STRENGTHEN GOVERNANCE AND LEGISLATIVE FRAMEWORK The Cybersecurity Act The Government will introduce a new Cybersecurity Act. This new legislation will equip CSA with the necessary powers to effectively address increasingly sophisticated threats to national cybersecurity. The new Cybersecurity Act will establish a comprehensive framework for the prevention and management of cyber incidents, and complement the existing Computer Misuse and Cybersecurity Act (CMCA), which will continue to govern the investigation of cybercrime. It will: Require CII owners and operators to take responsibility for securing their systems and networks. This includes complying with policies and standards, conducting audits and risk assessments, and reporting cybersecurity incidents. CII owners and operators will also be required to participate in cybersecurity exercises to ensure their readiness in managing cyber incidents; and “We will develop a standalone Cybersecurity Act that provides for stronger and more proactive powers.” Minister-in-charge of Cybersecurity, Dr Yaacob Ibrahim, 2015 Facilitate the sharing of cybersecurity information with and by CSA. Recognising that cybersecurity breaches will happen despite our best efforts, the Act will empower CSA and sector regulators to work closely with affected parties to expeditiously resolve cybersecurity incidents and recover from disruptions. CSA has been and will continue to work closely with sector regulators, CII stakeholders and industry players in formulating detailed proposals for the new Act. A key principle is to adopt a risk-based approach to cybersecurity, and to build in sufficient flexibility to take into account the unique circumstances and regulations in each sector. The need for stronger cybersecurity laws In 2013, the Government amended the then-Computer Misuse Act to strengthen Singapore’s capability in responding to national-level cyber threats. This became the Computer Misuse and Cybersecurity Act (CMCA). When there is an actual or suspected cyber threat, the CMCA empowers the Minister of Home Affairs to direct affected parties to share vital information, and carry out necessary measures to mitigate the impact of the threat. Additionally, some sector regulators have other legislative powers to enforce cybersecurity requirements on their licensees. These powers, however, vary from sector to sector, depending on the operating environment and level of technology adoption in each sector. 18 CHAPTER 1 Today, cybersecurity threats have become more sophisticated. Essential services around the world, including Singapore’s, face a greater risk of being disrupted. In the recent past, cyber perpetrators have demonstrated attacks on a range of essential services, including the power grid and key banking systems. There is a need to implement more robust laws that allow for a more proactive approach to national cybersecurity. Many countries have also strengthened their cybersecurity laws over the past few years, focusing on areas such as standards for essential service providers, information sharing, and cyber crisis management. CHAPTER 1 19

Select target paragraph3