Section 22
Powers to investigate and prevent serious cybersecurity incidents etc.
(1)
Where the Commissioner receives information regarding a cybersecurity threat or incident which satisfies the severity threshold in subsection (3), the Commissioner may exercise, or may authorise the
Deputy Commissioner, an Assistant Commissioner, a cybersecurity officer or an authorised officer to exercise, such of the powers mentioned in subsection (2) as are necessary to investigate the cybersecurity threat or incident for the purpose of —
(a)
assessing the impact or potential impact of the cybersecurity threat or incident;
(b)
eliminating the cybersecurity threat or otherwise preventing any or further harm arising from the cybersecurity incident; or
(c)
preventing a further cybersecurity incident.
(2)
The powers mentioned in subsection (1) are the following —
(a)
any power mentioned in section 21(2)(a), (b), (c) or (d);
Cybersecurity 32
(b)
direct, by written notice, any person to carry out such remedial measures, or to cease carrying on such activities, as may be specified to the person, in relation to a computer or computer system that the incident response officer has reasonable cause to suspect is or was affected by the cybersecurity incident, in order to minimise cybersecurity vulnerabilities in the computer or computer system;
Examples
Examples of remedial measures include —
(a)
the removal of malicious software from the computer;
(b)
the installation of software updates to address cybersecurity vulnerabilities;
(c)
temporarily disconnecting infected computers from a computer network until paragraph (a) or (b) is carried out; and
(d)
the redirection of malicious data traffic towards a designated computer or computer system.
(c)
require the owner of a computer or computer system to take any action to assist with the investigation, including but not limited to —
(i)
preserving the state of the computer or computer system by not using it;
(ii)
monitoring the computer or computer system for a specified period of time;
(iii)
performing a scan of the computer or computer system to detect cybersecurity vulnerabilities and to assess the manner and extent that the computer or computer system is affected by the cybersecurity incident; and
(iv)
allowing the incident response officer to connect any equipment to the computer or computer system, or install on the computer or computer system any computer program, as is necessary for the purpose of the investigation;
(d)
after giving reasonable notice to the owner or occupier of any premises, enter those premises if the incident response officer
Cybersecurity 33
reasonably suspects that there is within the premises a computer or computer system that is or was affected by the cybersecurity incident;
(e)
access, inspect and check the operation of a computer or computer system that the incident response officer has reasonable cause to suspect is or was affected by the cybersecurity incident, or use or cause to be used any such computer or computer system to search any data contained in or available to such computer or computer system;
(f)
perform a scan of a computer or computer system to detect cybersecurity vulnerabilities in the computer or computer system;
(g)
take a copy of, or extracts from, any electronic record or computer program contained in a computer that the incident response officer has reasonable cause to suspect is or was affected by the cybersecurity incident;
(h)
subject to subsection (5), with the consent of the owner, take possession of any computer or other equipment for the purpose of carrying out further examination or analysis.
(3)
A cybersecurity threat or incident satisfies the severity threshold mentioned in subsection (1) if —
(a)
it creates a risk of significant harm being caused to a critical information infrastructure;
(b)
it creates a risk of disruption to the provision of an essential service;
(c)
it creates a threat to the national security, defence, foreign relations, economy, public health, public safety or public order of
Brunei Darussalam; or
(d)
the cybersecurity threat or incident is of a severe nature, in terms of the severity of the harm that may be caused to persons in
Brunei Darussalam or the number of computers or value of the information put at risk, whether or not the computers or computer systems put at risk are themselves critical information infrastructure.
Cybersecurity 34
(4)
An incident response officer exercising the power mentioned in subsection (2)(e) may require any assistance the incident response officer needs to gain such access from —
(a)
any person whom the incident response officer reasonably suspects uses or has used the computer or computer system; or
(b)
any person having charge of, or who is otherwise concerned with the operation of, such computer or computer system.
