Debated in Parliament on 10 Sep 2018.
Mr Dennis Tan Lip Fong asked the Minister for Communications and Information whether the Government will put in place appropriate security assessment measures for cybersecurity staff or contractors working with the Civil Service, Statutory Boards, banks and other organisations or businesses, who are foreigners, Employment Pass holders, Singapore PRs or new citizens, including those originating from the country that is linked to the Advance Persistent Threat group who carried out the recent cyberattack against SingHealth, NUS and NTU.
All Public Service staff and contractors dealing with Government cybersecurity matters who require access to classified Government information, must undergo security screening by the authorities. Similarly, organisations in the Critical Information Infrastructure (CII) sectors, such as Banking and Finance as well as Land Transport, are required by their respective sectoral regulators to screen all staff and contractors with access to key infrastructure, such as information technology systems. Such measures go some way towards mitigating the "insider" risk, though they are not foolproof.
The Cyber Security Agency (CSA) will also license organisations offering penetration testing and managed security operations centre monitoring services as well as individuals directly engaged for such services, to ensure they meet certain criteria, including that their key executive officers are fit and proper persons. Under the Cybersecurity Code of Practice issued by CSA, all CII owners must calibrate a vendor’s access to their CII, based on their organisations’ business needs and cybersecurity risk profile.