Debated in Parliament on 3 Feb 2020.
Ms Joan Pereira asked the Prime Minister whether there have been cases of data breach in Government agencies where suppliers and subcontractors engaged by third party vendors are involved and, if so, how does the Government ensure that such parties are vetted and accredited to ensure that they are qualified to provide the required services and put in place the needed cybersecurity safeguards for our systems.
In 2019, there were 15 data incidents that involved a lapse by the third party vendors of Government agencies. None of these incidents involved the supplier to or subcontractor of these direct vendors to Government agencies.
In managing the subcontractors of Government's third party vendors, the key principle is that the Government's direct vendor remains fully responsible for upholding the cybersecurity and data protection measures to the standards defined by the Government's Instruction Manual and other internal regulations. Failure to do so will result in penalties for contractual breaches by the direct vendor.
In other words, the rules are not circumvented just because the third party vendor has outsourced some of the work. For example, third party vendors are required to install updated anti-virus software on the endpoint devices used to process Government data. The same requirement extends to subcontractors that perform such work on their behalf.
In addition, as private sector companies, both the direct vendor and sub-contractors that handle Government data are subject to the Personal Data Protection Act and may face penalties when they breach the data protection requirements stipulated in the Act.
As follow up to the recommendations of the Public Sector Data Security Review Committee (PSDSRC), we will implement, by 30 April 2020, improved and more consistent standards of cybersecurity and data protection to govern the Government's direct vendors and their subcontractors. Government agencies will clearly specify the cybersecurity and data protection requirements in the contracts with their direct vendors. Government agencies will also conduct regular audits, and any non-compliance to these requirements by vendors or subcontractors will be flagged out and corrected.