REGULATION

The Computer Misuse and Cybercrime (Critical Information Infrastructure and Cybercrime Management) Regulations, 2024

Legal Notice No. 44 of 9 February 2024 operationalizes CMCA implementation. It sets detailed compliance, governance, operations-center, audit, reporting, and…

The Computer Misuse and Cybercrime (Critical Information Infrastructure and Cybercrime Management) Regulations, 2024

Regulatory role: These Regulations translate the Act into implementable controls. They establish detailed procedures for cybersecurity operations centers, critical infrastructure designation and obligations, cybersecurity capability development, incident reporting pathways, and audit/compliance enforcement.

Objects and principles: The Regulations provide frameworks for monitoring and responding to cyber threats, protecting and managing critical information infrastructure, auditing compliance, and building national capability. They are guided by coordination, public-private collaboration, accountability, resilience, rights-respecting security, and mutual trust among stakeholders.

Scope: Application is broad across public and private sectors, including members of the public, owners of critical information infrastructure, service providers, and other relevant entities connected to cybersecurity operations.

Three-tier operations center model: The framework establishes National, Sector, and CII-level cybersecurity operations centers. It assigns clear roles for real-time monitoring, threat intelligence sharing, incident response coordination, capacity building, and escalation/reporting between CII operators, sector regulators, and the national center.

Designation and directives: The Director may designate critical systems and notify owners, then issue directives within defined timelines. Where directives are ignored, enforcement steps include notices to show cause, implementation plans, administrative sanctions, regulator engagement, and recommendation of investigations.

Localisation and transfer controls: Owners are required to keep critical information infrastructure data in Kenya unless approval is granted for external hosting. Review considers security safeguards, national security, public interest, and data protection concerns before any such approval.

Owner obligations and baseline controls: Owners must implement physical and technical security controls, access management, periodic maintenance/testing, risk assessments, business continuity and disaster readiness, and administrative controls over personnel and removable media. Baseline controls also include internal cybersecurity policy, data protection alignment, and appointment/designation of a Chief Information Security Officer.

Audit and compliance regime: Owners submit compliance reports and risk registers; the Director conducts annual or threat-triggered audits. Audits combine compliance-based and risk-based methods and must include findings, recurring issues, mitigation status, and recommendations for stronger governance and controls.

NPKI and national capability building: The Regulations set National Public Key Infrastructure components and responsibilities, then provide for training guides, information sharing frameworks, certification standards, automation/checklists, and collaboration with government, private sector, training institutions and international partners.

Incident reporting system: Critical infrastructure incidents must be reported to sector operations centers within 24 hours. The Regulations also require cybercrime reporting channels, cybercrime desks at police stations and posts, specialized personnel training, public awareness programs, and anonymous reporting mechanisms with protections for good-faith whistleblowing.

Data rights and legal safeguards: The Data Protection Act, 2019 applies to processing of personal data under these Regulations, maintaining legal consistency between national cybersecurity and privacy compliance.