Week 2 Lecture 3 Law 2 CSEC1001 CMA 1990 - Copy

CSEC1001 Foundation of Computing and Cyber Security

Week 2 - Lecture 3

  • Introduction at De Montfort University by Mr. Ivan Stafford

The Computer Misuse Act 1990

  • Overview of the Act and criminal law

Learning Objectives

  • Understand basics about crime and criminal offences

  • Recognize that hacking is a criminal offence

  • Note the evolution of the Act over a short period

  • Acknowledge serious offences and penalties defined by the Act

Basics of a Crime

  • Two required elements for establishing a crime:

    • Actus Reus: The physical action involved in the crime.

    • Mens Rea: The mental state or guilty intention of the perpetrator.

Mens Rea Explained

  • Mens Rea involves:

    • A guilty intention or thought level (subjectively or objectively evaluated).

    • Determined by judge or jury on a qualitative basis.

Instigation of the Computer Misuse Act 1990

  • Case Study: R v. Gold and Schifreen

    • Culprits obtained login details from a BT engineer through shoulder surfing.

    • This access potentially led to nuclear system activation, highlighting a gap in criminal law.

Need for the Computer Misuse Act

  • Previous crimes (theft, fraud, blackmail) did not encompass the new forms of cyber-crime.

Recklessness vs. Intent

  • The Act differentiates between:

    • Recklessness required for some offences (Section 3).

    • Intent required for others.

Definition of Recklessness

  • Based on R v. Caldwell [1982], where a reasonable person would have noted the risk.

    • Recognizes both obvious risk and disregard of risk.

Current Recklessness Standard

  • R v G [2003] established a subjective view, focusing on the defendant's known circumstances.

Criminal Standard of Proof

  • Must be proven beyond reasonable doubt.

Criminal Offences Created by the CMA 1990

  1. Section 1: Unauthorised access to computer material (Hacking).

  2. Section 2: Unauthorised access with intent for further criminal acts.

  3. Section 3: Unauthorised acts intending to impair computer operations or reckless to impairing them.

  4. Section 3A: Making or supplying articles for offences under Section 1 or 3.

  5. Section 3ZA: Unauthorised acts causing serious damage or risk thereof.

Definition of Computer

  • Deliberately broad, covering technological advancements.

    • Defined in case law as a device for storing, processing, and retrieving information.

Section 1 Details

  • A person is guilty if they intentionally secure unauthorised access.

Section 2 Details

  • Focus on intent to further commit or aid in committing an offence.

Section 3 Details

  • Covers intentional unauthorised acts affecting computer operations or data.

Section 3A Details

  • Covers creating or supplying articles for offences.

Section 3ZA Details

  • Defines the serious damage that could result from unauthorised acts toward human welfare, environment, economy, or national security.

Penalties for Section 3ZA Offence

  • Maximum imprisonment of 14 years or life imprisonment for severe cases affecting welfare or national security.

Territorial Scope of the CMA 1990

  • Offences can occur regardless of the location of the act or offender, but must have a significant link with domestic jurisdiction.

Warrants for Enforcement

  • Judges may issue search warrants based on reasonable grounds for believing an offence is committed.

Definition of Premises

  • Clarification that 'premises' includes various physical and movable structures.

Conclusion

  • Overview of the Computer Misuse Act 1990 and its implications on cybersecurity laws.