**Review on Cybersecurity Policies in Several Countries**

**Tan Ivy<sup>1\*</sup>, Mohamad Fadli bin Zolkipli <sup>2</sup>  
***<sup>1,2</sup> School of Computing,  
Universiti Utara Malaysia, Sintok, 06010 Bukit Kayu Hitam, Kedah*

*Corresponding author: [\*](mailto:*norpah020@uitm.edu.my)  
*Received Date: 25 March 2021*  
*Accepted Date: 31 March 2021*  
*Published Date: 31 May 2021

**HIGHLIGHTS**

  - Cybersecurity is a way that allows organizations to protect computer networks from targeted attackers, invaders, and opportunistic malware.

  - Cyberattack is an attack released by cybercriminals who use more than one computer against one or more computers or networks.

  - Cybersecurity policies are essential in different countries due to the fact cyberattacks and records breaches are probably costly.

  - Cybersecurity strategy was implemented in different countries in order to enhance the safety and resilience of the country’s infrastructure and services.

**ABSTARCT**

*The purpose of this paper is to study the network security policies and strategies of different countries. As the cybersecurity attacks are gradually increasing around the world, people are extremely insecure when using the Internet. Therefore, each country has established their own cybersecurity policies and strategy in order to reduce crime rate and protect the personal safety of citizens while using internet. In this paper, it reviewed the cybersecurity policies and the cybersecurity strategies in several countries such as Japan, Australia, Malaysia, and the European Unions. As conclusion, it is important to promote cybersecurity awareness or the policies of cybersecurity efficiently and using the right cybersecurity strategy so that all internet users can use internet with no worry of cybersecurity attack.*

*Keywords: Cybersecurity, Cybersecurity Attack, Cybersecurity policy, Cybersecurity Strategy*

# **INTRODUCTION**

Cybersecurity is the safety of internet-linked systems which includes hardware, software, and information from cyber threats. The major body of technology, practice, and process aimed at protecting networks, systems, devices, and data from threats, destruction, or unauthorized access is known as cybersecurity. Information technology security is another term for cyber security. A successful network security method has multi-layer protection, which is distributed on the protected computer, network, program or data. Cybersecurity may also be described as a set of principles and practices for protecting our online information and computing resources against attacks. Since data leakage and cyberattacks can be costly, cybersecurity policies are critical. Meanwhile, employees are always vulnerable spot in an organization's security. For example, employees share the passwords, click the malicious attachments or malicious website link, use unauthorized cloud software application, ignore to encrypt sensitive data and files. Cybersecurity is an important issue for IT departments and C-level executives alike. However, cybersecurity has to be the concern of every employee (not only IT professionals and senior manager) in the organization.

An effective method to educate every employee is a cybersecurity policy which explains everyone’s responsibility in protecting IT systems and data. Cyber security policies set standards of behaviour for activities such as encrypting email attachments and limiting social media use. The organization is responsible for protecting the organization’s written documents against threats and the measures to be taken in case of threats. Cyber security policies are also crucial to an organization's credibility and public image. Partners, customers, shareholders, and potential employees want evidence that organizations can protect their sensitive data. If there is no cybersecurity policy, the organization would not be possible to provide such evidence.

The organizational structure of this article is as follows. Introduction is discussed in Section 1 while literature review is presented in Section 2. Furthermore, the review on cybersecurity policies in different countries is discussed in Section 3. Moreover, Section 4 shows cybersecurity strategy in different countries and cybersecurity threats will be presented at Section 5. Finally, a conclusion is constructed as a suggestion to prevent cybersecurity threats.

# **LITERATURE REVIEW**

# **CYBERSECURITY ATTACK TYPES**

# **Distributed Denial of Service (DDoS) Attacks and Denial of Service (DoS) Attacks  
**

Denial of service attack (DoS) is a type of cyberattack in which an attacker denial of legality users’ access to a computer by making the memory resources to deal with valid requests (Raiyn, J. 2014). DDoS assault is likewise a cybersecurity attack on device resources; however, it's far initiated via way of means of a massive quantity of different hosts, that are inflamed with malicious software program managed via way of means of the attacker. Most not unusual place kinds of this attacks are TCP SYN flood attack, smurf attack, teardrop attack and so on. Figure 1 shows the example of DDoS attack which is TCP SYN flood attack.

