SINGAPORE Law and Practice Contributed by: Lim Chong Kin, David N Alfred, Albert Pichlmaier and Goh Boon Yeow, Drew & Napier LLC
their own CII to identify security vulnerabilities that could be exploited by a cyber threat actor. Owners of CII are required to conduct a penetration test on the CII at least once: • every 12 months, for CII which is an information technology system; and • every 24 months, for CII which is an operational technology system. Owners of CII must conduct penetration tests on rel - evant CII assets after implementing any major system changes to the CII. It is the responsibility of CII owners to ensure that third-party penetration testing service providers and their penetration testers possess industry-recog - nised accreditations and certifications respectively, for example CREST or equivalent accreditations and certifications. Owners of CII are required to establish a red teaming or purple teaming attack simulation plan, and conduct a red teaming or purple teaming attack simulation on its CII at least once every 24 months. Cybersecurity Service Provider Licences The Cybersecurity Services Regulation Office (CSRO) was set up to administer the licensing framework for CSPs under the Cybersecurity Act. All providers of a managed security operations centre monitoring services and penetration testing services as defined in the Cybersecurity Act to the Singapore market must apply to the CSRO for a cybersecurity service provider’s licence. IoT Devices In 2020, the MDDI (then Ministry of Communication and Information) introduced the Cybersecurity Label - ling Scheme (CLS). The CLS was, initially a voluntary scheme for Wi-Fi routers and smart home hubs, and was subsequently expanded to include all smart home devices. The CLS provides four cybersecurity rating levels for registered IoT devices and other smart devices to help
consumers easily assess the level of security offered and make informed choices in purchasing a device. At Level 1, the product meets basic security require - ments, whilst at Level 4, the product has undergone structured penetration tests by approved third-party test labs. In 2024, the CSA updated Singapore’s Operational Technology Cybersecurity Masterplan. It now includes operators of operational technologies that support physical control functions such as IoT and industrial IoT devices, as such devices have become new attack surfaces for threat actors to exploit. The key initiatives under the masterplan include: • enhancing the operational technology cybersecu - rity talent pipeline; • enhancing information sharing and reporting; • uplifting operational technology cybersecurity resil - ience beyond CII; and • promoting secure-by-development principles. The Singapore Cybersecurity Strategy 2021 empha - sises enhancing response capabilities for the state, organisations and individuals rather than expanding legislation relating to cyber-resilience (please refer to 1.1 Cybersecurity Regulation Strategy for more details). Apart from the Cybersecurity Act and the other leg - islation mentioned in 1.2 Cybersecurity Laws , the legislative status of cyber-resilience in Singapore remains relatively sparse compared to that of other jurisdictions. Instead, security-by-design outcomes for connected products are driven through product assurance and labelling schemes, as well as techni - cal requirements in targeted areas. Notably, the CLS is intended to incentivise manufacturers to build in stronger cybersecurity provisions. Residential gate - ways are also subject to IMDA technical security specifications, with compliant routers qualifying for CLS recognition. 4. Cyber-Resilience 4.1 Cyber-Resilience Legislation
292 CHAMBERS.COM
Powered by FlippingBook