PROTECT OUR
ESSENTIAL SERVICES
Operators increasingly rely on computer networks and the Internet
to maintain essential services and to serve their businesses and
consumers. For CII operators, the gain in efficiency and productivity
is significant – but so are the increased vulnerabilities of essential
services to cyber disruption.
To ensure the continuous delivery of essential services, CII operators
need both physical resilience and cyber resilience. Cyber resilience
is the ability of our CIIs to withstand cyber-attacks, allowing them
to continue operating under the toughest conditions and recover
quickly after a disruption. We must raise the cyber resilience of our
essential services, and we can achieve this only with the trust and
participation of all stakeholders – the Government, CII operators,
and the cybersecurity community.
Implement CII Protection Programme
The Government will roll out a holistic CII Protection Programme
for government agencies and CII operators. It will build on the
Cybersecurity Readiness Maturity Assessment programme
implemented in 2012, which has enabled agencies and operators
identify areas for improvement.
The CII Protection Programme will, firstly, establish the foundation
to facilitate information exchange among CII operators through clear
policies and guidelines. Second, it will enable targeted and systematic
improvements through clearer measurements of governance
maturity and networks’ cybersecurity hygiene. Third, it will require
operators to foster a culture of cyber-risks literacy across all levels in
organisations, proactively address cyber-risks and ensure that their
practices are consistent with policies. With a deep understanding of
cyber risks, sectors take ownership and provide management focus to
implement effective CII protection plans that are tailored to the unique
circumstances of each sector.
The goal is for all critical sectors to establish robust and systematic
cyber risk management processes and capabilities that are effective
against the evolving cyber threats.
Systematic Cyber Risk Management
Singapore will:
Implement across all critical sectors, a CII Protection Programme
with robust and systematic cyber risk management processes.
A key part of the CII Protection Programme is to grow a culture
of cyber risk awareness across all levels of a CII organisation.
From the CEO to the employee, cybersecurity must be seen
as a business concern and not just one for the IT department.
Pre-empt cyber vulnerabilities by going upstream and
promoting Security-by-Design practices. Cybersecurity
will no longer be an afterthought, but will be consciously
implemented throughout the lifecycle of technology systems.
A systematic cyber risk management framework comprises:
1
thorough identification and prioritisation of cyber risks and CIIs through
risk assessments, vulnerability assessments and system reviews;
2
well-informed and conscious trade-offs in security, cost and functionality,
decided at management levels of appropriate seniority;
3
sound systems and procedures to mitigate and manage these risks,
including disaster recovery and business continuity plans;
4
effective implementation that encompasses awareness building and
training across the organisation; and
5
continuous measurement of performance through process audits and
cybersecurity exercises.
Cybersecurity Maturity Assessment
The Government has been using the Readiness Maturity Index (RMI) framework
to assess the readiness of CII sectors in terms of their capabilities for risk-based
mitigation, early detection of threats, and robustness of the response measures.
The RMI is the metaphorical health check that directs the CII sectors’ effort to
manage cyber risks, and facilitates the development of action plans to improve
governance and procedures.
12
CHAPTER 1
CHAPTER 1
13