Act 854
Act 854
LAWS OF MALAYSIA
Act 854
Publisher’s Copyright C
PERCETAKAN NASIONAL MALAYSIA BERHAD
All rights reserved. No part of this publication may be reproduced, stored in a retrieval system or transmitted in any form or by any means
electronic, mechanical, photocopying, recording and/or otherwise without the prior permission of Percetakan Nasional Malaysia Berhad
(Appointed Printer to the Government of Malaysia).
Cyber Security 3
LAWS OF MALAYSIA
Act 854
ARRANGEMENT OF SECTIONS
Part I
PRELIMINARY
Section
Part II
5. Establishment of Committee
6. Functions of Committee
7. Meetings of Committee
8. Committee may invite others to attend meetings
9. Committee may establish subcommittees
Part III
Section
Part V
CODE OF PRACTICE
Part VI
Section
Part VIII
ENFORCEMENT
Part IX
GENERAL
53. Appeal
54. Service of document
55. Obligation of secrecy
56. Protection against suit and legal proceedings
6 Laws of Malaysia Act 854
Section
57. Prosecution
58. Liability of director, etc., of company, etc.
59. Liability of person for act, etc., of employee, etc.
60. Compounding of offences
61. Power to exempt
62. Power to amend Schedule
63. Power to make regulations
64. Saving
Schedule
Cyber Security 7
LAWS OF MALAYSIA
Act 854
[ ]
Part I
PRELIMINARY
1. (1) This Act may be cited as the Cyber Security Act 2024.
2. (1) This Act shall bind the Federal Government and State
Governments.
Extra-territorial application
(2) For the purposes of subsection (1), this Act shall apply
if for the offence in question, the national critical information
infrastructure is wholly or partly in Malaysia.
Interpretation
Part II
Establishment of Committee
(l) not more than two other persons who shall be appointed
by the Committee from among persons of standing and
experience in cyber security.
12 Laws of Malaysia Act 854
Functions of Committee
Meetings of Committee
(5) The Chairman may authorize the use of a live video link,
live television link or any other electronic means of communication
for the purposes of any meeting of the Committee.
Part III
DUTIES AND POWERS OF CHIEF EXECUTIVE
10. (1) The Chief Executive shall have the following duties:
(g) to carry out any other duties imposed upon him under
this Act or as directed by the Committee.
(2) The Chief Executive shall have all such powers as may be
necessary for, or in connection with, or reasonably incidental to,
the carrying out of his duties under this Act.
13. (1) The Chief Executive may issue such directive as the
Chief Executive considers necessary for the purpose of ensuring
compliance with this Act.
(a) state, to the best of his knowledge and belief, where the
document may be found; and
(b) identify, to the best of his knowledge and belief, the last
person who had custody of the document and state,
to the best of his knowledge and belief, where that
last-mentioned person may be found.
(5) Subsection (4) shall not bar, prevent or prohibit the institution
of any prosecution for any offence as provided by this section
or the disclosure or production of false information or document
in relation to a notice in writing under this section furnished to
the Chief Executive pursuant to this section.
(6) Any person who fails to comply with the directions of the
Chief Executive under subsection (1) commits an offence and
shall, on conviction, be liable to a fine not exceeding two hundred
thousand ringgit or to imprisonment for a term not exceeding
three years or to both.
Part IV
(2) The Minister may appoint more than one national critical
information infrastructure sector lead for any of the national
critical information infrastructure sectors.
(4) Where the Chief Executive finds that the audit report
submitted under subsection (2) is insufficient, the Chief Executive
may direct the national critical information infrastructure entity to
rectify the audit report within the period as may be determined
by the Chief Executive.
(2) The Chief Executive shall, before carrying out any cyber
security exercise under subsection (1), issue a notice in writing
to the national critical information infrastructure entity concerned
notifying his intention to carry out such cyber security exercise
in respect of the national critical information infrastructure entity.
(3) The Chief Executive may give any directions to the national
critical information infrastructure entity as the Chief Executive
thinks fit for the purpose of the cyber security exercise
carried out under this section.
Part V
CODE OF PRACTICE
Code of practice
(b) the matters as set out in subsection (2) have been given
due consideration; and
(4) The code of practice under this section shall take effect
on the date of the endorsement of the code of practice by the
Chief Executive.
Part VI
(3) This Part shall not apply in the case where the cyber security
service is provided by a company to its related company.
28. Any person may apply for a licence under this Part if the
person—
Renewal of licence
30. (1) A licensee may apply to renew its licence issued under
section 29 at least thirty days before the date of expiration of
the licence in such manner as may be prescribed.
Conditions of licence
(2) The Chief Executive may at any time vary or revoke the
conditions imposed on a licence under subsection (1).
