Part II - The Zambia Cyber Security Agency
3. Establishment of Zambia Cyber Security Agency
- There is established the Zambia Cyber Security Agency in the Office of the President which is responsible for the administration of this Act under the general direction of the President.
- The Agency shall be responsible for the coordination of cyber security matters in the Republic.
- The Agency shall collaborate with relevant institutions which are constitutionally mandated to defend the Republic in cyber warfare and offensive cyber operations to uphold the sovereignty of the Republic.
4. Functions of Agency
The functions of the Agency are to—
- subject to the Zambia Security Intelligence Service Act, 1998, coordinate activities relating to cyber security and cyber resilience;
- take measures in response to cyber security incidents which may threaten critical information, critical information infrastructure or any information or infrastructure in the Republic likely to be affected by a cyber security incident;
- disseminate information on cyber threats and vulnerabilities;
- identify and ensure the protection of critical information and critical information infrastructure;
- establish codes of practice and standards for cyber security and monitor compliance with the codes of practice and standards by controllers;
- issue licences for the provision of cyber security services;
- regulate the conduct of cyber security service providers;
- promote and undertake research and development relating to cyber security;
- promote and undertake capacity building, education and awareness activities on matters relating to cyber security;
- undertake information security audits on critical information and critical information infrastructure;
- adopt standards for cyber security products and services and certify cyber security products and services;
- develop and implement a national cyber security response plan;
- undertake digital forensics;
- provide technical assistance and collaborate with other relevant national and international institutions in matters relating to this Act; and
- advise the President on matters relating to cyber security.
5. Director-General and other staff
- The President shall, appoint a Director-General of the Agency who shall be a public officer.
- The Director-General is the chief executive officer of the Agency and is responsible for the day to day management of the Agency.
- The President shall appoint a Deputy Director-General, Directors and Deputy Directors who are necessary for the implementation of the provisions of this Act.
- The Director-General shall, on the recommendation of the Staff Board, appoint other officers below the rank of Deputy Director that are necessary for the implementation of the provisions of this Act.