Wednesday, 10 July 2013

Atlast ! Cyber Security Policy for Pakistan- Inter Services Cyber Command

Senate Committee on Defence and Defence Production Chairman Mushahid Hussain Sayed Monday stressed on establishing a 'cyber security task force' in collaboration with various ministries and security organisations. In his address of welcome at a seminar on 'Defending Cyber Security Strategy for Pakistan,' Senator Mushahid presented his seven-point action plan for promoting cyber security in the country. 
He apprehended that this cyber security threat can affect Pakistan's national defence, security, intelligence, diplomacy, nuclear and missile programme, economy, energy, education, civil aviation as well as industrial and manufacturing units both in the private and public sector. So cyber security is an issue of paramount importance for Pakistan's stability and progress. 

Mushahid quoted that even President Obama has declared that the "cyber threat is one of the most serious economic and national security challenges we faces as a nation" and that "America's prosperity in the 21st century will depend on cyber security." He maintained that Pakistan's cyber security has to have three fundamental elements. Pakistan's digital infrastructure must have the ability to 
                                                                 - resist attacks, 
                                                                 - cyber penetration 
                                                                 - disruption. 
Defend against emerging cyber threats, whether state sponsored or otherwise, and ability to retaliate regionally, at least. The country should have ability to recover quickly from cyber incidents whether caused by cyber aggression, accident or natural disaster. 

Following the recommendations made in seminar, action plan for a Cyber Secured Pakistan has been proposed which includes relevant legislation to preserve, protect and promote Pakistan cyber security, drafting for which has already begun. Bills in Parliament for Cyber Security will be tabled. 

Cyber security threat should be accepted and recognised as new, emerging national security threat by the Government of Pakistan, similar to the threats like terrorism and military aggression. Establishing a National Computer Emergency Response Team (PKCERT). Establishing a Cyber-Security Task Force with affiliation of Ministry of Defence, Ministry of IT, Ministry of Interior, Ministry of Foreign Affairs, Ministry of Information and our security organisations plus relevant and leading professionals from the private security so that Pakistan can take steps to combat this new emerging threat and formulate Cyber Security Strategy for Pakistan. 

Under the office of the Chairman, Joint Chiefs of Staff Committee, an Inter-Services Cyber Command should be established to co-ordinate cyber security and cyber defence for the Pakistan Armed Forces. Within the framework of Saarc, Pakistan should take the initiative to initiate talks among the 8-member states particularly India to establish acceptable norms of behaviour in cyber security among the SAARC countries so that these countries are not engaged in cyber warfare against each other. If Pakistan and India can have an agreement not to attack each other nuclear installations, why not an agreement could be reached seeking the prevention of cyber warfare against each other, the committee recommended. 


* source of report is dependent and copied from Business recorder

Tuesday, 25 June 2013

NATIONAL SECURITY AGENCY OF UNITED STATES DID BOUNDLESS CYBER CRIME WITH “BOUNDLESS INFORMANT”

