{"id":38,"date":"2026-09-02T07:32:47","date_gmt":"2026-09-02T07:32:47","guid":{"rendered":"https:\/\/legal.sg\/?post_type=docs&#038;p=38"},"modified":"2026-09-02T09:45:25","modified_gmt":"2026-09-02T09:45:25","slug":"cybersecurity","status":"publish","type":"docs","link":"https:\/\/legal.sg\/?docs=notes\/data-protection-and-cyber-regulation\/cybersecurity","title":{"rendered":"Cybersecurity"},"content":{"rendered":"\n<ol class=\"wp-block-list\">\n<li>Cybersecurity Act 2018 (CYSA), Sections 7, 10 to 16, 19 and 20 and First<br>Schedule<\/li>\n\n\n\n<li>Cyber Security Agency, Cybersecurity Code of Practice for Critical<br>Information Infrastructure, Section 3 (Governance Requirements)<\/li>\n\n\n\n<li>Personal Data Protection Act 2012 (PDPA), Sections 24 and 26A to 26E<\/li>\n\n\n\n<li>Personal Data (Notification of Data Breaches) Regulations 2021 (DBNR)<\/li>\n\n\n\n<li><a href=\"https:\/\/legal.sg\/?docs=notes\/data-protection-and-cyber-regulation\/cybersecurity\/singhealth-case\" data-type=\"link\" data-id=\"https:\/\/legal.sg\/?docs=notes\/data-protection-and-cyber-regulation\/cybersecurity\/singhealth-case\">[2019] SGPDPC 3 Singapore Health Services Pte Ltd and Integrated Health Information Systems Pte Ltd:<\/a> <strong>SingHealth hacking<\/strong>\n<ol class=\"wp-block-list\">\n<li><strong>The Parties:<\/strong> SingHealth (as the database owner and data controller) and Integrated Health Information Systems Pte Ltd (IHiS) (as the central IT vendor and data intermediary). <\/li>\n<\/ol>\n<\/li>\n\n\n\n<li>Personal Data Protection Commission (PDPC), Advisory Guidelines on Key<br>Concepts in the Personal Data Protection Act (Strongly Recommended)<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Introduction<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The focus is to protect <strong>Confidentiality<\/strong>, <strong>Integrity, <\/strong>and <strong>Availability <\/strong>(&#8220;CIA&#8221;) of systems and data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Long title of the Cybersecurity Act:<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td>An Act to <strong>[A] <\/strong>require or authorise the taking of measures to prevent, manage and respond to cybersecurity threats and incidents, <strong>[B] <\/strong>to regulate owners of critical information infrastructure, <strong> [C &#8211; non-examinable]<\/strong> to regulate cybersecurity service providers, and for matters related thereto, and to make consequential or related amendments to certain other written laws.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Introduction The focus is to protect Confidentiality, Integrity, and Availability (&#8220;CIA&#8221;) of systems and data. Long title of the Cybersecurity Act: An Act to [A] require or authorise the taking of measures to prevent, manage and respond to cybersecurity threats and incidents, [B] to regulate owners of critical information infrastructure, [C &#8211; non-examinable] to regulate [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":31,"menu_order":3,"comment_status":"open","ping_status":"closed","template":"","doc_tag":[],"class_list":["post-38","docs","type-docs","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/legal.sg\/index.php?rest_route=\/wp\/v2\/docs\/38","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/legal.sg\/index.php?rest_route=\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/legal.sg\/index.php?rest_route=\/wp\/v2\/types\/docs"}],"author":[{"embeddable":true,"href":"https:\/\/legal.sg\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/legal.sg\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=38"}],"version-history":[{"count":5,"href":"https:\/\/legal.sg\/index.php?rest_route=\/wp\/v2\/docs\/38\/revisions"}],"predecessor-version":[{"id":49,"href":"https:\/\/legal.sg\/index.php?rest_route=\/wp\/v2\/docs\/38\/revisions\/49"}],"up":[{"embeddable":true,"href":"https:\/\/legal.sg\/index.php?rest_route=\/wp\/v2\/docs\/31"}],"wp:attachment":[{"href":"https:\/\/legal.sg\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=38"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/legal.sg\/index.php?rest_route=%2Fwp%2Fv2%2Fdoc_tag&post=38"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}