Singapore legislation
Regulation 24
of Electronic Transactions (Certification Authority) Regulations 2010
Regulation 24
Incident handling
Subregulation 1
An accredited certification authority must implement an incident management plan that must provide at the least for management of the following incidents: (a)compromise of key;
(b)
penetration of certification authority system and network;
(c)
unavailability of infrastructure;
(d)
fraudulent registration and generation of certificates, certificate suspension and revocation information.
Subregulation 2
If any incident mentioned in paragraph (1) occurs, it must be reported to the Controller within 24 hours.