![SYN Flood DDoS Attack | Cloudflare](202-1-617-1-4-20210509_media/media/image1.png)

Figure 1: TCP SYN flood attack

**Malware**

Malware attack is a common type of network attack. Malware operates the victim's system without authorization. The main purpose of malware is to steal, encrypt or delete sensitive data from your system. It can also change the intent of a function without your consent. Most common types of malware attack are trojans, viruses, worms, adware, spyware, ransomware, and scareware (Bendovschi, A., 2015). Figure 2 shows the example of malware attack which is trojans attack.

![What is a Trojan Virus | Trojan Horse Malware | Imperva](202-1-617-1-4-20210509_media/media/image2.jpeg)

Figure 2: Trojan Virus

**Man-in-the-Middle (MitM) Attacks**

The man-in-the-middle attack means that the attacker intervenes between two communication ends, so every message sent by victim A to victim B will arrive the attacker before arriving the destination. Other risks posed by such attacks include unauthorized access to sensitive information, otherwise the attacker may change the information/messages arriving at the destination. Figure 3 shows the example of man-in-the-middle cyberattack.

![](202-1-617-1-4-20210509_media/media/image3.jpeg)

Figure 3: Man-in-the-Middle cyber attack

**Phishing**

Phishing is one of the most common types of cyberattacks. Phishing is a technology designed to pilfer users' private information by feigning to be a trusted source like a website (Bendovschi, A., 2015). Phishing attacks can also be carried out through certain online forums and social media sites via sends messages with hidden intent directly from another user. Phishers often use other public information resources and social engineering to gather information about your work, activities and so on which providing advantage to the attacker when it comes to convincing you rather than talking about themselves. There are various types of phishing attacks such as spear phishing, whaling and pharming. Figure 4 shows the example of phishing attack which is spear phishing.

![Spear Phishing Attack - an overview | ScienceDirect Topics](202-1-617-1-4-20210509_media/media/image4.jpeg)

Figure 4: Spear phishing

# **CYBERSECURITY POLICIES IN DIFFERENT COUNTRIES**

**Cybersecurity Policy of Japan**

In December 2004, Japan re-examined the role and functions of the government in information security issues and start organizing functions and systems which involving the information security issues. This is because Japan needs to strengthen the government-centered system. In addition, Japan has built the National Information Security Center (hereinafter referred to as NISC) as an information security control tower under the jurisdiction of the government in year 2005. In addition, it has established safety standards, stipulated protective measures level for crucial infrastructure, and administers the CEPTOAR- Council, which aims at public partnerships and private partnerships (Min et. al.,2015). Japan formulated the "First National Information Security Strategy: Facing the Establishment of a Trusted Society" in 2006 and put forward the basic concepts and policy directions for information security. Especially, Japan has also contributed to form the international cybersecurity standards. The stage of government intervention is characterised through voluntary self-regulation, and numerous authorities departments enforce a public cooperation system and personal cooperation system in Japan. For example, the Ministry of interior and communications of Japan, together with the Ministry of communications enterprises and economy, has organized a Public-Private Partnership Committee called "Telecom ISAC Japan". The Bureau of industry and commerce also manipulate the cooperative information system with manufacturing employees through the Japan network security information sharing Partnership Initiative (J-CSIP). In this situation, every government and the private sector work one on one to promote self-cooperation. However, Japan expressed their willingness to establish a cybersecurity governance committee to encourage public-private partnerships and implement government-led strategies to overcome difficulties in inter-departmental cooperation (Persadha et. al.,2015).

