Section 9
Designation of critical information infrastructure
(1)
The Commissioner may, by written notice to the owner of a computer or computer system, designate the computer or computer system as a critical information infrastructure for the purposes of this Act, if the
Commissioner is satisfied that —
(a)
the computer or computer system is necessary for the continuous delivery of an essential service and the loss or compromise of the computer or computer system will have a debilitating effect on the availability of the essential service in Brunei Darussalam; and
(b)
the computer or computer system is located wholly or partly in Brunei Darussalam.
(2)
A notice issued under subsection (1) shall —
(a)
identify the computer or computer system that is being designated as a critical information infrastructure;
(b)
identify the owner of the computer or computer system so designated as a critical information infrastructure;
(c)
inform the owner of the computer or computer system, regarding the duties and responsibilities of the owner under this Act that arise from the designation;
(d)
provide the name and contact particulars of the officer assigned by the Commissioner to supervise the critical information infrastructure;
(e)
inform the owner of the computer or computer system that any representation against the designation is to be made to the
Commissioner by a specified date, being a date not earlier than 14 days after the date of the notice; and
(f)
inform the owner of the computer or computer system that the owner may appeal to the Minister against the designation and provide information on the applicable procedure.
Cybersecurity 16
(3)
Any designation under subsection (1) has effect for a period of 5 years, unless it is withdrawn by the Commissioner before the expiry of the period.
(4)
The person who receives a notice under subsection (1) may request the Commissioner to proceed under subsection (5) on showing proof that —
(a)
the person is not able to comply with the requirements in this
Part for the reason that the person has neither effective control over the operations of the computer or computer system, nor the ability or right to carry out changes to the computer or computer system; and
(b)
another person has effective control over the operations of the computer or computer system and the ability and right to carry out changes to the computer or computer system.
(5)
If the Commissioner is satisfied that the conditions mentioned in subsection (4)(a) and (b) are met, the Commissioner may amend the notice issued to the person under subsection (1) and address and send that amended notice to the person mentioned in subsection (4)(b).
(6)
During the period when a notice amended under subsection (5) is in effect, the provisions of this Part apply to the person mentioned in subsection (4)(b) as if every reference to the owner of a critical information infrastructure is a reference to the person mentioned in subsection (4)(b).
(7)
Where —
(a)
a notice issued under this section and amended under subsection (5) is addressed and sent to the person mentioned in subsection (4)(b); and
(b)
the person mentioned in subsection (4)(b) then ceases to have the control, ability and right mentioned in that provision, the owner of the critical information infrastructure shall notify the
Commissioner of this without delay.
(8)
Where a critical information infrastructure is owned by the
Government and operated by a Ministry, the Permanent Secretary allocated to the Ministry who has responsibility for the critical information
Cybersecurity 17
infrastructure is treated as the owner of the critical information infrastructure for the purposes of this Act.
(9)
A notice issued under this section need not be published in the
Gazette.
Power to obtain information to ascertain if computer etc. fulfils criteria of critical information infrastructure 10.
(1)
This section applies where the Commissioner has reason to believe that a computer or computer system may fulfil the criteria of a critical information infrastructure.
(2)
The Commissioner may, by notice issued in such form and manner as the Commissioner may determine, require any person who appears to be exercising control over the computer or computer system, to provide to the Commissioner, within a reasonable period specified in the notice, such relevant information relating to that computer or computer system as may be required by the Commissioner for the purpose of ascertaining whether the computer or computer system fulfils the criteria of a critical information infrastructure.
(3)
Without affecting the generality of subsection (2), the
Commissioner may in the notice require the person who appears to be exercising control over the computer or computer system to provide —
(a)
information relating to —
(i)
the function that the computer or computer system is employed to serve; and
(ii)
the person or persons who is or are, or other computer or computer systems that is or are, served by that computer or computer system;
(b)
information relating to the design of the computer or computer system; and
(c)
such other information as the Commissioner may require in order to ascertain whether the computer or computer system fulfils the criteria of a critical information infrastructure.
Cybersecurity 18
(4)
Any person who, without reasonable excuse, fails to comply with a notice issued under subsection (2) is guilty of an offence and liable on conviction to a fine not exceeding $100,000, imprisonment for a term not exceeding 2 years or both and, in the case of a continuing offence, to a further fine not exceeding $5,000 for every day or part thereof during which the offence continues after conviction.
(5)
Any person to whom a notice is issued under subsection (2) is not obliged to disclose any information that is subject to any right, privilege or immunity conferred, or obligation or limitation imposed, by or under any law, contract or rules of professional conduct in relation to the disclosure of such information.