{"id":85864,"date":"2023-01-17T08:30:00","date_gmt":"2023-01-17T08:30:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/archives\/85864"},"modified":"2023-01-17T08:30:00","modified_gmt":"2023-01-17T08:30:00","slug":"crest-throws-support-behind-cyberup-cma-reform-campaign","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=85864","title":{"rendered":"Crest throws support behind CyberUp CMA reform campaign"},"content":{"rendered":"<div><img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2023\/01\/crest-throws-support-behind-cyberup-cma-reform-campaign.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>Campaigners who want to reform the UK\u2019s <a href=\"https:\/\/www.legislation.gov.uk\/ukpga\/1990\/18\/contents\">Computer Misuse Act<\/a> (CMA) of 1990 to protect cyber security researchers and analysts from <a href=\"https:\/\/www.computerweekly.com\/news\/252492416\/Security-pros-fear-prosecution-under-outdated-UK-laws\">the threat of being prosecuted for doing their jobs<\/a> have an important new backer in the form of cyber professional accreditation and assurance body <a href=\"https:\/\/www.crest-approved.org\/\">Crest International<\/a>.<\/p>\n<p>The <a href=\"https:\/\/www.cyberupcampaign.com\/\">CyberUp<\/a> campaign argues that the CMA, which turns 33 this year, is laughably out of date and does not properly reflect the evolution of the cyber security profession over the past three decades.<\/p>\n<p>The group\u2019s main concern is that the wording of the law, in particular the concept of \u201cunauthorised access\u201d to a program or data held on a computer.<\/p>\n<p>Since defensive security activity frequently entails scanning, interrogating and accessing computer systems, the campaign says a prosecutor could successfully argue that a cyber professional breaks the law when they use common and accepted defensive techniques in their work.<\/p>\n<p><a href=\"https:\/\/www.computerweekly.com\/news\/252500572\/Government-to-reform-Computer-Misuse-Act\">Reform was promised in 2021<\/a>, but the process has become bogged down even though there is now a widely agreed consensus <a href=\"https:\/\/www.computerweekly.com\/news\/252523826\/Report-reveals-consensus-around-Computer-Misuse-Act-reform\">that the law must be changed<\/a>.<\/p>\n<p>\u201cCrest has supported and admired the efforts of the CyberUp Campaign since its inception, so it is great to make this support official,\u201d said Rob Dartnall, chair of Crest\u2019s UK Council.<\/p>\n<p>\u201cThe Computer Misuse Act is out of date and its view of security testing and threat intelligence is not fit for today\u2019s increasingly digitised world with ever growing and more sophisticated cyber threats.<\/p>\n<p>\u201cIn 2021, CyberUp secured a comprehensive review of the act, so it is now important for industry in the UK to collaborate to ensure substantial reform happens. We will be working with the campaign to help engage industry and drive forward successful reform.\u201d<\/p>\n<p>A spokesperson for the CyberUp campaign said: \u201cThe CyberUp Campaign is delighted to have Crest International on board as a supporter.<\/p>\n<p>\u201cWe are very much looking forward to working with Crest and its members in the UK to ensure the reform of the Computer Misuse Act. The UK is on the precipice of a historic change in our cyber crime laws. Help from organisations like Crest is essential if we are to make sure this once-in-a-generation opportunity does not go to waste.\u201d<\/p>\n<p><a href=\"https:\/\/www.cyberupcampaign.com\/news\/new-research-legitimate-cyber-security-activities-in-the-21st-century\">An August 2022 report<\/a> produced by the CyberUp campaign set out to reassure policymakers that reform would not open up a \u201cWild West\u201d of cyber vigilantism.<\/p>\n<p>The report categorises cyber activities into acts that cause no or limited harm but deliver benefit, acts that cause harm and deliver benefit, acts that cause no harm and deliver no benefit, and acts that cause harm and deliver no benefit.<\/p>\n<p>In the first category, CyberUp proposed the government make a total of 13 activities defensible in law \u2013 the use of application programming interface (API) keys, banner grabbing, the use of beacons, the implementation of firewalls and network access controls, the use of honeypots, the use of open directory listings, passive intelligence gathering, port scanning, the use of sandboxes or tarpits, taking down servers or botnets, sink-holing, web scraping, and malware analysis.<\/p>\n<p>Activities likely to fit the final category, which would remain indefensible in law, could include hacking back, conducting distributed denial-of-service attacks, the use of malware and ransomware, malicious \u201csocially undesirable\u201d acts, the validation of exploits or proof of a failed security boundary, and breaking into systems deemed part of critical national infrastructure.<\/p>\n<p>The report also highlighted some grey areas, particularly around activity described as <a href=\"https:\/\/www.techtarget.com\/whatis\/definition\/active-defense\">active defence<\/a>, which can include actions such as infiltrating the networks or systems of threat actors, verifying passive-detected vulnerabilities, exploiting vulnerabilities, credential stuffing, neutralising suspicious or malicious assets, active intel gathering, the use of botnets, and active investigation and forensic analysis.<\/p>\n<p>The campaign\u2019s work continues.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Campaigners who want to reform the UK\u2019s Computer Misuse Act (CMA) of 1990 to protect cyber security researchers and analysts from the threat of being prosecuted for doing their jobs have an important new backer in the form of cyber professional accreditation and assurance body Crest International. The CyberUp campaign argues that the CMA, which [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":85865,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-85864","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/85864","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=85864"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/85864\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/85865"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=85864"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=85864"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=85864"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}