(5)
Where the owner of the computer or other equipment does not consent to the exercise of the power mentioned in subsection (2)(h), the power may be exercised if the Commissioner is satisfied that —
(a)
the exercise of the power is necessary for the purposes of the investigation;
(b)
there is no less disruptive method of achieving the purpose of the investigation; and
(c)
after consultation with the owner, and having regard to the importance of the computer or other equipment to the business or operational needs of the owner, the benefit from the exercise of the power outweighs the detriment caused to the owner, and the Commissioner has issued to the incident response officer a written authorisation to exercise the power.
(6)
The incident response officer shall, immediately after the completion of the further examination or analysis on the computer or other equipment which was taken into possession in exercise of the power mentioned in subsection (2)(h), return the computer or other equipment to the owner.
(7)
Any person who —
(a)
in relation to an investigation under this section, wilfully misstates or without reasonable excuse, refuses to give any information, provide any statement or produce any record, document or copy required of the person by the incident response officer under section 21(2);
Cybersecurity 35
(b)
in relation to an investigation under this section, fails, without reasonable excuse, to comply with an order issued by a Magistrate under section 21(5);
(c)
fails, without reasonable excuse, to comply with a direction or requirement of an incident response officer under subsection (2)(b)
or (c); or
(d)
fails, without reasonable excuse, to comply with a lawful demand of an incident response officer made in the discharge of the duties of the incident response officer under this section, is guilty of an offence and liable on conviction to a fine not exceeding $25,000, imprisonment for a term not exceeding 2 years or both.
Production of identification card by incident response officer 23.
Every incident response officer, when exercising any of the powers under this Part, shall declare the office of the incident response officer and shall, on demand, produce to any person affected by the exercise of that power such identification card as the Commissioner may direct to be carried by the incident response officer when exercising such power.
Appointment of cybersecurity technical experts 24.
(1)
The Commissioner may, in writing, appoint any of the following as a cybersecurity technical expert for a specified period to assist any incident response officer in the course of an investigation under section 21 or 22 —
(a)
a public officer or an employee of a statutory body;
(b)
an individual (who is not a public officer or an employee of a statutory body) with suitable qualifications or experience to properly perform the role of a cybersecurity technical expert.
(2)
The role of a cybersecurity technical expert is to provide such advice of a technical nature as the incident response officer may require in the course of an investigation under section 21 or 22.
(3)
The Commissioner may, for any reason that appears to the
Commissioner to be sufficient, at any time revoke the appointment of an individual as a cybersecurity technical expert.
Cybersecurity 36
(4)
The Commissioner shall issue to each cybersecurity technical expert an identification card which shall be carried at all times by the cybersecurity technical expert when performing the role of a cybersecurity technical expert.
(5)
A cybersecurity technical expert whose appointment as such ceases shall return any identification card issued to the cybersecurity technical expert under subsection (4) to the Commissioner.
Emergency cybersecurity measures and requirements 25.
(1)
The Minister may, if satisfied that it is necessary for the purposes of preventing, detecting or countering any serious and imminent threat to —
(a)
the provision of any essential service; or
(b)
the national security, defence, foreign relations, economy, public health, public safety or public order of Brunei Darussalam, by a certificate under the hand of the Minister, authorise or direct any person or organisation specified in the certificate (referred to in this section as the specified person) to take such measures or comply with such requirements as may be necessary to prevent, detect or counter any threat to a computer or computer system or any class of computers or computer systems.
(2)
The measures and requirements mentioned in subsection (1) may include, without limitation —
(a)
the exercise by the specified person of the powers in section 18(1) of the Computer Misuse Act (Chapter 194);
(b)
requiring or authorising the specified person to direct another person to provide any information that is necessary to identify, detect or counter any such threat, including —
(i)
information relating to the design, configuration or operation of any computer, computer program or computer system; and
(ii)
information relating to the cybersecurity of any computer, computer program or computer system;
Cybersecurity 37
(c)
providing to the Minister or the Commissioner any information (including real time information) obtained from any computer controlled or operated by the specified person, or obtained by the specified person from another person pursuant to a measure or requirement under paragraph (b), that is necessary to identify, detect or counter any such threat, including —
(i)
information relating to the design, configuration or operation of any computer, computer program or computer system; and
(ii)
information relating to the cybersecurity of any computer, computer program or computer system; and
(d)
providing to the Minister or the Commissioner a report of a breach or an attempted breach of cybersecurity of a description specified in the certificate under subsection (1) relating to any computer controlled or operated by the specified person.
