The South African and Senegalese Legislative Response to Malware-Facilitated Cybercrime
 

Author:

S Mabunda
 

Summary: 

This article adopts a doctrinal methodology to interrogate the legislative responses of South Africa and Senegal to the threat of malware as contained in the provisions of the South African Cybercrimes Act 19 of 2022 and the Senegalese Cybercrime Law 2008-11 respectively. The article finds that both countries have employed the Confidentiality, Integrity, and Availability cybersecurity model (CIA triad) to inform
how the offences in the legislations are defined and formulated. Interestingly, it notes that although the same model is used by both countries, the way that the CIA triad has been incorporated into the respective laws differs in significant ways, with potentially varying results. Given that both South Africa and Senegal are parties to the Council of Europe Convention on Cybercrime (Budapest Convention), to different extents, it is appropriate to use the Convention as the benchmark against which to judge the respective provisions. To do so, this article draws upon the specific offences provided for in both countries regarding unauthorized access to and interference with computer systems. Despite South Africa’s decision not to ratify the Budapest Convention and Senegal’s leap to ratify, it appears that South
Africa has adhered more closely to the Convention than Senegal. Seemingly odd, it may be viewed as a testament to the fact that the Convention is meant to guide countries in their legislative endeavours rather than being prescriptive.

To read the book chapter, please click the button below:

Link to book chapter