POTRAZ To HouseNational Cyber Security Centre If Cyber Security And Data Protection Bill Is Passed Into Law

Farai Mudzingwa Avatar

The draft of the Cybersecurity bill was finally gazetted – it’s one step closer to coming into law or (if parliamentarians aren’t happy with it) being rejected.

One of the more topical issues outlined in the bill is the fact that POTRAZ will become the “National Cyber Security Centre” if the bill is effected into law.

The Postal and Telecommunications Regulatory Authority established in terms of the Postal and Telecommunications Act [Chapter 12:05] is hereby designated as the Cyber Security Centre.

CYBER SECURITY AND DATA PROTECTION BILL, 2019

This new National Cyber Security Centre (NCSC) is mandated to carry out the following functions;

  1. Advise & implement government policy on cybercrime and cybersecurity;
  2. identify areas for intervention to prevent cybercrime;
  3. coordinate cybersecurity and establish a national contact point available daily around-the-clock;
  4. establish and operate a protection-assured whistle-blower system that will enable members of the public to confidentially report to the Committee cases of alleged cybercrime;
  5. promote and coordinate activities focused on improving cybersecurity and preventing cybercrime by all interested parties in the public and private sectors;
  6. provide guidelines to public and private sector interested parties on matters relating to awareness, training, enhancement, investigation, prosecution and combating cybercrime and managing cybersecurity threats;
  7. oversee the enforcement of the Act to ensure that it is enforced reasonably and with due regard to fundamental human rights and freedoms;
  8. provide technical and policy advice to the Minister;
  9. advise the Minister on the establishment and development of comprehensive legal framework governing cybersecurity matters

Criticisms..

The biggest question mark I have is that of conflict of interest. The NCSC is under POTRAZ which is a government organisation. Will that hierarchy be allowed to “establish and operate a protection-assured whistle-blower system”?

Ok here’s a clearer way to think about it. The POTRAZ board is appointed by the government (usually the ICT Minister). So what happens when a whistleblower exposes the ICT Minister, the government or the President who appointed said Minister?

Will this Whistle-blower system be allowed to carry out its mandate when a targeted Minister/President can simply appoint a new board that ensures the Whistleblower is actually exposed instead of being protected. Separation of powers is important and as long as it doesn’t exist the NCSC will be a facade.

Parts of the NCSCs mandate aren’t clear. One example is “coordinate cybersecurity”. It’s vague and doesn’t clearly spell out what coordinating cybersecurity is. The clearer the mandate the better the NCSC will be at doing its job and the easier it will be for taxpayers to hold it accountable.

Lastly, and this is less of a criticism and more of me thinking out loud – does POTRAZ already have the capacity to carry out what is being proposed here or that will be built out once the law is put into place?

,

One response

What’s your take?

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  1. Robert

    Whisteblower where are that thou hidding ?

    Crazy notion to want to convert POTRAZ into the Spy Center

    Minister Supa and his predecessor had enough time to implement a separate Cyber Security Command Center crafted along the lines of the one in SA and Zambia.

    But well then divided priorities and skills shortage will always deal a hard blow on this.

    POTRAZ is a telecoms regulator and not a spy camp. This must be rejected.

2023 © Techzim All rights reserved. Hosted By Cloud Unboxed