traditional laws are often limited by geographical boundaries,
making it difficult to prosecute cybercriminals who operate across international borders. Cybercrimes
can originate from anywhere in the world, and enforcing traditional laws against perpetrators located
in different jurisdictions can be complex and impractical
2) Complexity of Cyber Offenses: Cybercrimes involve sophisticated techniques and technologies
that may not be adequately addressed by traditional legal frameworks. The rapid evolution of
cyber threats, including hacking, malware, phishing, and ransomware, requires specialized knowledge
and expertise to investigate and prosecute effectively
3) Global Nature of Cyberspace: Cyberspace operates on a global scale, with interconnected
networks and digital platforms that transcend national borders. Traditional laws designed for
offline activities may not be well-suited to regulate online behavior and digital transactions,
necessitating a separate legal framework for cyberspace
Limitations of Traditional Law and Need For a
Separate Law for Cyber Crime
4. Monitoring of crime: The sheer volume of information involved and being processed
every second makes monitoring and tracking of information very difficult. Internet
surveillance programs such as India’s CMS and America’s PRISM have been deployed
5. Anonymity and Pseudonymity: Perpetrators of cybercrimes can hide their identities
behind anonymous or pseudonymous online personas, making it challenging for law
enforcement agencies to identify and apprehend them. Traditional laws may lack
provisions to address the anonymity and obfuscation techniques used by cybercriminals
6. Patterns: Cybercrime patterns are difficult to identify. This may be due to the fact that
cybercrime is still relatively new. As such the crime map that law enforcement use to
allocate resources for physical space may not apply to cybercrime. The challenge of
identifying cybercrime patterns is also compounded by the fact that cybercrime is not
accurately documented and countries do not track the incidence of cybercrime in the
same way physical space crime is tracked
Limitations of Traditional Law and Need For a
Separate Law for Cyber Crime
7. Evidence Collection and Preservation: Cybercrimes often leave digital traces and
electronic evidence that require specialized techniques for collection, preservation,
and analysis. Traditional law enforcement agencies may lack the technical expertise
and resources to gather and handle digital evidence effectively.
8. Protection of Digital Rights: Individuals' digital rights, including privacy, data
protection, and freedom of expression, require specific legal protections in the digital
domain. Traditional laws may not adequately address emerging challenges related to
online privacy, data security, and surveillance.
9. Cybersecurity Threats: Cybercrimes pose significant risks to national security, critical
infrastructure, and economic stability. A separate law for cybercrime is needed to
establish proactive measures for preventing, detecting, and responding to cybersecurity
threats and cyberattacks.
Cyber Law in India – The Information Technology
Act of India, 2000
The IT Act of India, 2000, is a landmark legislation that was enacted to provide legal recognition
and regulatory framework for electronic transactions, digital signatures, and cybercrimes in India.
The Act was passed by the Indian Parliament on May 9, 2000, and came into force on October 17,
2000
Apart from the provisions for punishment, the IT Act also empowers the Central Government to
issue directions to block access of any information on an intermediary or computer resource for the
public, if it feels necessary in the interest of the State. It can also intercept, decrypt or monitor such
information
Purpose of the IT Act:
The primary purpose of the IT Act is to facilitate e-commerce, electronic governance, and
digitalization of processes by providing legal certainty and security in electronic transactions
It aims to create an enabling environment for electronic communication, electronic records, and
digital signatures, thereby promoting the growth of information technology and the digital
economy in India
Scope of the IT Act
The IT Act applies to the entire territory of India and to any offense or contravention
committed outside India by any person, regardless of their nationality or residence, if
the act or conduct involves a computer, computer system, or computer network
located in India
It covers various aspects of electronic transactions, including electronic contracts,
electronic signatures, electronic records, and electronic payments
The Act also addresses cybercrimes and provides legal mechanisms for investigating
and prosecuting offenses related to unauthorized access, hacking, data breaches,
cyber terrorism, and other cyber offenses
Some Key Provisions of the IT Act
Legal Recognition of Electronic Records: The IT Act provides legal recognition to
electronic records and digital signatures, treating them on par with their paper-based
counterparts. This provision ensures that electronic contracts, agreements, and documents
are legally valid and enforceable in India
Regulation of Electronic Commerce: The Act regulates electronic commerce (e-
commerce) transactions by establishing legal frameworks for electronic contracts, electronic
payments, and online transactions. It provides guidelines for conducting business
electronically and addresses issues related to electronic authentication, payment gateways,
and consumer protection in e-commerce
Cybercrime Provisions: The IT Act contains provisions to address various forms of
cybercrimes, including unauthorized access, hacking, data breaches, cyber terrorism, and
online fraud. It defines offenses related to computer systems, networks, and data, and
prescribes penalties for individuals or entities found guilty of committing cyber crimes.
