Singapore legislation

Regulation 3

of Cybersecurity (Systems of Temporary Cybersecurity Concern) Regulations 2025

Regulation 3

Information relating to system of temporary cybersecurity concern

Subregulation 1

For the purposes of section 17D(1) of the Act, a notice to the owner of a system of temporary cybersecurity concern to furnish information required under that provision must be given in writing in the form set out on the Internet website at https://www.csa.gov.sg.

Subregulation 2

The Commissioner may by notice under section 17D(1) of the Act require the owner of the system of temporary cybersecurity concern to provide to the Commissioner —

(a)

the following information on the design, configuration and security of the system of temporary cybersecurity concern:

(i)

a network diagram depicting every key component and interconnection in the system of temporary cybersecurity concern, and any external connection and dependency that the system of temporary cybersecurity concern may have;

(ii)

for every key component in the system of temporary cybersecurity concern, the following details:

(A)

its name and description;

(B)

its physical location;

(C)

any operating system and version;

(D)

any key software and version;

(E)

its internet protocol address and any open port, if the component is internet facing;

(F)

the name and address of the operator, if the owner is not the operator;

(iii)

the types of data processed on or stored in the system of temporary cybersecurity concern;

(iv)

the name and contact of every individual having overall responsibility for the cybersecurity of the system of temporary cybersecurity concern;

(b)

the following information on the design, configuration and security of any other computer or computer system under the owner’s control that is interconnected with or that communicates with the system of temporary cybersecurity concern:

(i)

the name and description of that other computer or computer system;

(ii)

the physical location of that other computer or computer system;

(iii)

the name and address of its operator, if the owner is not the operator;

(iv)

a description of any function provided by that other computer or computer system;

(v)

the types of data exchanged with the system of temporary cybersecurity concern;

(vi)

the operating system and version;

(vii)

the key software and version;

(viii)

how that other computer or computer system is interconnected with or communicates with the system of temporary cybersecurity concern, including the communication protocol of that other computer or computer system with the system of temporary cybersecurity concern;

(c)

the name of any outsourced service provider supporting the system of temporary cybersecurity concern, and the nature of the outsourced service; and

(d)

any other information that the Commissioner may require in order to ascertain the level of cybersecurity of the system of temporary cybersecurity concern.

Subregulation 3

In this regulation, “physical location” —

(a)

in relation to a key component of a system of temporary cybersecurity concern that is a virtual computer or virtual computer system, means the physical location of the physical computing resources deployed for the simulation of the key component of the virtual computer or virtual computer system; or

(b)

in relation to a computer or computer system that is a virtual computer or virtual computer system, means the physical location of the physical computing resources deployed for the simulation of the virtual computer or virtual computer system.