Skip to content

Section 32

Duty to keep and maintain record

of Cyber Security Act 2024

ActIn forceProvision 32 of 64
Section 32
(1)

A licensee shall, on each occasion where the licensee is engaged to provide cyber security service, keep and maintain the following records:

(a)

the name and address of the person engaging the licensee for the cyber security service;

(b)

the name of the person providing the cyber security service on behalf of the licensee, if any;

(c)

the date and time of cyber security service that was provided by the licensee or other person on behalf of the licensee;

(d)

details of the type of cyber security service provided;

and

(e)

such other particulars as may be determined by the

Chief Executive.

(2)

The information referred to in subsection (1) shall be—

(a)

kept and maintained in the manner as may be determined by the Chief Executive;

(b)

retained for a period of not less than six years from the date the cyber security service was provided; and

(c)

produced to the Chief Executive at any time as the

Chief Executive may direct.

Act 854

(3)

Any person who contravenes subsection (1) or (2) commits an offence and shall, on conviction, be liable to a fine not exceeding one hundred thousand ringgit or to imprisonment for a term not exceeding two years or to both.