**Cybersecurity Policy of Australia**

Australia government has been implemented a number of policies in order to protect its cyber assets. There are major reasons for the Australian government suppose that one of the most crucial regulations is cybersecurity. The first reason is cyberattacking have affected Australian businesses and individuals. The second reason is the potential damage caused by cyber-attacks to credibility of individuals or groups in Australian ICT. Cyber security should be seen as a team effort. The organization are not able to technically address every issue and satisfied all expectations. As a result, few people in Australia have created a different role to deal with cyber security issues. Australian Federal Government is the first role, and it has four responsibilities. First responsibility is to formulate, and implement laws, regulations, and policies related to network security. It must then engage in global cybersecurity to strengthen cooperation and coordination in dealing with cyber threats. Second, it must offer public cybersecurity policies as a tool for investigating cybercrime activities. Giving suggestions, operational capabilities and references to distinguish and discover cybersecurity attacks is the last responsibility. Moreover, state and regional governments will be assumed as second role. Generally, state and regional governments have the same responsibility as the federal government. The greater responsibility of state and regional governments is actually educating people, especially children and young people, about cybersecurity attacks or threats and how to deal with them. ISPs consider third actors, whether legal or illegal, to provide Internet service for every traffic and transaction. Furthermore, the ISP is responsible for providing its users with secure lines of communication. One of the practical actions taken by the ISP community in terms of online safety is to refuse to provide sites that contain inappropriate content, such as misuse a child. Next, they volunteer to identify malware affecting users' computers, notify users, and offer help and repair suggestions. Some ISPs also provide customers with anti-virus and network security software while they are conducting online activities. The owner and manager of information and communication technology (ICT) systems is last role which including individuals and companies. This group plays an important role because they are able to execute cyber security system in their own facilities (Persadha et. al.,2015). If each of them implements a strong network security system, malware will not easily spread between systems.

**Cybersecurity Policy of Malaysia**

Malaysia has a series of existing legislation which dealing with the cyber environment. Technology, and Innovation (MOSTI) is one of Ministry of Science which in charge for devising a framework for the national cybersecurity policy of ICT. Malaysia has formulated a policy called the National Cyber Security Policy (NCSP) through this institution. MOSTI is used to monitor the agency’s response to computer emergencies, known as the Malaysian Computer Emergency Response Team (MyCERT) (Persadha et. al.,2015). The birth of NCSP stems from Malaysia’s 2020 vision that ICT is the hinge to every industry. Malaysia has to receive the danger of revealing its data and resources to cybersecurity threats especially if the target of the cyberattack is the Critical National Information Infrastructure (CNII) to this end. Therefore, NCSP is a true and via application to protect CNII security. This is because NCSP very important to ensure the CNII is secure, self-reliant and flexible to increase the level of prosperity and welfare of the nation. It is important to the nation when each asset, whether functional, or physical, is associated with CNII. Therefore, any degradation or impairment of capabilities would endanger the image, defence, national economy, and security, government work capabilities, safety and public health. Malaysia able to implement NCSP in order to defend its CNII. Malaysia Cyber Security Agency (CSM) was established in order to obtain field support from NCSP. CSM is responsible for operational services, including cybersecurity emergency, information security professional development, and so on. Malaysia also believes that there was a terrorist attack on the CNII facility. The tendency to carry out terrorist attacks via ICT due to the fact which may have the significant impact on the country under attacked, serious damage under bad conditions due to discontinuation of essential services. In this regard, the information and communication technology use are more harmful than regular attacks in terrorism. Another Malaysian government agency brought into the implementation of cyber security is the Malaysian Communications and Multimedia Commission (MCMC). In Malaysia, this agency is responsible for overseeing and managing multimedia activities and communications. Then, this includes telecommunication regulations, broadcasting, Internet service providers (ISPs), express delivery and postal, and digital certificate authorization. The Personal Data Protection Act 2010 (PDPA) is designed to protect personal data from abuse in the case of personal data protection (Sunkpho, et. al., 2018).

**Cybersecurity Policy of European Union**

European cybersecurity policies are customized and enforce with multi and multilevel stakeholder structure. Not only are domestic and foreign policy separate, but the legislative powers and the private-public spheres of authority and responsibility are politically interrelated (Bendiek, A., & Porter, A. L, 2013). Cybersecurity in European Union is a relatively new field, from playing a secondary auxiliary role in the integration process, it has become its unique policy field in year 2013 (Helena Carrapico & Benjamin Farrand, 2020). The core for the new area of policy is to strive for system and policy consistency which is seen as the key to effectively addressing the current cyber challenges facing Europe. Consistency is particularly important in the EU's cybersecurity policy because its governance has long been highly fragmented, with the relevant actors working independently in different areas of law. The continuous pursuit of policy consistency, as well as the increasing attacks on crucial information infrastructure, personal data and business data, has prompted the European Union to further enhance their new role by issuing the first cybersecurity strategy in year 2013. The Directive sets out event reporting voluntary for the private sector which including basic service operators and digital service providers (Carrapico & Barrinha, 2018).

