Debated in Parliament on 14 Jan 2013.
Order for Second Reading read.
Mdm Speaker, may I first add my congratulations to you on your election as Speaker.
Thank you.
I look forward to your firm and fair handling of the administration and affairs of this House.
Mdm Speaker, I beg to move, "That the Bill be now read a Second time."
Madam, we last amended the Computer Misuse Act in 2003 to strengthen Singapore's defence against cyberattacks. Over the past decade, we have witnessed tremendous technological change. Cyberspace has become an integral part of our daily lives, and is used extensively for the delivery of a wide range of public and private sector services. At the same time, our increasing dependence on cyberspace has brought about new risks and vulnerabilities. Hence, it is timely to review our legislative framework to ensure that it remains
Page: 45
relevant and effective in protecting our economy and society against cyber threats.
In recent years, the number of cyberattacks across the world has risen sharply. Criminals, terrorists and state-sponsored groups have been exploiting cyberspace to their advantage. In 2010, McAfee uncovered an average of 55,000 new malicious software (or malware) threats every day. This figure is now 100,000 – double what it was just two years ago. A 2012 report by the World Economic Forum ranked cyberattacks among the top five global risks.
Critical Information Infrastructure, or CII, refers to systems which are necessary for the delivery of essential services to the public in various key sectors. These sectors include energy, water, finance and banking, Government, healthcare, infocomm, security and emergency services, and transportation. Cyberattacks often occur with little warning and have tremendous potential for contagion. They can disrupt daily lives and threaten our nation's security, economy, public health and safety. They can bring a country to a complete standstill. It is precisely because of this that CIIs are prime targets of cyberattacks.
Cyberattacks on CII pose a real and present danger to all countries. Widespread damage can easily result from a single piece of malicious software or the exploitation of one point of weakness. In 2007, Estonia encountered a series of cyberattacks which lasted three weeks and resulted in widespread damage to society and the economy. It crippled the country's government and banking services for many days, while users were unable to access the Internet across a wide range of functions. In the US, the reported number of such attacks has increased 20-fold within the last two years. According to a McAfee report in 2011, nearly two-thirds of critical infrastructure companies worldwide reported regular findings of malware designed to sabotage their systems. It is estimated that 24 hours of down time from a major cyberattack would cost a critical infrastructure enterprise, on average, more than US$6 million.
The technology and sophistication of saboteurs are also rapidly evolving. In July 2010, Stuxnet, a sophisticated form of malware, was discovered – reportedly responsible for infecting 45,000 industrial control systems worldwide. Many of these systems were integral to a country's critical infrastructure, such as energy, water and communication networks. Two years on, Stuxnet has been joined by other equally if not more sophisticated malware. One of them, known as Flame, has been described by some experts as being 20 times more powerful than any known cyber warfare programme, including
Page: 46
Stuxnet. We can expect the potential for damage to be far more severe. To prevent a successful attack, we need a nimble and comprehensive response that can guard against a broad spectrum of attacks and threats.
Singapore is not immune to cyberattacks of this nature. We are a highly inter-connected nation. As of 2011, 85% of Singapore households had access to broadband at home, while 81% of businesses used the Internet. With cyberspace being essential to many aspects of our lives, we are vulnerable in many ways to any breaches. In fact, we, too, have been the target of cyberattacks in recent years. For example, in the lead-up to the APEC 2009 meetings held in Singapore, there were at least seven waves of malicious email attacks which targeted members of the APEC Organising Committee and APEC delegates from various countries. While these attacks did not target our CII, they are indicative of the potential for future attacks against other Singapore targets.
The cyber threats that we face today are sophisticated and malicious. Our legislative framework must keep pace with the nature of this evolving cyber threat. Section 15A of the Computer Misuse Act, or CMA, was introduced in 2003. It empowers the Minister for Home Affairs to authorise measures to prevent or counter cyber threats to our CII in the event of an outright cyberattack or where there is specific intelligence received of an imminent attack. These powers are no longer adequate, given the operating environment that I have described.
To make our CII more robust and resilient against cyber threats, my Ministry has reviewed section 15A of the CMA. The review was undertaken in consultation with CII operators and regulators. It also took into account legislative enhancements which other countries, such as the United States, Israel, Estonia, South Korea and Australia, have implemented or are considering.
The amendments to section 15A will strengthen the cybersecurity of our CII by enabling the Government to take more effective and timely measures to prevent, detect and counter cyberattacks that may threaten national security, essential services, defence or the foreign relations of Singapore. This approach is no different to how we deal with national security threats in the physical realm. For example, if there is credible intelligence of a potential terrorist threat to our aviation sector, we would immediately take pre-emptive steps to enhance security measures at our airport and carriers in response to the threat. Similarly, in cyberspace, we must take proactive and upstream action against a threat before it materialises to cause any harm. The proposed amendments will
Page: 47
strengthen our ability to do so. It will enhance our ability to act against cyber threats, with safeguards to ensure that the enhanced powers are exercised appropriately.
Madam, let me now elaborate on the key amendments.
Clause 2 of the Bill amends the long title of the Bill to reflect the substance of the re-enacted section 15A. Clause 3 of the Bill amends the short title of the Act to "Computer Misuse and Cybersecurity Act". These amendments will more accurately reflect the scope of the Act, including its objective of securing Singapore against cyber threats that may endanger our national interests.
Clause 4 of the Bill repeals and re-enacts section 15A to enhance the powers to act against cyber threats and introduce corresponding safeguards.
Sub-section (1) of the new section 15A empowers the Minister to issue a certificate to authorise or direct a person or an entity to take measures or comply with requirements necessary to prevent, detect or counter a threat to the national security, essential services, defence or foreign relations of Singapore.
