{"id":3213,"date":"2024-04-22T20:00:00","date_gmt":"2024-04-23T01:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cyber-risk\/licensed-to-bill-nations-mandate-certification-licensure-of-cybersecurity-pros"},"modified":"2024-04-22T20:00:00","modified_gmt":"2024-04-23T01:00:00","slug":"licensed-to-bill-nations-mandate-certification-licensure-of-cybersecurity-pros","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/04\/22\/licensed-to-bill-nations-mandate-certification-licensure-of-cybersecurity-pros\/","title":{"rendered":"Licensed to Bill? Nations Mandate Certification &amp; Licensure of Cybersecurity Pros"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt9e4db3c560a51b47\/6626ff9ccc81a574edaa976e\/kualalumpurcity_rudi1976_Alamy_Stock_Photo.jpeg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/licensed-to-bill-nations-mandate-certification-licensure-of-cybersecurity-pros.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/licensed-to-bill-nations-mandate-certification-licensure-of-cybersecurity-pros.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Malaysia has joined at least two other nations \u2014 Singapore and Ghana \u2014 in passing laws that require cybersecurity professionals or their firms to be certified and licensed to provide some cybersecurity services in their country.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">On April 3, the upper house of the Malaysian Parliament, known as the Dewan Negara, passed the Cyber Security Bill 2024, following its passage in the lower house the previous month. The bill, which will become law following its signing by the King and its publication in the Government Gazette, is structured as umbrella legislation and will act as a framework for future government activity securing critical infrastructure and improving the national state of cybersecurity.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While the legislation mandates licensing, the actual requirements for cybersecurity professionals and service providers will come later, Malaysia-based law firm Christopher &amp; Lee Ong <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.christopherleeong.com\/media\/7832\/2024_27_03-cybersecurity-bill.pdf\" rel=\"noopener\">stated in an advisory<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;While the Bill does not specify the types of cyber security services that are subject to the licensing regime &#8230; this will likely apply to service providers that provide services to safeguard information and communications technology device of another person \u2014 [for example,] penetration testing providers and security operation centres,&#8221; the law firm stated.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Malaysia joins Asia-Pacific neighbor Singapore, which has required the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.csa.gov.sg\/News-Events\/Press-Releases\/2022\/csa-kicks-off-licensing-framework-for-cybersecurity-service-providers\" rel=\"noopener\">licensing of cybersecurity service providers (CSPs)<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> for the past two years, and the West African nation of Ghana, which requires the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.csa.gov.gh\/licensing_and_accreditation\" rel=\"noopener\">licensing of CSPs and the accreditation of cybersecurity professionals<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. More widely, governments <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/cybersecurity-certification-framework\" rel=\"noopener\">such as the European Union<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> have normalized cybersecurity certifications, while other agencies \u2014 <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.dfs.ny.gov\/industry_guidance\/cybersecurity\" rel=\"noopener\">such as the US state of New York<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> \u2014 require certification and licenses for cybersecurity capabilities in specific industries.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"License to Hack in Ghana\">License to Hack in Ghana<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While many governments require businesses to obtain licenses to offer cybersecurity services, Ghana is the only nation to require individuals to have a license, says Alexey Lukatsky, managing director of cybersecurity business consulting at Positive Technologies, a Moscow-based cybersecurity provider.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The uniqueness of Ghana&#8217;s approach lies in the fact that licensing requirements apply not to all cybersecurity specialists, but to those who plan to work in four specific areas \u2014 vulnerability assessment and penetration testing, digital forensics, managed cybersecurity services, cybersecurity training, and cybersecurity GRC,&#8221; he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Singapore&#8217;s government has taken a proactive approach to prompting private industry to adopt stringent cybersecurity regulations, with organizations so far <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-analytics\/singapore-sets-high-bar-in-cybersecurity-preparedness\" rel=\"noopener\">implementing more than 70%<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> of the requirements needed for a &#8220;Cyber Essentials&#8221; certification.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We most certainly think that having a bare minimum standard will engender more confidence across the ecosystem as there will be assurance that \u2014 among others \u2014 penetration testing, security audits, and incident response services to be provided are on par with industry expectations and evolving technologies,&#8221; says Serene Kan, a partner in the IP &amp; technology practice at Wong &amp; Partners, member firm of Baker McKenzie International.