# **CYBERSECURITY STRATEGIES OF DIFFERENT COUNTRIES**

**Cybersecurity Strategy of Japan**

Japan's 2010 National Cyber Security Strategy focuses mainly on protecting national information systems by taking defensive measures against large-scale cybersecurity attacks, large-scale network attacks have become more and more popular recently. A number of well-crafted action plans have been developed to achieve the best delivery of national information system security (Oluwafemi & Agada, 2015). Since then, Japan has continuously formulated and revised its information security strategy, and finally formulated a cybersecurity strategy in year 2013. The protected target area is magnified from a strategy centered on information security to a cyber security strategy, and the importance of cyberspace is recognized in this strategy (Min, et. al., 2015). In addition, Japan’s cyber security strategy also has many similarities with the United States, such as establishing public and private cyber security standards, forming an information sharing system between stakeholders, etc. In addition, Japan is also trying to exercise global leadership by proposing cybersecurity J-initiatives.

**Cybersecurity Strategy of Australia**

Australia's cybersecurity strategy has been approved since 2013 which is included in its National Security Strategy and Defence White Paper. In addition to the National Security Strategy, Australia also wants to identify national security risks in order to protect their assets and infrastructure, such as organised crime, malicious cyber activity and so on. The long-term priority is to integrate network policies and actions to enhance the defence capability of Australia's digital network. The National Security Strategy emphasises the cybersecurity strategy as a fundamental pillar of future in Australia. The national laws and law enforcement agencies are committed to securing the privacy of their citizens and their cyber environment. They have determined cyberattacks that affect businesses, government agencies, and citizens, such as identity theft, denial of service, and cyber espionage. In 2011 and 2012, Australia’s cybersecurity spending was 480 million Australian dollars. Their approach includes intelligence alliances with 125 countries to deal with cybersecurity threats and implementing cyber programs between industry and government. The Australia-US alliance is the most crucial security relationship (Sabillon et. al., 2016).

**Cybersecurity Strategy of Malaysia**

One of the cybersecurity techniques they have got to conquer the cyber threat is the enforcement of the law on this issue. Both the private organizations and Malaysian Government have been involved in improving this approach. Some of the institutions from government sector are responsible for dealing cyberthreats. The government agency in Malaysia is Cybersecurity Malaysia which responsible for security quality management, cyber security emergency services, cyber security strategic engagement and research as well as Information Security professional development. The agency manages three portals of cyber security strategy policy research, such as Critical National Information Infrastructure (CNII), malware research center and cyber technology research (Sabillon et. al., 2016).

**Cybersecurity Strategy of European Union (EU)**

Currently all international locations withinside the European Union have a National Cybersecurity Strategy (NCSS) as a key coverage feature, assisting them to address dangers that have the ability to undermine the fulfilment of financial and social advantages from cyberspace. The cybersecurity strategy appears to focus on the proposed "Digital Agenda for Europe (DAE)" action plan as the comprehensiveness of the European Union cybersecurity strategy drawn up in 2010. The Cyber Security Strategy sets out five specific action plans and coordinated programmes, including the relevant public and private stakeholders, such as the EC, European Cyber and Information Security Alliance (ENISA) and European Cyber Crime Centre (EC3) in order to implement these five plans. It is recommended to use Network and Information Security (NIS) for successfully implementing the program through the Network Security Policy. The NIS aims to protect information security by establishing a common EU standard, which regulates online stability monitoring and the establishment of CERT (Min et. al., 2015).

