BillBuddy
Back to SBN-1163

Cybersecurity Act

SBN-1163 · 20th Congress · verbatim text↗ Official Senate PDF

Senate Olier of thr Secretary TWENTIETH CONGRESS OF THE REPUBLIC OF THE PHILIPPINES First Regular Session ) AUG -7 P6:21 SENATE RECEIVED BY: S. No. 1163 Introduced by Senator Jinggoy Ejercito Estrada AN ACT ESTABLISHING THE NATIONAL CYBERSECURITY AGENCY, DEFINING THEIR POWERS AND FUNCTIONS, AND APPROPRIATING FUNDS THEREFOR AND FOR OTHER PURPOSES EXPLANATORY NOTE In today's hyperconnected digital age, cybersecurity is not merely a technical concern but a matter of national security, public safety, and economic resilience. The Philippines, like many other countries, faces an increasingly sophisticated threat landscape where cyberattacks target not just individuals and businesses but vital sectors that comprise our Critical Information Infrastructure (CII)— including energy, telecommunications, banking, transportation, healthcare, and government services. Our current cybersecurity framework, while guided by Republic Act No. 10175 or the Cybercrime Prevention Act of 2012 and supported by existing policies under the Department of Information and Communications Technology (DICT), remains fragmented, under-resourced, and inadequately equipped to defend against advanced and persistent threats. The fast pace of digital transformation, proliferation of smart devices and networks, and increasing reliance on technology necessitate an institutional response that is agile, specialized, and comprehensive. This measure seeks to address these systemic gaps by establishing the National Cybersecurity Agency (NCSA)-a dedicated government agency attached to the DICT

which shall serve as the primary entity responsible for the planning, coordination, implementation, and enforcement of the country's cybersecurity strategy. The NCSA will serve as the primary policy, planning, coordinating, and implementing entity for the nation's cybersecurity strategy, with comprehensive powers including the establishment of the National Computer Emergency Response Team (NCERT), formulation of cybersecurity standards, and coordination of government-wide cybersecurity efforts. The proposed bill establishes a robust framework for protecting Critical Information Infrastructure (CII) through systematic identification, designation, and monitoring processes. CII operators will be required to comply with mandatory cybersecurity standards, submit regular audit reports, and report cybersecurity incidents to the NCERT within specified timeframes. The measure includes provisions for government assistance to CII operators, including access to government technical controls, priority co-location services, and secure cryptographic systems. To address the critical shortage of cybersecurity professionals, the proposed legislation creates the National Cybersecurity College under NCSA jurisdiction. The College will provide specialized education, training, and research in cybersecurity, develop professional certification programs, and establish partnerships with academic institutions to create a pipeline of qualified cybersecurity experts for both public and private sectors. The measure introduces the Cybersecurity Anchor of Trust System (CATS), a voluntary certification program for commercial entities to demonstrate cybersecurity trustworthiness. This system will promote cybersecurity excellence while supporting the development of secure digital ecosystems essential for economic growth and investor confidence. To ensure sustainable funding, the proposed bill establishes the Cybersecurity Risk Management and Mitigation Fund (CRMMF) for risk mitigation, prevention, and emergency response activities. It also authorizes the NCSA to collect fees, fines, and

penalties, with a portion dedicated to enhancing cybersecurity capabilities and infrastructure. The proposed legislation adopts Zero Trust Architecture principles, aligning with international cybersecurity best practices and positioning the Philippines as a regional leader in advanced cybersecurity approaches. It includes comprehensive information- sharing mechanisms between government and private sector entities while maintaining strict confidentiality protections for sensitive information. Governance provisions establish clear accountability measures, including mandatory annual reporting to the Office of the President, regular audits, and transparency requirements. The proposed bill includes appropriate penalties for non- compliance while providing due process protections and appeal mechanisms for affected entities. This comprehensive cybersecurity framework addresses immediate security challenges while building institutional foundations for long-term cyber resilience. It balances security imperatives with privacy rights, economic considerations with regulatory requirements, and national interests with international cooperation, positioning the Philippines as a trusted and secure participant in the global digital economy. In view of the foregoing, the immediate passage of this measure is earnestly sought. JINGGOY EJERCITO ESTRADA

Offire of the Setectare TWENTIETH CONGRESS OF THE REPUBLIC OF THE PHILIPPINES First Regular Session 25 AUG - 7 PE 21 SENATE RECEIVED BY: S. No. 1163 Introduced by Senator Jinggoy Ejercito Estrada AN ACT ESTABLISHING THE NATIONAL CYBERSECURITY AGENCY, DEFINING THEIR POWERS AND FUNCTIONS, AND APPROPRIATING FUNDS THEREFOR AND FOR OTHER PURPOSES Be it enacted by the Senate and the House of Representatives of the Philippines in Congress assembled: CHAPTER 1 GENERAL PROVISIONS

Section 1. Short Title. — This Act shall be known as the "Cybersecurity Act".

