Table of contents exchange of letters with the minister executive summary



Download 5.91 Mb.
View original pdf
Page32/329
Date27.11.2023
Size5.91 Mb.
#62728
1   ...   28   29   30   31   32   33   34   35   ...   329
Report of the COI into the Cyber Attack on SingHealth 10 Jan 2019

COI Report – Part II
Page 27 of 425

support). Of note is the Production Enhancement Team, also known as the SCM Application Team, which provides support for end-user issues with applications in the SCM system.
9.1.5
The SingHealth GCIO and Cluster ISO
70. Each of the Clusters, including SingHealth, has a Group Chief Information Officer (“GCIO”) and an Information Security Officer (“Cluster
ISO”), both of whom are IHiS employees. This arrangement has been in place since the formation of IHiS in 2008. The Cluster GCIOs are accountable to the Clusters for Chief Information Officer (“CIO”) services, such as IT capability development, and systems resilience and security and are concurrently accountable to IHiS’ CEO for the quality of CIO services provided to the Clusters and other IHiS leadership responsibilities.
71. The Cluster GCIOs are accountable to the Clusters for Chief Information Officer (“CIO”) services, such as IT capability development, and systems resiliency and security and are concurrently accountable to IHiS CEO for the quality of CIO services provided to the Clusters and other IHiS leadership responsibilities.
72. The SingHealth GCIO is Benedict Tan Wee Bor (“Benedict”). GCIO Benedict has a reporting line to IHiS CEO Bruce as well as to SingHealth management via SingHealth Deputy GCEO (Organisational Transformation and
Informatics) (“Dy GCEO”) Professor Kenneth Kwek (“Prof. Kenneth”).
73. The SingHealth GCIO’s roles and responsibilities include a) Strategic IT planning to align IT to support SingHealth's business objectives, including IT capability development, systems resiliency and security (i.e. Keeping The Lights On orb KTLOb), and IT cost-effectiveness.



COI Report – Part II
Page 28 of 425

(b) Working with MOHH’s Group Internal Audit team (“GIA”) in connection with yearly internal audits on SingHealth's IT systems. c) Ensuring that SingHealth's IT enterprise programs remain aligned with security requirements, ensuring compliance with prevailing security policies and standards, and overseeing SingHealth's IT risk assessment.
74. The SingHealth GCIO is supported by the SingHealth GCIO office, which comprises about 50 staff, who are mostly IT directors from SingHealth's PHIs and domain or business analysts.
75.
SingHealth GCIO Benedict is assisted by Cluster ISO Wee Jia Huo
(“Wee”) in fulfilling his responsibility for cybersecurity in SingHealth. Wee is the only staff in the SingHealth GCIO office who has a portfolio specific to security, with no officers reporting to him. For cybersecurity matters, the GCIO office (including Wee) works collaboratively with IHiS CSG and IHiS Delivery Group. The SingHealth GCIO office is reliant on IHiS delivery group for both technical implementation of cybersecurity measures and compliance with cybersecurity policy and procedure.
76. The SingHealth Cluster ISO’s roles and responsibilities include a) Working on IT risk assessment (see section 12.3.2 (pg 44) below b) Liaising with internal auditors GIA and on followup on any audit findings or observations c) Being part of the security incident response and reporting process see paragraph a) (pg 38) below and d) Assisting GCIO in raising end-user awareness of IT security in
SingHealth.



Download 5.91 Mb.

Share with your friends:
1   ...   28   29   30   31   32   33   34   35   ...   329




The database is protected by copyright ©ininet.org 2024
send message

    Main page