Singapore Cybersecurity Act 2018
Evidence request list. 27 controls, 27 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
CII
Per Singapore Cybersecurity Act 2018 + 2024 amendments: CII. Requirements include (a) understand CII Designation per Commissioner + (b) Notification of Material Changes to the CII + (c) maintain compliance with codes of practice + (d) cooperate with CSA Singapore + Commissioner of Cybersecurity.
- SG Cybersecurity Act evidence for SGCYBER-1
- CII + CSA cooperation partial
Cybersecurity Act: Administration and Definitions
Define key terms including critical information infrastructure, cybersecurity incident, and cybersecurity service
- definitions register
- interpretation memo
- Glossary
- inconsistent terms
- outdated definitions
- scope confusion
Appoint Commissioner of Cybersecurity responsible for administration and enforcement of the Act
- appointment record
- ToR
- reporting line documentation
- unclear mandate
- weak ToR
- no documentation
Commissioner advises government on cybersecurity, raises awareness, and promotes development of cybersecurity strategy
- Commissioner function mapping
- engagement procedures
- regulatory correspondence
- compliance documentation
- weak engagement procedures
- no function mapping
- missing documentation
Commissioner may issue or approve codes of practice and standards of performance for cybersecurity
- codes of practice mapping
- standards alignment records
- compliance evidence
- executive reports
- no codes mapping
- weak alignment
- missing evidence
Cybersecurity Act: CII Designation and Owner Duties
CII owners must conduct cybersecurity risk assessment at least annually in prescribed form and manner
- annual risk assessment report
- CSA submission records
- methodology documentation
- remediation tracking
- assessment skipped
- weak methodology
- no remediation tracking
CII owners must conduct annual cybersecurity audit of CII compliance by approved auditor
- annual audit report
- auditor selection records
- audit scope documentation
- CSA submission
- audit not performed
- weak scope
- missed submission
CII owners must notify Commissioner of prescribed cybersecurity incidents in respect of CII
- incident notification procedure
- CSA notification log
- incident triage records
- timeline documentation
- delayed notification
- weak triage
- incomplete records
Commissioner designates computer systems as Critical Information Infrastructure for 5-year periods across 11 essential service sectors
- CII designation records
- owner notification
- asset characterization
- designation review schedule
- no designation process
- weak characterization
- missing notification
CII owners must comply with codes of practice, standards of performance, and written directions from Commissioner
- code compliance documentation
- directions response records
- compliance dashboards
- audit reports
- weak code compliance
- no directions tracking
- missing audits
Cybersecurity Act: CII Technical Safeguards
Implement access control measures for the CII that enforce least privilege, segregation of duties, strong authentication, and oversight of privileged access including third parties.
- Privileged access management tool configuration
- Access reviews on the prescribed cadence
- MFA enforcement evidence for all administrative access
- Just-in-time access workflow records
- Standing privileged accounts retained for operational convenience
- Access reviews performed but exceptions not closed within review cycle
- Third-party privileged access provisioned via shared credentials
Maintain tested disaster recovery and business continuity capabilities for the CII so that essential services continue or recover within recovery time and recovery point objectives appropriate to the sector.
- DR plan with sector-aligned RTO and RPO
- BCP documentation covering CII essential services
- DR test reports demonstrating successful recovery
- Records of lessons learned and improvements
- DR plan exists but recovery objectives not aligned with sector regulator expectations
- Testing limited to component restore rather than end-to-end service recovery
- Lessons learned logged but not implemented before next test
Maintain a documented incident response plan that aligns with sector lead CII regulator expectations and ensures consistent decision-making during a cybersecurity incident affecting a CII.
- Approved IR plan referencing CII obligations and sector lead expectations
- Sector-specific playbooks (finance, healthcare, energy, transport, telecom, water)
- Annual plan review records
- Tabletop exercise outputs
- Plan written in generic terms with no sector regulator references
- Playbooks exist for some sectors but not for newer CII categories
- Plan not refreshed after machinery-of-government changes to sector regulators
Maintain a 24x7 cybersecurity detection and response capability for the CII, with sufficient staffing, tooling, and runbooks to detect, triage, and contain incidents within prescribed timelines.
