African countries are taking great strides in their efforts to combat cybercrime. As a multibillion-dollar industry, the need for appropriate legislation addressing cybercrime is imperative, particularly as far as legislating malware goes. Among the African countries that have taken legislative steps to address cybercrime are South Africa and Senegal, both taking cues from the Council of Europe Convention on Cybercrime (Budapest Convention). This paper interrogates the legislative responses of both countries to the threat of malware as contained in the respective provisions of the South African Cybercrimes Act 19 of 2022 and the Senegalese Cybercrime Law 2008-11. It finds that both countries have employed the Confidentiality, Integrity, and Availability cybersecurity model (CIA triad) to inform how the offences in the legislations are defined and formulated. Interestingly, it notes that although the same model is used by both countries, the way that the CIA triad has been incorporated into the respective laws differs in significant ways, with potentially varying results. Given that both South Africa and Senegal are parties to the Budapest Convention, to different extents, it is appropriate to use the Convention as the benchmark against which to judge the respective provisions. To do so, this paper draws upon the specific offences provided for in both countries regarding unauthorized access to and interference with computer systems. Despite South Africa’s decision not to ratify the Budapest Convention and Senegal’s leap to ratify, it appears that South Africa has adhered more closely to the Convention than Senegal. Seemingly odd, it may be viewed as a testament to the fact that the Convention is meant to guide countries in their legislative endeavors rather than being prescriptive.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

The South African and Senegalese Legislative Response to Malware-Facilitated Cybercrime

  • Sagwadi Mabunda

摘要

African countries are taking great strides in their efforts to combat cybercrime. As a multibillion-dollar industry, the need for appropriate legislation addressing cybercrime is imperative, particularly as far as legislating malware goes. Among the African countries that have taken legislative steps to address cybercrime are South Africa and Senegal, both taking cues from the Council of Europe Convention on Cybercrime (Budapest Convention). This paper interrogates the legislative responses of both countries to the threat of malware as contained in the respective provisions of the South African Cybercrimes Act 19 of 2022 and the Senegalese Cybercrime Law 2008-11. It finds that both countries have employed the Confidentiality, Integrity, and Availability cybersecurity model (CIA triad) to inform how the offences in the legislations are defined and formulated. Interestingly, it notes that although the same model is used by both countries, the way that the CIA triad has been incorporated into the respective laws differs in significant ways, with potentially varying results. Given that both South Africa and Senegal are parties to the Budapest Convention, to different extents, it is appropriate to use the Convention as the benchmark against which to judge the respective provisions. To do so, this paper draws upon the specific offences provided for in both countries regarding unauthorized access to and interference with computer systems. Despite South Africa’s decision not to ratify the Budapest Convention and Senegal’s leap to ratify, it appears that South Africa has adhered more closely to the Convention than Senegal. Seemingly odd, it may be viewed as a testament to the fact that the Convention is meant to guide countries in their legislative endeavors rather than being prescriptive.