SECURE GOVERNMENT NETWORKS Government systems are among the prime targets for cyber-attackers. Government systems contain sensitive data, including those about their citizens; they may be linked to essential services supplied by CII operators; they are used to support a gamut of public services including the maintenance of national security and sustaining the economy. Hence, the Government will spare no effort in safeguarding its systems and networks. The Government has undertaken, in this current term, to work towards a goal of setting aside 8 per cent of its ICT expenditure on cybersecurity. The Government sector is already identified as one of the eleven CII sectors in the national cyber response plan. The Government’s plans as a CII sector lead incorporate many of the elements of the larger national plan. They involve: Reducing the attack surface presented by Government systems and erecting multiple layers of security controls and network segmentation according to vulnerability and need; Expanding our capacity to detect, correlate and analyse threats, using automation and other technologies; and Sharpening the skills of our incident responders and stress-testing our systems through more complex and realistic attack scenarios. Cybersecurity professionals on duty at Cyber-Watch Centre (CWC) Reducing Attack Surface The Government has put in place long-term measures including on-going and proactive reviews of the ICT operating environments, to ensure that security controls are commensurate with rapidly evolving threats. For example, in view of the increased frequency of targeted attacks on Government networks, the Civil Service will separate Internet surfing from the networks that hold classified data according to vulnerability, exposure and need. At the same time, the Government will continue its approach of adopting new technologies to deliver secure and resilient digital services. It is also looking into risk reduction initiatives to minimise the potential loss of citizens’ data or prolonged outages of digital services. 20 CHAPTER 1 Enhancing Situational Awareness through Technology The Monitoring and Operations Control Centre (MOCC), Cyber-Watch Centre (CWC), and Threat Analysis Centre (TAC) provide the Government with cyber situational awareness of its networks. We will continue to invest in technologies such as analytics, automation, artificial intelligence, and other state-of-the-art security technologies. This will maintain the centres’ operational excellence, to enable timely detection and response to a cyber incident. Preparing for Cyber Breaches The Government has expanded considerable effort in building a team of highly-skilled security incident responders. However, we recognise that no system is 100 per cent foolproof and breaches may still occur even despite the best of our efforts. We will continue to hold regular cybersecurity exercises to stress test our procedures and capabilities for a realistic evaluation of our proficiency, and conduct redteaming sessions to validate the security of our systems. The Government will work with the sectors to ensure that CII protection plans are in place for expedient remediation to restore essential services. Cyber-Watch Centre (CWC) The Cyber-Watch Centre (CWC) was established by the Infocommunications Development Authority of Singapore (IDA) in 2007 to monitor cyber threats to government networks and provide early warning of impending cyberattacks. To improve the detection of malicious activities which could affect access to online public services, the CWC was upgraded in 2015 with a wider range of detection capabilities and enhanced correlation capabilities. This is an example of a proactive defence-in-depth security measure to mitigate increasingly sophisticated attacks and enhance infocomm infrastructure security. CHAPTER 1 21

Select target paragraph3