Seksyen 1
(1)
Peraturan-peraturan ini bolehlah dinamakan Peraturan-Peraturan
Keselamatan Siber (Pemberitahuan Insiden Keselamatan Siber) 2024.
The full official text, structured for quick navigation. Copy any provision or jump straight to a section.
Peraturan-Peraturan Keselamatan Siber (Pemberitahuan Insiden Keselamatan Siber) 2024 is Malaysia P.U. (A), cited as P.U. (A) 220 2024, currently marked in force and first recorded in 2024.
P.U. (A) 220
WARTA KERAJAAN PERSEKUTUAN
FEDERAL GOVERNMENT
GAZETTE
PERATURAN-PERATURAN KESELAMATAN SIBER
(PEMBERITAHUAN INSIDEN
KESELAMATAN SIBER) 2024
CYBER SECURITY (NOTIFICATION OF
CYBER SECURITY INCIDENT) REGULATIONS 2024
DISIARKAN OLEH/
JABATAN PEGUAM NEGARA/
ATTORNEY GENERAL’S CHAMBERS
P.U. (A) 220 2
AKTA KESELAMATAN SIBER 2024
PERATURAN-PERATURAN KESELAMATAN SIBER (PEMBERITAHUAN INSIDEN
KESELAMATAN SIBER) 2024
Opening note
Peraturan-peraturan ini bolehlah dinamakan Peraturan-Peraturan
Keselamatan Siber (Pemberitahuan Insiden Keselamatan Siber) 2024.
Tempoh pemberitahuan dan butiran maklumat
Orang yang diberi kuasa bagi entiti infrastruktur maklumat kritikal negara hendaklah memberitahu dengan segera, melalui cara elektronik, mengenai suatu insiden keselamatan siber yang telah atau mungkin telah berlaku sebagaimana yang diperuntukkan di bawah seksyen 23 Akta apabila insiden keselamatan siber itu diketahui oleh entiti infrastruktur maklumat kritikal negara.
Dalam masa enam jam daripada insiden keselamatan siber itu diketahui oleh entiti infrastruktur maklumat kritikal negara, orang yang diberi kuasa hendaklah mengemukakan butiran maklumat seperti yang berikut:
butiran entiti infrastruktur maklumat kritikal negara yang terlibat, sektor infrastruktur maklumat kritikal negara dan ketua sektor infrastruktur maklumat kritikal negara yang berkaitan dengannya; dan
P.U. (A) 220 3
jenis dan perihal insiden keselamatan siber;
Dalam masa empat belas hari selepas pemberitahuan yang disebut dalam subperaturan (1), orang yang diberi kuasa hendaklah mengemukakan setakat yang boleh maklumat tambahan seperti yang berikut:
butiran infrastruktur maklumat kritikal negara yang tejejas oleh insiden keselamatan siber itu;
maklumat mengenai apa-apa insiden yang berhubungan dengan, dan cara insiden itu yang berkaitan dengan, insiden keselamatan siber itu;
kesan insiden keselamatan siber terhadap infrastruktur maklumat kritikal negara atau mana-mana komputer atau sistem komputer yang saling bersambung; dan
Orang yang diberi kuasa oleh entiti infrastruktur maklumat kritikal negara hendaklah menyediakan, dari semasa ke semasa, kemas kini lanjut mengenai insiden keselamatan siber sebagaimana yang dikehendaki oleh Ketua Eksekutif.
Cara pengemukaan maklumat
Pengemukaan maklumat di bawah subperaturan 2(2) dan (3) hendaklah dibuat melalui Sistem Pusat Penyelarasan dan Kawalan Siber Negara atau sekiranya berlaku gangguan pada Sistem Pusat Penyelarasan dan Kawalan Siber Negara, dengan komunikasi sebagaimana yang ditentukan oleh Ketua Eksekutif.
Dibuat 19 Ogos 2024
[MKN(S).10.600-9/2/4 Jld.9(5); PN(PU2)768]
DATO’ SERI ANWAR BIN IBRAHIM
Perdana Menteri
P.U. (A) 220 5
CYBER SECURITY ACT 2024
CYBER SECURITY (NOTIFICATION OF CYBER SECURITY INCIDENT)
REGULATIONS 2024
Opening note
These regulations may be cited as the Cyber Security (Notification of
Cyber Security Incident) Regulations 2024.
These Regulations come into operation on 26 August 2024.
Period of notification and particulars of information 2.
An authorized person of a national critical information infrastructure entity shall immediately, by electronic means, give a notification of a cyber security incident that has or might have occurred as provided under section 23 of the Act when the cyber security incident comes to the knowledge of the national critical information infrastructure entity.
Within six hours from the time the cyber security incident comes to the knowledge of the national critical information infrastructure entity, the authorized person shall submit the following particulars of information:
the particulars of the national critical information infrastructure entity concerned, the national critical information infrastructure sector and national critical information infrastructure sector lead to which it relates; and
P.U. (A) 220 6
the type and description of the cyber security incident;
Within fourteen days after the notification referred to in subregulation (1), the authorized person shall provide to the fullest extent practicable the following supplementary information:
the particulars of the national critical information infrastructure affected by the cyber security incident;
the information on any incident relating to, and the manner in which such incident relates to, the cyber security incident;
the particulars of the tactics, techniques and procedures of the cyber security incident;
P.U. (A) 220 7
the impact of the cyber security incident on the national critical information infrastructure or any computer or interconnected computer system; and
The authorized person of the national critical information infrastructure entity shall provide, from time to time, further updates on the cyber security incident as the Chief Executive may require.
Manner of submission of information 3.
The submission of information under subregulations 2(2) and (3) shall be made through the National Cyber Coordination and Command Centre System or in the event of disruption in the National Cyber Coordination and Command Centre System, by the communication as may be determined by the Chief Executive.
Made 19 August 2024
[MKN(S).10.600-9/2/4 Jld.9(5); PN(PU2)768]
DATO’ SERI ANWAR BIN IBRAHIM
Prime Minister
If one provision's text doesn't match the official source, use Suggest a fix beside that provision — it opens an editor next to the source document. For anything else — a missing amendment, a broken link, out-of-date content, or a removal request — report it here.