For example, a CII operator may be required to provide information relating to the design, configuration, operation and security of computers, computer programmes or computer services. This will help identify and address cyber threats and system vulnerabilities. A CII operator may also be required to report cybersecurity breaches to the Minister or an authorised public officer. This will provide situational awareness of cyber threats at the national level and help assessments on the need for further security measures. Before a certificate is issued by the Minister, CII stakeholders will be consulted on the implications, where practicable. The measures required under the certificate will be limited to what is necessary to safeguard national security, defence, foreign relations, or essential services.
I want to emphasise that it is also in the interests of a CII stakeholder to proactively invest in preventive cybersecurity measures. This is because a successful cyberattack could lead to significant financial loss and reputational damage for the CII stakeholder. Hence, as domain owners responsible for the security of their assets, CII stakeholders will generally be expected to bear the cost of these measures.
Page: 48
Given the severity of the threat that cyberattacks can pose to the nation, the new sub-section (4) makes it an offence if a person fails to take any measure, or comply with the directions of the Minister, under section 15A of the Act. Similarly, non-compliance with the directions of a person who is acting pursuant to the certificate issued by the Minister under section 15A will also be an offence. It will also be an offence to obstruct a person from complying with the Minister's directions to him. These offences will be punishable with a fine not exceeding $50,000, or imprisonment for a term not exceeding 10 years or both.
New sub-sections (6) and (7) confer various immunities for acts done in good faith pursuant to the Minister's certificate under section 15A of the Act, including any direction given pursuant to such a certificate. This is necessary to ensure that those who are acting pursuant to the certificate or direction can perform their functions without being constrained for fear of civil or criminal liabilities.
For example, if a malware is detected to be targeting a particular make and model of equipment used by our CII operators, the Minister may issue a certificate to the CII operators to direct that certain cybersecurity measures be taken. In the course of implementing these measures in good faith, if there is service degradation or disruption that results in the failure of the CII operators to meet their contractual Service Level Agreements with their customers, the CII operators can claim immunity in any legal proceedings against them by their customers.
Information that the Minister may direct CII operators to provide to aid in the prevention, detection and countering of cyber threats will generally be technical in nature. For example, information pertaining to network design architecture, firewall rules and software algorithms, this may be required to help with the early detection of an attempted cyberattack or an ongoing cyberattack.
A new sub-section (8) introduces safeguards to restrict the use and disclosure of information obtained under the Minister's certificate.
The information obtained is to be used or disclosed only for the purpose of preventing, detecting or countering the cyber threat. Otherwise, the written permission of the party from whom the information was obtained would be required before it can be used or disclosed. Information can also be divulged to
Page: 49
a law enforcement authority if it reveals an offence.
In addition, disclosure or use will be permissible if there is a need to comply with a requirement of a court or a written law.
Contravention of the safeguards prescribed in sub-section (8) will be punishable with a fine not exceeding $10,000, or imprisonment for a term not exceeding 12 months or both.
Lastly, the new sub-section (12) expands the definition of "essential services". Currently, it covers services directly related to communications infrastructure, banking and finance, public utilities, public transportation, or public key infrastructure, as well as emergency services like police, civil defence and medical services. For the purpose of this Act, the scope of "essential services" will be expanded to include services directly related to land transport infrastructure, aviation, shipping and health services.
Mdm Speaker, our cybersecurity capabilities must continue to adapt, grow and remain relevant in this fast changing cyber threat landscape.
This requires the close collaboration amongst the stakeholders. The proposed legislative amendments will provide the Government with greater ability to work with our stakeholders to take timely actions against cyber threats to our CII. These enhanced powers come with important safeguards to ensure that they are used in an effective and responsible manner to protect our national interests. Mdm Speaker, I beg to move.
Question proposed.
Mdm Speaker, I rise to support the Bill. The new section 15A gives the Minister wider powers to take action once he is satisfied that it is necessary to prevent, detect or counter a cyber threat to Singapore. It also provides that the Government may require persons to provide information concerning such threats. Failure to comply with the Minister's directions will be made an offence.
The cumulative effect of the Bill is to give the Government greater teeth to deal with potential cyber threats. In particular, the Government is conferred
Page: 50
wide discretion in the exercise of such powers and I can understand that approach. Cyber threats, obviously, cannot be dealt with like conventional armed or terrorist threats. Anticipation, detection and timeliness of response are particularly critical. urther, the intrusion or attack may be through privately managed systems. The Minister therefore requires the necessary tools to deal with these threats.
There are, however, three points that I would like to raise in relation to the Bill.
First, the Minister may invoke such powers not only in the prevention or the countering of threats to Singapore, but also in the detection of such threats. These powers may be invoked in the context that extends beyond our national security and defence concerns, such as to preserve foreign relations.
I accept that there are practical reasons for granting the Government such wide powers. As I have said, given the reliance of critical industries on computer systems and the sophistication of modern hacking techniques, it is vital that we cast a wider net to better protect our nation against cyber threats. However, the enormous power and wide discretion the Bill confers on the Government to affect measures and to obtain data from private companies and individuals will inevitably raise questions about whether those powers will always be properly used. Such power, while conferred in the national interest, should go hand in hand with increased accountability and appropriate checks and balances.
Thus, the legislative framework should provide for proper safeguards to prevent abuse or an over-reach of powers. It is unrealistic and would defeat the purpose of the Act for the Minister's decision to be reviewed at the time he exercises it. However, would it not be possible to institute periodic reviews by a separate panel to ensure that such powers have been properly exercised and information gathered properly used or archived and, in the appropriate cases, destroyed? These reviews may be held in camera to strike a balance between accountability and confidentiality. They will promote public confidence in the system.
The second point relates to the proposed section 15A(6). This sub-section confers criminal and civil immunity on anyone who in good faith implements any measure or acts according to directions he receives under the Act. And this gives rise to two issues:
Page: 51
First, whether the threshold for immunity is set too low. Under the Act, all that is required is that the person acts in good faith. Should he not also be expected to act with some reasonable care?
