Promote Security-by-Design Why is Security-by-Design important? Security-by-Design is an approach in the system development lifecycle process to ensure that our applications and systems are built, deployed, maintained, upgraded and disposed of securely. The Government will promote the adoption of Security-by-Design in several ways: Progressively institutionalise Security-by-Design into the governance framework for CII protection; Promote the practice of penetration testing to discover vulnerabilities early for remediation at the design stage; Build a strong community of practice in product and system testing based on established international standards, such as the Common Criteria product assurance certification; and Continue to refine methodologies and develop new security validation tools to improve the efficacy of Security-by-Design. Opening of the CREST Examination Facility for Penetration Testing Certifications and Accreditations at the Singapore Institute of Technology The implementation of Security-by-Design has to be complemented with highly skilled professionals who can carry out security validation processes rigorously and proficiently. The introduction of CREST penetration testing certifications and accreditations in Singapore is one means of raising the professional competency standards. Security-by-design is a best practice to ensure that system is developed with security consideration upfront and throughout its lifecycle. By integrating risk assessment into the system development lifecycle, trade-offs between security, cost and functionality are deliberated. The trade-off decisions should be made by well-informed management at the appropriate level of decision making. This ensures that the system is optimised for the conditions in which it is to be used. Subscribing to Security-by-Design will reduce piecemeal implementation and the need for costly and often ineffective retrofitting. Cybersecurity, when thoughtfully considered and incorporated at the design stage of a system will result in an organically robust system design that can better withstand cyber threats. CHAPTER 1 Mr Ravi Menon, Managing Director, Monetary Authority of Singapore (MAS), Global Technology Law Conference, June 2015 Designing cybersecurity into FinTech The Monetary Authority of Singapore (MAS) has formed a Financial Technology & Innovation Group since August 2015 to drive the Smart Financial Centre initiatives. This Group is responsible for formulating regulatory policies and 1 2 3 14 “The first priority on our journey towards a Smart Financial Centre is therefore to continually strengthen the industry’s cybersecurity.” developing strategies to facilitate the use of technology and innovation to enhance efficiency and better manage risks in the financial sector. Efforts by MAS to manage risks associated with FinTech include: Establishing a FinTech Innovation Lab that allows stakeholders to experiment with FinTech solutions, including security solutions; Establishing “regulatory sandboxes” that can be used to carve out a safe and conducive space to experiment with FinTech solutions, and where the consequences of failure can be contained; and Providing financial support through the Financial Sector Technology & Innovation scheme for projects that uplift the cybersecurity ecosystem in Singapore. CHAPTER 1 15

Select target paragraph3