PROTECT OUR ESSENTIAL SERVICES Operators increasingly rely on computer networks and the Internet to maintain essential services and to serve their businesses and consumers. For CII operators, the gain in efficiency and productivity is significant – but so are the increased vulnerabilities of essential services to cyber disruption. To ensure the continuous delivery of essential services, CII operators need both physical resilience and cyber resilience. Cyber resilience is the ability of our CIIs to withstand cyber-attacks, allowing them to continue operating under the toughest conditions and recover quickly after a disruption. We must raise the cyber resilience of our essential services, and we can achieve this only with the trust and participation of all stakeholders – the Government, CII operators, and the cybersecurity community. Implement CII Protection Programme The Government will roll out a holistic CII Protection Programme for government agencies and CII operators. It will build on the Cybersecurity Readiness Maturity Assessment programme implemented in 2012, which has enabled agencies and operators identify areas for improvement. The CII Protection Programme will, firstly, establish the foundation to facilitate information exchange among CII operators through clear policies and guidelines. Second, it will enable targeted and systematic improvements through clearer measurements of governance maturity and networks’ cybersecurity hygiene. Third, it will require operators to foster a culture of cyber-risks literacy across all levels in organisations, proactively address cyber-risks and ensure that their practices are consistent with policies. With a deep understanding of cyber risks, sectors take ownership and provide management focus to implement effective CII protection plans that are tailored to the unique circumstances of each sector. The goal is for all critical sectors to establish robust and systematic cyber risk management processes and capabilities that are effective against the evolving cyber threats. Systematic Cyber Risk Management Singapore will: Implement across all critical sectors, a CII Protection Programme with robust and systematic cyber risk management processes. A key part of the CII Protection Programme is to grow a culture of cyber risk awareness across all levels of a CII organisation. From the CEO to the employee, cybersecurity must be seen as a business concern and not just one for the IT department. Pre-empt cyber vulnerabilities by going upstream and promoting Security-by-Design practices. Cybersecurity will no longer be an afterthought, but will be consciously implemented throughout the lifecycle of technology systems. A systematic cyber risk management framework comprises: 1 thorough identification and prioritisation of cyber risks and CIIs through risk assessments, vulnerability assessments and system reviews; 2 well-informed and conscious trade-offs in security, cost and functionality, decided at management levels of appropriate seniority; 3 sound systems and procedures to mitigate and manage these risks, including disaster recovery and business continuity plans; 4 effective implementation that encompasses awareness building and training across the organisation; and 5 continuous measurement of performance through process audits and cybersecurity exercises. Cybersecurity Maturity Assessment The Government has been using the Readiness Maturity Index (RMI) framework to assess the readiness of CII sectors in terms of their capabilities for risk-based mitigation, early detection of threats, and robustness of the response measures. The RMI is the metaphorical health check that directs the CII sectors’ effort to manage cyber risks, and facilitates the development of action plans to improve governance and procedures. 12 CHAPTER 1 CHAPTER 1 13

Select target paragraph3