Skip to content

Evidence request lists

Singapore Cybersecurity Act 2018

Evidence request list. 27 controls, 27 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

CII

SGCYBER-1
Critical Information Infrastructure (CII) Designation and Registration

Per Singapore Cybersecurity Act 2018 + 2024 amendments: CII. Requirements include (a) understand CII Designation per Commissioner + (b) Notification of Material Changes to the CII + (c) maintain compliance with codes of practice + (d) cooperate with CSA Singapore + Commissioner of Cybersecurity.

Artefacts an auditor will ask for
  • SG Cybersecurity Act evidence for SGCYBER-1
Where this commonly fails
  • CII + CSA cooperation partial

Cybersecurity Act: Administration and Definitions

SCA-S2
Interpretation and Definitions

Define key terms including critical information infrastructure, cybersecurity incident, and cybersecurity service

Artefacts an auditor will ask for
  • definitions register
  • interpretation memo
  • Glossary
Where this commonly fails
  • inconsistent terms
  • outdated definitions
  • scope confusion
SCA-S3
Appointment of Commissioner

Appoint Commissioner of Cybersecurity responsible for administration and enforcement of the Act

Artefacts an auditor will ask for
  • appointment record
  • ToR
  • reporting line documentation
Where this commonly fails
  • unclear mandate
  • weak ToR
  • no documentation
SCA-S4
Commissioner Functions and Duties

Commissioner advises government on cybersecurity, raises awareness, and promotes development of cybersecurity strategy

Artefacts an auditor will ask for
  • Commissioner function mapping
  • engagement procedures
  • regulatory correspondence
  • compliance documentation
Where this commonly fails
  • weak engagement procedures
  • no function mapping
  • missing documentation
SCA-S5
Cybersecurity Codes and Standards

Commissioner may issue or approve codes of practice and standards of performance for cybersecurity

Artefacts an auditor will ask for
  • codes of practice mapping
  • standards alignment records
  • compliance evidence
  • executive reports
Where this commonly fails
  • no codes mapping
  • weak alignment
  • missing evidence

Cybersecurity Act: CII Designation and Owner Duties

SCA-S10
Annual Risk Assessment

CII owners must conduct cybersecurity risk assessment at least annually in prescribed form and manner

Artefacts an auditor will ask for
  • annual risk assessment report
  • CSA submission records
  • methodology documentation
  • remediation tracking
Where this commonly fails
  • assessment skipped
  • weak methodology
  • no remediation tracking
SCA-S11
Annual Audit

CII owners must conduct annual cybersecurity audit of CII compliance by approved auditor

Artefacts an auditor will ask for
  • annual audit report
  • auditor selection records
  • audit scope documentation
  • CSA submission
Where this commonly fails
  • audit not performed
  • weak scope
  • missed submission
SCA-S14
Incident Notification

CII owners must notify Commissioner of prescribed cybersecurity incidents in respect of CII

Artefacts an auditor will ask for
  • incident notification procedure
  • CSA notification log
  • incident triage records
  • timeline documentation
Where this commonly fails
  • delayed notification
  • weak triage
  • incomplete records
SCA-S7
CII Designation

Commissioner designates computer systems as Critical Information Infrastructure for 5-year periods across 11 essential service sectors

Artefacts an auditor will ask for
  • CII designation records
  • owner notification
  • asset characterization
  • designation review schedule
Where this commonly fails
  • no designation process
  • weak characterization
  • missing notification
SCA-S9
Compliance with Codes and Directions

CII owners must comply with codes of practice, standards of performance, and written directions from Commissioner

Artefacts an auditor will ask for
  • code compliance documentation
  • directions response records
  • compliance dashboards
  • audit reports
Where this commonly fails
  • weak code compliance
  • no directions tracking
  • missing audits

Cybersecurity Act: CII Technical Safeguards

SCA-AC-1
Access Control and Privileged Access for CII

Implement access control measures for the CII that enforce least privilege, segregation of duties, strong authentication, and oversight of privileged access including third parties.