Second, this provision may have the counter-intuitive effect of causing companies to be less proactive in implementing measures to detect or deter cyber threats, and only act when the Minister issues his directions so that they can enjoy their legal immunity. This is clearly not desirable. I accept that companies will likely want to act before their systems are attacked as their own commercial reputations will be at stake. However, they may be less inclined to do so if the threat does not prejudice them but another party. In any event, companies should be encouraged to take proactive measures. So, would the Minister, therefore, also consider having the power of granting immunity to companies which may have acted in advance of any directions he issues to deal with cyber threats? And this can be for deserving companies on a case-by-case basis, in addition to the blanket immunity which the Bill confers.
Finally, a matter for clarification. Could the Minister explain the relationship between section 15A sub-section (8) and sub-section (10)? Sub-section (8) states that information obtained from parties may be disclosed to the Police or any law enforcement agency, if the information discloses an offence. Presumably, that is to facilitate the investigation of and prosecution for that offence. However, sub-section (10) states that where an offence is disclosed, pursuant to the exercise of powers under the section, no information for that offence may be admitted as evidence in civil or criminal proceedings. If so, what is the referral to the Police for?
On the whole, I commend the Bill for enhancing Singapore's regime against cyber threats and cybercrime. As computer hacking techniques become increasingly sophisticated, we must protect ourselves from those who seek to exploit our dependence on computer systems. In these times, national security is not just about defending our physical borders. There is clearly much at stake here. At the same time, we must always remain aware of the potential for over-reaching and implementing the appropriate safeguards. Mdm Speaker, I support the Bill.
Mdm Speaker, the proposed amendments are timely and convey the toughening of the Government's stance against potential cyber threats which may have severe
Page: 52
ramifications on Singapore's national interests and national security. In line with this broad objective, the renaming of the Act as the "Computer Misuse and Cybersecurity Act" is more than symbolic as it reflects a shift in focus from general computer offences to more targeted legislation directed at preventing and containing cyberattacks on our essential services, defence and even foreign relations. And, therefore, thank you, Mdm Speaker, for allowing me to join in this debate and to support this Bill.
In view of the increasing prevalence of cyber threats, the Ministry of Home Affairs has proposed to amend section 15A of the existing Act for effective and timely measures to be taken to make Singapore's Critical Information Infrastructure (CII) robust and resilient against cyberattacks. The emphasis here is on the pre-emptive nature of these measures, which empowers and allows the Minister to order a person or organisation to act against any cyberattack even before it has begun. This is in line with similar moves made by other countries with respect to their own cybersecurity legislation and, more broadly, reflects a much needed awareness and responsiveness on Singapore's part to the fast-changing developments in the cybersphere, as well as the legal best practices of other jurisdictions in regulating their cybersphere.
Such tightening of measures is pertinent in light of two major factors, and these two major factors reflect why I support the Bill. First, the fast-moving nature of the cyber world, and, two, the recent increase in cyberattacks. These demand more sophisticated protection. Legislative vigilance is crucial in order to tackle new potential computer abuses, such as the denial or interruption of computer services and unauthorised disclosure of access codes. This is compounded by the fact that cyberattacks worldwide have increased in frequency, speed and sophistication, which means that they are difficult to detect, and often occur without early warning. In Singapore, for example, about 1,000 cybercrime cases, including hacking, were reported under the same Act over the past five years. In order to meet such heightened demands, in terms of both volume and complexity, the amended Act takes a more sophisticated approach to provide for enhanced penalties proportionate to the different levels of potential and actual harm caused. Failure to act on the directions of the Minister, for example, will be made a criminal offence as it should be.
That said, Mdm Speaker, one concern is the pre-emptive nature of the powers accorded to the Minister, which would allow him to order telcos or banks to disclose how their computer networks are designed, or disclose reports of any attempted breach, in order to detect or counter a threat. This has, thus, far been justified by the need to thwart potentially crippling cyberattacks, and is part of the Government's larger efforts to counter the spread and
Page: 53
sophistication of these attacks. Although the Government has acknowledged that the disclosure of such information may be sensitive and has, thus, put in place some form of legal safeguards to protect the use of such data, it might be beneficial and prudent for the Government, to explain to the public what threshold must be met or what factors will play in the mind of the Ministry of Home Affairs before the power to issue directions is exercised. Notwithstanding this clarification sought, Mdm Speaker, I support the Bill.
Mdm Speaker, I welcome this Bill. Being a hyper-connected society, our national security is being redefined by cyberspace. The Internet was first developed to supplement the analogue communications among American soldiers and scientists, and trust was a very fundamental attribute in such a set-up. This enabled people who communicated with one another to trust others based on who they said they were. There was also trust that the information conveyed would be handled according to existing legal and social norms. Of course, those norms and the element of trust are now severely under threat.
Indeed, the Internet is under severe threat in three key areas: (1) piracy and intellectual property; (2) privacy; and (3) security. All three elements, in varying degrees, are given attention to in the proposed amendments, with security being the focal point of the Bill.
This Bill seeks to provide the authorities with pre-emptive powers to deal with a potential danger when there is intelligence that a cyberattack is imminent and could cripple critical infrastructure, such as public utilities, telecommunications, banking and transportation systems.
Mdm Speaker, the ready, convenient and affordable access to the Internet today has a trade-off. Users of the Internet are vulnerable to various kinds of cyberattacks. These range from online personal surveillance, hacking, corporate and governmental espionage, the hijacking of web traffic, to the remote manipulation of computer-controlled industrial, governmental and military processes. In short, the integrity of the Internet as a reliable, safe and open infrastructure is under threat. And we have to adapt to the changed environment as individuals and as a society.
