SINGAPORE Law and Practice Contributed by: Lim Chong Kin, David N Alfred, Albert Pichlmaier and Goh Boon Yeow, Drew & Napier LLC
1.3 Cybersecurity Regulators Cyber Security Agency of Singapore
are necessary for delivering the essential service, the Commissioner may designate the provider as respon - sible for the cybersecurity of that third-party-owned CII, and the provider must ensure comparable cyber - security standards through legally binding commit - ments. If the risk of a cyber-attack is high and the loss or compromise of the computer or computer system will have a serious detrimental effect on the national security, defence, foreign relations, economy, public health, public safety or public order of Singapore, the Commissioner may designate the computer or com - puter system as a STCC, and subject the STCC to obligations similar to CII. The Cybersecurity Services Regulation Office (CSRO) was set up within the CSA in 2022 to administer the licensing framework of CSPs under the Cybersecurity Act, responding to the industry’s queries and feed - back, and sharing of resources on licensable cyber - security services. Currently, there are 11 sectors in which there may be essential services (ie, services which are essential to national security, defence, foreign relations, the econ - omy, public health, public safety or the public order of Singapore): • energy; • info-communications;
The regulatory authority responsible for the adminis - tration and enforcement of the Cybersecurity Act is the CSA. The CSA is part of the Prime Minister’s Office and is managed by the Ministry of Digital Develop - ment and Information (MDDI), and led by the Commis - sioner of Cybersecurity. The Minister for Digital Devel - opment and Information (as the Minister-in-charge of Smart Nation and Cybersecurity) may appoint Assis - tant Commissioners from sectoral regulators who understand the unique context and complexity of their respective sectors to advise and assist the Commis - sioner on the co-ordination of cybersecurity efforts. Under the Cybersecurity Act, the Commissioner’s functions and duties include, but are not limited to: • advising the Singapore government or any other public authority on cybersecurity matters; • monitoring and responding to cybersecurity threats, whether such cybersecurity threats occur in or outside Singapore; • identifying, designating and regulating provider- owned CII, designated providers responsible for third-party-owned CII and STCC; • establishing cybersecurity codes of practice and standards of performance for implementation by owners of provider-owned CII, designated pro - viders responsible for third-party-owned CII and STCC; • developing and promoting the cybersecurity ser - vices industry in Singapore; and • licensing and establishing standards in relation to CSPs. In general, the Cybersecurity Act applies to any com - puter or computer system, whether physical or virtual, and located wholly or partly in Singapore which may be designated as CII. The Commissioner may confer such a designation when satisfied that the computer or computer systems are necessary for the continuous delivery of an essential service, and the loss or com - promise of such systems will have a debilitating effect on the availability of the essential service in Singapore. Where an essential service provider relies on third- party-owned computers or computer systems that
• media; • water; • healthcare; • banking and finance; • security and emergency services; • aviation;
• land transport; • maritime; and • services relating to the functioning of the govern - ment. The Commissioner has broad powers to investigate and prevent cybersecurity threats or incidents, includ - ing making requests for information to be provided or, in serious cases, direct remedial measures to be taken by any person (including those who are not owners of CII).
285 CHAMBERS.COM
Powered by FlippingBook