COI Report – Part VII
Page
317 of
425 924. It is also clear that many front-line IT staff were not even
aware of the above documents, including a)
Sze Chun; b) Katherine c)
Lum; d) Steven e) Henry and f) Chan Chee Choong.
925. There is no clarity on whom staff ought to raise any potential security incidents to. Director CSG, Kim Chuan’s position is that staff should inform their boss or the SMD. On the other hand, GCIO Benedict has emphasised that speed of reporting matters more than the chain of reporting, and maintained a presence in a TigerConnect chat group containing
staff from the delivery group, whom he expected to raise IT issues directly to him. IHiS CEO Bruce stated that in addition to the GCIO, the SMD Lead, Hann Kwang, should also be kept informed
of IT security incidents, even though Hann Kwang does not appear in any documented reporting flow.
926. Further, even within the SMD team for SingHealth, processes were inconsistent and unclear. During the response to the Cyber Attack, Benjamin was reporting his observations to various individuals including both Wee and Ernest through multiple modes,
including TigerConnect, Whatsapp, email, and in person, and it was unclear who had the responsibility for reporting upwards. This lack of consistency had been flagged several times during earlier TTXes. During the 2016 TTX, the external conductors had found that the members of the SIRT were not familiar with the written incident response procedures. A TTX in 2018