Sec. 2. Declaration of Policy. - It is hereby declared a policy of the State:

a) To recognize the vital role of communications and information in nation- building; b) To recognize the maintenance of peace and order, the protection of life, liberty, and property, and the promotion of the general welfare are essential for the enjoyment by all the people of the blessings of democracy; c) To serve and protect the people, and as the Constitution guarantees the right of the people to be secure in their persons, houses, papers, and effects against unreasonable searches and seizure, and that the privacy of communication and correspondence shall be inviolable except upon lawful order of the court, cybersecurity and information security are important to the protection of the Filipino society;

d) To adopt measures to effectively prevent and combat cybersecurity offenses by facilitating detection, investigation, and prosecution of offenses at both the domestic and international levels, and by providing arrangements for fast and reliable international cooperation; and e) To adopt a Zero Trust Architecture in cybersecurity, as appropriate in the Philippine context and aligned with international standards and best practices.

Sec. 3. Definition of Terms. — For purposes of this Act, the following terms

shall mean: a) Availability refers to the property of being accessible and usable upon demand by an authorized entity. b) Computer Network refers to a system that connects two or more computing devices for transmitting and sharing information. Computing devices include everything from a mobile phone to a server. These devices are connected using physical wires such as fiber optics, but they can also be wireless. c) Computer System refers to any device or group of interconnected or related devices, one or more of which, pursuant to a program, performs automated processing of data. It covers any type of device with data processing capabilities including, but not limited to, computers and mobile phones. The device consisting of hardware and software may include input, output, and storage components which may stand alone or be connected in a network or other similar devices. It also includes computer data storage devices or media, both physical and virtual. d) Confidentiality refers to property that information is not made available or disclosed to unauthorized individuals, entities, or processes. e) Critical Information Infrastructure (CII) refers to a computer or a computer system located wholly or partly in the Philippines, necessary for the continuous delivery of an essential service, and the loss or compromise of the computer or computer system will have a debilitating effect on the availability of the essential service in the Philippines. CIls consist of information process and information and communications

technology which form part of the operation of the critical infrastructures. f) Critical infrastructure (CI) refers to any public service which owns, uses, or operates systems and assets, whether physical or virtual, so vital to the Republic of the Philippines that the incapacity or destruction of such systems or assets would have a detrimental impact on national security, including telecommunications and other such vital services as may be declared by the President of the Philippines. g) Cybercrime encompasses illegal activities conducted using computers or the web which may involve malicious intent. Involves activities violating laws and regulations such as the Cybercrime Prevention Act (Republic Act No. 10175, as amended), resulting in severe consequences such as privacy breaches, disruption of critical services. h) Cybersecurity refers to the collection of tools, policies, risk management approaches, actions, training, best practices, assurance, and technologies that can be used to protect the cyber environment and organization and user's assets. i) Cyberspace refers to a complex environment emerging from the interaction of people, software, and services on the internet by means of technology devices and networks connected to it, which does not exist in any physical form. j) Information and communications technology (ICT) encompasses all technologies for the capture, storage, retrieval, processing, display, representation, organization, management, security, transfer, and interchange of data and information. k) Information security refers to the protection of information and systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide confidentiality, integrity, and availability. 1) Integrity refers to the property of accuracy and completeness. m) National Computer Emergency Response Team (NCERT) refers to a group of information security experts and practitioners responsible for responding to cybersecurity incidents of an organization with the aim of

minimizing the impact or damage and ensuring recovery of affected systems. n) Non-Repudiation refers to the ability to prove the occurrence of a claimed event or action and its originating entities. 0) Privacy refers to having the personal control over personal information. P) Security Operations Center (SOC) refers to the focal point for security operations and computer network defense of an organization. The purpose of the SOC is to defend and monitor an organization's systems and networks on an ongoing basis. The SOC is also responsible for detecting, analyzing, and responding to cybersecurity incidents in a timely manner. q) Zero Trust (ZT) refers to an evolving set of cybersecurity paradigms that move defenses from static, network-based perimeters to focus on users and resources. It is a set of security primitives rather than a particular set of technologies. Zero trust assumes that there is no implicit trust granted to user accounts based solely on their physical or network location (i.e., local area networks versus the internet) or to endpoints (devices) based on their ownership (e.g., enterprise or personally owned). Zero trust focuses on protecting resources (e.g., devices, services, workflows, network accounts) rather than network segments, as the network location is no longer seen as the prime component to the security posture of the resource. r) Zero Trust Architecture (ZTA) refers to an enterprise's cybersecurity plan that utilizes zero trust concepts and encompasses component relationships, workflow planning, and access policies. CHAPTER 2 ORGANIZATION OF THE NATIONAL CYBERSECURITY AGENCY

Sec. 4. Creation of the National Cybersecurity Agency (NCSA) - There is hereby

created a National Cybersecurity Agency, which shall be an attached agency to the Department of Information and Communications Technology (DICT).

