CYBER SECURITY LAW IN CAMEROON

Operators of information systems must take every technical administrative measure to ensure the security of services offered. They have to put in place standardized systems enabling them to at all times identify, assess, process or manage any risk relating to the security of the information systems of the services provided directly or indirectly.

Operators of information systems have to set up technical mechanisms to avoid any hitches that may be prejudicial to the steady functioning of systems, their integrity, authentication, non-repudiation by third party users, confidentiality of data and physical security.

Mechanisms provided for has to be subject to the approval and visa of the Agency.

Information systems platforms have to be protected against any radiation or intrusion that may impair the integrity of data transmitted and ay other external attack notably, through intrusions detection system.

Corporate bodies whose activity is to provide access to information systems is bound to inform users of:

  • The dangers associated with the use of unprotected information systems notably for private individuals;
  • The need to install parental control devices;
  • Specific security violation risks notably, the generic family of viruses; etc.

Operators of information systems must inform users of the prohibition to use electronic communication networks for the publishing of illicit content or any other act that is likely to affect the security of networks or information systems. Such prohibition shall equally concern the designing, of misleading viruses, spywares, potentially undesirable software or any other device leading to fraudulent practices.

Operators of information systems are bound to conserve the connection and traffic data of their information systems for a period of 10 (ten) years.

Operators of information systems are bound to set up mechanisms for monitoring and controlling access to the data of their information systems. Such data may be accessible in the course of judicial inquiries.

The installations of operators of information systems may be subject to search or seizure, on the order of a judicial authority, under conditions provided for by the laws and regulations in force.

Operators of information systems must assess and revise their security systems and, where necessary, make the appropriate modifications to their security practices, measures and techniques according to technological change.

Operators of information systems and users may cooperate mutually with a view to implementing the security practices, measures and techniques of their systems.

Electronic communication networks and information systems content providers are bound to ensure the availability of material, aw well as the data stored in their installations. They shall be bound to set up filters in order to avoid any attacks that may be prejudicial to personal data and the privacy of users.

Electronic communication networks and information systems shall be subject to a regime of compulsory and periodic auditing of their security systems by the agency.

Security audit and severity scale rating shall be undertaken each year or as required by the prevailing circumstances.

Audit reports shall be confidential and addressed to the Minister in charge of Telecommunication.