Laws of Malaysia·Act 854
CYBER SECURITY ACT 2024
AKTA KESELAMATAN SIBER 2024
Official editions
View on the Attorney-General's Chambers portal (lom.agc.gov.my)Business activities this Act regulates
We haven't mapped this Act to specific MSIC business activities. Many federal Acts are general statutes (company law, employment, taxation, procedure) that apply across business activities generally rather than regulating one industry. Where an Act governs a specific licence, the regulated activities appear here.
Consolidated text (extract)
Cyber Security
LAWS OF MALAYSIA
Act 854
CYBER SECURITY ACT 2024
1
2
Laws of Malaysia
Act 854
Date of Royal Assent
...
...
18 June 2024
Date of publication in the
Gazette
...
...
26 June 2024
Publisher’s Copyright C
PERCETAKAN NASIONAL MALAYSIA BERHAD
All rights reserved. No part of this publication may be reproduced, stored in a retrieval system or transmitted in any form or by any means
electronic, mechanical, photocopying, recording and/or otherwise without the prior permission of Percetakan Nasional Malaysia Berhad
(Appointed Printer to the Government of Malaysia).
Cyber Security
LAWS OF MALAYSIA
Act 854
CYBER SECURITY ACT 2024
ARRANGEMENT OF SECTIONS
Part I
PRELIMINARY
Section
1.
Short title and commencement
3.
Extra-territorial application
2.
4.
This Act binds the Federal Government and State Governments
Interpretation
Part II
NATIONAL CYBER SECURITY COMMITTEE
5.
Establishment of Committee
7.
Meetings of Committee
6.
8.
9.
Functions of Committee
Committee may invite others to attend meetings
Committee may establish subcommittees
Part III
DUTIES AND POWERS OF CHIEF EXECUTIVE
10.
Duties and powers of Chief Executive
11.
National Cyber Coordination and Command Centre System
12.
Appointment of cyber security expert
13.
Directive of Chief Executive
14.
Power to gather information
3
4
Laws of Malaysia
Act 854
Part IV
NATIONAL CRITICAL INFORMATION INFRASTRUCTURE SECTOR LEAD
AND NATIONAL CRITICAL INFORMATION INFRASTRUCTURE ENTITY
Section
15.
Appointment of national critical information infrastructure sector lead
16.
Functions of national critical information infrastructure sector lead
17.
Designation of national critical information infrastructure entity
18.
Designation of national critical information infrastructure sector lead as
national critical information infrastructure entity
19.
Revocation of designation of national critical information infrastructure
entity
20.
Duty to provide information relating to national critical information
infrastructure
21.
Duty to implement code of practice
22.
Duty to conduct cyber security risk assessment and audit
23.
Duty to give notification on cyber security incident
24.
Cyber security exercise
Part V
CODE OF PRACTICE
25.
Code of practice
26.
Directions under other written law shall be consistent with code of
practice
Part VI
CYBER SECURITY SERVICE PROVIDER
27.
Licensing of cyber security service provider
28.
Qualifications for application of licence
29.
Application for licence
30.
Renewal of licence
31.
Conditions of licence
32.
Duty to keep and maintain record
33.
Revocation or suspension of licence
34.
Transfer or assignment of licence
Cyber Security
Part VII
CYBER SECURITY INCIDENT
Section
35.
Cyber security incident
Part VIII
ENFORCEMENT
36.
Authorization of public officer
37.
Authority card
38.
Power of investigation
39.
Search and seizure with warrant
40.
Search and seizure without warrant
41.
List of seized objects, etc.
42.
Cost of holding seized object, etc.
43.
Release of seized object, etc.
44.
Forfeiture of seized object, etc.
45.
Property in forfeited object, etc.
46.
Access to computerized data
47.
No cost or damage arising from seizure to be recoverable
48.
Power to require attendance of person acquainted with case
49.
Examination of person acquainted with case
50.
Admissibility of statement in evidence
51.
Additional powers
52.
Obstruction
Part IX
GENERAL
53.
Appeal
54.
Service of document
55.
Obligation of secrecy
56.
Protection against suit and legal proceedings
5
6
Laws of Malaysia
Section
57.
Prosecution
58.
Liability of director, etc., of company, etc.
59.
Liability of person for act, etc., of employee, etc.
60.
Compounding of offences
61.
Power to exempt
62.
Power to amend Schedule
63.
Power to make regulations
64.
Saving
Schedule
Act 854
7
Cyber Security
LAWS OF MALAYSIA
Act 854
CYBER SECURITY ACT 2024
An Act to enhance the national cyber security by providing for
the establishment of the National Cyber Security Committee,
duties and powers of the Chief Executive of the National Cyber
Security Agency, functions and duties of the national critical
information infrastructure sector leads and national critical
information infrastructure entities and the management of cyber
security threats and cyber security incidents to national critical
information infrastructures, to regulate the cyber security service
providers through licensing, and to provide for related matters.
[
]
ENACTED by the Parliament of Malaysia as follows:
Part I
PRELIMINARY
Short title and commencement
1. (1) This Act may be cited as the Cyber Security Act 2024.
(2) This Act comes into operation on a date to be appointed
by the Minister by notification in the Gazette.
8
Laws of Malaysia
Act 854
This Act binds the Federal Government and State Governments
2. (1) This Act shall bind the Federal Government and State
Governments.
