Skip to content

Section 34

Licensees’ infrastructure information security

of Ocean Thermal Energy Conversion Enactment 2024

State EnactmentIn forceProvision 34 of 37
Section 34
(1)

Any licensee as directed by the Commission shall be responsible for the preservation of confidentiality, integrity and availability of the licensees’ information, information systems and supporting network infrastructure pertaining to the construction or operation of the facility or plantship, duties and other matters as provided under this Enactment.

(2)

The licensee shall —

(a)

take the necessary measures, establish and implement standards and employ the relevant information security controls to prevent, avoid, remedy, recover or restore its information, document, instrument or records stored in its computers and for its operational system by its computers from any risk of —

(i)

threat or unauthorized access; and

(ii)

intrusion or removal;

(b)

take necessary measures to ensure the resiliency of its supporting network infrastructure to minimize business impact against various threats to the construction or operation of the facility or plantship; and

(c)

ensure that the reliability, continuity and quality of the construction or operation of the facility or plantship, its performance of duties and conformity to the provisions of this Enactment shall not be jeopardized thereby, and shall, within the time specified by the Commission, submit such information as required by the Commission and in the event of any incident which may interfere or affect the performance of the licensed construction

28

or operation of the facility or plantship, report to the Commission and other relevant authorities.

(3)

Any licensee who fails or neglects to comply with or contravenes any provision of this section commits an offence and shall, on conviction, be liable to a fine not exceeding one million ringgit or to imprisonment for a term not exceeding ten years or to both.

(4)

For the purposes of this section —

“supporting network infrastructure” refers to relevant connection, network devices, hardware and software that provides network services in supporting business functions;

“information security controls” refers to means of managing risk, including policies, procedures, guidelines, practices or organizational structures, which can be administrative, technical, management or legal in nature; and

“resiliency” means an ability of an organization to resist being affected by an incident.