Table of contents exchange of letters with the minister executive summary



Download 5.91 Mb.
View original pdf
Page188/329
Date27.11.2023
Size5.91 Mb.
#62728
1   ...   184   185   186   187   188   189   190   191   ...   329
Report of the COI into the Cyber Attack on SingHealth 10 Jan 2019

COI Report – Part VII
Page 220 of 425

50
RECOMMENDATION #15: COMPETENCE OF COMPUTER
SECURITY INCIDENT RESPONSE PERSONNEL MUST BE
SIGNIFICANTLY IMPROVED ............................................................................ 408
50.1
The Computer Emergency Response Team must be well trained to more effectively respond to security incidents ..................................................... 408 The Computer Emergency Response Team must be better equipped with the necessary hardware and software ................................................................ 414 A competent and qualified Security Incident Response Manager who understands and can execute the required roles and responsibilities must be appointed ...................................................................................................... 415
51
RECOMMENDATION #16: A POST-BREACH INDEPENDENT
FORENSIC REVIEW OF THE NETWORK, ALL ENDPOINTS, AND THE
SCM SYSTEM SHOULD BE CONSIDERED. 421
52
CONCLUSION ON RECOMMENDATIONS .............................................. 424
.



COI Report – Part VII
Page 221 of 425

35 PREAMBLE
665. In this Part, the Committee makes its recommendations on TORs #3, #4, and #5. The recommendations are made in light of the Committee’s findings, the testimony of expert witnesses and CSA, and submissions from the public. The Committee has also taken into consideration the comprehensive, careful, and thoughtful recommendations by the Solicitor-General, and the collective recommendations from MOH, MOHH, SingHealth, and IHiS.
35.1 Terminology
666. The importance of the recommendations and the seriousness with which we take their implementation are denoted by the use of the following terms a) The term “MUST” indicates requirements to be followed strictly and from which no deviation ought to be permitted. The use of MUST reflects our view that the degree of necessity for implementation of these recommendations is particularly high. b) The term “SHOULD” indicates that, among several possibilities, one is recommended as particularly suitable, without mentioning or excluding others, or that a certain course of action is preferred but not necessarily required, or that (in the negative form) a certain possibility or course of action is discouraged but not prohibited. There may exist valid reasons in particular circumstances to choose a different course, but the full implications must be understood and carefully weighed before choosing a different course.

Download 5.91 Mb.

Share with your friends:
1   ...   184   185   186   187   188   189   190   191   ...   329




The database is protected by copyright ©ininet.org 2024
send message

    Main page