Debated in Parliament on 14 Nov 2012.
Mr Zaqy Mohamad asked the Deputy Prime Minister and Minister for Home Affairs (a) what is the Ministry's assessment of the US House of Representatives' Intelligence Committee's report on Chinese telecommunications companies posing a security threat to the US corporate and government interests; (b) what is the current risk to Singapore and how pervasive is the use of these technologies within the Government and other telecommunications infrastructure; and (c) whether feedback has been received from multinational corporations with regard to such security concerns.
Page: 1301
In early October 2012, the US House of Representatives' Intelligence Committee published a report on the potential security risk to US corporate and government interests posed by two particular non-US telecommunications companies. The report made a number of recommendations for US government agencies, Congressional Committees, and the two non-US companies to consider. We are monitoring the developments.
Singapore takes the issue of cybersecurity seriously. A trusted, secure and resilient information and communications (or infocomm) infrastructure is critical to Singapore's national security and economic interests. MHA works closely with the Ministry of Communications and Information (MCI) and the Infocomm Development Authority (IDA) to put in place robust measures to secure our Government and national infocomm infrastructure. This is done by identifying the security threats, assessing the attendant risks, and implementing controls to mitigate the risks. Our approach does not differentiate between products or suppliers by brand or country of origin.
Page: 1302
Within the Government sector, infocomm infrastructure is evaluated for compliance with security requirements before deployment. Additional security safeguards are put in place where needed. The infrastructure is also regularly monitored, tested and reviewed to ensure that it continues to meet stringent security standards.
For the telecommunications sector, IDA has also taken steps to strengthen the security of our Internet Infrastructure. In February 2011, IDA issued a mandatory Code of Practice to designated Internet Access Service Providers (IASPs). The Code requires information on threats and vulnerabilities to be shared with IDA to enable effective mitigation measures to be taken. MHA is also working with IDA to put in place additional risk mitigation measures to prevent our infocomm infrastructure from being compromised by foreign governments or other groups or individuals acting against Singapore's interests. Periodic audits on the designated Providers will be conducted and IDA will impose penalties if they fail to comply with the security requirements.
We will continue to work with stakeholders to strengthen our security regime to ensure the integrity and resilience of our infocomm services, taking into account new technologies and risks.
Page: 1302