Sec. 5. Mandate. - The NCSA shall be the primary policy, planning,

coordinating, implementing, and administrative entity that will plan, develop,

coordinate, and implement the overall national cybersecurity strategy of the government.

Sec. 6. Powers and Functions. - The Agency shall exercise the following

powers and functions: 1) Policy Planning and Coordination a) Formulate policies and recommendations on issues concerning cybersecurity, advise Congress and other government agencies on all aspect of cybersecurity, and propose legislation and amendments thereto; b) Formulate and implement the National Cybersecurity Plan; c) Ensure the participation of all stakeholders in policy formulation and implementation; d) Lead the whole-of-government effort to formulate cybersecurity regulations, in accordance with international standards and best practices; e) Set national standards on the generation, management, use, optimization, and, if applicable, disposal of cybersecurity products, protocols, and crypto-primitives such as, but not limited to: Public Key Infrastructures (PKI); secure routing protocols; secure network elements; protective Domain Name Service; encryption and decryption protocols, and authentication protocols; f) Coordinate all cybersecurity activities of the government, in partnership with the private sector and other stakeholders; g) Advise the President, Congress, Judiciary, and Constitutional bodies on all cybersecurity-related issues and concerns; h) Create the National Vulnerability Disclosure Program. The program shall be the gateway for the security researchers to submit vulnerabilities of the online assets of the Philippine government; 2) CII Protection a) Formulate and set cybersecurity minimum standards for CIls, in coordination with relevant administrative agencies exercising regulatory functions over CIIs;

b) Ensure compliance of CIIs to cybersecurity minimum standards requirements; c) Conduct audit and assessment of the cybersecurity posture of CIIs, all National Government Agencies, including Government-Owned and/or Controlled Corporations (GOCCs), State Universities and Colleges (SUCs), and Local Government Units (LGUs). The Congress and the Judiciary may request the NCSA to assist them in the conduct of cybersecurity audit and assessment; d) Establish a liaison network of CERTs (or CERTs Points of Contact) among CIls to facilitate communication and information sharing; e) Regulate and provide oversight over private cybersecurity service providers such as, but not limited to Vulnerability Assessment and Penetration Testing (VAPT) service providers, security operations center providers, etc.; f) Upon request, provide analysis, expertise, and other technical assistance to critical infrastructure owners and operators, and if appropriate, provide those analyses, expertise, and other technical assistance in coordination with Sector-Specific Agencies and other government departments and agencies; 3) Cyber Threats and Incidents Response a) Establish the NCERT and a robust incident response capability to promptly detect, analyze, and mitigate cyber incidents affecting national security or public interest and to collaborate with relevant government agencies, private sector entities, and international partners for coordinated incident response; b) Enhance cyber threat intelligence and situational awareness; c) Establish a liaison network of CERTs (or CERTs Points of Contact) among government agencies to support the implementation of the mandate of NCERT; d) Perform vulnerability assessment and penetration testing initiatives to detect, identify, and analyze cyber threats and to properly attribute cyber-attacks against CIIs;

e) Initiate legal proceedings for the collection of computer data and summon witnesses to appear in any proceedings, investigation, or inquiry of the NCSA regarding cybersecurity incidents of national government agencies (NGAS) and instrumentalities, and CIl; f) Collect open source data and conduct data analysis for proactive cybersecurity measures against misinformation, deceptive content, and other forms of attacks on integrity of information; 4) Research and Development a) Lead in the development of cybersecurity technologies, tools, and standards, in partnership with the academe, other government research institutions, and international partners; 5) Capacity Building a) Develop and implement training programs to build and maintain a highly skilled cyber workforce in the government; b) Partner with academic institutions, industry stakeholders, and foreign counterparts to promote knowledge sharing, resource sharing, and skills development in cybersecurity; c) Prescribe personnel qualifications and other qualification standards essential to the effective development on cybersecurity field of expertise; d) Co-develop with the Civil Service Commission (CSC) the cybersecurity qualification standards; 6) Information Sharing a) Gather, assess, and distribute actionable intelligence regarding cyber threats, emerging patterns, and potential vulnerabilities, thereby bolstering the nation's cyber situational awareness and facilitating informed decision-making processes; b) Develop a mechanism for information-sharing between the government (or public) and the private sector; c) Issue cybersecurity advisories or guidelines regularly or as needed; 7) International Cooperation

a) Foster international collaboration and cooperation for the promotion of cybersecurity; b) Support the government's efforts to establish the Philippines as a regional digital hub; c) Represent the Republic of the Philippines, in coordination with other relevant agencies in international cybersecurity cooperation; 8) Regulatory a) In any investigation under Chapter 6: Prohibited Acts, after due notice and hearing, the NCSA may impose sanctions, collect fees, fines, and penalties for the violation of laws, rules, regulations, orders, and issuances on CIIs; and b) Exercise such other powers as may be provided by law, as well as those which may be implied from, or which are necessary or incidental to the carrying out of the express powers granted the NCSA to achieve the objectives and purposes of this law.