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In the United States, such efforts have not gained much ground. Instead, many professional organizations <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/niccs.cisa.gov\/education-training\/cybersecurity-certifications\" rel=\"noopener\">offer certification of specific sets of skills<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. ISC2, for example, administers the well-known Certified Information Systems Security Professional (CISSP) accreditation, while CompTIA offers the Security+ certification, and ISACA \u2014 formerly the Information Systems Audit and Control Association \u2014 offers the Certified Information System Auditor (CISA) certification, among others.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">ISC2 and ISACA declined to comment for this article.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Lack of Protections for Free Speech\">Lack of Protections for Free Speech<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While the requirements appear to improve the overall maturity of the countries&#8217; cybersecurity posture, legislation has often raised concerns over potential cost to freedom of speech and other individual rights.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Governments that gain broad power to regulate activities related to cybersecurity by default have powers to control digital services. This often results in targeting journalistic activities and whistleblowers by requiring &#8220;pre-approval under arbitrary standards subject to change or revocation,&#8221; according to Article 19, a human rights organization.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The Malaysian cybersecurity bill, for example, is &#8220;unnecessary and flawed in its current state,&#8221; the organization stated.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Although posing as a \u2018cybersecurity\u2019 instrument, the Bill will give the government unaccountable control of computer-related activities, as well as nearly unlimited search and seizure powers,&#8221; the organization <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.article19.org\/resources\/malaysia-the-cyber-security-bill-is-a-threat-to-freedom-of-expression-online\/\" rel=\"noopener\">said in an analysis of the bill<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. &#8220;Its criminal provisions do not require any actual intent to violate, effectively introducing many strict liability offences.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In particular, cybersecurity researchers could be put in jeopardy, since the release of source code or cyber-offensive research would require a license, the organization stated.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Yet often licensing requirements are just putting a government stamp on certification best practices that already exist and requirements that job applicants have specific cybersecurity certifications, but with a local twist, says Positive Technologies&#8217; Lukatsky.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The approach that Ghana has pursued, for example, &#8220;resembles the establishment of a registry of all cybersecurity specialists since it is unlikely that in this or any other country there are many independent lone specialists who can work with serious organizations, where the risks of hiring unqualified personnel are too high,&#8221; he says. &#8220;The main reason for such requirements is that as the number of cyberattacks grows, specialists who understand what they are doing and why they are doing it are needed to detect and prevent them \u2014 how to apply international best practices and how to adapt them to local specifics.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/licensed-to-bill-nations-mandate-certification-licensure-of-cybersecurity-pros\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Malaysia has joined at least two other nations \u2014 Singapore<\/p>\n","protected":false},"author":12,"featured_media":3214,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3213","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/licensed-to-bill-nations-mandate-certification-licensure-of-cybersecurity-pros.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/licensed-to-bill-nations-mandate-certification-licensure-of-cybersecurity-pros.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/licensed-to-bill-nations-mandate-certification-licensure-of-cybersecurity-pros.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/licensed-to-bill-nations-mandate-certification-licensure-of-cybersecurity-pros.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/licensed-to-bill-nations-mandate-certification-licensure-of-cybersecurity-pros.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/licensed-to-bill-nations-mandate-certification-licensure-of-cybersecurity-pros.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/licensed-to-bill-nations-mandate-certification-licensure-of-cybersecurity-pros.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/licensed-to-bill-nations-mandate-certification-licensure-of-cybersecurity-pros.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/licensed-to-bill-nations-mandate-certification-licensure-of-cybersecurity-pros.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/licensed-to-bill-nations-mandate-certification-licensure-of-cybersecurity-pros.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/licensed-to-bill-nations-mandate-certification-licensure-of-cybersecurity-pros.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3213","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3213"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3213\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3214"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3213"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3213"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3213"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}