Laws of Malaysia·Act 854

CYBER SECURITY ACT 2024

AKTA KESELAMATAN SIBER 2024

Official editions

  • English edition
    CYBER SECURITY ACT 2024
    PDF
  • Edisi Bahasa Melayu
    AKTA KESELAMATAN SIBER 2024
    PDF
View on the Attorney-General's Chambers portal (lom.agc.gov.my)

Business activities this Act regulates

We haven't mapped this Act to specific MSIC business activities. Many federal Acts are general statutes (company law, employment, taxation, procedure) that apply across business activities generally rather than regulating one industry. Where an Act governs a specific licence, the regulated activities appear here.

Consolidated text (extract)

Cyber Security LAWS OF MALAYSIA Act 854 CYBER SECURITY ACT 2024 1 2 Laws of Malaysia Act 854 Date of Royal Assent ... ... 18 June 2024 Date of publication in the Gazette ... ... 26 June 2024 Publisher’s Copyright C PERCETAKAN NASIONAL MALAYSIA BERHAD All rights reserved. No part of this publication may be reproduced, stored in a retrieval system or transmitted in any form or by any means electronic, mechanical, photocopying, recording and/or otherwise without the prior permission of Percetakan Nasional Malaysia Berhad (Appointed Printer to the Government of Malaysia). Cyber Security LAWS OF MALAYSIA Act 854 CYBER SECURITY ACT 2024 ARRANGEMENT OF SECTIONS Part I PRELIMINARY Section 1. Short title and commencement 3. Extra-territorial application 2. 4. This Act binds the Federal Government and State Governments Interpretation Part II NATIONAL CYBER SECURITY COMMITTEE 5. Establishment of Committee 7. Meetings of Committee 6. 8. 9. Functions of Committee Committee may invite others to attend meetings Committee may establish subcommittees Part III DUTIES AND POWERS OF CHIEF EXECUTIVE 10. Duties and powers of Chief Executive 11. National Cyber Coordination and Command Centre System 12. Appointment of cyber security expert 13. Directive of Chief Executive 14. Power to gather information 3 4 Laws of Malaysia Act 854 Part IV NATIONAL CRITICAL INFORMATION INFRASTRUCTURE SECTOR LEAD AND NATIONAL CRITICAL INFORMATION INFRASTRUCTURE ENTITY Section 15. Appointment of national critical information infrastructure sector lead 16. Functions of national critical information infrastructure sector lead 17. Designation of national critical information infrastructure entity 18. Designation of national critical information infrastructure sector lead as national critical information infrastructure entity 19. Revocation of designation of national critical information infrastructure entity 20. Duty to provide information relating to national critical information infrastructure 21. Duty to implement code of practice 22. Duty to conduct cyber security risk assessment and audit 23. Duty to give notification on cyber security incident 24. Cyber security exercise Part V CODE OF PRACTICE 25. Code of practice 26. Directions under other written law shall be consistent with code of practice Part VI CYBER SECURITY SERVICE PROVIDER 27. Licensing of cyber security service provider 28. Qualifications for application of licence 29. Application for licence 30. Renewal of licence 31. Conditions of licence 32. Duty to keep and maintain record 33. Revocation or suspension of licence 34. Transfer or assignment of licence Cyber Security Part VII CYBER SECURITY INCIDENT Section 35. Cyber security incident Part VIII ENFORCEMENT 36. Authorization of public officer 37. Authority card 38. Power of investigation 39. Search and seizure with warrant 40. Search and seizure without warrant 41. List of seized objects, etc. 42. Cost of holding seized object, etc. 43. Release of seized object, etc. 44. Forfeiture of seized object, etc. 45. Property in forfeited object, etc. 46. Access to computerized data 47. No cost or damage arising from seizure to be recoverable 48. Power to require attendance of person acquainted with case 49. Examination of person acquainted with case 50. Admissibility of statement in evidence 51. Additional powers 52. Obstruction Part IX GENERAL 53. Appeal 54. Service of document 55. Obligation of secrecy 56. Protection against suit and legal proceedings 5 6 Laws of Malaysia Section 57. Prosecution 58. Liability of director, etc., of company, etc. 59. Liability of person for act, etc., of employee, etc. 60. Compounding of offences 61. Power to exempt 62. Power to amend Schedule 63. Power to make regulations 64. Saving Schedule Act 854 7 Cyber Security LAWS OF MALAYSIA Act 854 CYBER SECURITY ACT 2024 An Act to enhance the national cyber security by providing for the establishment of the National Cyber Security Committee, duties and powers of the Chief Executive of the National Cyber Security Agency, functions and duties of the national critical information infrastructure sector leads and national critical information infrastructure entities and the management of cyber security threats and cyber security incidents to national critical information infrastructures, to regulate the cyber security service providers through licensing, and to provide for related matters. [ ] ENACTED by the Parliament of Malaysia as follows: Part I PRELIMINARY Short title and commencement 1. (1) This Act may be cited as the Cyber Security Act 2024. (2) This Act comes into operation on a date to be appointed by the Minister by notification in the Gazette. 