Govt rolls out IT tools to boost security of sensitive data

A total of 13 solutions have been recommended to address data breaches

Claudia Tan HS

Published Mon, Jul 15, 2019 · 09:50 PM

Singapore

THE Public Sector Data Security Review Committee has started rolling out IT tools to improve the government's management of citizens' sensitive data before the full set of recommendations and findings is due on Nov 30.

The committee was convened by Prime Minister Lee Hsien Loong in April this year following a spate of cyber and data security breaches.

Chaired by Senior Minister Teo Chee Hean, the committee includes four ministers and experts from the private sector. It had been tasked to review data practices and to recommend steps to improve the government's protection of data and incident response.

In a briefing on Monday, a Smart Nation and Digital Government Office (SNDGO) spokesperson said that many data breaches have been a result of human error. Hence, digital solutions and IT tools will help the government and public servants become more competent in safeguarding data.

For one, an email data protection tool will be implemented to prevent accidental disclosure of confidential data through email. This tool scans for potential risks of data breaches and prompts the sender to double-check the email contents as well as intended recipients. The email will only be sent out upon confirmation.

Another tool that will be rolled out ensures that data on sent files have not been modified in any way by requiring the sender to provide a digital signature to confirm the integrity of the file.

Lastly, files containing confidential data will be password protected to ensure only authorised users can access and change the contents of the files.

These three measures can be easily implemented on existing systems without deep integration, said the SNDGO spokesperson.

They are part of the 13 digital solutions currently recommended and the committee aims to implement them across all government agencies by the end of the year.

To date, the committee has carried out a government-wide stock-take of data management practices and in-depth inspections of key IT systems of financial and healthcare agencies that manage high volumes of sensitive data.

The agencies are: the Ministry of Health, the Health Sciences Authority, the Health Promotion Board, the Central Provident Fund Board and the Inland Revenue Authority of Singapore.

Inspections on other agencies will be carried out in phases in the coming weeks.

Besides digital solutions, the committee acknowledges that given the current technological landscape, it is also important to focus on process and people measures as the range of threats to data security has increased.

"This is in view of the increasing complexity of our systems, the greater demand for the use of data to provide convenient digital services to the public, and the need to use data for better policy-making," said the SNDGO in a statement.

Process measures include procedures that enable agencies to protect against data security threats as well as respond swiftly to incidents.

Meanwhile, people initiatives aim to improve data security capabilities among public officers.

Such measures are recommended in light of recent data security breaches and potential threats.

The latest data breach involved the personal information of more than 800,000 blood donors being put online for over two months.

Singapore also suffered its worst cyberattack in June last year where personal particulars of about 1.5 million SingHealth patients were stolen.