Regulation 7
Report of cybersecurity incident in respect of third‑party‑owned critical information infrastructure, etc.
Subregulation 1
Paragraph (2) applies to the following cybersecurity incidents:
a prescribed cybersecurity incident mentioned in section 16I(4)(a) or (b) of the Act;
a prescribed cybersecurity incident mentioned in section 16I(4)(c) of the Act which results in any disruption or degradation to the continuous delivery, in Singapore, of the essential service (where the third‑party‑owned critical information infrastructure is necessary for the continuous delivery);
a cybersecurity incident mentioned in section 16I(4)(d) of the Act.
Subregulation 2
For the purposes of section 16I(4) of the Act, if a cybersecurity incident mentioned in paragraph (1) occurs, the designated provider responsible for the third‑party‑owned critical information infrastructure in respect of which the incident occurred must notify the Commissioner of the occurrence of the cybersecurity incident within the following prescribed periods and in the following prescribed form and manner:
within 2 hours after becoming aware of the occurrence — by submitting the following details in the manner mentioned in paragraph (6):
the particulars of the third‑party‑owned critical information infrastructure;
the name and contact number of the owner of the third‑party‑owned critical information infrastructure;
the nature of the cybersecurity incident, whether the incident occurred in respect of the third‑party‑owned critical information infrastructure or any other relevant computer or computer system, and when and how the incident occurred;
if the relevant computer or computer system in respect of which the cybersecurity incident occurred is a computer or computer system under the provider’s control that does not fall within section 16I(4)(b) of the Act — the purpose of the computer or computer system;
the resulting effect that has been observed, including how the third‑party‑owned critical information infrastructure or any other relevant computer or computer system has been affected;
the name, designation, organisation and contact number of the individual submitting the notification;
within 72 hours after becoming aware of the occurrence — by providing, to the fullest extent practicable, the following supplementary details in writing in the form set out on the Internet website at https://www.csa.gov.sg:
any updates and supplementary details in respect of the details submitted under sub‑paragraph (a);
the cause of the cybersecurity incident;
the impact of the cybersecurity incident on the third‑party‑owned critical information infrastructure or any other relevant computer or computer system, or on the business operations of the designated provider responsible for the third‑party‑owned critical information infrastructure;
the remedial measures that have been taken;
within 30 days (including any Saturday, Sunday and public holiday) after the submission mentioned in sub‑paragraph (b) is made — by providing a final incident report containing the following details in writing in the form set out on the Internet website at https://www.csa.gov.sg:
the details submitted under sub‑paragraphs (a) and (b);
to the fullest extent practicable, any updates and supplementary details in respect of the details submitted under sub‑paragraphs (a) and (b).
Subregulation 3
Paragraph (4) applies to a prescribed cybersecurity incident mentioned in section 16I(4)(c) of the Act which does not result in any disruption or degradation to the continuous delivery, in Singapore, of the essential service (where the third‑party‑owned critical information infrastructure is necessary for the continuous delivery).
Subregulation 4
For the purposes of section 16I(4) of the Act, if a prescribed cybersecurity incident mentioned in paragraph (3) occurs, the designated provider responsible for the third‑party‑owned critical information infrastructure in respect of which the incident occurred must notify the Commissioner of the occurrence of the cybersecurity incident in the following prescribed form and manner and within the following prescribed periods:
by providing to the Commissioner, to the fullest extent practicable, the following details in a consolidated quarterly report in writing in the form set out on the Internet website at https://www.csa.gov.sg, no later than the end of the third working day following the end of the quarter in which the designated provider became aware of the cybersecurity incident:
the date and time of the cybersecurity incident;
the particulars of the third‑party‑owned critical information infrastructure;
the name and contact number of the owner of the third‑party‑owned critical information infrastructure;
the computer or computer system in respect of which the cybersecurity incident occurred, and the purpose of that computer or computer system;
the nature of the cybersecurity incident, and when and how it occurred;
the cause of the cybersecurity incident;
the resulting effect of the cybersecurity incident;
the impact of the cybersecurity incident on the computer or computer system mentioned in sub‑paragraph (iv), on the third‑party‑owned critical information infrastructure, or on the business operations of the designated provider responsible for the third‑party‑owned critical information infrastructure;
the remedial measures that have been taken;
if any of the circumstances mentioned in paragraph (5) occurs — by submitting to the Commissioner —
within 2 hours after the occurrence of the circumstance — the following details in the manner mentioned in paragraph (6):
the details set out in paragraph (2)(a);
the circumstance mentioned in paragraph (5) that has occurred;
within 72 hours after the occurrence of the circumstance — the supplementary details set out in paragraph (2)(b) (to the fullest extent practicable) in the form set out on the Internet website at https://www.csa.gov.sg; and
within 30 days (including any Sunday and public holiday) after the submission mentioned in sub‑paragraph (ii) is made — a final incident report containing the details set out in paragraph (2)(c).
Subregulation 5
The circumstances mentioned in paragraph (4)(b) are as follows:
the designated provider becomes aware that the cybersecurity incident has any effect which is observable by any member of the public;
the designated provider becomes aware that the cybersecurity incident was caused by or related to an exploitation of a vulnerability which was a zero‑day vulnerability at the time of the exploit;
the designated provider becomes aware that any indicator of compromise that is associated with an advanced persistent threat and that was previously notified in writing to the designated provider by the Commissioner was detected in relation to the cybersecurity incident;
the designated provider suspects that the cybersecurity incident may have been caused by an advanced persistent threat.
Subregulation 6
The manner of submission mentioned in paragraphs (2)(a) and (4)(b)(i) is submission —
by calling the telephone number specified by the Commissioner; or
if the designated provider is unable to submit the details in the manner set out in sub‑paragraph (a) within a reasonable time —
by text message to the telephone number specified by the Commissioner; or
in writing, in the form set out on the Internet website at https://www.csa.gov.sg, to the electronic address specified by the Commissioner.