Debated in Parliament on 14 Jan 2013.
Mr Baey Yam Keng asked the Minister for Communications and Information with regard to the recent hacking of the website of the People's Association and 16 related sites (a) whether more information about the hackers has been found; (b) whether there is any leakage of personal information of visitors to the affected websites; (c) what risks did visitors to the websites face; and (d) what actions have been taken to enhance cyber security of Government websites.
Madam, let me begin by congratulating you on your election as Speaker of Parliament. Madam, I would like to assure the Member that the Government takes a serious view of security breaches and remains vigilant to cyber security threats. These measures include establishing security policies, standards and guidelines, conducting regular security tests, as well as scans for vulnerabilities. Government agencies are also required to conduct security reviews and audits periodically to ensure compliance with the security policies and standards. At the whole-of-Government level, the Cyber Watch Centre (CWC) monitors Government websites and provides timely alerts when intrusions are detected. In the event of a security incident, IDA's Government IT Security Incident Response (GITSIR) team coordinates with agencies to perform investigations and supports agencies' response to the incident.
On the recent defacement of the People's Association's websites, the Member has asked whether more information about the hackers has been found. Police investigations for the case are currently ongoing. While the defaced websites carried the signature of the "HighTech Brazil HackTeam", a known hacking group that targets government and private websites around the world, the actual identity of the perpetrators has yet to be established. Preliminary investigations have traced the hacking activities to Internet Protocol addresses in foreign countries, and the Police have already requested
Page: 39
assistance from their foreign counterparts as part of their investigations.
The Member has also asked whether the personal information of visitors was compromised and whether visitors faced any risks visiting the affected websites during that period. The affected websites provide general information about the People's Association and its programmes, and the websites were not used to carry out online transactions other than allowing the public to submit online feedback. Based on preliminary findings, there was no evidence of any leakage of visitors' personal information. The affected websites were taken offline upon detection of the website defacement and visitors were not exposed to further risks.
IDA has worked with the People's Association to quickly fix the vulnerability in a software tool used by one of the affected websites to gain access to the system. The affected websites were restored progressively between 4 December 2012 and 7 December 2012 with enhanced security measures implemented. Following the incident, IDA notified all Government agencies about the software vulnerability and is working with them to check that the same vulnerability does not exist elsewhere. No other similar hacking attempts were detected.
Madam, my Ministry and IDA will continue to work closely with the Government agencies to strengthen the security of our websites. Where needed, additional security safeguards and risk mitigating measures would be put in place to ensure the integrity of our websites, taking into account new technologies and risks.
Thank you, Madam. I would like to ask Minister: given this recent attack, how would the parameters or guidelines for cyber-security for Government websites and the parameters for periodic reviews be enhanced to prevent future attacks? The second question is: given the prevalent use of SingPass for many of the Government websites, how is the Government going to ensure the security of such transactions for our citizens?
Madam, I would like to assure the Member and the House that there is a system in place which monitors Government websites on a continual basis. It is really to ensure that if there is a detection of an incident, we will move in very rapidly. Meanwhile, there are policies and guidelines in which we have encouraged all agencies dealing with highly sensitive data or websites to put in place proper systems. They are being audited, not only by the IDA, but they are expected to be audited on their own
Page: 40
through acquiring expertise from the private sector. Most importantly, the regular reviews by the team within IDA and Government help us to ensure that we learn better and, at the same time, put in place new measures.
To the Member's final question about SingPass, it has been working quite well. We are not resting on our laurels. We will continue to monitor the situation. Thus far, the system is safe and secure.
To the Member's other question of whether our parameters and policies will change from this incident, we are reviewing this. The incidents are still undergoing investigation. And certainly, we will learn from this as to whether we need to enhance it or not. One thing that we have learnt is that we were aware of this vulnerability. In fact, the agencies using this software were told to do so to check ahead of time. There was a lapse in maintenance, and the agency responsible has informed us that they will step up the maintenance regime to ensure that the checking and the auditing are done in a more timely manner.