After a series of data breach cases recorded in Singapore in the past year, the entire public service will now be required to follow a common framework to protect citizens’ personal data, starting with 13 new measures.
These digital measures, a few of which are being implemented, look at making databases unusable if the information in it has been wrongly extracted, detect abnormal transmission and limit users’ access rights.
These technical measures were announced on Monday (15 July) and they are the first of the many to come from a new Public Sector Security Review Committee, which was summoned by Prime Minister Lee Hsien Loong in April 2019.
They were convened following a government-wide stocktake of how data management was conducted at five important agencies in Singapore handling medical and financial data of citizens.
Examples of the measures include having sensitive files encrypted and extremely private information of individuals, like one’s HIV status, are to be kept hidden in a separate system with tighter controls. Besides that, personal information of ministers and other prominent individuals are also to be placed in different systems with more stringent protection.
It is said that these new 13 measures will fall on a common definition of what is required for sensitive information as laid out in the new Information Sensitivity Framework. It will also replace the current practices by public agencies, many of which designed the practices themselves.
All 13 measures will eventually be implemented in accordance to the highest level of protection for the most sensitive information. For example, the database of patients with infectious diseases and individuals who are declared bankrupt will have the highest form of protection involving most, if not all, of the 13 measures.
Additionally, more measures will be introduced later on and will be included in the committee’s final report due this November. Some of the planned measures include methods to better handle third-party vendors as well as train government servants on data security practices in order to prepare Singapore for a safer digital future.
“These include measures to better ensure high data protection standards by third parties that handle government data,” noted a spokesman from the Smart Nation and Digital Government Office.
The committee was formed following a series of cyber-security breaches over the year, which includes the most recent incident where personal data of over 800,000 blood donors retrieved illegally and uploaded on an unauthorised server for more than two months. Secur Solutions Group, a Health Sciences Authority technology vendor, was said to be responsible for the incident.
If that is not all, in January this year, the Ministry of Health (MOH) said that the private information of 14,200 HIV-positive individuals had been leaked by an American named Mikhy Farrera-Brochez who had lived in Singapore. He got hold of the data through his partner, Ler Teck Siang, a local doctor who at one time headed MOH’s National Public Health Unit.
However, the worst cyber-attack that hit the Republic involved the database of the country’s largest public healthcare cluster SingHealth, and it happened in June last year. Hackers managed to secure the personal information of 1.5 million patients and outpatient prescription information of 160,000 individuals, including PM Lee.

Lapses highlighted in AGO report

Just yesterday (16 July), the Auditor-General’s Office (AGO) released its latest report where it highlighted lapses in the IT controls mainly in the Ministry of Manpower (MOM), Singapore Customs and the Ministry of Defence (MINDEF).
It said that MOM did not know that five servers for two of its IT system were not able to send logs to its IT security monitoring system for nearly seven months because of outdated configurations. Besides that, its operating systems (OS) operators, who were all outside vendors, had unrestricted access to IT system processing work permits and employment passes.
“Any unauthorised activity could compromise the confidentiality and integrity of the data in the system. The administrators could delete audit trails to remove any trace of unauthorised activities carried out,” said AGO.
On top of that, seven vendor staff at Customs had the access to the most privileged OS user account without password authentication. They could do it in six out of the seven system servers checked by AGO.
As for MINDEF, it did not review the access records by vendors to its controlled information since 2014. Additionally, AGO also noted that a number of IT vendor staff were granted access to read personnel and payroll information.
Although the government is now trying to curb the problem by rolling out these 13 new measures, but what is interesting is that they seem to place more importance to the personal data of ministers compared to citizens, since it will be kept in different systems with more stringent protection.
As such, we can’t help but wonder why the personal information of a regular citizen is any different from the ministers?
Shouldn’t all Singaporeans be protected with the same level of security?

