The powers mentioned in subsection (1) are the following:
(a) any power mentioned in section 19(2)(a), (b), (c) or (d);
(b) direct, by written notice, any person to carry out such remedial measures, or to cease carrying on such activities, as may be specified to the person, in relation to a computer or computer system that the incident response officer has reasonable cause to suspect is or was affected by the cybersecurity incident, in order to minimise cybersecurity vulnerabilities in the computer or computer system;Examples Examples of remedial measures include —
(a) the removal of malicious software from the computer;
(b) the installation of software updates to address cybersecurity vulnerabilities;
(c) temporarily disconnecting infected computers from a computer network until paragraph (a) or (b) is carried out; and
(d) the redirection of malicious data traffic towards a designated computer or computer system.
(c) require the owner of a computer or computer system to take any action to assist with the investigation, including but not limited to —
(i) preserving the state of the computer or computer system by not using it;
(ii) monitoring the computer or computer system for a specified period of time;
(iii) performing a scan of the computer or computer system to detect cybersecurity vulnerabilities and to assess the manner and extent that the computer or computer system is affected by the cybersecurity incident; and
(iv) allowing the incident response officer to connect any equipment to the computer or computer system, or install on the computer or computer system any computer program, as is necessary for the purpose of the investigation;
(d) after giving reasonable notice to the owner or occupier of any premises, enter those premises if the incident response officer reasonably suspects that there is within the premises a computer or computer system that is or was affected by the cybersecurity incident;
(e) access, inspect and check the operation of a computer or computer system that the incident response officer has reasonable cause to suspect is or was affected by the cybersecurity incident, or use or cause to be used any such computer or computer system to search any data contained in or available to such computer or computer system;
(f) perform a scan of a computer or computer system to detect cybersecurity vulnerabilities in the computer or computer system;
(g) take a copy of, or extracts from, any electronic record or computer program contained in a computer that the incident response officer has reasonable cause to suspect is or was affected by the cybersecurity incident;
(h) subject to subsection (5), with the owner’s consent, take possession of any computer or other equipment for the purpose of carrying out further examination or analysis.