Such cyberattacks, in essence, are about the control, distribution and safety of information. And information has been described as a strategic resource that
Page: 54
is as valuable and influential today as capital, labour and land had been in the industrial age.
Mdm Speaker, cyber warfare, as well as cyberattacks, involves deception and sabotage and can be a strategic game changer as we become more dependent on the Internet for the purposes of work, leisure, education, as well as military operations. It is a non-traditional security threat that is quickly becoming more mainstream and common as cyberspace evolves into a new domain of conflict.
Much as we see it as a technical issue, cybersecurity is ultimately a security, economic and political challenge. Much as our laws have had a defensive stance, they must now evolve in tandem with the changing security threat so that they possess offensive capabilities as well. This is primarily in the pre-emptive powers that the Bill seeks to provide in the new proposed section 15A.
Mdm Speaker, would the Minister outline our nation's strategy in dealing with persistent and sophisticated cyberattacks? In particular, even as we focus on the pre-emptive strikes to deal with the security threat that the Internet poses, how will the proposed amendments make our system and our response to a real and present danger resilient?
By resilience, what I mean is how the various stakeholders ranging from the Government to the corporate sector are prepared and able to continue with their operations in a degraded environment, especially when we are unable to pre-empt or counter a cyberattack. Madam, the Bill is primarily concerned with active defence – detecting attacks before they take place. Is our critical infrastructure, our systemic response up to scratch where resilience is concerned?
Mdm Speaker, as I see it, the various stakeholders have different perspectives on cybersecurity and the nature of the risks that cyberattacks pose to their interests. This Bill is an important step in countering cyber threats but it does not strike me as being an attempt to elicit a coherent policy response.
To be sure, this is not the intent of the Bill but, perhaps, it could have gone further. I hope the Minister can discuss how the Government intends to ensure that the cyberspace within our jurisdiction does not suffer from a "tragedy of the commons" phenomenon in which stakeholders assume that someone – usually the Government in our context – is providing the necessary security and so reduce the need for other stakeholders to internalise those risks. This goes
Page: 55
beyond business continuity plans; it is inherently about whether we can cope, as a society, with a sophisticated cyberattack and not be paralysed or thrown into a gridlock in various facets of our lives.
With our vast and growing infrastructure, cybersecurity is an area where there is a pressing need for better incentives and a "whole-of-society" approach should be pursued. Matters are compounded when there is invariably a sense of futility and despair over the size and complexity of the threat, particularly for companies. This, in turn, reduces the incentive to put investments and to cooperate in mutually beneficial ways.
Mdm Speaker, should our laws require companies and organisations to report incidents when their systems have been hacked and data stolen? Such "breach laws" can provide advance warning of further attacks, and also require people to be informed if the stolen data significantly affects them. This can also incentivise companies and organisations to spend more on cybersecurity and be innovative in countering such a threat. Developing defensive cyber capabilities cannot be the sole preserve of the Government.
Mdm Speaker, would the Home Affairs Ministry consider imposing greater penalties on persons who breach their duty to protect information obtained pursuant to those proposed powers? Sub-section 9 of the proposed section 15A provides for a penalty of a fine not exceeding $10,000 or to a jail term not exceeding 12 months or both. This strikes me as being relatively not so onerous a punishment considering that intellectual property, trade secrets and sensitive operational details of an organisation can potentially be involved. I am aware that the Minister has said that primarily technical details would be obtained but it is possible that non-technical details could also be required.
Furthermore, why not protect such information obtained under the Official Secrets Act since the information relates intimately to national security, essential services and Singapore's foreign relations? The transnational nature of cyber threats, often involving non-state actors as well, also means that there is a need to protect such information obtained. There must be complete confidence that the authorities will properly handle the information obtained, and that privacy, intellectual property, proprietary data, confidential information and the like are adequately protected.
Finally, would the Minister also provide an update on the National Cyber Security Centre? Will public education be a key remit of this security centre given that our cybersecurity is only as strong as our weakest link? Cyberattacks
Page: 56
are increasingly common and we must not allow the Internet to be the Trojan horse. Mdm Speaker, on that note, I support the Bill.
Mdm Speaker, in October last year, US Defence Secretary Leon Panetta urged the US Congress to pass a cybersecurity law. He said that hackers had infiltrated the control systems of US critical infrastructure operating chemical, electricity and water plants, and warned of more destructive attacks that could cause loss of life if successful.
As the Minister had articulated, Singapore is not immune to such risks, as much as we hope that they never materialise. As such, we need measures to protect the computer systems that run our key critical infrastructure against cyber threats. While I support the Bill, I still have a few queries for the Minister.
First query is on the existing power in section 15A of the Computer Misuse Act which already allows the Minister to authorise the taking of such measures as necessary to prevent or counter any threat to computer service. I would imagine that owners of critical infrastructure who care about their own commercial reputation or who understand the serious consequences that may flow from a successful attack would implement proportionate protective measures. Could we have a sense from the Minister why there is now a necessity to not only authorise but to compel them to comply with the security requirements? Have they been slow to do so, on their own accord, or have existing protective measures been assessed to be inadequate to counter the real threats out there?
Second query: the operation of many parts of critical infrastructure and systems are heavily dependent on infocomm technology, Internet connectivity and computer systems. This leverage on technology has permitted such infrastructure to take on unprecedented scale, sophistication and efficiency. The Achilles' heel, however, is their vulnerability to attack by hackers whether they be mischief makers, criminals, terrorists or even governments. Typically, states and governments respond by adding layers of stringent protective and detection measures. However, in the event that these measures fail, and parts of our system are effectively pushed back into the "Stone Age", do we have contingency measures to ensure that life goes on? In short, how operationally ready and prepared are we as a country in the event that critical systems fail or malfunction?