Some Key Provisions of the IT Act
Liability of Intermediaries: The Act imposes responsibilities and
liabilities on internet service providers (ISPs), web hosting providers,
social media platforms, and other intermediaries for the content
transmitted or hosted on their platforms. Intermediaries are required to
exercise due diligence and implement measures to prevent the
dissemination of unlawful or offensive content
Digital Signatures and Certifying Authorities: The IT Act regulates
the use of digital signatures and establishes certifying authorities
responsible for issuing digital certificates. Digital signatures provide
authentication and integrity to electronic documents and transactions,
ensuring their authenticity and non-repudiation
Cyber Crime and Punishment in India
Penalties under Cyber Crimes:-
a) Section 43 and 66 –
Section 43 and 66 of the IT Act punishes a person committing data theft, transmitting
virus into a system, hacking, destroying data, or denying access to the network to an
authorized person with maximum imprisonment up to 3 years or a fine of rupees 5 lacs or
both. At the same time data theft is also punishable under Section 378 and Section 424 of
IPC with maximum imprisonment of 3 years or fine or both; and imprisonment of 2 years
or fine or both respectively. Denying access to an authorized person or damaging a
computer system is penalized under Section 426 of IPC with imprisonment of up to 3
months or fine or both
66E - Tampering with computer source documents is a punishable offence under Section
65 of the IT Act. Section 66E provides the punishment for violation of privacy. It states that
if any person captures, publishes, or distributes an image of a private area of a person
without his/her consent has committed a breach of privacy and is punishable with
imprisonment up to 3 years or a fine up to 2 lacs or both
Cyber Crime and Punishment in India
Section 66F
Section 66F covers a crucial matter which is cyber terrorism and prescribes punishment for the
same. It provides the acts which constitute cyber terrorism like denial of access or penetrating
through a network or transmitting virus/malware utilizing which he is likely to cause death or
injury to any person, which is all done with the purpose to threat the integrity, sovereignty, unity,
and security of India or create terror in the minds of its citizen
66B and 66 C
Section 66B of the IT Act and Section 411 of IPC deal with the offense of dishonestly receiving
stolen computer resources or devices. Section 66C of the IT Act prescribes punishment for identity
theft and states that any person who uses the identity credentials of a person for fraud or in a
dishonest manner is liable for punishment with imprisonment up to 3 years and a fine up to
Rupees 3 lacs. Cheating by personation using a computer resource is punishable under Section 66D
of the IT Act. Similar provisions for these offenses are given under IPC under Section 419, 463, 465,
and 468. IT Act not only punishes persons but corporate as well if they fail to implement and
maintain a reasonable and diligent mechanism to protect the sensitive data of any person in
their possession. Such a body corporate is liable to pay compensation to the aggrieved person
who has suffered a loss due to the negligence of the corporation
Cyber Crime and Punishment in India
Section 67– Acts related to publishing, transmission or causing publication of obscene/
lascivious in nature
The large amounts of ‘obscene 'material that circulate on the Internet have long attracted
comment in India. Not surprisingly, then, in the same way as obscenity is prohibited offline
in the country, so it is online as well. The most important tools to curtail it are sections 67
and 67A of the IT Act, prohibiting obscene and sexually explicit material respectively.
Whoever publishes or transmits or causes to be published or transmitted in the
electronic form any material which contains sexually explicit act or conduct shall be
punished onset conviction with imprisonment of either description for a term which
may extend to five years and with fine which may extend to ten lakh rupees and in the
event of second or subsequent conviction with imprisonment of either description for a term
which may extend to seven years and also with fine which may extend to ten lakh rupees.