Sec. 7. Composition. - The NCSA shall be headed by a Director-General with

the rank of Undersecretary and shall be assisted by two Deputy Directors-General with the rank of Assistant Secretaries.

Sec. 8. Qualifications. - The following are the minimum qualifications of the

Director-General and Deputy Directors-General of the NCSA: a) Director-General - The Director-General shall be appointed by the President. No individual shall be appointed as Director-General of the NCSA unless he or she is a citizen residing in the Philippines for the past 10 years, of good moral character, has at least five (5) years of government experience and ten (10) years cumulative experience as a cybersecurity, information privacy, or information security professional, and has at least a Master's Degree in Cybersecurity, Information Security, or any other related master's degree. b) Deputy Directors-General - The Deputy Directors-General of the NCSA shall be appointed by the President. No individual shall be appointed Deputy Directors-General of the NCSA unless they are citizens residing in the Philippines for the past 10 years, of good moral character,

possessing proven integrity, and having unquestionable integrity, with a track record of leadership, recognized competence with the appropriate educational background in cybersecurity or any related field, with at least six (6) years of supervisory or management experience in the field of cybersecurity, data privacy, information technology (IT), IT risk management, or any combination thereof.

Sec. 9. Transfer of Agencies and Personnel to the NCSA - The Department of

Information and Communications Technology - Cybersecurity Bureau (DICT-CSB) and its corresponding Divisions along with their powers and functions, applicable funds 10 and appropriations, records, equipment, property, and personnel, are hereby transferred to the NCSA. All offices, services, divisions, units, and personnel not otherwise covered by this Act for transfer to NCSA shall be retained under the DICT, which shall continue to operate under its current name and functions. The NCSA is hereby attached to the DICT for policy and program coordination, and shall continue to operate and function laterally and in accordance with prevailing laws. a) All powers and functions related to cybersecurity, including but not limited to the formulation of the National Cybersecurity Plan, establishment of the NCERT, and the facilitation of international cooperation on intelligence regarding cybersecurity matters, are hereby transferred to NCSA; and b) The laws and rules on government reorganization as provided for in Republic Act No. 6656, otherwise known as the Reorganization Law, shall govern the reorganization process of NCSA.

Sec. 10. Separation and Retirement from Service. - Employees who are

separated from service within six (6) months from the effectivity of this Act as a result of the consolidation and/or reorganization under the provisions of this Act shall receive separation benefits to which they may be entitled under Executive Order No. 366, s. 2004. Those who are qualified to retire under existing retirement laws shall be allowed to retire and receive retirement benefits to which they may be entitled under applicable laws and issuances.

Sec. 11. Structure and Staffing Pattern. - Subject to the approval of the

2 Department of Budget and Management (DBM), NCSA shall determine its organizational structure and create new divisions or units as it may deem necessary. The NCSA shall appoint officers and employees in accordance with the civil service 5 law, rules, and regulations. a) Considering the highly technical nature of the personnel required for the NCSA, the NCSA may promulgate a separate set of qualification and competency standards for eligibility as career officers in NCSA. The NCSA qualification and competency standards shall only be applicable to NCSA unless adopted by the CSC as applicable for the entire Philippine government; and b) The NCSA may request detail of personnel from other government departments, agencies, bureaus, offices, and institutions, subject to the approval of the head of office and availability of personnel, to ensure the effective coordination, integration, and fusion of activities relative to cybersecurity.

Sec. 12. Magna Carta. - All of the NCSA, including personnel providing technical

support to the implementation of the program, services, and projects, shall be entitled to the benefits outlined in Republic Act No. 3439, as amended by Republic Act No. 11312, known as the Magna Carta for Scientists, Engineers, Researchers, and other Science and Technology Personnel in Government Service.

Sec. 13. Transition Period. - The transfer of functions, assets, funds,

equipment, properties, transactions, and personnel of the affected agencies to NCSA shall be completed within six (6) months from the effectivity of this Act. During this transition period, existing personnel shall continue to assume their posts in holdover capacities until new appointments are issued. After the transfer of the agencies specified in Section 9 of this Act, NCSA, in coordination with DBM, shall determine and create new positions, the funding requirements of which shall not exceed twenty-five percent (25%) of the equivalent cost of positions abolished. CHAPTER 3 CRITICAL INFORMATION INFRASTRUCTURES (CII)

Sec. 14. Designation of Critical Information Infrastructure (CII). - The NCSA

will have the duty and power to oversee the ClIs in the Philippines. 1) The NCSA shall identify entities that own, operate or maintain CII ("CII entities" from hereon), using a risk-based approach, as prescribed by the NCSP and shall adopt a set of criteria for identifying CIIS. 2) After the confirmation of the CII designation, the NCSA will issue a written notice to the owner of the computer or computer system, designating said system as a Cil for the purposes of this Act. 3) A notice issued under subparagraph I must: a) Identify the computer or computer system that is being designated as a CII; b) Identify the owner of the computer or computer system so designated as a CII; c) Inform the owner of the computer or computer system, regarding the owner's duties and responsibilities under this Act that arise from the designation; d) Inform the owner of the computer or computer system that any representations against the designation are to be made to the NCSA by a specified date, being a date not earlier than fourteen (14) days after the date of the notice; and e) Inform the owner of the computer or computer system that the owner may appeal to the NCSA against the designation, and provide information on the applicable procedure. 4) Any designation under Subsection I shall be in effect for a period of five (5) years, unless it is withdrawn by the NCSA before the expiration of the period.