From the last few days, the news highlighting Edward Snowden whereabouts was of main interest but what did he revealed to Guardian and washington post  is much more important as it relates to national security. I didn’t used the name of any country when I talk about national security because this is the worst form of crime ever did in the history of nations where national security of all the countries is at risk. Therefore naming any one country will not do the job. We are talking about boundless crime did by US-NSA data mining tool namely “boundless informant”. It would be not out of place to mention what Julian assange (founder of wikileaks) Lawyer, Michael Ratner said, "You have to have a country that's going to stand up to the United States".
 Edward Snowden, a system administrator born on 21 june, 1983, employee/contractor in the CIA who gave documents to “The Guardian” and “The Washington Post” newspapers disclosing U.S. surveillance programs that collect vast amounts of phone records and online data in the name of foreign intelligence, often sweeping up information of American citizens. Through this tool officials have the ability to collect phone and Internet information broadly but need a warrant to examine specific cases where they believe terrorism is involved. And more surprisingly everything was being done under an unconstitutional statute of united states i.e. Foreign Intelligence Surveillance Act of 1978. American civil liberties union has challenged this act as unconstitutional and has also filed an appeal in the supreme court of United States which decided the matter namely Clapper Vs Amnesty International USA on 26th February 2013.    
As a Pakistani, I am least concerned with the internal matters of US, but what about our law, our information, our privacy, does it allow any one to violate the privacy of information of our nation. You must be shocked to know that Pakistan was the second largest country whose information’s privacy was compromised and 13.5 billion intelligence was violated by the US NSA. When I saw the heat image generated by the data mining tool i.e. boundless informant, there were only two countries in red colour and Pakistan was one of them. It means that we were on top of the list. What sort of information has been compromised is really important and can this happen again is more important. 
There are a number of questions which sparked in my mind as I saw the image. How is it possible, are we not protected as a nation. Where is the defence budget going if the information is not protected in Pakistan. Todays wars are not of weapons but of information. And we as a nation has failed to protect our information. In my point of view we need to take extra precautionary steps to fight against such acts of international cyber crime. It is very very alarming that how all the information was compromised without the intervention of our government. I am here to discuss and criticize on each and every level of our government. Whether it is the army who is concern with the national security, or it is the Pakistan telecommunication authority who is responsible to “promote and protect the interest of users of telecommunication services in Pakistan” u/s 4 (1)(c) of Pakistan telecommunication re-organization act 1996.  where is the writ of government, for god sake we are in the cyber era and we are still fighting Talibans for nothing. We don’t have any foreign policy w.r.t cyber crime, we do not have laws for cyber crime.  We are not even properly equipped with the level of expertise which are needed to counter cyber crime in todays world of technology. Our government must take concrete steps.

Saturday, 22 June 2013

Cyber Laws in Pakistan


Cyber Laws in Pakistan don’t have any exceptional history, as seen in the international trend, the cyber law making in Pakistan started mainly after 2001 i.e. Electronic Transaction Ordinance 2002. Furthermore a very pointing law, promulgated in 2007, i.e. Prevention of Electronic Crime Ordinance 2007 (PECO). I happened to study the PECO in reference to some cases. It looks good, complete and comprehensive and covering crime from every angle committed in a cyber environment. In start, I feel good about it but later on one thing keeps bothering me i.e. it did not provide a complete remedy for Intellectual Property rights infringement.
Later on, somehow I came to get a copy of Indian Information Technology Act 2000 . Things were very disappointing. I feel a very big and huge unfilled gap in the legislation of PECO, 2007. In fact I personally didn’t notice it unless or until I happened to get the Indian act for comparison. This unfilled gap was the awareness.  Awareness methods through which one can keep himself safe and secure. Here I am giving a comparison in a table form for the chapters of IT BILL 2000(India), ETO 2002(Pakistan) and PECO 2007(Pakistan).


In the above mentioned table, I tried to bring things in a very simple comparison. Nature and the basic architect of the different laws can be easily classified to make some conclusion. If we have a look on the IT bill 2000, which is implemented in India, we will notice that the designer has designed the Law with its basic emphasis on the awareness and introducing safety procedures. Whereas if we have a look to our laws structure, we do find punishments but no procedure to avoid those punishments or to avoid becoming a target or part of any such criminal activity which comes in the domain of cyber environment. Do we find any such thing in our laws?
I appreciate the steps our government has so far taken in establishing grounds for Laws related cyber environment in Pakistan. My request to the government is to change the nature and style of our legislation. May be we can adopt any more better and advanced model of cyber environment then other countries but not more disappointing.  

What Measures Should Government take? 
An incomplete and criminal nature of legislation supports the law enforcement agencies to misuse the loop holes left in the legislation. Our law should be focused on the procedures one can take to avoid any mishap. It is very unfortunate that in PECO, we don’t even find a single chapter related safety precautions. We don’t find anything dealing with the procedures for avoiding any cyber crime.
According to my point of view, in today’s world, computers are the weapons and therefore if we equip someone with this weapon, it’s the duty of government to also give them awareness of this weapon for its positive use. The government should initiate awareness campaign. The main interesting thing in this awareness campaign is that domain of this campaign is well defined i.e. computer literate or technology literate. What I suggest is that the government should introduce a compulsory subject in universities, from where most of our technology related public belongs. Contents of such subject should be covering the cyber environment, how to avoid being a target of cyber crimes or becoming part of such crimes.  Such Subject should be   from the Government to guide and to educate the computer literates about these cyber crimes. This will result in a network of information and automatically we will see the results of such awareness and control over cyber environment.

