Debated in Parliament on 20 Jan 2014.
Mr Vikram Nair asked the Minister for Communications and Information whether the Government is taking any steps to raise awareness of the importance of cybersecurity and what are the steps that individuals and businesses can take to protect themselves from cyber threats.
Mr David Ong asked the Minister for Communications and Information (a) what steps is the Government taking to harden its IT systems against cyber threats; and (b) how will the National Cybersecurity Masterplan 2018 help to improve the current situation.
I would like to assure Members that the Singapore Government takes a serious view of security threats in cyber space, as they can have significant impact in the physical world. Cyber attacks have the potential to cause disruptions and financial losses with major impact to the economy and society. As we rely more on the Internet, we can expect cyber threats to increase in number and sophistication against governments and corporations globally. Furthermore, unlike physical threats, hackers can come from anywhere and attack any system in the world.
Security of Government IT systems has been an important priority of the Government, since the First Infocomm Security Masterplan was launched in 2005. We seek to put in place infocomm security measures that are multi-layered and constantly updated to meet the changes in technologies and risks. Cybersecurity defence is constructed in many layers. Firstly, blocking of malicious traffic from other countries before it reaches Singapore. Secondly, defending at the frontier when the traffic reaches our Internet Service Providers (ISPs). Thirdly, before it reaches Government servers. Finally, protection against malware such as computer viruses from entering the computing devices of employees.
At each layer, four strategies are employed Prevention, Detection, Response and Recovery. Let me start with "Prevention". Efforts are made to patch software vulnerabilities, to ensure sufficient capacity in our storage and transmission facilities, and other means to avoid being taken down in an attack. However, there is no 100% guarantee that any organisation will be able to prevent all cyber attacks. Threats evolve rapidly and systems have become increasingly complex to defend.
Page: 136
Like other organisations, Government agencies must also rigorously test the compatibility of patches before they are deployed, to avoid a situation where e-services are inadvertently affected. There is thus a trade-off between security and the availability of services and agencies have to strike the right balance. In the current threat environment, websites may undergo more maintenance and downtime. We seek the public's understanding and patience as agencies seek to ensure systems are updated more frequently. If we cannot prevent every attack, it becomes important to "Detect" and "Respond" as soon as possible, for example, by identifying the threat and eliminating it. The fourth strategy is "Recovery", to bring the service, website or server back online as soon as possible, to minimise business disruption.
During the period in November 2013, when attempts were made to attack Government IT systems, many of the systems and capabilities that had been built up were activated to help defend our systems. While there were some instances where sites were subject to defacements or cross-site scripting attacks, these were detected and corrective actions applied in a timely fashion. The ongoing cybersecurity monitoring also helped detect a case where a list of contacts who subscribed to a museum e-newsletter was compromised. These cases were referred to the Police for investigation. We were also able to detect attempts to mount Distributed Denial-of-Service (DDoS) attacks, which were successfully foiled. A DDoS attack is an attempt to take down a website and make the website inaccessible to intended users. In many instances, innocent parties, through poor security practices, have their systems unknowingly hijacked by perpetrators of DDoS to mount DDoS attacks globally. That is why an important priority for Government is education and awareness for businesses and individuals.
The Government is also working to foster better cybersecurity practices of businesses and individuals. Current outreach efforts include the annual Cybersecurity Awareness Day, the National Infocomm Security Competition, the national security awareness campaign titled "Let's Stand Together" that included a theme on cybersecurity which took place from October to December last year and featured interactive games for participants to learn more about the potential impact of cyber threats and the importance of staying vigilant, and the annual Infocomm Security Seminar which reaches out to Government agencies, the industry and businesses. In partnership with the private sector through the Cybersecurity Awareness Alliance, information on protecting oneself online has also been made available through the "Go Safe Online" website at www.gosafeonline.sg. Businesses and individuals can play an important part by adopting essential practices found in the "Go Safe Online" website that include securing confidential information, using strong passwords,
Page: 137
making sure your computer software and anti-virus software are always updated, and regularly backing up important data. We believe that doing so will go a long way to help protect businesses’ intellectual property and the individuals’ personal data.
In July 2013, the Government announced a new National Cybersecurity Masterplan. The masterplan will enhance the Government's capability to deal with cyber threats not just within the Government, but at the national level as well. The masterplan focuses on three key areas.
Firstly, it aims to enhance the security and resilience of critical infocomm infrastructure. National cybersecurity exercises will continue to be conducted for critical industry sectors, with the addition of new cross-sector exercises. For the public sector, the existing Cyber Watch Centre and Threat Assessment Centre will be enhanced for improved detection and analytical capabilities.
Secondly, the masterplan aims to increase efforts to promote the adoption of appropriate infocomm security measures among individuals and businesses through collaborative efforts with the industry and trade associations.
Thirdly, the masterplan aims to grow Singapore's pool of infocomm security experts to boost cybersecurity capabilities. In October 2013, the Government had also announced the National Cybersecurity Research and Development Programme, which harnesses research and development efforts to improve the trustworthiness of cyber infrastructures to address a growing national challenge. These longer term programmes are intended to build tools, systems and expertise to deal with threats to a range of critical information infrastructure in Singapore.
The Government will reinforce current efforts and explore additional means to promote cybersecurity awareness. We hope that individuals and businesses will work with us, in striving towards a more secure and trusted infocomm environment for all in Singapore.
Page: 138