Subscribe
Notify of
0 Comments
Inline Feedbacks
View all comments
You May Also Like

While saying that Malaysia and Singapore are not the same, Anwar also listed qualities that transcend both sides of the causeway 

At a lecture at the Singapore Management University (SMU), Malaysian politician Anwar…

选举大事不应等闲视之 民主党:更公平竞选模式下,才有最强力委托

副总理兼财政部长王瑞杰前日声称,尽早举行大选,就能尽早把人民凝聚起来,应对当前挑战和未来的不确定因素。 对此民主党认为,尽管疫情还在持续,遗憾的是行动党仍有意要在这当儿举行选举,似乎把选举视为需要去“解决”掉的麻烦事,而不是举国参与决策未来的关键时刻,这是很危险的。 民主党称,目前仍有许多深远和严肃的议题待深究,更需要国人去参与那些关乎他们生计和孩子们将来的事务。 对此,该党呼吁行动党应舍弃以往的选举模式,特别是不仅仅是九天的竞选时间,反之应延长至21天。 在疫情下群众集会可能无法召开,这也让反对党处在相对不利的劣势。 民主党认为,要让选举有更实质的意义,理应让竞选的政党有平等的机会接触选民,让选民能熟悉各政党的政策倡议和政见要点。 这也包括允许各党能每晚都能登上全国性的亚洲新闻台频道、广播、主流媒体等,以及允许政党在熟食中心、组屋底层等公共空间发表演说。 “陈振声部长说行动党寻求强力委托。但有力的委托来自于,选民有足够的时间和机会,接触各政党平台和政见。那么国人去投票前,才能有足够的认知,针对国家未来走向作出明智的选择。” 该党也指,在行动党掌控大众媒体下的备受掣肘的竞选活动,加之近年来各种立法压缩网络空间,这反而让行动党可能赢得令人质疑的委托。      …

【选举】行动党竞选宣言 称保障国人工作共渡难关

人民行动党秘书长李显龙宣布竞选宣言,主要专注于协助国人在度过冠状病毒19疫情这一大难关,并喊出口号“守护生命、保障工作、共创未来(Our Lives,Our Jobs,Our Future)”. 李显龙总理今早(6月27日)在行动党脸书专页公布竞选宣言,包括重启经济、推动我国经济转型、保障国人职业、拯救企业及提升员工技能。 他指出,若在平常的大选中,该党的竞选宣言将着重在我国的重大发展项目上,如建设裕廊湖区、樟宜机场第五搭客大厦、年长者医疗保健及增建学前教育等。 “但是,今年大选和以往不同,我国面临着数十年来的最严重危机,我国政府的首要任务就确保能够度过此难关。” 他表示,因此行动党的竞选宣言将焦点放在保障国人和外籍客工们的安全,确保我国医疗体系能够挺过这次的疫情。 他补充道,竞选宣言的重点,也包括为了共同度过目前的不确定性和危机,彼此在互助互爱下应采取的措施。

总理称要打造能接受失败的社会

昨日,李显龙总理出席新跃社科大学部长论坛,与约500名学生对话与交流。论坛讨论的课题,包括教育面对的挑战,对创业的看法、以及青年对未来工作前景的疑虑等等。 有学生询及,对于创业精神和害怕失败的观点,李显龙先是坦言创业不易,什么都要自己来,但即便有最好的点子都可能失败,那就舍弃掉那点子尝试其他的,故此不应为失败感到耻辱。 李显龙续称,如果年轻人有这样的态度,不论是政府还是人民行动党物色新人,看到这年轻人,在履历上填写他们曾设立公司,但是公司倒闭了或面对困难,“我不会怪他们,我会问他这是什么、为何你要这要么做,如果他表现坚定、坚信自己(的努力),只不过最终没成功,我还是会录用他。” 他说,自己不会指望看到有人声称自己开了十间公司,而且每间都是独角兽,生活不是这样的。 另一方面,李显龙也认为,新加坡将面对最大的教育挑战,这是因为要创造一个适合成人持续受教育的体系,仍有许多调整工作。 “X世代”,即80、90后的学生重返校园,都可能会面对无法适应的情况,故此50、60岁年长学生也会面对问题,故此如何调整制度,让他们也可以持续学习? 他承认有必要提升较完善的支持网络,也确保雇主能理解,让学员能在工作和学习之间保持平衡。