(3)
Any measure or requirement mentioned in subsection (1) and any direction given by a specified person for the purpose of taking any such measure or complying with any such requirement —
(a)
does not confer any right to the production of, or of access to, information subject to legal privilege; and
(b)
subject to paragraph (a), has effect despite any obligation or limitation imposed or right, privilege or immunity conferred by or under any law, contract or rules of professional conduct, including any restriction on the disclosure of information imposed by law, contract or rules of professional conduct.
(4)
A specified person who, without reasonable excuse, fails to take any measure or comply with any requirement directed by the Minister under subsection (1) is guilty of an offence and liable on conviction to a fine not exceeding $50,000, imprisonment for a term not exceeding 10 years or both.
(5)
Any person who, without reasonable excuse —
(a)
obstructs a specified person in the taking of any measure or in complying with any requirement under subsection (1); or
Cybersecurity 38
(b)
fails to comply with any direction given by a specified person for the purpose of the specified person taking any such measure or complying with any such requirement, is guilty of an offence and liable on conviction to a fine not exceeding $50,000, imprisonment for a term not exceeding 10 years or both.
(6)
No civil or criminal liability is incurred by —
(a)
a specified person for doing or omitting to do any act if the specified person had done or omitted to do the act in good faith and for the purpose of or as a result of taking any measure or complying with any requirement under subsection (1); or
(b)
a person for doing or omitting to do any act if the person had done or omitted to do the act in good faith and for the purpose of or as a result of complying with a direction given by a specified person for the purpose of taking any such measure or complying with any such requirement.
(7)
The following persons are not considered to be in breach of any restriction on the disclosure of information imposed by law, contract or rules of professional conduct —
(a)
a specified person who, in good faith, obtains any information for the purpose of taking any measure under subsection (1)
or complying with any requirement under that subsection, or who discloses any information to the Minister or the Commissioner, in compliance with any requirement under that subsection;
(b)
a person who, in good faith, obtains any information, or discloses any information to a specified person, in compliance with a direction given by the specified person for the purpose of taking any measure under subsection (1) or complying with any requirement under that subsection.
(8)
The following persons, namely —
(a)
a specified person to whom a person has provided information in compliance with a direction given by the specified person for the purpose of taking any measure under subsection (1) or complying with any requirement under that subsection;
Cybersecurity 39
(b)
a person to whom a specified person provides information in compliance with any requirement under subsection (1), shall not use or disclose the information, except —
(i)
with the written permission of the person from whom the information was obtained or, where the information is the confidential information of a third person, with the written permission of the third person;
(ii)
for the purpose of preventing, detecting or countering a threat to a computer, computer system or class of computers or computer systems;
(iii)
to disclose to any police officer or other law enforcement authority any information which discloses the commission of an offence under this Act or any other written law; or
(iv)
in compliance with a requirement of a court or the provisions of this Act or any other written law.
(9)
Any person who contravenes subsection (8) is guilty of an offence and liable on conviction to a fine not exceeding $10,000, imprisonment for a term not exceeding 12 months or both.
(10)
Where an offence is disclosed in the course of or pursuant to the exercise of any power under this section —
(a)
no information for that offence may be admitted in evidence in any civil or criminal proceedings; and
(b)
no witness in any civil or criminal proceedings is obliged —
(i)
to disclose the name, address or other particulars of any informer who has given information with respect to that offence; or
(ii)
to answer any question if the answer would lead, or would tend to lead, to the discovery of the name, address or other particulars of the informer.
(11)
If any book, document, data or computer output which is admitted in evidence or liable to inspection in any civil or criminal proceedings
Cybersecurity 40
contains any entry in which any informer is named or described or which may lead to the discovery of the informer, the court shall cause those entries to be concealed from view or to be obliterated so far as may be necessary to protect the informer from discovery.