CSOC Singapore Cybersecurity Act and PDPA — Questions and Answers
Question 1: Which Singapore government agency is responsible for overseeing cybersecurity under the Cybersecurity Act?
- The Cyber Security Agency of Singapore (CSA) (Correct answer)
- The Infocomm Media Development Authority (IMDA)
- The Ministry of Home Affairs (MHA)
- The Singapore Police Force Cyber Crime Command
Correct answer: The Cyber Security Agency of Singapore (CSA)
The Cyber Security Agency of Singapore (CSA) is the national agency overseeing cybersecurity in Singapore. Under the Cybersecurity Act, CSA has powers to regulate critical information infrastructure, respond to cyber incidents, and promote cybersecurity across sectors.
Question 2: What is a Critical Information Infrastructure (CII) under Singapore's Cybersecurity Act?
- A computer or computer system that supports essential services whose disruption would have a serious impact on Singapore (Correct answer)
- Any IT infrastructure owned by the Singapore government
- All internet service provider infrastructure in Singapore
- Computer systems used by the Singapore Armed Forces for national defence
Correct answer: A computer or computer system that supports essential services whose disruption would have a serious impact on Singapore
Under the Cybersecurity Act, a CII is a computer or system that forms part of an essential service (e.g., energy, water, banking, healthcare, transport) whose disruption would significantly impact Singapore's national security, economy, or public safety.
Question 3: Under Singapore's Cybersecurity Act, what is the obligation of a CII owner when a cybersecurity incident occurs?
- The CII owner must notify CSA of the incident within the prescribed timeframe (Correct answer)
- The CII owner must resolve the incident independently without involving external parties
- The CII owner only needs to report incidents if data loss has occurred
- CII owners have no mandatory reporting obligation — reporting is voluntary
Correct answer: The CII owner must notify CSA of the incident within the prescribed timeframe
The Cybersecurity Act imposes mandatory incident reporting obligations on CII owners. They must notify CSA of specified cybersecurity incidents within prescribed timeframes so that CSA can coordinate national-level response if necessary.
Question 4: What powers does the Commissioner of Cybersecurity have under Singapore's Cybersecurity Act?
- Powers to investigate cybersecurity threats, require assistance from owners of computers, and authorise entry into premises during investigations (Correct answer)
- Powers to arrest and prosecute cybercriminals directly without police involvement
- Powers to revoke all operating licences of companies that suffer cybersecurity breaches
- Powers to mandate specific technology vendors for CII systems
Correct answer: Powers to investigate cybersecurity threats, require assistance from owners of computers, and authorise entry into premises during investigations
The Commissioner of Cybersecurity has extensive investigative powers under the Act, including the ability to investigate cyber threats, require computer owners to provide assistance, and enter premises during investigations, subject to legal safeguards.
Question 5: Under Singapore's Cybersecurity Act, which of the following is an offence?
- Providing false information to the Commissioner of Cybersecurity during an investigation (Correct answer)
- Hiring an unregistered cybersecurity auditor for an internal review
- Using open-source security tools without a vendor support agreement
- Failing to achieve a specific cybersecurity certification within a defined timeframe
Correct answer: Providing false information to the Commissioner of Cybersecurity during an investigation
Providing false information to the Commissioner of Cybersecurity during an investigation is a criminal offence under the Cybersecurity Act. The Act also creates other offences related to obstruction of investigations and unauthorised access.
Question 6: How does the Singapore Cybersecurity Act interact with other sector-specific regulations in Singapore?
- The Cybersecurity Act provides overarching cybersecurity requirements, while sector regulators such as MAS and MOH apply additional sector-specific cybersecurity rules (Correct answer)
- The Cybersecurity Act replaces all other sector-specific regulations for organisations that handle digital data
- Only the Cybersecurity Act applies — sector regulators have no authority over cybersecurity matters
- Sector regulators may override Cybersecurity Act requirements if they conflict with industry needs
Correct answer: The Cybersecurity Act provides overarching cybersecurity requirements, while sector regulators such as MAS and MOH apply additional sector-specific cybersecurity rules
The Cybersecurity Act operates alongside sector-specific regulations. For example, MAS has its own Technology Risk Management Guidelines for financial institutions, and MOH has similar requirements for healthcare. CII owners may be subject to both sets of requirements.
Which Singapore government agency is responsible for overseeing cybersecurity under the Cybersecurity Act?