Amendments in the Indian IT Act
A major amendment was made in 2008
It introduced Section 66A which penalized sending "offensive
messages“
It also introduced Section 69, which gave authorities the power of
"interception or monitoring or decryption of any information through
any computer resource“
The Central Monitoring System (CMS) is a mass electronic surveillance data
mining system used in India whereby all data intercepted by TSPs is
automatically transmitted to Regional Monitoring Centers, and
subsequently automatically transmitted to the Central Monitoring System
Amendments in the Indian IT Act - Salient
Features Of Information Technology Amendment Act
Liability of body corporate towards Sensitive Personal Data - New amendment was brought in
changes in Section 43 of IT Act 2000 in which for the first time anybody corporate which deals
with sensitive personal information does not have adequate controls resulting in wrongful loss
or wrongful gain to any person is liable to pay damages to that person to the tune of five crores
Introduction of virus, manipulating accounts, denial of services etc. made punishable-Section 66
has been amended to include offenses punishable as per section 43 which has also been amended to
include offenses as listed above; punishment may lead to imprisonment which may extend to
three years or with fine which may extend to five lakh rupees or with both. This is a change from
an earlier position where the introduction of the virus, manipulating someone’s account has been
made punishable with imprisonment for the first time
Phishing and Spam- While this has not been mentioned specifically but this can be interpreted in the
provisions mentioned here in Section 66 A. Through this section sending of menacing ( frightening
), annoying messages and also misleading information about the origin of the message has
become punishable with imprisonment up to three years and fine
Amendments in the Indian IT Act - Salient
Features Of Information Technology Amendment Act
Stolen Computer resource or communication device – Newly added Section 66B
has been introduced to tackle with acts of dishonestly receiving and retaining any
stolen computer resource. This has also been made punishable with three years or
fine of one lakh rupees or both
Misuse of Digital Signature -Section 66C. Dishonest use of somebody else’s digital
signature has been made punishable with imprisonment which may extend to three
years and shall also be liable to fine with may extend to rupees one lakh
Cheating - Cheating using computer resource has been made punished with
imprisonment of either description for a term which may extend to three years and
shall also be liable to fine which may extend to one lakh rupee (Section 66D)
Amendments in the Indian IT Act - Salient
Features Of Information Technology Amendment Act
Cyber terrorism - The newly introduced Section 66F talks about acts of cyber
terror which threatens the unity, integrity or sovereignty of India or strike
terror in the people or any section of the people
Child Pornography – Newly introduced Section 67 B attempts to address the issue
of child pornography. Through this section it has made the publication or
transmission of material in any electronic form which depicts children engaged
in sexually explicit act or conduct, anyone who creates, facilitates or records
these acts and images punishable with imprisonment of five years and fine which
may extend up to ten lakhs in first offence and seven years and fine of ten lakhs
on subsequent offence
Major Types of Regulation Covered by Cyber Law
India's cyber law, the Information Technology Act of 2000, covers many regulations to address
cybercrime and protect digital assets. Here are the main types of regulations covered by cyber law in
India:
Cybercrime: Cyber law in India defines and penalizes various types of cybercrimes, such as hacking,
cyberstalking, identity theft, phishing, and cyber terrorism. Consumers trust cyber laws to protect them from
online fraud. These laws are in place to prevent identity theft, credit card theft, and other online financial
crimes. A person guilty of identity theft may face federal or state criminal charges
Intellectual Property: Intellectual property is the work, designs, symbols, inventions or anything you own
that is intangible and usually patented or copyrighted. Cyber theft would mean the theft or illegal use of the
same intangible elements. Copyright infringement under cyber law defends the rights of individuals and
businesses to profit from their creative works through copyrights, trademarks, and patents
Trade Secrets: Online companies often depend on cyber law to protect their trade secrets. Take an example
of Google and other online search engines. They spend much time developing algorithms that produce
search results and other features like maps, smart assistance, and flight search services, etc. Cyber lawyers
help clients take legal action to protect their trade secrets
Major Types of Regulation Covered by Cyber Law
Electronic and Digital Signatures: Today, most people and companies use electronic signatures to
verify electronic records. Misuse of such digital signatures by another person is illegal and constitutes
a cybercrime. The law recognizes electronic signatures as legally valid and enforceable, providing a
framework for their usage
Data Security: Data security is a central concern in the Internet age, becoming a huge problem in
litigation. India's data protection and privacy regulatory mechanism is the Information Technology Act
2000. It has a few provisions under Sections 43A, 72 and 72A to tackle crimes associated with
personal data
Data Protection and Privacy: Cyber law in India protects personal and sensitive data by regulating
its collection, use, storage, and disclosure
Cybersecurity: Cyber law in India mandates companies and organizations to adopt adequate security
measures to protect their digital infrastructure from cyber threats
Cyber Forensics: Cyber law in India allows law enforcement agencies to conduct cyber forensic
investigations in cybercrime cases
Major Types of Regulation Covered by Cyber Law
Employment Contract Conditions: Some terms of the employment contract fall under
cyber law, including non-disclosure and non-compete clauses. This can also include the
usage of company email or other digital resources by the employees
