The government will be rolling out recommendations from the Public Sector Data Security Review Committee in 80% of its systems by the end of 2021, and the remaining 20% by end of 2030.
In his reply to the committee’s recommendation on 27 November, Prime Minister Lee Hsien Loong said, “Data is the lifeblood of the digital economy and a digital government. We need to use and share data as fully as possible to provide better public services.
“In doing so, we must also protect the security of the data and preserve the privacy of individuals, and yet not stifle digital innovation.”
Recommendations include public agencies collecting and retaining a person’s data only when it is strictly necessary and ensuring it is well safeguarded. In cases of data incidents involving government ministries, public agencies or statutory bodies, affected individuals are to be promptly notified. A single contact point will also be established to allow the public to report on data incidents.
On top of that, all public sector officers will have to go through a yearly data security training programme in an effort to improve the culture of safeguarding data.
Also, as the Personal Data Protection Act (PDPA), for which amendments are likely to be announced next year, will also include third-party government vendors handling government data. This means that those agents who we previously exempted from the PDPA will not be liable to financial penalties under the Act of up to S$1 million.
These recommendations fall under five broad measures aimed at better data protection and mitigating data compromise; improving detection of and response to data incidents; raising competency on data security in the public service, ensuring accountability for data protection at all levels of the government, and ensuring that data security is a sustained effort in the public service.
These are in tandem with the 13 technical measures that were announced by the committee in July which included strategies like encrypting sensitive files and hiding highly sensitive information in a separate system with strictly controls.
To oversee the data security across the public sector, a Digital Government Executive Committee will be appointed by the government. The current review committee, on the other hand, will take lead in implementing the latest recommended measures.
PM Lee says the government agrees that the recommendations should be implemented as soon as practicable, noting that three baseline technical measures have already been implemented in October 2019.

A string of security breaches in Singapore

These recommendations by the review committee come after an eight-month review which was commissioned following a series of data breaches in Singapore which have sparked questions of the country’s image as a tech innovator.
In March, Russian cybersecurity company Group-IB revealed its discovery of a massive data breach involving email log-in and passwords from several government organisations on the dark web since 2017 as well as over 19,000 compromised payment card details stolen and put up for sale by the hackers.
In a statement, Group-ID revealed that the breach involved Singapore’s Government Technology Agency, Ministry of Education, Ministry of Health, the Singapore Police Force and the National University of Singapore.
Also in March, insurance company AIA reported that one of its web portals containing the personal information of 200 people was found to be publicly accessible. In worse cases, the data of more than 800,000 blood donors were placed at risk over the internet due to unauthorised access by a Health Sciences Authority (HAS) vendor for over two months, also revealed in March.
Earlier in January, the Ministry of Health was notified by the police that the confidential data of 14,2000 individuals in the national HIV Registry as well as 2,4000 contacts has been illegally disclosed online.
Last year in October, 72 HealthHub accounts were illegally accessed. June 2018 saw the worse cyber attack in Singapore which resulted in the personal data breach of 1.5 million patients of healthcare cluster SingHealth, including the information of Prime Minister Lee Hsien Loong.
According to data research, the number of leaked cards has increased by 56% in 2018 compared to 2017, following a string of breaches and cyber attacks in both the public and private sector.

Subscribe
Notify of
0 Comments
Inline Feedbacks
View all comments
You May Also Like

哈佛赞我国对武汉冠病检测系统“几近完美”

武汉冠状病毒(COVID-19)在我国爆发至今已有77宗确诊病例,而我国的检测系统获得了美国哈佛大学赞扬,几乎“接近完美的黄金水准”。 哈佛大学研究员指出,我国的检测能力几乎完美,因为截止本月4日,我国已经成功检测出18起病例。 他们表示,若其他国家拥有同样的检测能力,估计全球可检测到的输入型病例会是目前的将近三倍。 研究员指出,我国在监测疾病和追踪接触者方面的能力和表现,一直以来都非常强。 当局表示,由于全球检测输入型病例的能力甚至没有我国的一半,因此估计病毒持续传播的潜在风险依然存在。

Seniors and students prefer cheaper transportation fares; working adults opt for reliability, says NUS study on public transport

According to a study done by the National University of Singapore (NUS)…

职总英康广告 反映青年夹心层挑战

职总英康在本周三上载了一段广告,描绘一个本地打工青年生活中面对的压力,既要照看自己的父母,更要为自己的孩子将来作长远规划,而这位青年的最终期望,是让自己成为“最后一代的夹心层”,不让自己的孩子也面对养父母和养家庭的压力。 视频一开始,一名名为“杨添”(译音)的年轻人,拿家用给父母,爸爸在点算他的家用,还反问他为什么这么少?今年没花红吗?青年就回答,不可能把所有的都给完他们。 之后镜头跳转到青年去提款,结单上显示他还有3万5千余存款,似乎他很努力存钱。 杨添感叹自己无法给到父母最好的:而家里冰箱坏了,仍是杨添帮忙找人来修理;把自己的旧手机给妈妈用,还要被爸爸酸是旧的。 去购物,车子不够坐,爸爸还抱怨道:“你应该买大点的车!”(爸爸很严苛啊!) 后来妈妈生病入院,父亲和杨添为了母亲住院病房的问题产生争执: 杨添其实已成家,即便和妻子讨论蜜月旅行,看到昂贵的旅行配套,也没敢下手,还建议妻子到比较近的国家旅游。 在选择中,杨添只能作出牺牲。在他的自白,他认为成长过程中得到父母给予的一切,但却没能成为他们所期待的那样,“我只是变成了… …平凡。”但杨添认为,自己是在未来打算。 后来,杨添家里终于迎来了小生命–女儿艾玛。他在自白中说道,他所做的一切不是为了自己,而是为了孩子,好让他将来不用面对自己现在面临的许多困难抉择。 “我的父母给了我所有,但那是过去的方法。我必须用不同的方式。”他说,他会好好规划自己的退休,不让自己的孩子将来成为夹心层,既要供养父母,又要照顾自己的家庭。 “我亲爱的艾玛,我将会成为最后的三明治一代,这是我对你的承诺。”…

Increase in HDB resale flat volumes while resale prices drop

While the number of Housing and Development Board (HDB) flats resold has…