Page: 57
Third query relates to cyberattacks which are a global phenomenon and often originate abroad. Close international cooperation is vital to complement domestic measures such as those envisioned under section 15A.
Fourth query: while I appreciate that the threats facing our critical infrastructure are varied and may come from many angles and take many forms, the power under the new section 15A does confer a very wide discretion on the Ministry of Home Affairs. This raises a number of related concerns.
First, how would the Ministry ensure that the privacy of ordinary individuals is not compromised inadvertently or otherwise, as part of surveillance and detection requirements?
Second, paragraphs (a) to (c) of sub-section (2) of this section envision that private individuals and corporations may be empowered to exercise extensive and intrusive powers of search and requisition of information that ordinarily are reserved for public as well as law enforcement officers. Their exercise of these powers is protected by a limited civil and criminal immunity. How will the Ministry ensure that these powers are exercised judiciously, proportionately and responsibly, while addressing concerns about privacy and fears about potential abuses?
Third, imposing excessive compliance costs that are disproportionate to the risks may have a chilling effect on our attractiveness as a business environment and raise the entry barrier to certain industries for local SMEs. How would the Ministry ensure that it strikes the appropriate balance – between, on the one hand, having robust and effective safeguards, while on the other hand ensuring that it remains commercially viable to run those businesses? There needs to be an open conversation therefore between Government, business or business federations on the evolving nature of cyber risks and what a proportionate level of security ought to be.
Fourth, if infrastructure operators believe that their safeguards are adequate, or feel that the obligations imposed are onerous or excessive, is there any avenue for them to appeal against an order under section 15A or to have the contents of the order varied? There is currently no such mechanism in the Bill. In short, Madam, what is the framework and what are the principles that
Page: 58
will guide the Ministry of Home Affairs in the exercise of this very broad power?
Fifth query: can I seek clarity on a matter of interpretation of the scope of power envisioned in section 15A(2)(a)? The overarching purpose of the provision in sub-section (1) is wide, which is, to "prevent, detect, and counter threats to national security, essential services, defence or foreign relations". But sub-section (2)(a) empowers or requires specified persons to exercise powers set out in sections 39 and 40 of the Criminal Procedure Code, which refer to the accessing of computers and encrypted computer data for the purposes of investigating arrestable offences. Two questions: first, does this mean that there must be an arrestable offence disclosed before sub-section (2)(a) can be invoked? Second and more fundamentally, does this mean that private individuals or enterprises will be given powers to investigate offences? What are the safeguards?
The sixth and final query is not specifically about prevention of cyberattacks, but about the policy on computer misuse in general and this follows the recent spate of intemperate online postings on Facebook, Twitter and elsewhere that potentially touch on racial or religious sentiments; in short, cybersecurity for the ordinary man and for society. For serious cases, we have provisions in the Sedition Act, Maintenance of Religious Harmony Act, Penal Code offences, and so on, which are investigated by the Police. But for less serious cases which though offensive, but are not necessarily made with criminal intent, would the Government consider setting up a tribunal to deal with and handle such cases, instead of requiring the Police to act at first instance? This tribunal could have powers to order take-down, press for apologies to be made, impose community service orders, order persons concerned to attend counselling or mediation, and so on. This could later be expanded to deal with less serious cases of cyberbullying or harassment, and bring cybersecurity to the ordinary man. Mdm Speaker, I support the Bill.
Mdm Speaker, we live in an uncertain age. There exist real and growing threats to our interests in cyberspace and these threats are increased with the advent of the "Internet economy". Online fraud and tax frauds by organised criminals are now on the rise. Cyberattacks, worldwide, have increased in speed, frequency and sophistication.
Page: 59
In the UK, in the 2012 Information Security Breaches Survey, it was found that 93% of large corporations and 76% of small businesses have had some form of cybersecurity breach in the past one year. The costs to these companies can indeed be large and significant.
Thus, debating this Bill is timely and necessary since the last review was done in 2003. The amendments are also in line with similar moves by other developed countries. I have five points to raise:
One, pertaining to section 15A, I am glad that the definition of "essential services" has been outlined and expanded in this Amendment to include a broader range of other health services, civil defence and also emergency services. I assume it would cover our new National Electronic Health Records which contains a tremendous amount of confidential and intimate information.
Two, I support the stiffer penalties in this Amendment quoted as they do, I hope, act as a form of deterrence.
Three, the Government cannot do all these alone. Industry players need to collaborate and join forces as well to safeguard the most valuable assets in our Critical Information Infrastructure (CII) which includes personal data, online services and, of course, our intellectual property. Together, the potential to handle and address cyber threats which can undermine our growth and prosperity will be stronger and more resilient. Madam, on the measures to strengthen the cybersecurity of CII, is there a deadline set for the implementation? Earlier today in the House, we heard the Minister for Communications and Information, in response to Question No 13, state that a review by the Government is ongoing and that there were lapses in the maintenance. This is quite worrying to me and I actually asked how long this review is going to take.
Four, will the MHA be stepping up on its training and skills acquisition in these and related areas in order to be able to counteract new tactics and strategies by cybercriminals today? In that same context, whilst planning and strategising, we must not forget the risk of cyber insider attacks. There must be some allowances made in order for companies or Ministries to weed these out. We need to ring-fence our security model for the anticipated increase in sharing of services that is bound to occur, including a common and standardised approach to assurance, single sign-on system for employee authentication, security monitoring, with effective policing of compliance and enhanced
Page: 60
network resilience.
Finally, Madam, considering the scope of the Internet today, we certainly cannot just focus our efforts in Singapore alone. What about international and cross-border cooperation? What are we doing in this area, bearing in mind the global nature these threats can take? In conclusion, I support the amendment Bill.
Order. I propose to take the break now. I suspend this Sitting and will take the Chair again at 4.05 pm.
Sitting accordingly suspended
at 3.45 pm until 4.05 pm.