Cyber Bullying: The law prohibits cyber bullying and provides legal recourse for
victims
Social Media: Cyber law in Uganda regulates the use of social media platforms and
holds them accountable for the content posted by users
Electronic Evidence: The law recognizes electronic evidence in legal proceedings,
providing a framework for admissibility
Cyber Tribunals: The law provides for establishing cyber tribunals to deal with
cybercrime cases and disputes arising from electronic transactions
Characteristics of Cyber law
The main characteristics of cyber laws are:
Cyber law covers online privacy, data protection, cybercrime, e-commerce, intellectual property, and digital
signatures
Cyber law is enforceable, and violators can face legal consequences. This includes fines, imprisonment, and
other penalties depending on the severity of the offence
Cyber law can be complex because it involves legal, technical, and policy issues. It requires a deep
understanding of the technology and the legal framework
There are security measures for electronic records and digital signatures
Cyber law defines a process for appointing an adjudication officer to conduct investigations
Cyber law provides legal recognition of digital signatures. Furthermore, digital signatures are required to use
an asymmetric cryptosystem and a hash function
Law enforcement officers, including police officers, can record public cases without a court order
Advantages of Cyber law
Cyber law protects individuals and businesses from various cybercrimes, such as hacking, identity
theft, online fraud, and cyberbullying
Cyber law mandates the protection of personal information and data privacy, ensuring that internet
users have control over their personal information and that organizations take adequate measures to
protect such information
Cyber law provides a legal framework for e-commerce transactions and helps establish trust between
parties by providing a secure and reliable platform for online transactions
These laws effectively regulate internet-related activities, including online transactions, intellectual
property rights, and content regulation
Cyber laws encourage innovation by protecting intellectual property rights, promoting technological
research and development, and enabling the creation of new digital products and services
Cybercrime Prevention
Advanced Cybersecurity Protection: This includes fundamental technologies like
firewalls, antivirus software, and intrusion detection systems, but more advanced
cybersecurity systems are evolving with artificial intelligence (AI) and machine learning
(ML)
Multifactor authentication (MFA) protocols that prevent data breaches, hacks, and
other direct cyber-attacks
A Virtual Private Network (VPN) is a service that enables users to browse the Internet
with reinforced security and anonymity. VPNs are engineered to encrypt online activity,
making it far more difficult for cyber-attackers to intercept and steal your data. VPNs
act as intermediaries between your device and the targeted server, adding their own
encryption layer and routing communication via their own servers. VPNs are especially
effective in helping protect against email frauds like phishing scams by masking your IP
address and location
Cybercrime Prevention
Email Security Solutions: Solutions like email encryption to protect email content from
interception, spam filters detect and prevent unwarranted and malicious emails from
reaching your inbox and antivirus software to detect and remove malicious attachments
from emails
Data backup and recovery solutions: Can help mitigate the damages from data loss by
creating backup copies of data and ensuring a faster recovery in the event of a ransomware
attack, data breach, or another form of cyber-attack
Password Manager: In addition to creating secure, difficult-to-hack passwords, password
managers are software applications that securely store multiple login credentials in an
encrypted database, all of which are locked behind a master password. Password managers
are commonly used by organizations, remote teams, and individuals to provide extra
security protection when surfing the web while safely maintaining passwords in a safe
space. The most common password managers include 1Password, KeePass, LastPass, and
Apple's iCloud Keychain
Cybercrime Prevention
Security awareness training: Security awareness training is intended to help
educate users on how to better identify, avoid, and mitigate the threat of cyber-
attacks. Security awareness training helps organizations establish a security-
conscious culture, creating a more resilient network to protect against cyber-
attackers
AI and ML Cyber Crime Protection: More advanced cyber crime prevention
technologies now utilize machine learning and artificial intelligence to gather and
analyze data, track and trace threats, pinpoint vulnerabilities, and respond to
breaches. For example, ML algorithms can detect and prevent fraud in financial
transactions by identifying patterns that indicate fraudulent activity and flagging
them for review. Similarly, AI technologies can detect and prevent cyber-attacks on
networks and systems by analyzing network traffic, identifying abnormal patterns,
and responding to threats in real-time
Emerging Trends in Cyber law
As technology advances, cyber law also needs to evolve constantly. Some emerging trends
in cyber law include:
Data protection laws: Increased data breaches pose the need for strengthening data protection
laws to protect internet users' personal information
Artificial Intelligence and Machine Learning: AI can optimize data breaches and interpret
emerging security threats through machine learning techniques. In future, we will see more and
more use of AI and ML to determine vulnerable information and information systems, recognize
connections between threats, and locate profiles of cybercriminals
Internet of Things (IoT): Blockchain data encryption ensures that the data is not accessible by
unauthorized parties while flowing through untrusted networks. As more devices become
connected to the internet, there is a need for laws and regulations to address issues such as data
privacy, security, and liability
Blockchain technology: The use of blockchain technology is increasing in various industries, and
laws and regulations are needed to govern its use, particularly in data privacy and security areas
Questions?