Artefacts an auditor will ask for
  • Privileged access management tool configuration
  • Access reviews on the prescribed cadence
  • MFA enforcement evidence for all administrative access
  • Just-in-time access workflow records
Where this commonly fails
  • Standing privileged accounts retained for operational convenience
  • Access reviews performed but exceptions not closed within review cycle
  • Third-party privileged access provisioned via shared credentials
SCA-DR-1
Disaster Recovery and Continuity for the CII

Maintain tested disaster recovery and business continuity capabilities for the CII so that essential services continue or recover within recovery time and recovery point objectives appropriate to the sector.

Artefacts an auditor will ask for
  • DR plan with sector-aligned RTO and RPO
  • BCP documentation covering CII essential services
  • DR test reports demonstrating successful recovery
  • Records of lessons learned and improvements
Where this commonly fails
  • DR plan exists but recovery objectives not aligned with sector regulator expectations
  • Testing limited to component restore rather than end-to-end service recovery
  • Lessons learned logged but not implemented before next test
SCA-IR-1
Incident Response Plan Aligned to Sector Requirements

Maintain a documented incident response plan that aligns with sector lead CII regulator expectations and ensures consistent decision-making during a cybersecurity incident affecting a CII.

Artefacts an auditor will ask for
  • Approved IR plan referencing CII obligations and sector lead expectations
  • Sector-specific playbooks (finance, healthcare, energy, transport, telecom, water)
  • Annual plan review records
  • Tabletop exercise outputs
Where this commonly fails
  • Plan written in generic terms with no sector regulator references
  • Playbooks exist for some sectors but not for newer CII categories
  • Plan not refreshed after machinery-of-government changes to sector regulators
SCA-IR-2
24x7 Detection and Response Capability

Maintain a 24x7 cybersecurity detection and response capability for the CII, with sufficient staffing, tooling, and runbooks to detect, triage, and contain incidents within prescribed timelines.

Artefacts an auditor will ask for
  • SOC roster covering 24x7 cycles
  • Detection use-case catalogue mapped to CII threats
  • Runbooks for prescribed incident scenarios
  • MTTD and MTTR metrics with targets
Where this commonly fails
  • After-hours coverage relies on on-call rotation only with no human on console
  • Detection use cases unchanged for years despite evolving threats
  • Metrics tracked but not reported to CII owner accountable executive
SCA-LOG-1
Logging, Monitoring, and Retention

Generate, protect, and retain security-relevant logs from CII systems for the prescribed retention period, with monitoring and alerting that supports detection and post-incident investigation.

Artefacts an auditor will ask for
  • Log source inventory mapped to CII boundary
  • SIEM ingestion and parsing configuration
  • Log retention policy meeting prescribed period
  • Integrity controls (immutable storage, signed logs)
Where this commonly fails
  • Application logs not forwarded to SIEM
  • Retention configured at infrastructure default rather than prescribed period
  • No integrity verification on stored logs
SCA-NSC-1
Network Segmentation and Zoning of the CII

Segment the CII from non-CII systems and the internet using zoning, firewalls, and other network security controls, with documented data flows and approved interconnections.

Artefacts an auditor will ask for
  • Zoning model documenting CII, DMZ, and corporate zones
  • Firewall ruleset reviews on the prescribed cadence
  • Interconnection approval records
  • Data-flow diagrams kept current
Where this commonly fails
  • Zoning documented at high level only, no enforcement at perimeter
  • Firewall changes implemented without referencing the zoning model
  • Interconnections approved for projects but not catalogued for ongoing governance
SCA-SC-1
Supply Chain Cybersecurity for CII

Manage supply chain cybersecurity risks for the CII, including third-party access, software supply chain integrity, and contractual obligations on suppliers whose services materially affect the CII.

Artefacts an auditor will ask for
  • Supplier inventory with criticality ratings for CII
  • Supplier due diligence and ongoing assurance evidence
  • Contract clauses requiring incident notification and audit rights
  • Software supply chain controls (SBOM, signing, build provenance)
Where this commonly fails
  • Supplier criticality assessed at procurement and never refreshed
  • Contracts predating Cybersecurity Act with no retrofitted clauses
  • Software supply chain controls applied to internal builds but not to vendor-supplied components
SCA-VM-1
Vulnerability and Threat Management for CII

Conduct regular vulnerability assessments and threat assessments on the CII, remediate identified vulnerabilities within prescribed timeframes, and track threat intelligence relevant to the CII sector.

