81

(i)

cyber security-related threats, any measures implemented to address such cyber
security-related threats and shortcomings in addressing such cyber security
related threats;

(ii)

any matter relevant to, incidental to or which may impact on the objects and
functions of the Cyber Security Centre as set out in subsection (5); and

(iii)

any other matter relating to this Act which the Director wishes to or may want to
bring to the attention of the Cyber Response Committee.
(5)

(a)

The objects and functions of the Cyber Security Centre are to—

facilitate the operational coordination of cyber security incident response
activities regarding national intelligence;

(b)

develop measures to deal with cyber security matters impacting on national
security;

(c)

facilitate the analysis of cyber security incidents, trends, vulnerabilities,
information-sharing, technology exchange on national security and threats in
order to improve technical response coordination;

(d)

provide guidance to and facilitate the identification, protection and securing of
National Critical Information Infrastructures;

(e)

ensure

the

assessment

and

testing

of

National

Critical

Information

Infrastructures, including vulnerability assessments, threat and risk assessments
and penetration testing, on the written request of the Director-General: State
Security;
(f)

provide coordination and guidance regarding corporate security and policy
development, governance, risk management and compliance, identity and
security management, security information and event management and cyber
forensics;

(g)

develop response protocols in order to guide coordinated responses to cyber
security incidents and interaction with the various stakeholders;

(h)

ensure the conducting of cyber security audits, assessments and readiness
exercises and provide advice on the development of national response plans;

Select target paragraph3