# **DISCUSSION  
**

More and more people spend more time on the Internet. The current global climate provides a mature hunting ground for hackers and other unfriendly online predators, as well as provides potential victims steadily and unconsciously. Up to now, although various countries have formulated a series of policies and strategies for cybersecurity. However, the cybercrime rate in many countries is still growing gradually according to statistics. According to the news reported by Cybersecurity ASEAN, there has already been 10722 cybercrime incidents reported in Malaysia in year 2019 which has been increase compared to the same period in 2018. Furthermore, approximately 8366 cybercrime incidents were stated from January to September 2020 primarily based totally on the statistics through Malaysia Computer Emergency Response Team (MyCert). Unfortunately, Japan is facing the same problem as what Malaysia faced. In year 2019, Japan has setting a new record of 9542 of cybercrime cases. Based on the research, the cybercrimes which uncovered by the police in Japan rose 5.6% year-on-year. Same thing was happened in Australia as well. According to the report proposed by the Australian Cyber Security Centre (ACSC), they received 59806 cybercrime reports in year 2020 which approximately 164 cybercrime reports per day or one report in every minutes.

Regarding the increase of cybercrime rate in 2020, there are some statements were worthy of discussion. In year 2020, most of the country was having lock down or Movement of Control Order (MCO) due to the Covid-19 pandemic. Within this period, people are required to stay at home most of the time. Therefore, people have more time to surf on internet and more vulnerable to the threats of cybercrime as they might give out their personal information via email or over the social media. On the other hand, some muddle users may click any URL links in spam emails or other messages from unknown sources. According to Communications and Multimedia Deputy Minister Malaysia, cyber fraud reported to cybersecurity in Malaysia increased by 22% between January and August 2020. Table 1 shows the comparison for the use of cybersecurity policy between different countries.

| **Country**    | **Cybersecurity Strategy**              |
| -------------- | --------------------------------------- |
| Japan          | The Personal Information Protection Act |
| Australia      | Australia’s Cybersecurity Strategy      |
| Malaysia       | MyCert                                  |
| European Union | National Cybersecurity Strategy (NCSS)  |

Table 1: The use of cybersecurity strategy between different countries.

# **CONCLUSION  
**

Nowadays, people's daily activities are inseparable from the network. Therefore, there are many criminals often use network vulnerabilities or cybersecurity attacks to do something illegal and make people panic. In the nutshell, it is important for peoples nowadays to increase their awareness and knowledge of cybersecurity attacks and abide by the cyber security regulations which set by the governments of each country. Therefore, the cybersecurity policies have to be well promoted no matter the government agencies of each country, private organizations, and even the people of all countries, they should promote cybersecurity awareness or the policies of cybersecurity to people around them so that more people know its importance, and everyone can use internet with no worry of cybersecurity attack. Thus, the government should strengthen the cybersecurity policies and improve the strategy in order to combat the cybercrimes. Besides, the users should be aware while using internet to avoid themselves becoming the victims of cybercrime.

# **ACKNOWLEGMENTS  
**

The authors would like to thank to all School of Computing members who involved in this study. This study was conducted for the purpose of System and Network Security Research Project. This work was supported by Ministry of Higher Education Malaysia and Universiti Utara Malaysia.

# **REFERENCES**

Abomhara, M., & Køien, G. M. (2015). Cyber Security and the Internet of Things: Vulnerabilities, Threats, Intruders and Attacks. Journal of Cyber Security and Mobility, 4(1), 65–88. doi:10.13052/jcsm2245-1439.414

Aliyeva, LM, & Hwang, G.-H. (2019). Establishment of an implementation model of cybersecurity policy and strategy for Azerbaijan information system. Digital Convergence Research, 17 (5), 23–31. [doi: 10.14400/JDC.2019.17.5.023](https://doi.org/10.14400/JDC.2019.17.5.023)

b Hashim, M. S. (2011, June). Malaysia's national cyber security policy: The country's cyber defence initiatives. In 2011 Second Worldwide Cybersecurity Summit (WCS) (pp. 1-7). IEEE. https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=\&arnumber=5978782

Bendovschi, A. (2015). Cyber-Attacks – Trends, Patterns and Security Countermeasures. Procedia Economics and Finance, 28, 24–31. doi:10.1016/s2212-5671(15)01077-1