Artefacts an auditor will ask for
  • Scan schedule covering CII assets at the prescribed frequency
  • Threat intelligence subscription with sector relevance
  • Remediation tickets meeting SLA per severity
  • Risk acceptance records for deferred remediation
Where this commonly fails
  • Scanning misses lateral systems within the CII boundary
  • Threat intelligence consumed by SOC but not by engineering or risk teams
  • Risk acceptances renewed without revisiting underlying risk

Cybersecurity Act: Investigation, Emergency Powers and Penalties

SCA-S32
Investigation of Cybersecurity Threats

Commissioner empowered to investigate cybersecurity threats and incidents to determine impact and prevent further harm

Artefacts an auditor will ask for
  • investigation response procedure
  • evidence preparation records
  • legal review documentation
  • regulator correspondence
Where this commonly fails
  • no procedure
  • weak evidence preparedness
  • missing legal review
SCA-S35
Emergency Measures

Commissioner may authorize emergency cybersecurity measures for serious threats to essential services

Artefacts an auditor will ask for
  • emergency response procedure
  • Commissioner direction tracking
  • compliance evidence
  • communication protocols
Where this commonly fails
  • no emergency procedure
  • weak direction tracking
  • missing communication plan
SCA-S36
Penalties for Non-Compliance

Non-compliance carries fine up to SGD 100,000 and/or imprisonment up to 2 years plus SGD 5,000 per day for continuing offenses

Artefacts an auditor will ask for
  • enforcement risk register
  • penalty schedule reference
  • compliance scorecard
  • executive briefings
Where this commonly fails
  • no enforcement awareness
  • weak briefing
  • no scorecard

Cybersecurity Act: Licensing of Cybersecurity Service Providers

SCA-S26
Licensing Framework

License penetration testing and managed SOC monitoring service providers due to access to sensitive information

Artefacts an auditor will ask for
  • licence application records
  • licensing requirements documentation
  • compliance evidence
  • renewal tracking
Where this commonly fails
  • unlicensed operations
  • weak renewal tracking
  • missing evidence
SCA-S28
License Conditions

License conditions may include maintaining confidentiality, qualifications, and professional standards

Artefacts an auditor will ask for
  • licence condition register
  • compliance dashboards
  • condition monitoring records
  • renewal records
Where this commonly fails
  • weak condition tracking
  • no monitoring
  • missing renewals

Enforcement

SGCYBER-5
Investigation, Enforcement, Cooperation

Per CSA: investigation powers + cooperation + penalties.

Artefacts an auditor will ask for
  • SG Cybersecurity Act evidence for SGCYBER-5
Where this commonly fails
  • CII + CSA cooperation partial

Incident Reporting

SGCYBER-3
Cyber Incident Reporting

Per CSA: report cyber incidents to Commissioner including significant cybersecurity incidents within timelines.

Artefacts an auditor will ask for
  • SG Cybersecurity Act evidence for SGCYBER-3
Where this commonly fails
  • CII + CSA cooperation partial

Licensing

SGCYBER-4
Licensing of Cybersecurity Services

Per CSA Part 5: cybersecurity service provider licensing for penetration testing + managed security operations.

Artefacts an auditor will ask for
  • SG Cybersecurity Act evidence for SGCYBER-4
Where this commonly fails
  • CII + CSA cooperation partial

Standards

SGCYBER-2
Codes of Practice, Standards, Audits

Per CSA: Codes of Practice and Standards of Performance + Cybersecurity Audits and Risk Assessments + Directions Issued by the Commissioner.

Artefacts an auditor will ask for
  • SG Cybersecurity Act evidence for SGCYBER-2
Where this commonly fails
  • CII + CSA cooperation partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Singapore Cybersecurity Act 2018 framework page.