8 Laws of Malaysia Act 854 This Act binds the Federal Government and State Governments 2. (1) This Act shall bind the Federal Government and State Governments. (2) Nothing in this Act shall render the Federal Government and State Governments liable to prosecution for any offence under this Act. Extra-territorial application 3. (1) This Act shall, in relation to any person, whatever his nationality or citizenship, have effect outside as well as within Malaysia, and where an offence under this Act is committed by any person in any place outside Malaysia, he may be dealt with in respect of such offence as if the offence was committed at any place within Malaysia. (2) For the purposes of subsection (1), this Act shall apply if for the offence in question, the national critical information infrastructure is wholly or partly in Malaysia. Interpretation 4. In this Act, unless the context otherwise requires— “this Act” includes any subsidiary legislation made under this Act; “cyber security threat” means an act or activity carried out on or through a computer or computer system, without lawful authority, that may imminently jeopardize or may adversely affect the cyber security of that computer or computer system or another computer or computer system; “directive” means a directive issued by the Chief Executive under section 13; “prescribed” means prescribed by Minister by regulations made under this Act; Cyber Security 9 “national critical information infrastructure entity” means any Government Entity or person designated as a national critical information infrastructure entity under section 17 or 18; “Government Entity” means— (a) any ministry, department, office, agency, authority, commission, committee, board, council or other body, of the Federal Government, or of any of the State Governments, established under any written law or otherwise; and (b) any local authority; “national critical information infrastructure” means a computer or computer system which the disruption to or destruction of the computer or computer system would have a detrimental impact on the delivery of any service essential to the security, defence, foreign relations, economy, public health, public safety or public order of Malaysia, or on the ability of the Federal Government or any of the State Governments to carry out its functions effectively; “cyber security incident” means an act or activity carried out on or through a computer or computer system, without lawful authority, that jeopardizes or adversely affects the cyber security of that computer or computer system or another computer or computer system; “Committee” means the National Cyber Security Committee established under section 5; “cyber security” means the state in which a computer or computer system is protected from any attack or unauthorized access, and because of that state— (a) the computer or computer system continues to be available and operational; (b) the integrity of the computer or computer system is maintained; and (c) the integrity and confidentiality of information stored in, processed by or transmitted through, the computer or computer system is maintained; 10 Laws of Malaysia Act 854 “Chief Executive” means the Chief Executive of the National Cyber Security Agency; “national critical information infrastructure sector lead” means any Government Entity or person appointed as a national critical information infrastructure sector lead under section 15; “computer” means an electronic, magnetic, optical, electrochemical, or other data processing device performing logical, arithmetic, storage or display function, and includes any data storage facility or communications facility directly related to or operating in conjunction with such device, but does not include an automated typewriter or typesetter, or a portable hand held calculator or other similar device which is non-programmable or which does not contain any data storage facility; “Minister” means the Minister charged with the responsibility for cyber security; “authorized officer” means any police officer of whatever rank or any public officer authorized under section 36; “cyber security service provider” means a person who provides a cyber security service; “cyber security service” means the cyber security service as may be prescribed under subsection 27(2); “national critical information infrastructure sector” means the national critical information infrastructure sector specified in the Schedule; “computer system” means an arrangement of interconnected computers that is designed to perform one or more specific functions, and includes— (a) an information technology system; and (b) an operational technology system such as an industrial control system, a programmable logic controller, a supervisory control and data acquisition system, or a distributed control system; “code of practice” means the code of practice referred to in section 25. Cyber Security 11 Part II NATIONAL CYBER SECURITY COMMITTEE Establishment of Committee 5. (1) A committee by the name of “National Cyber Security Committee” is established. (2) The Committee shall consist of the following members: (a) the Prime Minister who shall be the Chairman; (b) the Minister charged with the responsibility for finance; (c) the Minister charged with the responsibility for foreign affairs; (d) the Minister charged with the responsibility for defence; (e) the Minister charged with the responsibility for home affairs; (f) the Minister charged with the responsibility for communications; (g) the Minister charged with the responsibility for digital related matters; (h) the Chief Secretary to the Government; (i) the Chief of Defence Force; (j) the Inspector General of Police; (k) the Director General of National Security; and (l) not more than two other persons who shall be appointed by the Committee from among persons of standing and experience in cyber security. 12 Laws of Malaysia Act 854 (3) The Chairman shall appoint from among the members of the Committee a Deputy Chairman. (4) The Chief Executive shall be the secretary to the Committee. Functions of Committee 6. (1) The Committee shall have the following functions: (a) to plan, formulate and decide on policies relating to national cyber security; (b) to decide on approaches and strategies in addressing matters relating to national cyber security; (c) to monitor the implementation of policies and strategies relating to national cyber security; (d) to advise and make recommendations to the Federal Government on policies and strategic measures to strengthen national cyber security; (e) to give directions to the Chief Executive and national critical information infrastructure sector leads on matters relating to national cyber security; (f) to oversee the effective implementation of this Act; and (g) to do such other things arising out of or consequential to the functions of the Committee under this Act consistent with the purposes of this Act. (2) The Committee shall have all such powers as may be necessary for, or in connection with, or reasonably incidental to, the performance of its functions

Extract truncated for display. Download the official PDF above for the full text.