Bendiek, A., & Porter, A. L. (2013). European cyber security policy within a global multistakeholder structure. European Foreign Affairs Review, 18(2). https://kluwerlawonline.com/journalarticle/European+Foreign+Affairs+Review/18.2/EERR2013011

Carrapico, H., & Barrinha, A. (2018). European Union cyber security as an emerging research and policy field. European Politics and Society, 19(3), 299–303. doi:10.1080/23745118.2018.1430712

Gandhi, R., Sharma, A., Mahoney, W., Sousan, W., Zhu, Q., & Laplante, P. (2011). Dimensions of Cyber-Attacks: Cultural, Social, Economic, and Political. IEEE Technology and Society Magazine, 30(1), 28–38. doi:10.1109/mts.2011.940293

Helena Carrapico & Benjamin Farrand (2020) Discursive continuity and change in the time of Covid-19: the case of EU cybersecurity policy, Journal of European Integration, 42:8, 1111-1126, DOI: 10.1080/07036337.2020.1853122

Humayun, M., Niazi, M., Jhanjhi, N., Alshayeb, M., & Mahmood, S. (2020). Cyber Security Threats and Vulnerabilities: A Systematic Mapping Study. Arabian Journal for Science and Engineering. doi:10.1007/s13369-019-04319-2

Jang-Jaccard, J., & Nepal, S. (2014). A survey of emerging threats in cybersecurity. Journal of Computer and System Sciences, 80(5), 973–993. doi:10.1016/j.jcss.2014.02.005

Knapp, K. J., Franklin Morris, R., Marshall, T. E., & Byrd, T. A. (2009). Information security policy: An organizational-level process model. Computers & Security, 28(7), 493–508. doi:10.1016/j.cose.2009.07.001 

Lehto, M. (2013). The Cyberspace Threats and Cyber Security Objectives in the Cyber Security Strategies. International Journal of Cyber Warfare and Terrorism, 3(3), 1–18. doi:10.4018/ijcwt.2013070101

Min, K.-S., Chai, S.-W., & Han, M. (2015). An International Comparative Study on Cyber Security Strategy. International Journal of Security and Its Applications, 9(2), 13–20. doi:10.14257/ijsia.2015.9.2.02

Persadha, P. D., Waskita, A. A., & Yazid, S. (2015). Comparative Study of Cyber Security Policies among Malaysia, Australia, Indonesia: A Responsibility Perspective. 2015 Fourth International Conference on Cyber Security, Cyber Warfare, and Digital Forensic (CyberSec). doi:10.1109/cybersec.2015.36

Raiyn, J. (2014). International Journal of Security and Its Applications Vol.8, No.1 (2014), pp.247-256 http://dx.doi.org/10.14257/ijsia.2014.8.1.23

Sabillon, R., Cavaller, V., & Cano, J. (2016). National cyber security strategies: Global trends in cyberspace. International Journal of Computer Science and Software Engineering, 5(5), 67. <http://ijcsse.org/published/volume5/issue5/p1-V5I5.pdf>

Sterlini, P., Massacci, F., Kadenko, N., Fiebig, T., & van Eeten, M. (2019). Governance Challenges for European CyberSecurity Policies: Stakeholders Views. IEEE Security & Privacy, 0–0. doi:10.1109/msec.2019.2945309

Sunkpho, J., Ramjan, S., & Ottamakorn, C. (2018, March). Cybersecurity policy in ASEAN countries. In Information Institute Conferences. https://www.researchgate.net/profile/Jirapon-Sunkpho-2/publication/324106226\_Cybersecurity\_Policy\_in\_ASEAN\_Countries/links/5abdc2ea45851584fa6fca37/Cybersecurity-Policy-in-ASEAN-Countries.pdf

Tomic, D., Saljic, E., & Cupic, D. (2018). Cyber-Security Policies of East European Countries. Handbook of Cyber-Development, Cyber-Democracy, and Cyber-Defense, 1039–1055. doi:10.1007/978-3-319-09069-6\_59

Zhang, H., Tang, Z., & Jayakar, K. (2018). A socio-technical analysis of China’s cybersecurity policy: Towards delivering trusted e-government services. Telecommunications Policy, 42(5), 409–420. doi:10.1016/j.telpol.2018.02.004
