Cybersecurity
- Cybersecurity Act 2018 (CYSA), Sections 7, 10 to 16, 19 and 20 and First
Schedule - Cyber Security Agency, Cybersecurity Code of Practice for Critical
Information Infrastructure, Section 3 (Governance Requirements) - Personal Data Protection Act 2012 (PDPA), Sections 24 and 26A to 26E
- Personal Data (Notification of Data Breaches) Regulations 2021 (DBNR)
- [2019] SGPDPC 3 Singapore Health Services Pte Ltd and Integrated Health Information Systems Pte Ltd: SingHealth hacking
- The Parties: SingHealth (as the database owner and data controller) and Integrated Health Information Systems Pte Ltd (IHiS) (as the central IT vendor and data intermediary).
- Personal Data Protection Commission (PDPC), Advisory Guidelines on Key
Concepts in the Personal Data Protection Act (Strongly Recommended)
Introduction
The focus is to protect Confidentiality, Integrity, and Availability (“CIA”) of systems and data.
Long title of the Cybersecurity Act:
| An Act to [A] require or authorise the taking of measures to prevent, manage and respond to cybersecurity threats and incidents, [B] to regulate owners of critical information infrastructure, [C – non-examinable] to regulate cybersecurity service providers, and for matters related thereto, and to make consequential or related amendments to certain other written laws. |
Leave a Reply