Sitting resumed at 4.05 pm
[Mdm Speaker in the Chair]
Debate resumed.
Mdm Speaker, I would like to thank all the Members who have spoken and for their general support of the Bill and its policy intent. I would endeavour to address the key points that Members have raised specifically pertaining to the enhanced powers and safeguards in the Bill, as well as some broader issues such as other measures to enhance capabilities and collaboration in tackling cyber threats.
First, let me address Mr Desmond Lee's point on the need for the enhanced powers. Let me reiterate that the cyber threats that we face today are extremely malicious, with tremendous potential to cause widespread damage within a very short span of time. An example is the high-profile "July 2009 Cyber Attacks", which targeted government and financial services websites in South Korea. In an emergency measure to restore the networks that were disabled by the attacks, some 30,000 virus-infected computers were denied Internet access by Korean Internet operators, on the instruction of the Korean Communications Commission. The economic costs associated with the disruption of services
Page: 61
were significant.
A more recent example is the series of aggressive denial-of-service attacks on financial institutions in the US, believed to be perpetrated by a group of Iranian hackers. The attacks targeted at least 10 major banks. Their websites were flooded with massive log-in attempts which disrupted remote banking services and affected many customers. The first wave started in September last year and the attacks are still ongoing today.
We need robust measures, given the prevalence and increasingly potent nature of cyber threats. This requires all parties concerned to collaborate – the Government as well as industry players and other stakeholders within the cyberspace ecosystem.
We have been working with the various industry regulators to reach out to the CII owners and operators to harden their systems against cyber threats. They have generally been cooperative. It is about working together in a more upstream, proactive manner. Indeed, the CII owners and regulators recognise that it is in their interests to put in place a certain level of security measures to meet their business needs so as to ensure the sustainability of services to their customers and also to protect themselves from potential financial losses arising from an attack.
However, beyond the direct business impact on the individual entity, a successful attack on a CII can have broader implications. These are the externalities which, if not accounted for, could lead to a "tragedy of the commons" as Asst Prof Eugene Tan had talked about. A cyberattack can have knock-on effects, disrupt key sectors of our economy and threaten our national security, including the lives of individuals. The legislative powers in this Bill will ensure that we have the ability to promptly step up the protection of our CII to protect our national interests before damage is caused. At the same time, CII operators will not be encumbered by fear of liability as long as they have acted in good faith when complying with the Minister's directions to counter the cyber threat.
Mr Desmond Lee and Mr Christopher de Souza spoke about the scope of the powers. Specifically, Mr Lee asked whether the powers in the Bill are too broad and Mr de Souza asked about the situations under which the enhanced powers may be invoked, and if the threshold levels or triggers for exercising such powers could be specified.
Page: 62
Let me respond. The powers in the Bill may be exercised to direct that measures be taken when there is an assessed threat that may endanger our national security. An example is when there is credible intelligence that a new malware targeting CII has been developed, or that malware has been used against another country. If we assess the current defences of the CII to be inadequate, a certificate may be issued to direct CII operators to step up their cybersecurity measures. So that is the general approach. However, given the rapidly changing nature and complexity of the threat we are facing, it is neither possible nor practical to specify in detail the precise triggers for the activation of powers in the legislation.
The proposed powers are needed to enable anticipatory actions to be taken against such evolving threats in a timely manner. So, in many instances, the level of specificity may be difficult to afford at the time of assessment. Ultimately, the decision to exercise the powers will have to be a judgement call by the Minister, informed by the assessment of the relevant Government agencies. I want to reassure the Members of the House that it is a decision that will be made only after a considered and thorough assessment of the threat and vulnerabilities. This approach is not unique to Singapore. Laws in other countries, such as South Korea and Estonia, are similarly crafted to give the enforcement agencies sufficient flexibility and also the authority to take effective actions against threats to national security, including cyber threats.
Mr Desmond Lee, Mr Hri Kumar and Asst Prof Eugene Tan also spoke on the need for safeguards to prevent abuse of powers. This is an important point. Mr Hri Kumar suggested setting up a panel to conduct periodic reviews after the Minister's decision has been taken to ensure that such powers have been properly exercised.
Mdm Speaker, let me assure the House that the powers will be used judiciously. The assessment of whether there is a threat to the national security, essential services, defence and foreign relations of Singapore is a decision to be made by the Executive. There are adequate safeguards to ensure the reasonable and justified exercise of these powers. Section 15A circumscribes the use of the powers to situations where there is a likely threat to the national security, essential services, defence or foreign relations of Singapore. So, the Minister is constrained by the language of section 15A when acting. His discretion is not unfettered.
In addition, there is a robust process of procedural safeguards to ensure that these powers are properly exercised. A consultation process will be
Page: 63
undertaken with the affected CII stakeholders, where practicable. The CII stakeholders will generally be given the opportunity to make representation at three stages.
The first is to the sector regulator and the Government security authority. The second is to a high-level National Committee, comprising several Permanent Secretaries. And finally, to the Minister for Home Affairs. This process will help to surface potential concerns of the CII stakeholders and any impediments that they may face in carrying out the required measures. Remedies can then be considered to address these concerns. This three-stage representation will be applied and adapted based on the prevailing threat assessment and circumstances. Furthermore, after the Minister has issued the certificate, aggrieved parties can still have recourse to judicial review.
I would also like to reassure the Members that the Government will undertake periodic internal reviews on the actions taken so that the measures can be calibrated or recalibrated as needed in future. We do not intend to have an external review panel, as suggested by Mr Hri Kumar, given the sensitivity and nature of the content.