Sec. 15. Regulation of Providers of Essential Services Who Rely on Third-Party

Owned CII. - Providers remain responsible for the cybersecurity and resilience of the computer systems they rely on to deliver essential services, even if those systems are managed by a third party. Providers who depend on third-party-owned CII must secure legally binding commitments from these vendors ensuring that the third party

1 meets the cybersecurity standards and requirements applicable to CII, including incident reporting, auditing, and risk assessment.

Sec. 16. Compliance requirements for organizations and the CIls. - The NCSA,

in coordination with concerned government regulatory agencies, shall create a list of 5 compliance requirements for CIls. In determining the compliance requirements for 6 organizations and CIIs, due consideration shall be given to minimizing their impact on the cost of services provided by the organizations and/or CIls. These shall include at least the following: a) List of authorized personnel and their level of access to the computer system labeled as CIl; b) List of supply chain service providers of the CII including foreign service providers, if any; c) Brand, make, model, and other particulars (including operating system) of any computer or computing system of the CII; d) Network diagrams showing the network segmentation of the CII components; e) Technical and procedural controls being implemented to mitigate cybersecurity risks; f) The cybersecurity or information security framework used for risk assessment and adoption of technical and procedural controls; g) Initial audit report; h) Cybersecurity incident handling organization and protocol being implemented by the CII operator; and i) Organization and technical contact persons of the CII operators.

Sec. 17. Internal Review and Audit of CIls. - All CII operators shall take the

necessary steps to identify, assess, and institute technical or procedural controls to mitigate cybersecurity risks related to the CII at least once every three (3) years. At least once every two (2) years (or at such higher frequency as may be directed by the NCSA in any particular case), all CII operators must submit an authenticated audit report performed by a NCSA recognized auditing firm that specializes in cybersecurity. Audit reports shall be submitted to NCSA and shall be kept in record for a period of not less than five (5) years.

Sec. 18. Mandatory Disclosure of Cybersecurity Incidents on CIls. -

a) Organizations operating CIs shall notify the government regulator and NCSA through the NCERT within four (4) hours upon discovery of a critical or high-risk cybersecurity incident. NCSA shall define the taxonomy, including classification and categorization of which cybersecurity incidents are considered "critical", "high risk" and "moderate". For moderate risk cybersecurity incidents, the CIl operator shall inform NCSA or NCERT of the incident within twenty-four (24) hours; b) In the event of ransomware or extortion attacks, the affected CII entities are required to disclose in their report whether they have made any payments or complied with the demands of the threat actor; and c) CERTs shall coordinate with law enforcement agencies ; in filing of cybercrime cases.

Sec. 19. Assistance extended by the government to CII operators. - Operators

of CII may request assistance for NCSA to provide the following: a) Use of government technical controls and systems for the defense and protection of the CII ; b) Priority co-location with government data centers subject to availability; and c) Use of government secure crypto-primitives such as digital certificates, etc.; and d) Knowledge management platform to facilitate faster sharing of information between the industry, NCSA, government regulators, and other concerned organizations.

Sec. 20. Confidentiality of CII Related Documents. - The official list of CIls,

including their assessment, evaluation, audit, and technical reports shall be considered documents related to National Security and thus, are considered confidential and classified. The President, upon the recommendation of NCSA, may declassify these documents. If a subpoena duces tecum is issued for any of these classified documents, NCSA shall inform the body who ordered the subpoena that the document can only

1 be opened or scrutinized in executive session, and/or shall be disclosed only to a 2 limited number of people on a strict need-to-know basis.

Sec. 21. Withdrawal or Removal of CII Designation. - The NCSA, through a

written resolution, may withdraw or remove the designation of any CII at any time if 5 the NCSA is of the opinion that the computer or computer system no longer fulfills the 6 criteria of a CII. The NCSA shall notify in writing the CII operator of the withdrawal or 7 removal of their designation within 14 days upon the issuance of the resolution.

