Kenya: Computer Misuse and Cybercrimes (Critical Information Infrastructure and Cybercrime Management) Regulations including measures establishing Cybersecurity Operations Centres entered into force

Description

Computer Misuse and Cybercrimes (Critical Information Infrastructure and Cybercrime Management) Regulations including measures establishing Cybersecurity Operations Centres entered into force

On 9 February 2024, the Computer Misuse and Cybercrimes (Critical Information Infrastructure and Cybercrime Management) Regulations, 2024, entered into force to provide a framework for monitoring, detecting, and responding to cybersecurity threats in Kenya’s cyberspace. The regulations establish Cybersecurity Operations Centres, including the National Cybersecurity Operations Centre, Sector Cybersecurity Operations Centres, and Critical Information Infrastructure Cybersecurity Operations Centres, to coordinate threat response and capacity building. They outline the designation and protection of critical information infrastructure, requiring owners to implement security measures, conduct risk assessments, and comply with directives issued by the Director of the National Computer and Cybercrimes Coordination Committee (NC4). The regulations also mandate the appointment of a Chief Information Security Officer, regular audits, and the submission of compliance reports to ensure adherence to cybersecurity standards and safeguard critical systems and data.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection authority governance
Regulated Economic Activity
cross-cutting
Implementation Level
national
Government Branch
executive
Government Body
central government

Complete timeline of this policy change

Hide details
2023-08-29
in consultation

On 29 August 2023, the Ministry of Interior and National Administration opened a public consultatio…

2023-09-22
processing consultation

On 22 September 2023, the Ministry of Interior and National Administration will close the public co…

2024-02-08
adopted

On 8 February 2024, Computer Misuse and Cybercrimes (Critical Information Infrastructure and Cyberc…

2024-02-09
in force

On 9 February 2024, the Computer Misuse and Cybercrimes (Critical Information Infrastructure and Cy…

We use cookies and other technologies to perform analytics on our website. By opting in, you consent to the use by us and our third-party partners of cookies and data gathered from your use of our platform. See our Privacy Policy to learn more about the use of data and your rights.