Thursday, 13 June 2013

whats there for the FIA-NR3C in budget 2013-Pakistan

the new Pakistan government has allocated PKR 147.7 million for the FIA- NR3C (national response centre for cyber crime) Rawalpindi. Hope they will also take initiative for the passing of new law related the cyber crime which is badly needed right now.
and one suggestion for the NR3C to use a part of this budget to promote the laws and they can even manage it by taking sponsors from telecom sectors. I think they will have no objection or problem in supporting the FIA- NR3C as they are one of the major affectees of cyber crime.

Wednesday, 26 December 2012

GOING FOR THE SKY FALL: CYBER CRIME

Recently I saw James Bond movie, named “SKYFALL”.  Its basic theme or the reality simulated in the movie can be best understood with statement of Leon e. Panneta, US defense secretary who quotes as, “An aggressor nation or extremist group could use these kinds of cyber tools to gain control of critical switches”.
Movies are like simulated reality which we usually face in our real life especially talking with reference to Pakistan and cyber crime. In Pakistan we have laws for everything although the phase of implementation of these laws is very selective and sensitive. In light of my little experience as a practicing lawyer, it is job of a street guy or a rich guy to survive in Pakistan and to get through all the legal requirements for normal living and to meet the expenditures of daily routine including utility bills.
Today Pakistan is getting equipped with all the latest online payment techniques and methods similar to the one adopted in developed countries but if a state like US, is worried about the threat of cyber crime or cyber terrorism as can be seen from the statement of their defense secretary then why Pakistani Government feel so comfortable before opening this new Pandora box of online payment methods without any proper legislation. In my career as cyber laws expert in Pakistan, I have not seen cyber criminals equipped with state of the art technology or technique. I have seen mostly illiterate criminals with knowledge of loop holes in the security system which they breach for their ulterior motives. Their adopted methods are very simple but rare. We do have hackers in Pakistan but till to-date most of the hacking, defacing done by them seems to be just a show off their skills. We need to address them properly and on time before their mind get polluted with ideas of misusing their skills. We need to limit them by implementing laws through our law enforcement agencies. but unfortunately in the world of cyber, Pakistan is a like a country where there is traffic on motorway but no laws or rules to control that traffic therefore probability of  accidents is very high.
The domain of Cyber crime cannot be limited with a couple of words. It is available in every form and in today’s world every walk of life is affected from cyber crime. The basic reason for such a vast domain of affectees is due to revolutionary changes in the life style across the worldwide. Just for sake of arguments few days back, a Turkish hacker claim to deface the national website of our law enforcement agencies and got access of sensitive data. Can we make him accountable in Pakistan? Our active law dealing with cyber crime i.e. Electronic Transactions Ordinance 2002(ETO), whose preamble says that it is applicable in Pakistan only, can we go and get that hacker sitting in Turkey to make him accountable. I think it’s hard unless we couple some sections of Pakistan Penal Code with the ETO to get our desired results. It is also pertinent to mention here that this Turkish hacker claim that he simply want to show his skills to challenge some renowned Pakistani Hackers. This unwanted race of showing skills can take things to disastrous results.
I think Pakistan government must come up with some strict but good and different legislation from the previous Prevention of Electronic Crime Ordinance 2007(PECO) where the crux of the ordinance was only of penal nature. The person drafting the law must understand that he is drafting something for the betterment of the public in whole, to give good policies in their drafts so that laws can be meaningful and implementable. In this regard I found Indian ITBill 2000 very informative and comparatively applicable; with solutions to problem which one can face in the world of cyber crime. I would like to end my thoughts with some interesting canto from practically anonymous book called Poetic Justice by "J.P.C." published in 1947 which enlivens my criticism:
I am the parliamentary draftsman; I compose the country's laws.
Of half the litigation in the nation, I am undoubtedly the cause.
I am the parliamentary draftsman, and my sentences are long.
They are full of inconsistencies grammatically wrong.
I put parliamentary wishes into language of my own,
And though no one understands them they’re expected to be known.