- SOC roster covering 24x7 cycles
- Detection use-case catalogue mapped to CII threats
- Runbooks for prescribed incident scenarios
- MTTD and MTTR metrics with targets
- After-hours coverage relies on on-call rotation only with no human on console
- Detection use cases unchanged for years despite evolving threats
- Metrics tracked but not reported to CII owner accountable executive
Generate, protect, and retain security-relevant logs from CII systems for the prescribed retention period, with monitoring and alerting that supports detection and post-incident investigation.
- Log source inventory mapped to CII boundary
- SIEM ingestion and parsing configuration
- Log retention policy meeting prescribed period
- Integrity controls (immutable storage, signed logs)
- Application logs not forwarded to SIEM
- Retention configured at infrastructure default rather than prescribed period
- No integrity verification on stored logs
Segment the CII from non-CII systems and the internet using zoning, firewalls, and other network security controls, with documented data flows and approved interconnections.
- Zoning model documenting CII, DMZ, and corporate zones
- Firewall ruleset reviews on the prescribed cadence
- Interconnection approval records
- Data-flow diagrams kept current
- Zoning documented at high level only, no enforcement at perimeter
- Firewall changes implemented without referencing the zoning model
- Interconnections approved for projects but not catalogued for ongoing governance
Manage supply chain cybersecurity risks for the CII, including third-party access, software supply chain integrity, and contractual obligations on suppliers whose services materially affect the CII.
- Supplier inventory with criticality ratings for CII
- Supplier due diligence and ongoing assurance evidence
- Contract clauses requiring incident notification and audit rights
- Software supply chain controls (SBOM, signing, build provenance)
- Supplier criticality assessed at procurement and never refreshed
- Contracts predating Cybersecurity Act with no retrofitted clauses
- Software supply chain controls applied to internal builds but not to vendor-supplied components
Conduct regular vulnerability assessments and threat assessments on the CII, remediate identified vulnerabilities within prescribed timeframes, and track threat intelligence relevant to the CII sector.
- Scan schedule covering CII assets at the prescribed frequency
- Threat intelligence subscription with sector relevance
- Remediation tickets meeting SLA per severity
- Risk acceptance records for deferred remediation
- Scanning misses lateral systems within the CII boundary
- Threat intelligence consumed by SOC but not by engineering or risk teams
- Risk acceptances renewed without revisiting underlying risk
Cybersecurity Act: Investigation, Emergency Powers and Penalties
Commissioner empowered to investigate cybersecurity threats and incidents to determine impact and prevent further harm
- investigation response procedure
- evidence preparation records
- legal review documentation
- regulator correspondence
- no procedure
- weak evidence preparedness
- missing legal review
Commissioner may authorize emergency cybersecurity measures for serious threats to essential services
- emergency response procedure
- Commissioner direction tracking
- compliance evidence
- communication protocols
- no emergency procedure
- weak direction tracking
- missing communication plan
Non-compliance carries fine up to SGD 100,000 and/or imprisonment up to 2 years plus SGD 5,000 per day for continuing offenses
- enforcement risk register
- penalty schedule reference
- compliance scorecard
- executive briefings
- no enforcement awareness
- weak briefing
- no scorecard
Cybersecurity Act: Licensing of Cybersecurity Service Providers
License penetration testing and managed SOC monitoring service providers due to access to sensitive information
- licence application records
- licensing requirements documentation
- compliance evidence
- renewal tracking
- unlicensed operations
- weak renewal tracking
- missing evidence
License conditions may include maintaining confidentiality, qualifications, and professional standards
- licence condition register
- compliance dashboards
- condition monitoring records
- renewal records
- weak condition tracking
- no monitoring
- missing renewals
Enforcement
Per CSA: investigation powers + cooperation + penalties.
- SG Cybersecurity Act evidence for SGCYBER-5
- CII + CSA cooperation partial
Incident Reporting
Per CSA: report cyber incidents to Commissioner including significant cybersecurity incidents within timelines.
- SG Cybersecurity Act evidence for SGCYBER-3
- CII + CSA cooperation partial
Licensing
Per CSA Part 5: cybersecurity service provider licensing for penetration testing + managed security operations.
- SG Cybersecurity Act evidence for SGCYBER-4
- CII + CSA cooperation partial
Standards
Per CSA: Codes of Practice and Standards of Performance + Cybersecurity Audits and Risk Assessments + Directions Issued by the Commissioner.
- SG Cybersecurity Act evidence for SGCYBER-2
- CII + CSA cooperation partial
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Singapore Cybersecurity Act 2018 framework page.