Sec. 22. Motion for Reconsideration of CII Certification. - CIIs may file for

9 motion for reconsideration of the scoring or rating, and revocation of certificate to 10 NCSA within thirty (30) days from the receipt of the decision. CHAPTER 4 CYBERSECURITY IOT CERTIFICATION

Sec 23. Cybersecurity Anchor of Trust System (CATS). - NCSA shall promulgate

rules and procedures for certifying cybersecurity trustworthiness of service, suppliers, or technologies. Towards this end, the Agency in consultation with other government agencies and the private sector shall devise a rating or scoring system for assessing information security and cybersecurity standards considering various criteria. Such scoring system shall be reviewed periodically at least once every two (2) years or as may be deemed necessary by the Agency. The Agency may charge reasonable fees to defray the administrative cost of the services rendered.

Sec. 24. Voluntary Rating System. - Any local or foreign commercial entities

may voluntarily submit themselves for certification.

Sec. 25. Validity of Certification. - The certification issued by NCSA shall be

valid for a maximum period of two (2) years: Provided, That NCSA, may impose a shorter validity period depending on the criticality of the business or the cybersecurity risks relevant to the business of the person: Provided, further, That the Agency, upon recommendation by NCERT, may require re-certification prior to the expiration of the certification due to factors increasing the cybersecurity risks relevant to the business of the person.

Sec. 26. Cybersecurity loT Certification Appeal. - Agencies with cybersecurity

loT certification may file for an appeal of the scoring or rating, and revocation of certificate to NCSA within thirty (30) days from receipt of the decision. CHAPTER 5 NATIONAL CYBERSECURITY COLLEGE

Sec. 27. Establishment of the National Cybersecurity College. - There shall be

established a National Cybersecurity College under the jurisdiction of the NCSA which shall be responsible for providing specialized education, training, and research in the field of cybersecurity.

Sec. 28. Board of Trustees. - The College shall be under the direction, control,

and supervision of a Board of Trustees, which shall be composed of seven (7) members, as follows: a) A representative from the DICT with the rank of at least Assistant Secretary; b) A representative from NCSA with the rank of at least a Deputy Director- General; c) A representative from the Department of Science and Technology (DOST) with the rank of at least an Assistant Secretary; d) A Commissioner of the Commission on Higher Education (CHED); e) A representative from the Department of Justice with the rank of at least Assistant Secretary; f) A representative from the Department of the Interior and Local Government with the rank of at least Assistant Secretary; g) One representative from the Private Sector, to be appointed for a term of three (3) years by the aforementioned Trustees. The Board of Trustees shall elect among themselves the Chairman and the Vice- chairman of the Board.

Sec. 29. Powers and Functions of the Board of Trustees. - The Board of

Trustees is vested with the following powers and functions: a) Preparation and adoption of rules and regulations deemed necessary for the effective discharge of its responsibilities;

b) Authorization of the fields of human resource development, investigation, and major studies, allocating available funds without influencing specific methodologies or conclusions; c) Constitution of the Executive Committee, as hereinafter defined; d) Appointment of the President and one or more Vice-Presidents to assist the President in the administration of the College; e) Periodic review of the administration and programs of the College; f) Cause the development of academic programs and courses designed for different educational levels addressing the varied requirements of cybersecurity professionals, to be offered at the College; in g) Design curricula for professional training and certifications cybersecurity catering to individuals and organizations in the public and private sectors, fostering a competent workforce equipped to tackle evolving cyber threats, to be provided at the College; h) Conduct research and development activities aimed at advancing knowledge and technologies in the field of cybersecurity, contributing to the nation's cyber resilience and innovation; i) Cause the collection of fees as applicable, in accordance with established guidelines, regulations, and laws.

Sec. 30. Executive Committee. - An Executive Committee shall be established,

consisting of the President of the College and not fewer than three nor more than five other members nominated by the Board of Trustees and approved by the President of the Republic of the Philippines.

Sec. 31. Functions of the Executive Committee. - The Executive Committee

shall administer the affairs of the College in accordance with functions, powers, and responsibilities delegated by the Board of Trustees, excluding the power to fill vacancies on the Board and to amend the rules and regulations of the College.

Sec. 32. President of the College. - The President of the College shall be its

chief executive officer, appointed by the Board of Trustees. The President's powers and duties include submitting policies and measures for consideration, recommending, coordinating, and administering programs and projects, directing and supervising

1 operations, submitting annual reports, and exercising other powers vested by the 2 Board.

Sec. 33. Financia/ Support. - Until the College achieves financial self-sufficiency,

its operations shall be financed through contributions from founding institutions. An endowment fund shall be created from appropriations from the national government, grants, donations, and other sources of funding as may be approved by law, up until the College attains self-support capability, administered by the Board of Trustees.

Sec. 34. Expenditures and Disbursements. - Expenditures and disbursements

made by the College shall not be subject to procurement requirements and restrictions imposed by existing laws upon government agencies.

Sec. 35. Staff Appointments. - Appointments to the administrative, academic,

or research staff of the College may be on a part-time basis and shall be exempt from certain requirements and restrictions, ensuring flexibility in staffing arrangements.