(a) the name and address of the person engaging the licensee
for the cyber security service;
(c) the date and time of cyber security service that was provided
by the licensee or other person on behalf of the licensee;
(b) retained for a period of not less than six years from the
date the cyber security service was provided; and
Part VII
(2) The investigation carried out under this Part shall be for
the purposes of—
Part VIII
ENFORCEMENT
Authority card
Power of investigation
38. (1) An authorized officer shall have all the powers necessary
to carry out an investigation in relation to any cyber security
incident under this Act.
41. (1) Where any seizure is made under this Act, an authorized
officer making the seizure shall prepare a list of the object, book,
account, document, computerized data, signboard, card, letter,
pamphlet, leaflet, notice, facility, apparatus, vehicle, equipment,
device, thing or matter seized and shall sign the list.
(2) When any witness is called for the prosecution or for the
defence, other than the accused, the court shall, on the request of
the accused or the prosecutor, refer to any statement made by that
witness to an authorized officer in the course of an investigation
under this Act and may then, if the court thinks fit in the interest
of justice, direct the accused to be furnished with a copy of the
statement and the statement may be used to impeach the credit of the
witness in the manner provided by the Evidence Act 1950 [Act 56].
(3) Where the accused had made a statement during the course
of an investigation, such statement may be admitted in evidence
in support of his defence during the course of the trial.
Additional powers
(2) Any person who fails to comply with the requirement made
under subsection (1) commits an offence and shall, on conviction,
be liable to a fine not exceeding one hundred thousand ringgit or
to imprisonment for a term not exceeding two years or to both.
Obstruction
Part IX
GENERAL
Appeal
(2) The Minister may, after considering the appeal made under
subsection (1), confirm or set aside the decision appealed against.
Service of document
54. (1) Subject to subsection (2), the Chief Executive may allow
any information, particulars or document required to be submitted
or furnished under this Act to be submitted or furnished by an
electronic medium or by way of an electronic transmission.
Cyber Security 45
Obligation of secrecy
55. (1) Except for any of the purposes of this Act or for the
purposes of any civil or criminal proceedings under any written
law or where otherwise authorized by the Committee, any member
of the Committee, the Chief Executive or any authorized officer,
whether during or after his tenure of office or employment, shall
not disclose any information obtained by him in the course of
his duties.
Prosecution
Compounding of offences
60. (1) The Minister may, with the approval of the Public
Prosecutor, make regulations prescribing—
(4) If the amount specified in the offer is not paid within the time
specified in the offer, or such extended time as the Chief Executive
may grant, prosecution for the offence may be instituted at any time
after that against the person to whom the offer was made.
Power to exempt
(3) The regulations made under this Act may prescribe an act
or omission in contravention of the regulations to be an offence
and may prescribe penalties of a fine not exceeding two hundred
thousand ringgit or to imprisonment for a term not exceeding
three years or to both.
Saving
64. On the date of the coming into operation of this Act, any
measures, standards and processes which have been implemented
to ensure the cyber security of a national critical information
infrastructure and imposed on any Government Entity or person under
Directive of the National Security Council No. 26 shall, so long as
it is consistent with the provisions of this Act, continue to remain
in force until it is revoked under the National Security Council
Act 2016 [Act 776].
50 Laws of Malaysia Act 854
Schedule
[Section 4]
1. Government
3. Transportation
6. Healthcare services
8. Energy
+DNFLSWD3HQFHWDN +
3(5&(7$.$11$6,21$/0$/$<6,$%(5+$'
6HPXD+DN7HUSHOLKDUD7LDGDPDQDPDQDEDKDJLDQMXDGDULSDGDSHQHUELWDQLQLEROHKGLWHUELWNDQVHPXODDWDXGLVLPSDQGLGDODPEHQWXN
\DQJEROHKGLSHUROHKLVHPXODDWDXGLVLDUNDQGDODPVHEDUDQJEHQWXNGHQJDQDSDMXDFDUDHOHNWURQLNPHNDQLNDOIRWRNRSLUDNDPDQGDQDWDX
VHEDOLNQ\DWDQSDPHQGDSDWL]LQGDULSDGD3HUFHWDNDQ1DVLRQDO0DOD\VLD%HUKDG 3HQFHWDNNHSDGD.HUDMDDQ0DOD\VLD\DQJGLODQWLN
',&(7$.2/(+
3(5&(7$.$11$6,21$/0$/$<6,$%(5+$'
.8$/$/80385
ZZZSULQWQDVLRQDOFRPP\
HPDLOFVHUYLFH#SULQWQDVLRQDOFRPP\
7HO
%$*,3,+$.'$1'(1*$13(5,17$+.(5$-$$10$/$<6,$
WJW24/0572 26-06-2024