Mr Desmond Lee asked what cybersecurity measures and requirements are being contemplated and whether these could be used to intrude into an individual's privacy. Madam, let me assure the House that the powers under the Bill are not intended to intrude into privacy. The measures and requirements are mainly technical, operational or procedural in nature. For example, CII operators may be required to implement network perimeter defence devices, such as firewalls, or to perform regular vulnerability scanning of their systems to identify potential loopholes. These measures are non-intrusive with respect to personal privacy.
Likewise, any information required by the Minister under the certificate to deal with cyber threats will generally be technical and not personal in nature. For example, to aid in the detection of cyber threats, the Minister may request information such as network logs on the machine transactional requests, system event logs and system audit logs containing failed login attempts. Only anonymised data would be required. The consultation process with the CII stakeholders prior to the issuance of the certificate will help to ensure that any information required is justified and not unduly onerous.
Mr Hri Kumar, Mr Desmond Lee and Asst Prof Eugene Tan spoke on the need for proper management and use of the information obtained. This is yet
Page: 64
another important point. Mr Desmond Lee also asked whether CII operators may be required to disclose certain confidential or proprietary information and how such information will be protected.
The need for Government to access proprietary information, such as source codes for security vetting or assurance purposes, is not unique to Singapore. Indeed, it is also required in the US and UK, for example. Safeguards have been included in the Bill to prohibit information obtained under the certificate from being used or disclosed other than for the purpose of preventing, detecting or countering a cyber threat, or for the other purposes specified in the Bill.
Asst Prof Eugene Tan asked if the penalties for contravention of the safeguards relating to use and disclosure of information in the Bill are too low given the sensitive nature of the information. The penalties are consistent with those provided for in similar provisions in other legislation, such as section 28 of the Electronic Transactions Act, and section 27B of the Economic Development Board Act. In addition, the Official Secrets Act may also be applicable depending on the circumstances of the case, to address the point raised by Asst Prof Eugene Tan.
To supplement these safeguards, the Government will also consider entering into contractual non-disclosure agreements with vendors to address their specific needs and concerns. An example is the Microsoft's Government Security Program (GSP) which facilitates access by governments worldwide to Microsoft's product source code and other technical information. Under the GSP Code agreement – the Singapore Government has signed with Microsoft – there are non-disclosure provisions for information shared by Microsoft that is commercially sensitive.
We will work closely with the CII stakeholders to define the security obligations upfront, and ensure that the need for sharing of information is balanced with sufficient safeguards to protect their commercial interests.
Mr Hri Kumar asked about the relationship between sub-sections (8) and (10) of the amended section 15A. In particular, he sought clarification on the purpose of furnishing information obtained under section 15A to the Police. If information obtained under section 15A reveals an offence, sub-section (8) allows that information to be given to the Police to commence investigations. Sub-section (10) does not allow that information to be admitted as evidence in court. This sub-section is intended to protect the identity of the informer and the circumstances in which the powers were invoked. Disclosure of such
Page: 65
information may hinder or jeopardise efforts to neutralise the threat. However, from the information given to the Police, pursuant to sub-section (8), the Police will gather new evidence using its investigative powers. And this new evidence will be admissible in court whereas the initial information given to the Police will not be admissible. I hope that clarifies.
Asst Prof Eugene Tan highlighted that "breach laws" which mandate the reporting of cybersecurity incidents, such as hacking, could potentially enhance our national sentinel by providing advance warning of further attacks. Companies and organisations can already report cyber incidents voluntarily to the Singapore Computer Emergency Response Team (SingCert). However, making reporting of cybersecurity incidents mandatory, at this juncture, for all companies could incur significant compliance cost. A balanced and targeted approach is needed. We need to strike a balance between national interest and commercial interest, so as to ensure that the cost imposed on the private sector is reasonable. This is why the current mandate requires only CII stakeholders to report cybersecurity breaches.
Mr Desmond Lee sought clarifications on the application of sub-section 2(a), which provides for the powers under sections 39 and 40 of the Criminal Procedure Code (CPC) to be exercised. The circumstances for these powers to be exercised are specified under sub-section (1) of section 15A of the CMA, that is, there must be a threat to the national security, essential services, defence or foreign relations of Singapore. Under such situations, the Minister may direct CII operators to perform these actions so as to prevent, detect or counter the cyber threat. There is no need for there to be an offence, arrestable or not, before the powers can be invoked. The powers are also not meant to be exercised for the investigation of offences.
The reference to sections 39 and 40 of CPC relates only to the powers stated in these provisions. And with the amendments, the references to the specific sub-sections of sections 39 and 40 of the CPC will provide a clearer indication of the relevant powers within the legislation. For example, the Minister will be able to require the CII operators to access, inspect and check the operation of the computer. This power is found in section 39(1)(a) of the CPC.
To encourage CII operators to take measures proactively, Mr Hri Kumar suggested empowering the Minister to grant immunity for measures taken in advance of any directives issued by the Minister. The immunity provisions are intended to enable CII operators to take the necessary actions against a threat to our security, without being constrained by fear of liabilities arising from
Page: 66
contracts or other laws. Should CII operators of their own volition identify measures which they think are necessary and are concerned that the measures could subject them to liabilities, they should put forth the recommendation to the relevant sector regulator and Government security authority for consideration.
As Mr Hri Kumar pointed out, such actions taken in view of broader national interests may have implications beyond the individual CII operator. Trade-offs will have to be made at the national level, especially for measures over and above what the CII operators intend to undertake of their own accord. If the Minister is satisfied that a proposed action is necessary and there is a need to render immunity to the CII operators, a certificate can and will be issued immediately.
Mr Hri Kumar also asked whether the threshold for immunity is set too low, and whether an entity should be expected to act with some reasonable standard of care. Depending on the facts of the case, if a person acts unreasonably, then it may be said that he had not acted in good faith. Put another way, requiring a person to act in good faith does not preclude the need for him to act with reasonable care. The immunity provision in the Bill is consistent with similar provisions in other legislations, such as sections 39 and 40 of the Criminal Procedure Code.
