Singapore legislation

Regulation 24

of Electronic Transactions (Certification Authority) Regulations 2010

Regulation 24

Incident handling

Subregulation 1

An accredited certification authority must implement an incident management plan that must provide at the least for management of the following incidents: (a)compromise of key;

(b)

penetration of certification authority system and network;

(c)

unavailability of infrastructure;

(d)

fraudulent registration and generation of certificates, certificate suspension and revocation information.

Subregulation 2

If any incident mentioned in paragraph (1) occurs, it must be reported to the Controller within 24 hours.