Glossary
Budapest Convention. The Council of Europe Convention on Cybercrime, the main international treaty on cybercrime. Countries can be parties, signatories or neither. See the Council of Europe’s page on the Convention.
CARICOM IMPACS. The Caribbean Community Implementation Agency for Crime and Security. It runs regional workshops and programmes, including on incident response.
CIRT / CSIRT / CERT. A team that responds to cybersecurity incidents. “National” ones act for a whole country. Different countries use different names for the same function.
CMM (Cybersecurity Capacity Maturity Model). A framework from the Global Cyber Security Capacity Centre at the University of Oxford. The OAS–IDB report uses it to assess countries across five dimensions: policies and strategies, culture and society, education and skills, legal and regulatory frameworks, and technologies and standards.
Cybercrime law. Legislation that defines offences such as illegal access, data interference and computer-related fraud, and sets out how they are investigated and prosecuted.
Data protection law. Legislation that governs how personal data is collected and used, often creating a regulator such as an information commissioner.
IDB. The Inter-American Development Bank, co-publisher of the OAS–IDB report.
National cybersecurity strategy. A government document that sets objectives for cybersecurity governance, critical infrastructure protection and capacity building. Some countries have one, some are drafting one, and some rely on a policy framework instead.
NDMA. Guyana’s National Data Management Authority. CIRT.GY sits within it.
OAS / CICTE. The Organization of American States and its Inter-American Committee against Terrorism, co-authors of the report.
Commencement order. The instrument that brings an enacted law into force. A law can be passed and gazetted but not operational until it is issued. This is the status the Data Protection Act 2023 was reported in.