Mr Desmond Lee asked about the compliance cost to CII operators arising from the measures or requirements. As domain owners responsible for the security and business continuity of their assets, the operators would generally be expected to bear the cost of the measures. We have put in place safeguards and processes to ensure that the measures will be reasonable and limited to what is necessary to safeguard our national security defence, foreign relations or essential services. Nevertheless, should a CII operator feel that there is a strong justification for Government funding, the operator may work through its sector regulator to explore leveraging on existing sources of funds.
Assoc Prof Fatimah Lateef asked whether there is a deadline set for the implementation of the measures. The amended powers will take effect as soon as possible after the Bill has been passed by Parliament and the President's assent has been received. There is no single fixed timeline for CII operators to comply with measures directed by the Minister. This will vary, depending on the nature of the threat, the assessment of the CII system's risks and vulnerabilities, the type of measures required and the readiness of each sector.
Page: 67
CII operators will be consulted accordingly.
I will now move on to the other suggestions by Members to strengthen cybersecurity.
Asst Prof Eugene Tan asked about our national strategy in dealing with cybersecurity threats and requested an update on the National Cyber Security Centre (NCSC). First, let me assure the House that the Government adopts a holistic approach towards strengthening the cybersecurity of the nation. The proposed amendment to section 15A is one of the key pillars supporting these larger national initiatives. The Critical Information Infrastructure Protection (CIIP) Programme initiated in 2009 aims to better address the cyber security needs of our CII. It provides for engagement platforms and regular cyber-exercises to test and subsequently enhance our cyber responsiveness. We will also be training IT professionals to be cyber defenders and be equipped with the relevant skill sets to complement national incident responders.
Let me also clarify that the NCSC is an operational centre and public education is not one of its core functions. It serves to enhance early detection and acts as a nodal point for coordinating incidents response. Phase 1 of the NCSC, which focuses on cyber monitoring of CII for the security and emergency services sector, has already been completed, and the project is on schedule.
I agree with Asst Prof Tan that public education is an important component of our overall strategy. This is an area that the Government is also firmly committed to. One such public education initiative is Governmentware, an annual IT security seminar run by the Singapore Infocomm Technology Security Authority (SITSA).
Apart from that, the Cyber Security Awareness Alliance, formed in 2008, leverages on the diverse strengths and resources of its members from across the public, private and people sectors, to promote the adoption of good cybersecurity practices among individuals and businesses.
Assoc Prof Fatimah Lateef spoke on the importance of training and skills acquisition in cybersecurity. The Government works closely with the industry in these areas to strengthen our national capacity to deal with cyber threats.
Memoranda of Understanding (MOU) have been signed between various Government agencies and the Institutes of Higher Learning (IHLs) to collaborate in many areas, from the development of courseware on IT security modules to
Page: 68
undertaking joint research projects.
Assoc Prof Fatimah Lateef highlighted cyber risks posed by insiders. The enhanced powers will cover cyber threats to national security in general and apply regardless of whether the threats originate externally or internally. We must also recognise that insider threats cannot be fully eliminated using technical means alone. Essential service operators must, therefore, adopt strong technical measures and strict internal checks and balances to minimise their exposure to such risks. And, where applicable, the Government will work with CII stakeholders to address such risks.
Unlike traditional crime, cyber threats can be perpetrated very easily across geographical boundaries and jurisdictions in the physical world. As Assoc Prof Fatimah Lateef and Mr Desmond Lee have rightly pointed out, it is crucial for the international community to cooperate in tackling these threats.
Our security and law enforcement agencies have formed strong partnerships with their counterparts in other countries to strengthen capabilities in this area. These partnerships enable the sharing of early cyber threat intelligence and cyber defence initiatives, and thereby enhance our ability to stay ahead of the evolving threats.
The INTERPOL Global Complex for Innovation slated to open in Singapore next year will also facilitate cyber research and innovation, and provide cybersecurity training and operational support for law enforcement agencies around the world.
Finally, let me address other issues pertaining to cyberspace.
Offensive communications in the cyberspace can vary widely from insensitive remarks made on the spur of the moment to serious forms of hate speech. Mr Desmond Lee suggested setting up a tribunal to deal with less serious cases of online posting that inflame racial or religious sentiments, as well as minor cases of cyber bullying and harassment.
The Ministry of Home Affairs is currently working with the Ministry of Law and the Ministry of Communications and Information to review our legislative framework and the remedies available to victims of cyber harassment. I want to thank Mr Lee for his suggestions, which we will take into consideration as part
Page: 69
of the review.
Mdm Speaker, the threats in cyberspace have grown significantly over the years. They have also become more varied and sophisticated. Of particular concern are cyber threats against CII. This Bill will greatly enhance our ability to take timely and effective measures to prevent, detect and counter these threats.
I want to assure the House that the enhanced powers, which come with safeguards, will be used judiciously. The powers will be invoked to avert threats that may endanger our national security, essential services and the defence or foreign relations of Singapore. The Minister will issue a certificate only after careful consideration of the implications, and after being satisfied that the measures are practical and reasonable.
These measures will make our CII more robust and resilient to the growing cyber threats that we face. I urge Members of the House to give your full support to the Computer Misuse (Amendment) Bill.
*Question put, and agreed to.*
*Bill accordingly read a Second time and committed to a Committee of the whole House.*
*The House immediately resolved itself into a Committee on the Bill. – [Mr S Iswaran].*
*Bill considered in Committee.*
[Mdm Speaker in the Chair]
The citation year "2012" will be changed to "2013", as indicated in the Order Paper.
Clauses 1 to 5 inclusive ordered to stand part of the Bill.
The Schedule ordered to stand part of the Bill.
Bill reported without amendment; read a Third time and passed.
Page: 70