Licensing Framework for Cybersecurity Service Providers

Licensing Framework for Cybersecurity Service Providers

The Singapore Cyber Security Agency (CSA) has announced the commencement of its cybersecurity service provider licensing system under Part 5 of the Cybersecurity Act (CS Act). The licensing structure, as well as Part 5 of the CS Act and the Second Schedule to the CS Act, went into force on April 11th.

 

The approach intends to better protect consumers’ interests while also addressing the information imbalance that exists between consumers and cybersecurity service providers. Over time, the regulatory regime is expected to improve service providers’ standards and reputations. The CSA will license two categories of cybersecurity service providers, according to a news release: penetration testing and managed security operations center (SOC) monitoring.

 

Because service providers delivering these two services have extensive access to clients’ computer systems and sensitive information, they are prioritized. The client’s business could be interrupted if that access is misused. Furthermore, because these services are now widely available and used in the market, they have the potential to have a substantial impact on the whole cybersecurity landscape.

 

Existing cybersecurity service providers who are already in the business of delivering either or both licensable cybersecurity services will have six months (until October 11, 2022) to apply for a license under the new framework. According to the press release, cybersecurity service providers that fail to apply for a license in a timely manner will be required to stop providing licensable cybersecurity services until a license is secured. The license is valid for two years, with costs of $500 and $1,000 for individuals and businesses, respectively. To help businesses cope with the impact of COVID-19, a one-time 50% cost waiver will be offered for all license applications submitted within the first twelve months.

 

CSA held a four-week consultation period from September 20 to October 18, 2021, to get feedback on the proposed license conditions and draught subsidiary legislation. A total of 29 replies were received from a variety of local and international industry actors, trade associations, and members of the general public. The comments were taken into account when the licensing framework was finalized, according to the press release.

 

The Cybersecurity Services Regulation Office (CSRO) was established by the CSA to oversee the licensing framework and to enable communications with the industry and the general public on all licensing-related issues. The CSRO’s responsibilities include implementing the licensing framework, which includes things like monitoring licensing processes and imposing and enforcing license requirements. It will also reply to licensees’, businesses’, and the general public’s questions and feedback. It will create and share materials with consumers about licensable cybersecurity services, such as a list of licensees.

 

CSA introduced a cybersecurity certification program earlier this month to assist businesses in implementing suitable cybersecurity measures based on their cyber risk profiles. The marks validate cybersecurity measures adopted at the organizational level, not the cybersecurity of specific products or services, according to OpenGov Asia. The Cyber Essentials mark is recommended by the CSA for businesses that are just starting out on their digital transformation journey. The Cyber Trust mark is recommended if the majority of corporate operations are handled digitally. Customers will be able to see whether businesses have implemented robust cybersecurity measures and what actions they’ve done to prevent cyber-attacks, such as testing various scenarios and establishing a business continuity plan.

Share:

Related Posts

ssg

Green Tech in Singapore

  The National University of Singapore (NUS) has signed a Master Research Collaboration Agreement with Keppel Infrastructure Holdings Pte Ltd (Keppel Infrastructure), a Singapore-based energy solution provider in which Temasek

Read More »
Empathy in Online Education: Digitizing It

Empathy in Online Education: Digitizing It

A Look at the Future of Home-Based Education As the physical world becomes increasingly engulfed in this never-ending pandemic,  the majority of Singaporean households have begun to migrate even further into the digital realm, where the infected COVID-19 cannot infiltrate.  This fluid and imagined online places have brought a great deal of comfort and protection, allowing people to speak freely without being masked or separated from others. Humans are essentially emotional beings who need socializing from other humans as well as recognition and acceptance from one another. In the year 2020, home-based learning (HBL) has become a buzzword in education. It has opened up new avenues for flexible learning, with a plethora of resources and collaborative work opportunities available both locally and globally.  While we consider the future of HBL for our children,  we must keep in mind that not every child is born and raised in the same circumstances;  the challenges faced by one student may be vastly different from those faced by another.  As a result, a standardized teaching technique may no longer be as relevant as it once was; instead, the community must thoroughly research, comprehend,  and encourage each student along his or her own individual learning path. Such idealistic ideals are attainable if the first step is to offer each student,  as well as the student’s family, enough assistance,  whether in the form of equipment, skills, time, or money.  Once such a foundation has been built,  anxiety and feelings of inadequacy will be reduced,  allowing for the development of a type of “mental compassion” and  understanding of each other’s situation. 

Read More »