(2) Nothing in this Act shall render the Federal Government
and State Governments liable to prosecution for any offence under
this Act.
Extra-territorial application
3. (1) This Act shall, in relation to any person, whatever his
nationality or citizenship, have effect outside as well as within
Malaysia, and where an offence under this Act is committed by
any person in any place outside Malaysia, he may be dealt with
in respect of such offence as if the offence was committed at
any place within Malaysia.
(2) For the purposes of subsection (1), this Act shall apply
if for the offence in question, the national critical information
infrastructure is wholly or partly in Malaysia.
Interpretation
4. In this Act, unless the context otherwise requires—
“this Act” includes any subsidiary legislation made under
this Act;
“cyber security threat” means an act or activity carried out
on or through a computer or computer system, without lawful
authority, that may imminently jeopardize or may adversely affect
the cyber security of that computer or computer system or another
computer or computer system;
“directive” means a directive issued by the Chief Executive
under section 13;
“prescribed” means prescribed by Minister by regulations made
under this Act;
Cyber Security
9
“national critical information infrastructure entity” means any
Government Entity or person designated as a national critical
information infrastructure entity under section 17 or 18;
“Government Entity” means—
(a) any ministry, department, office, agency, authority,
commission, committee, board, council or other body,
of the Federal Government, or of any of the State
Governments, established under any written law or
otherwise; and
(b) any local authority;
“national critical information infrastructure” means a computer
or computer system which the disruption to or destruction of the
computer or computer system would have a detrimental impact
on the delivery of any service essential to the security, defence,
foreign relations, economy, public health, public safety or public
order of Malaysia, or on the ability of the Federal Government or
any of the State Governments to carry out its functions effectively;
“cyber security incident” means an act or activity carried out
on or through a computer or computer system, without lawful
authority, that jeopardizes or adversely affects the cyber security
of that computer or computer system or another computer or
computer system;
“Committee” means the National Cyber Security Committee
established under section 5;
“cyber security” means the state in which a computer or
computer system is protected from any attack or unauthorized
access, and because of that state—
(a) the computer or computer system continues to be available
and operational;
(b) the integrity of the computer or computer system is
maintained; and
(c) the integrity and confidentiality of information stored in,
processed by or transmitted through, the computer or
computer system is maintained;
10
Laws of Malaysia
Act 854
“Chief Executive” means the Chief Executive of the National Cyber
Security Agency;
“national critical information infrastructure sector lead” means
any Government Entity or person appointed as a national critical
information infrastructure sector lead under section 15;
“computer” means an electronic, magnetic, optical, electrochemical,
or other data processing device performing logical, arithmetic,
storage or display function, and includes any data storage facility
or communications facility directly related to or operating in
conjunction with such device, but does not include an automated
typewriter or typesetter, or a portable hand held calculator or
other similar device which is non-programmable or which does
not contain any data storage facility;
“Minister” means the Minister charged with the responsibility
for cyber security;
“authorized officer” means any police officer of whatever rank
or any public officer authorized under section 36;
“cyber security service provider” means a person who provides
a cyber security service;
“cyber security service” means the cyber security service as
may be prescribed under subsection 27(2);
“national critical information infrastructure sector” means
the national critical information infrastructure sector specified in
the Schedule;
“computer system” means an arrangement of interconnected
computers that is designed to perform one or more specific
functions, and includes—
(a) an information technology system; and
(b) an operational technology system such as an industrial
control system, a programmable logic controller,
a supervisory control and data acquisition system, or
a distributed control system;
“code of practice” means the code of practice referred to in
section 25.
Cyber Security
11
Part II
NATIONAL CYBER SECURITY COMMITTEE
Establishment of Committee
5. (1) A committee by the name of “National Cyber Security
Committee” is established.
(2) The Committee shall consist of the following members:
(a) the Prime Minister who shall be the Chairman;
(b) the Minister charged with the responsibility for finance;
(c) the Minister charged with the responsibility for foreign
affairs;
(d) the Minister charged with the responsibility for defence;
(e) the Minister charged with the responsibility for home
affairs;
(f) the Minister charged with the responsibility for
communications;
(g) the Minister charged with the responsibility for digital
related matters;
(h) the Chief Secretary to the Government;
(i) the Chief of Defence Force;
(j) the Inspector General of Police;
(k) the Director General of National Security; and
(l) not more than two other persons who shall be appointed
by the Committee from among persons of standing and
experience in cyber security.
12
Laws of Malaysia
Act 854
(3) The Chairman shall appoint from among the members of
the Committee a Deputy Chairman.
(4) The Chief Executive shall be the secretary to the Committee.
Functions of Committee
6. (1) The Committee shall have the following functions:
(a) to plan, formulate and decide on policies relating to
national cyber security;
(b) to decide on approaches and strategies in addressing
matters relating to national cyber security;
(c) to monitor the implementation of policies and strategies
relating to national cyber security;
(d) to advise and make recommendations to the Federal
Government on policies and strategic measures to
strengthen national cyber security;
(e) to give directions to the Chief Executive and national
critical information infrastructure sector leads on matters
relating to national cyber security;
(f) to oversee the effective implementation of this Act; and
(g) to do such other things arising out of or consequential to
the functions of the Committee under this Act consistent
with the purposes of this Act.
(2) The Committee shall have all such powers as may be
necessary for, or in connection with, or reasonably incidental to,
the performance of its functions
Extract truncated for display. Download the official PDF above for the full text.