Penetration Tests and Criminal Law*

Penetration Tests and Criminal Law*

Information systems play a central role in all aspects of life, because these systems to protect against potential attacks, it has never been so important. A computing system is resistant against any attack in understanding whether infiltration (penetration) of the tests, it is obvious that they are one of the most effective tools. However, these tests should not be exceeded when performing the legal limits otherwise would be out of the question, it is clear that because of criminal responsibility.

 

What Is Penetration Testing?

Penetration testing, cyber attacks that are performed in order to uncover the vulnerabilities of an information technology system are [1]. These tests are the weaknesses of the information system, it is detected by these other people are made for the purpose of requiring that are detected and resolved before. In this way, information security in information systems in question-based manner can be performed [2].

 

Penetration tests, these tests will carry out the test with the owners of the party who applied informatics within the framework of agreements arranged between the system are implemented. These contracts, the scope of penetration testing, quality, reporting of results, and contain provisions on various issues such as privacy. However, regardless of the content of the contracts in question are drawn to penetration testing with the agreement of the practitioner limit: “the Quran should not exceed. Indeed, the movement of a breach of this agreement, the law eliminates that matter to you. Penetration testing on the other hand the implementation of the acquisition of trade secrets, unfair competition and the emergence of personal data in the sense that imposes responsibilities on issues such as the acquisition of civil and criminal. In this article, we will focus on criminal liability and sanctions.

Penetration tests and TCK

 

TCK some of the crimes that are defined in, stands out in terms of penetration tests. On this subject, although it does not appear to be able to go for a limited count of Penal Code Section 243, 244, 136 and 137. items stand out.

 

 The crime of entering into the informatics system (m of the Penal Code. 243)

 

Article 243 of the Penal Code. the item in which is organized the crime of entering information into the system, an IT system in a way that part or all of the perpetrator or occurs against the law to get there on purpose to stay with continuing [3]. TPC m. 243 provision in an unlawful manner is searched in the wording of the infiltration of the movement is important. Because the crime in question is, in terms of unlawfulness, it is mandatory for the formation of tipiklig.

 

The consent of the owner of that system or a data processing system is provided within the framework of a contract legally valid if confirmed by computing the crime of entering the system as soon as [4]. Then,  to be entered into within the framework of the information system penetration tests and to stay here, it will not be a contract made under this act it is against the law. Turns out that they’ll go outside the limits of the contract corresponding to the test participants. In other words, the limits of this crime are followed as long as the convention does not create. For example, an information technology system infiltration in the contract is planned to be implemented for only a portion of the test, while practitioners in the event that they come into the system under test to the whole system information TCL will entering the realization of the crime.

 

System block, destruction, or destruction, or change data to a Crime (Penal Code m. 244)

 

in penetration testing, the subject may not always be entered into a system. For example, if a DDoS attack is performed within the scope of these tests, the system will be blocked. Because the system will prevent the prevention or restriction of fulfilling the functions of an IT system or means slowing down the system [5]. In that case, an infiltration test in the context of a data processing system of access to prevention, restriction or slowing down in the case of the typical elements of this crime will occur.

 

The crackdown on the computing system, made within the knowledge and consent of those concerned is Article 244 of the Penal Code. the crime defined in article will find not confirmed. However, the consent given is exceeded in the event that you will find it is self evident that the fault in question is confirmed [6]. For this reason, the test infiltration of the contract, a breach of state law that eliminates this time, “the consent of the person concerned” (TCK m. 26) will be. Indeed, the contracts in question, penetration testing of the test applied informatics practitioners between the natural or legal person who is the owner of the system are organized. Therefore, the law of the case, which eliminates the existence of a breach of this agreement should be agreed. Thus, even if the element of unlawfulness developed the typical elements of a crime is to restore the contract in accordance with Article 244 of the Penal Code under test that is applied to an infiltration. the crime defined in article will find not confirmed.

 

The crime of possession or Dissemination of the Data (m of the Penal Code. 136)

 

nowadays, banking and e-commerce sector in the digital domain requires personal data that is stored in various responsibilities. Penetration testing, cyber security is used as a measure for the purpose of technical. In this context, accessing the system, the practitioners of personal data in the system can get the opportunity of having access to quality data.

 

In such a case, the infiltration test or spread hijack this data practitioners in the case of Article 136 of the Penal Code. or dissemination of the crime of possession of the item defined in the data that will be processed it is self evident. Indeed, penetration testing contract in violation of the law will give them that authority doesn transactions.

 

However, the Penal Code of m. 137/2 qualified held in lieu of hal, is important for our subject. That provision in accordance with this crime, is committed by taking advantage of a profession and art, the penalty will be increased by half. To apply to become qualified in this field, there must be the causal relationship between relevant professional activities in the commission of an offense [7].

 

An infiltration test penetration testing practitioners of personal data by abusing the rights and obligations arising from the contract of acquisition or qualified under a state of spreading of the crime in question should be evaluated. Because of the perpetrator during the execution of this Test access to the personal data and are spreading to take over them this way. In these circumstances, while taking advantage of the convenience of penetration testing is to increase the penalty on the offender who committed this crime should go.

 

It should also be noted, penetration testing practitioners in the case of Article 239 of the Penal Code. the item will also be on the agenda. Indeed, with this article adjective or duty, that is the necessary foundation of art profession or trade secrets, banking secrets or customer information to unauthorized persons or the person who claimed the secret is in the nature of up to three years in prison and would be punished with an administrative fine of five thousand, it is stated that until the day.

Conclusion and evaluation

 

For all these reasons, practitioners infiltration test, in fact, they walk a fine line. If the limit is exceeded during the implementation of the contract drawn in penetration testing discussed above will be processed on the crimes defined in the Penal Code, it is obvious that many crimes. Therefore, penetration testing contracts, especially those in the test providers in terms of an agreement is only between the parties should not be seen as guidelines should be considered to prevent a breach of the law.

 

Notes

 

*Av. Penned by Jalil Aktaş, this study is the first digital newsletter published by the Istanbul Bar Association, Law Commission of Informatics 1. the issue was published.

 

[1] IBM, “what is penetration testing?”,  https://www.ibm.com/topics/penetration-testing date of access: 24.01.2024.

 

[2] Gallant, Tuncay / AKYILDIZ Muhammed Alparslan, penetration tests on a network model for the evaluation of a cyber attack scenarios, “Journal of Süleyman Demirel University Institute of Sciences”, Volume:18, Issue:1, 2014, (ss.14-21), s.14.

 

[3] TOUGH, Muhammet Sefa, In light of Supreme Court decisions, the crime of entering into or staying informatics system (m of the Penal Code. 243), “Journal of the Justice Academy of Turkey”, year: 12, No: 45, January 2021, (ss.1 – 28), s. 9.

 

[4] KARAKEHYA Hakan, Computing the Turkish Penal Code, the crime of entering the system, “Journal of Computational Physics”, Vol: 81, 2009, (ss. 1-24), s. 16.

 

 [5] ERMEYDAN, drip,drop “in the Turkish Penal Code, cyber crimes”, the Elite, 2. Printing, Ankara, 2023, s. 120-121.

 

[6] YILMAZ, House, Article 244 of the Penal Code No. 5237. The item held in Crimes in the field of Informatics, “Journal of Computational Physics”, Vol: 92, 2011, (ss. 62-100), s. 79.

 

[7] TESTS Hasan Export of personal data is unlawful Distribution or possession Crime (TCK md. 136), “Journal of personal data protection”, 2(1), 2020, (ss. 33-62), s. 52.

Av. Celil Aktaş, LL.M.

Our Other Blog Posts