Debated in Parliament on 13 Jul 2015.
Mr Zaqy Mohamad asked the Minister for Communications and Information (a) what contingency plans are in place in the event of a hacking or internal breach of Government systems taking place and information about citizens or public officers is leaked; and (b) what additional measures, budget, capabilities and systems has the Government put in place to assure citizens of the security of their data and transactions.
It is not possible to prescribe in advance exactly what will be done in the event of a leakage of personal information from Government systems.
Page: 126
However, certain key principles will be upheld in the handling of an incident.
Firstly, it will be our priority to ensure that citizens’ interests are not further compromised. Should the accounts of members of the public be breached, we will take immediate measures, such as suspending the accounts until users are able to reset their passwords.
Secondly, we will need to carry out a thorough investigation to understand when and how the information was leaked. It is not always possible to be 100% sure how the breach occurred, as the event might have taken place a long time ago and essential forensic evidence lost. However, our agencies will strive to arrive at the best possible assessment, using all available information and facts. We also recognise that as more facts come to light over time, the original assessments may have to be further revised.
Thirdly, based on the findings of the investigation, our agencies will assess what sort of additional measures need to be undertaken, in addition to the initial set of preventive measures adopted when the breach was first detected. Our agencies will work closely with relevant agencies, including the Cyber Security Agency and the Police, in managing such an incident.
The unauthorised disclosure of personal information causes immense inconvenience and distress to affected individuals. In some cases, the information, once leaked, cannot be recovered and the harm cannot be undone.
This is why the Government believes that it is important to invest significantly in the prevention of attacks or inadvertent disclosures in the first place. We have to adopt a "security-by-design" approach so that security considerations are integrated upfront when new IT systems are being developed. The Cyber Security Agency is working with relevant stakeholders to promote this concept not just in the Government sector, but across all sectors. We also need agencies to have effective real-time monitoring of their IT systems, so that if any attack occurs, they can be detected at the earliest possible opportunity.