Malaysia legislation

Section 4

of CYBER SECURITY ACT 2024

Section 4

In this Act, unless the context otherwise requires—

“this Act” includes any subsidiary legislation made under this Act;

“cyber security threat” means an act or activity carried out on or through a computer or computer system, without lawful authority, that may imminently jeopardize or may adversely affect the cyber security of that computer or computer system or another computer or computer system;

“directive” means a directive issued by the Chief Executive under section 13;

“prescribed” means prescribed by Minister by regulations made under this Act;

Cyber Security 9

“national critical information infrastructure entity” means any

Government Entity or person designated as a national critical information infrastructure entity under section 17 or 18;

“Government Entity” means—

(a)

any ministry, department, office, agency, authority, commission, committee, board, council or other body, of the Federal Government, or of any of the State

Governments, established under any written law or otherwise; and

(b)

any local authority;

“national critical information infrastructure” means a computer or computer system which the disruption to or destruction of the computer or computer system would have a detrimental impact on the delivery of any service essential to the security, defence, foreign relations, economy, public health, public safety or public order of Malaysia, or on the ability of the Federal Government or any of the State Governments to carry out its functions effectively;

“cyber security incident” means an act or activity carried out on or through a computer or computer system, without lawful authority, that jeopardizes or adversely affects the cyber security of that computer or computer system or another computer or computer system;

“Committee” means the National Cyber Security Committee established under section 5;

“cyber security” means the state in which a computer or computer system is protected from any attack or unauthorized access, and because of that state—

(a)

the computer or computer system continues to be available and operational;

(b)

the integrity of the computer or computer system is maintained; and

(c)

the integrity and confidentiality of information stored in, processed by or transmitted through, the computer or computer system is maintained;

Act 854

“Chief Executive” means the Chief Executive of the National Cyber

Security Agency;

“national critical information infrastructure sector lead” means any Government Entity or person appointed as a national critical information infrastructure sector lead under section 15;

“computer” means an electronic, magnetic, optical, electrochemical, or other data processing device performing logical, arithmetic, storage or display function, and includes any data storage facility or communications facility directly related to or operating in conjunction with such device, but does not include an automated typewriter or typesetter, or a portable hand held calculator or other similar device which is non-programmable or which does not contain any data storage facility;

“Minister” means the Minister charged with the responsibility for cyber security;

“authorized officer” means any police officer of whatever rank or any public officer authorized under section 36;

“cyber security service provider” means a person who provides a cyber security service;

“cyber security service” means the cyber security service as may be prescribed under subsection 27(2);

“national critical information infrastructure sector” means the national critical information infrastructure sector specified in the Schedule;

“computer system” means an arrangement of interconnected computers that is designed to perform one or more specific functions, and includes—

(a)

an information technology system; and

(b)

an operational technology system such as an industrial control system, a programmable logic controller, a supervisory control and data acquisition system, or a distributed control system;

“code of practice” means the code of practice referred to in section 25.

Cyber Security 11