Sec. 36. Exemption from Taxes. - The College, its assets, acquisitions, income,

operations, and transactions shall be exempt from taxes, fees, charges, imports, licenses, and assessments, except import taxes, duties, and fees.

Sec. 37. Collaboration. - The National Cybersecurity College shall collaborate

with other educational institutions, government agencies, industry partners, and international organizations to enhance cybersecurity education, training, and research efforts in the Philippines.

Sec. 38. Partnership. - The College may partner with State Universities and

Colleges (SUCs), public and private academic institutions to accredit and establish them as Institutions of Cybersecurity Excellence.

Sec. 39. Reporting. - The Board of Trustees shall submit an annual report to

the NCSA, detailing its activities, accomplishments, and financial status. CHAPTER 6 PROHIBITED ACTS AND PENALTIES

Sec. 40. Non-compliance of CII operators. - In the event that a CII operator

fails willfully or negligently to comply with the orders, directive, mandate, remediation, and any other regulations of NCSA, the same shall incur penalties as provided for this Act. This includes submission of documentary requirements, and providing NCSA access to necessary computer data during investigations of cyber-attacks.

Sec. 41. Disclosure of Confidential Information. - Any individual who has access

2 to CIl and information is prohibited to disclose them. The unauthorized disclosure of these confidential information, either willfully or through negligence, shall be penalized.

Sec. 42. Penalties. - The following penalties shall be applied for violations of

this Act: a) Any individual who either willfully, or through negligence causes the unauthorized disclosure of confidential or sensitive information shall be penalized by imprisonment ranging from six (6) years to twelve (12) years or a fine of not less than Five hundred thousand pesos (P500,000.00), or both; b) Any unauthorized disclosure of confidential or sensitive information affecting national defense or national security, with intent or reason to believe that the same is to be used to the injury of the Philippines or to the advantage of any foreign nation or enemy of the State, whether domestic or foreign, shall suffer the penalty of life imprisonment or by a fine of not less than One million pesos (P 1,000,000.00), or both; c) Any employee who leaves or severs employment with the CII operator/owner, willfully or negligently discloses, damages, disposes of, or destroys critical, sensitive, or classified information in violation of this Act and other existing laws, rules, and regulations, contravenes or fails to comply with any provision of this Act shall be held liable without prejudice to any criminal prosecution; d) Upon violation of any enumerated prohibited acts, the CII operator shall receive a formal written warning from the NCSA ordering the CII to show cause within seven (7) days from receipt thereof; e) If the CII operator fails to comply with the written warning, NCSA shall impose a fine equal to half of one percent (0.5%) of the CII operator's average gross annual income for a period of five years. An additional half of one percent (0.5%) shall be added for each subsequent infraction, with the penalty resetting after the CII operator finally complies with the directives;

f) A CII operator's willful disregard of a lawful order given by NCSA to comply with this Act and its implementing rules and regulations within a reasonable time frame will result in the CII operator's license being revoked on grounds of non-compliance to a regulatory requirement; g) The CII operator has the right to appeal any penalties imposed under this section. To initiate an appeal, the CII operator must submit a written notice of appeal to the NCSA within fifteen (15) days from the receipt of the penalty notice or the revocation order. The appeal must include a detailed statement of the grounds for contesting the penalty and any supporting evidence. Upon receipt of the appeal, the NCSA shall review the case and may hold a hearing if deemed necessary. The CII operator will be notified of the hearing date and will have the opportunity to present their case. Following the review or hearing, the NCSA will issue a written decision on the appeal. The decision of the NCSA shall be final and may be challenged only through appropriate judicial review, as provided by applicable law.

Sec. 43. Liability under the Anti-Terrorism Act (ATA) of 2020. - Any person

who, within or outside the Philippines, regardless of the stage of execution, engages in acts intended to cause extensive interference with, damage, or destruction to Critical Infrastructure, as defined under Section 3 (f) of this Act or Section 3 (a) of Republic Act No. 11479, or to CIIs designated under Chapter 3 of this Act, committed by, through and with the use of information and communications technologies or otherwise, when the purpose of such act, by its nature and context is to intimidate the general public or a segment thereof, create an atmosphere or spread a message of fear, to provoke or influence by intimidation the government or any international organization, or seriously destabilize or destroy the fundamental political, economic, or social structures of the country, or create a public emergency or seriously undermine public safety, shall be liable under Section 4 (c) of Republic Act No. 11479, otherwise known as the Anti-Terrorism Act of 2020. CHAPTER 7 MISCELLANEOUS PROVISIONS

Sec. 44. Authority to Accept Assistance and/or Donations. - The NCSA is

2 authorized to accept donations, contributions, grants, bequests or gifts from domestic or foreign sources, for purposes relevant to its mandates and functions, subject to existing laws, rules and regulations.

