Table of contents exchange of letters with the minister executive summary


response personnel must be significantly improved



Download 5.91 Mb.
View original pdf
Page197/329
Date27.11.2023
Size5.91 Mb.
#62728
1   ...   193   194   195   196   197   198   199   200   ...   329
Report of the COI into the Cyber Attack on SingHealth 10 Jan 2019
response personnel must be significantly improved

The Computer Emergency Response Team must be well trained to more effectively respond to security incidents. The Computer Emergency Response Team must be better equipped with the necessary hardware and software. A competent and qualified Security Incident Response Manager who understands and can execute the required roles and responsibilities must be appointed.
Recommendation #16: A post-breach independent forensic review of the
network, all endpoints, and the SCM system should be considered

IHiS should consider working with experts to ensure that no traces of the attacker are left behind.



COI Report – Part VII
Page 235 of 425

36 RECOMMENDATION #1: AN ENHANCED SECURITY
STRUCTURE AND READINESS MUST BE ADOPTED BY
IHIS AND PUBLIC HEALTH INSTITUTIONS
#VIGILANCE GOVERNANCE PEOPLE DEVELOPMENT
682. All organisations, whether commercial, nonprofit or governmental, need to build a secure organisation to ensure long-term success. This means that organisations must implement and maintain a strong security posture, including in relation to cybersecurity. This is particularly relevant to organisations like
IHiS and the public health institutions (“PHIs”), which own and/or maintain public sector IT systems which contain large databases of personal data – failing to secure the organisation can lead to potentially devastating consequences beyond the four walls of the organisation.
683. Over the course of the Inquiry, the evidence showed that certain aspects of the public healthcare sector’s cybersecurity posture were poor, in particular on the sector’s mindset towards cybersecurity. This was the case even at the MOHH level. At the same time, even for aspects of the public healthcare sector’s cybersecurity posture that are adequate, there is scope to further improve. The recommendations below aim to address this.

Download 5.91 Mb.

Share with your friends:
1   ...   193   194   195   196   197   198   199   200   ...   329




The database is protected by copyright ©ininet.org 2024
send message

    Main page