STRENGTHEN GOVERNANCE
AND
LEGISLATIVE FRAMEWORK
The Cybersecurity Act
The Government will introduce a new Cybersecurity Act. This new legislation will equip
CSA with the necessary powers to effectively address increasingly sophisticated threats
to national cybersecurity.
The new Cybersecurity Act will establish a comprehensive framework for the prevention
and management of cyber incidents, and complement the existing Computer Misuse and
Cybersecurity Act (CMCA), which will continue to govern the investigation of cybercrime.
It will:
Require CII owners and operators to take responsibility for securing their systems
and networks. This includes complying with policies and standards, conducting
audits and risk assessments, and reporting cybersecurity incidents. CII owners and
operators will also be required to participate in cybersecurity exercises to ensure
their readiness in managing cyber incidents; and
“We will develop a standalone
Cybersecurity Act that
provides for stronger and
more proactive powers.”
Minister-in-charge of Cybersecurity,
Dr Yaacob Ibrahim, 2015
Facilitate the sharing of cybersecurity information with and by CSA. Recognising that
cybersecurity breaches will happen despite our best efforts, the Act will empower
CSA and sector regulators to work closely with affected parties to expeditiously
resolve cybersecurity incidents and recover from disruptions.
CSA has been and will continue to work closely with sector regulators, CII stakeholders
and industry players in formulating detailed proposals for the new Act. A key principle is
to adopt a risk-based approach to cybersecurity, and to build in sufficient flexibility to take
into account the unique circumstances and regulations in each sector.
The need for stronger cybersecurity laws
In 2013, the Government amended
the then-Computer Misuse Act to
strengthen Singapore’s capability
in responding to national-level
cyber threats. This became the
Computer Misuse and Cybersecurity
Act (CMCA). When there is an actual
or suspected cyber threat, the CMCA
empowers the Minister of Home
Affairs to direct affected parties to
share vital information, and carry
out necessary measures to mitigate
the impact of the threat. Additionally,
some sector regulators have other
legislative powers to enforce
cybersecurity requirements on their
licensees. These powers, however,
vary from sector to sector, depending
on the operating environment and
level of technology adoption in
each sector.
18
CHAPTER 1
Today, cybersecurity threats
have become more sophisticated.
Essential services around the
world, including Singapore’s, face
a greater risk of being disrupted.
In the recent past, cyber perpetrators
have demonstrated attacks on a
range of essential services, including
the power grid and key banking
systems. There is a need to implement
more robust laws that allow for a
more proactive approach to national
cybersecurity. Many countries have
also strengthened their cybersecurity
laws over the past few years,
focusing on areas such as standards
for essential service providers,
information sharing, and cyber
crisis management.
CHAPTER 1
19