Sec. 45. Appropriations. - The amount necessary for the initial implementation

6 of this Act shall be charged against the current and available appropriations of 7 concerned agencies. Thereafter, the amount needed for the implementation of this 8 Act shall be included in the annual General Appropriations Act. The State shall prioritize allocation of all available resources to ensure the 10 effective implementation of its mandates specified under this Act. All departments, bureaus, offices, and agencies of the government are hereby authorized to use at least five percent (5%) of their total budgetary allocation for the programs, activities, and projects to implement this Act. Funds to be allocated for this purpose shall not be used for intelligence, surveillance, or other similar activities and shall be subject to relevant government accounting and audit laws, rules, and procedures.

Sec. 46. Cybersecurity Risk Management and Mitigation Fund. - There is hereby

17 created a Cybersecurity Risk Management and Mitigation Fund (CRMMF). a) CRMMF shall be used for cybersecurity risk mitigation, prevention, and preparedness activities such as but not limited to training of personnel, procurement of equipment, and capital expenditures. It can also be utilized for the management of imminent or actual cybersecurity threats which may occur during the current fiscal year or those that occurred in the past two (2) years from the current fiscal year. Risk management activities include threat identification and detection, incident response, system recovery and protection, and other related works or services; b) The specific amount of the CRMMF and the appropriate recipient agencies shall be determined upon approval of the President of the Philippines in accordance with the favorable recommendation of the NCSA; c) Of the amount appropriated for the CRMMF, thirty percent (30%) shall be allocated as Quick Response Fund (QRF) or a contingent fund for

response and recovery activities in order to immediately bring affected CII systems to normal operation; and d) All departments/agencies that are allocated with the CRMMF shall submit to the NCSA their monthly statements on the utilization of CRMMF and make an accounting thereof in accordance with existing accounting and auditing rules.

Sec. 47. Report. - The NCSA shall submit an annual report to the Office of the

President on the implementation of this Act, as well as the operations of the Agency. 9 The NCSA shall also include in its report disclosures of cybersecurity vulnerabilities, 10 actionable protocols to mitigate cybersecurity vulnerabilities to information systems and industrial control systems.

Sec 48. Confidentiality. -

1) All parties involved in the application of this Act shall respect the confidentiality of information and data obtained in carrying out their tasks and activities in such a manner as to protect, in particular: a) Intellectual property rights, and confidential business information or trade secrets of a natural or juridical person, including source code, except in cases where the disclosure and access is necessary to protect the legitimate interest recognized by existing laws, rules, and regulations; b) Public and national security interests; c) Data of security agencies, ensuring that they will not be migrated into the private domain; and d) Integrity of criminal or administrative proceedings. 2) Without prejudice to paragraph I, information exchanged on a confidential basis between government departments, agencies, bureaus, offices, and institutions and the NCSA shall not be disclosed without the prior agreement of the originating government departments, agencies, bureaus, offices, and institutions. 3) Adequate protection shall be set in place between the information shared by the private sector and government agencies, particularly security and law enforcement agencies.

4) Paragraphs I and Il shall not affect the rights and obligations of the NCSA and notified bodies with regard to the exchange of information and the dissemination of warnings, nor the obligations of the persons concerned to provide information under existing laws, rules, and regulations. 5) The NCSA may exchange, when necessary, sensitive information with relevant authorities of third countries with which they have concluded bilateral or multilateral confidentiality arrangements guaranteeing an adequate level of protection.

Sec. 49. Utilization of the collected fees, fines, and penalties. - The NCSA is

hereby authorized to utilize at most forty percent (40%) of the fees and penalties collected for programs and projects aimed at enhancing cybersecurity capabilities and infrastructure within the jurisdiction. These funds shall be allocated towards initiatives such as cybersecurity awareness campaigns, capacity- building programs, research and development efforts, and the procurement of advanced cybersecurity technologies and tools: Provided, That at no circumstance shall the funds be used to augment salaries and personnel benefits. The utilization of the aforementioned fund shall be subject to government accounting manual and audit procedures, ensuring transparency, accountability, and proper fiscal management in accordance with the objectives and mandates of NCSA. Regular audits and reporting requirements shall be conducted to ensure the effective and efficient utilization of funds.

Sec. 50. Implementing Rules and Regulations. - Within one hundred twenty

(120) days from the effectivity of this Act, the DICT, the DBM, the CSC, and upon consultation with relevant stakeholders, shall promulgate the rules and regulations to effectively implement the provisions of this Act.

Sec. 51. Separability Clause. - If any provision of this Act is declared invalid or

unconstitutional, the remainder thereof not otherwise affected shall remain in full force and effect.

Sec. 52. Repealing Clause. - All laws, presidential decrees, executive orders,

letters of instructions, proclamations, or administrative regulations that are inconsistent with the provisions of this Act are hereby repealed, amended, or modified accordingly.

Sec. 53. Effectivity Clause. - This Act shall take effect after fifteen (15) days

2 following the completion of its publication in the Official Gazette or in any newspaper 3 of general circulation. Approved,

Text extracted from the scanned Senate document via OCR — it may contain recognition errors. The official PDF is the authoritative version.