TABLE OF CONTENTS EXCHANGE OF LETTERS WITH THE MINISTEREXECUTIVE SUMMARY ........................................................................................... iA.
Introduction ....................................................................................................... i
B.
The events of the Cyber Attack and
incident response by IHiS and SingHealth ....................................................................................................... ii
C.
Recommendations by the Committee ........................................................... viii
PART I – INTRODUCTION ...................................................................................... 11
Appointment and terms of reference of the Committee of Inquiry ................. 1 Assistance to the Committee ............................................................................ 3 Actions taken by the Committee before the hearings ...................................... 4 Conduct of the Inquiry ..................................................................................... 5
PART II – BACKGROUND INFORMATION RELEVANT TO THE INQUIRY ...................................................................................................................... 85
Introduction to this Part ................................................................................. 10
Roles of MOH, MOHH, SingHealth and IHiS in IT administration for the Public Healthcare Sector ................................................................................ 10 The Sunrise Clinical Manager system ........................................................... 17 Parts of the SCM system and network relevant to the Cyber Attack ............. 20 9
IHiS teams responsible for IT and IT security administration and operations ....................................................................................................... 22 National incident reporting framework for Critical Information Infrastructure .................................................................................................. 31 11
IHiS’ internal framework for incident reporting and response ...................... 34 IT and IT security governance for SingHealth .............................................. 40