Cyber Security Bill 2024 Tabled for First Reading
The Cyber Security Bill 2024, introduced for its first reading in the Parliament yesterday, signifies a proactive step towards enhancing national cyber security standards. Presented by Digital Minister Gobind Singh Deo, the Bill is anticipated to proceed to the second reading within the current Dewan Rakyat session. Here are a couple of key takeaways.
- Enforcing Compliance Measures and Standards – the Bill mandates stricter measures, standards, and processes in managing cyber security threats and incidents to protect the Critical National Information Infrastructure (CNII).
- Establishment of National Cyber Security Committee – the Bill establishes a national cyber security committee to be chaired by the Prime Minister, and comprising ministers responsible for finance, foreign affairs, defence, home affairs, communications, and digital matters. This committee also includes key personnels such as the Chief of the Armed Forces, Inspector-General of Police, Director-General of National Security, and cyber security experts.
- Duties and Powers of Chief Executive – the Bill outlines the duties and authorities of the Chief Executive of the National Cyber Security Agency (NCSA), empowering them to oversee cyber security management effectively. One central responsibility vested in the Chief Executive under the Bill is the upkeeping of a national cyber security system known as the “National Cyber Coordination and Command Centre System” for the purpose of managing cyber security threats and incidents.
- Licensing of Cyber Security Service Providers – Among others, the Bill also introduces licensing requirements for cyber security service providers to guarantee the quality and reliability of services provided, making it an offence to offer cyber security services without a license.
- Appointment of CNII Sector Leads – the Bill also allows ministerial appointments of CNII sector leads based on recommendations of the Chief Executive, enabling coordinated cyber security efforts within critical sectors. Emphasing transparency, the Bill mandates public disclosure of names of the appointed CNII sector leads on the official NCSA website.
- Critical National Information Infrastructure (CNII) Defined – the Bill defines Critical National Information Infrastructures (CNIIs) as computers or computer systems whose disruption or destruction would be crucial for national security, defence, foreign relations, economy, public health, safety, and public order.
The Cyber Security Bill 2024 is a comprehensive effort to safeguard national interests in an increasingly digital world. Stakeholders are encouraged to closely follow its progress to ensure robust cyber security frameworks are established and maintained in addressing evolving threats and technological advancements.