RESPOND DECISIVELY TO CYBER THREATS An effective cyber defence must assume that there can and will be successful cyber-attacks. When such attacks materialise, the cyber defenders must be able to mount a robust response and implement reliable recovery plans. This can only be possible with a comprehensive framework for preparedness. Singapore has developed a national cybersecurity response plan which allows for timely response and ground initiative at the local level, complemented with effective coordination and strategic support at the sectoral and national level. The plan envisages three tiers of response – Tier 1 for cyber campaigns that threaten national security, Tier 2 for cyber-attacks on a sector, and Tier 3 for cyber-attacks on a specific operator. The plan requires CSA to work closely with CII operators and the cybersecurity community to ensure an effective response. Integration of Threat Discovery, Analysis and Incident Response The National Cyber Security Centre (NCSC) monitors and analyses the cyber threat landscape to maintain cyber situational awareness and anticipate future threats. In the event of large-scale cyber incidents involving multiple sectors, NCSC coordinates with the sector regulators to provide a national level response and facilitate quick alerts to cross-sector threats. The Government is investing in technologies and systems that will strengthen and integrate the NCSC’s three key functions of threat discovery, threat analysis and incident response. This will enable faster threat discovery and operational response for cross-sector cyber incidents. The national response to a cyber-attack will be led by an inter-agency Cybersecurity Crisis Management Group, or CMG (Cyber). It is led by the Permanent Secretary of the Ministry of Communications & Information, supported by CSA, and comprises senior policy decisionmakers from government agencies overseeing the different critical sectors. CMG (Cyber) serves dual functions: (a) it is responsible for the development of cybersecurity policies and standards, and oversees the implementation of cybersecurity protection measures in the critical sectors; and (b) in a cyber crisis, it mobilises the necessary resources and directs the operational responses to provide a coordinated response to the threat. More Comprehensive Cybersecurity Exercises CHAPTER 1 Enhance its national cyber situational awareness by integrating threat discovery, analysis and incident responses. Conduct regular multi-sector cybersecurity exercises with more complex scenarios and involving more and more sectors. Through these exercises, we aim to identify vulnerabilities due to cross-sector interdependencies and stress-test coordination and communication across sectors. Build up more National Cyber Incident Response Teams (NCIRT) which can be mobilised to lend support to a sector or CII operator should they face an escalating cyber incident. Strengthen the Disaster Recovery Plans (DRP) and Business Continuity Plans (BCP) of essential services, especially against a cyber-attack. Expand the National Cyber Incident Response Team (NCIRT) Cybersecurity exercises are important ways to raise the readiness of sectors, build incident response plans and capabilities, and improve communication and coordination between the CII operators and government agencies. The Government will conduct these cybersecurity exercises at both the sector and national levels. National Cyber Incident Response Teams (NCIRT) are currently drawn from the incident response teams from CSA, Government Technology Agency (GovTech), the Ministry of Home Affairs (MHA) and the Ministry of Defence (MINDEF). They are part of the Tier 1 and Tier 2 response under the national cyber response plan. Sector exercises will run with more complex scenarios and more sophisticated attack methods. This will enhance the capability of the sectoral cyber response teams and the quality of incident management by the C-suite decision-makers in the CII operators. The Government will further enhance the capability of the NCIRTs to deal with more complex and challenging attack scenarios. It will also build up more NCIRTs by upgrading certain sectoral CIRTs and also consider raising additional NCIRTs from industry and academia. This will increase the national capacity to deal with large scale cyber-attacks. National-level exercises will encompass more and more sectors, with an emphasis on the interdependent nature of essential services. This will facilitate the discovery and mitigation of the sectors’ inter-dependencies, and stress-test the coordination and communication capabilities at the national level. 16 Singapore will: Exercise Cyber Star Over the past years, the Government has conducted sector level exercises to exercise individual critical sectors in their readiness and incidence response plans against a cyberattack. This culminated in Exercise Cyber Star, a multi-sector exercise conducted by CSA in March 2016. It brought together industry and Government representatives across the infocomm, Government, energy, and banking and finance sectors to exercise the response to a nationwide attack. The exercise was a milestone in building up cybersecurity readiness and validating the effectiveness of cross-sector cooperation. Recover, Restore, Remediate Resilience in essential services is especially applicable to CIIs, as a cyber-breach realistically cannot be prevented all the time. A resilient system will need to put in place prevention activities that must be integrated with an expedient incident response plan and a comprehensive recovery strategy to mitigate the effects of cyber incidents. As such, an important aspect following a cyberattack is to be able to return affected CIIs to normal operations as soon as possible, or to facilitate their continued operations in sub-optimal conditions through a prolonged attack. The Government will work with the sectors to ensure that robust Disaster Recovery Plans (DRP) and Business Continuity Plans (BCP) are built into their CII protection plans. CHAPTER 1 17

Select target paragraph3