Table of contents exchange of letters with the minister executive summary



Download 5.91 Mb.
View original pdf
Page40/329
Date27.11.2023
Size5.91 Mb.
#62728
1   ...   36   37   38   39   40   41   42   43   ...   329
Report of the COI into the Cyber Attack on SingHealth 10 Jan 2019

COI Report – Part II
Page 39 of 425

(c) Once CSG is alerted, Kim Chuan, who is Director of CSG and the Sector Lead point-of-contact, should review the information and determine if there is a reportable IT security incident, and if so, what the categorisation of the incident is according to CSA's framework. Kim Chuan is then to report the incident to CSA as per the NCIRF timelines, and update IHiS management and MOH. CEO, IHiS has acknowledged that “while Kim Chuan is the point-
of-contact for the Sector Lead, IHiS is the Sector Lead, and as the
CEO IHiS, I have the ultimate responsibility to ensure that
reporting to CSA is done appropriately”.
11.4 Technical incident response – the Security Incident Response
Team (“SIRT”), Security Incident Response Manager (“SIRM”)
and Computer Emergency Response Team (CERT)
109. The IR-SOP also details the methodology for incident response, which is to be undertaken by Security Incident Response Team (“SIRT”). The SIRT is responsible for investigating and verifying threats, and includes technical experts from various teams, who are also to trigger the necessary response to contain and remediate security incidents, and report services.
110. The SIRT consists of members from the following teams a) Cluster Information Security Officer b) Security Incident Response Manager (“SIRM”) c) Computer Emergency Response Team (“CERT”) d) Infrastructure Service Lead e) Application Service Lead



COI Report – Part II
Page 40 of 425

111. SingHealth’s SIRM is Ernest. The SIRT reports to the SIRM, and the
SIRM plays a key role in leading and coordinating technical incident response, namely to “lead the effort of the (SIRT) and coordinate activities between all of
its respective groups” and to “receive the initial IR alerts and responsible for
activating the IR team and managing all parts of the IR process”.
112. Of note is the SingHealth Computer Emergency Response Team
(“CERT”), the first responders who are responsible for performing incident analysis to determine the scope and nature of the incident, collect forensic evidence, tracking or tracing the intruder, and providing onsite assistance to help with incident recovery. The three-man CERT was established in March 2018. Benjamin is the one member of the CERT who has attended an incident response course (“Hacker Tools, Techniques, and Incident Handling” by SANS Institute, while the other two members have not received any formal incident response training.
113. Also included in the IR-SOP is a set of Security Incident Response Plans, or playbooks, that provide a step-by-step guide on the SIRT’s incident response for specific scenarios. Hann Kwang explained that the playbooks were targeted in terms of malware, ransomware and website defacement, as this was based on the threat intelligence for the healthcare sector “for the last 1, 2 years”. There was no playbook on attacks by Advanced Persistent Threats, and the existing playbooks lacked details on the tactics, tools, and procedures of advanced threat actors.

Download 5.91 Mb.

Share with your friends:
1   ...   36   37   38   39   40   41   42   43   ...   329




The database is protected by copyright ©ininet.org 2024
send message

    Main page