口頭答弁 · 2020-10-05 · 議会 14

公共調達訓練とIT脆弱性への対応

議員は、政府公務員の調達プロセス訓練およびIT制御の脆弱性に関する問題について質問し、定期的な訓練があるかどうかおよび体系的な問題があるかどうかについて懸念を持っています。政府は、監査報告書が指摘したIT制御の脆弱性を認め、政府のITシステムが複雑かつ分散しており、手動で権限を調整することに依存するとエラーが発生しやすいことを説明しており、Smart Nation と Digital Government グループが推進する自動化改善により、段階的に新しいツールを展開してエラーを減らしていると述べています。

重要なポイント

  • Procurement training for officers
  • IT privilege management gaps
  • Drive automation improvements
政府の立場

科学技術の向上を推進し、防御能力を維持する

質問の立場

予算効率と脅威の多様性に注目します

政策シグナル

科学技術駆動による国防現代化の強化

“Actions have been taken at the whole-of-Government level to address the gaps identified.”

参加者 (3)

全文翻訳(日本語)

Hansard 原文 · 2026-05-02

第25号議員Alex Yamは副首相兼財務大臣に対し、監査局長報告書が毎年指摘している弱点に鑑みて、(a) 公務員が官職者に政府の調達プロセスに適合するための十分な訓練と監督を確保する方法、(b) 入札を担当する官職者が最新の規制とプロセスを習得するため定期的に再研修コースに参加する必要があるかどうかを質問しました。

第26号議員Leong Eng Huaは副首相兼財務大臣に対し、最新の監査局長報告書に繰り返し現れた情報技術管理の過失に鑑みて、公共サービスに本質的なシステム的問題が存在するかどうか、ならびにこれらの弱点を解決するため講じられる有効な措置が何かを質問しました。

財務副第二大臣(Indranee Rajah女史)(副首相兼財務大臣代理):議長先生、第25号および第26号の質問をあわせて回答させていただくことをお許しくださるようお願い申し上げます。

議長:構いません。どうぞ。

Indranee Rajah女史:まず、監査局長報告書に示されているとおり、すべての機関が監査意見を非常に重視し、改善に取り組んでいることを、議員の皆様にお約束申し上げます。政府レベルでは、発見された不足を補うための行動が既に講じられています。

議長先生、2019年/2020年度の監査局長報告書は、情報技術管理に弱点が存在することを指摘しており、具体的には、第一に特権ユーザー活動のレビュー、第二にアカウントおよびユーザーアクセス権限の管理が含まれています。これらの問題は以前の報告書でも提起されていました。

背景を提供するため、まず政府の情報技術システムが段階的に構築されてきたことを説明します。1980年代に各省庁が初めてITシステムを構築することから始まり、その後すべての省庁および新しく設立された省庁とプロジェクトオフィスに拡張されました。

その後、複数年にわたるニーズをより効率的に満たすため、ITシステムは継続的にアップグレード、更新、または交換されてきました。したがって、現在、2,000を超える政府ITシステムを所有しており、これらのシステムは異なるベンダーによって異なるテクノロジーを使用して開発されています。各システムは独自のユーザーアクティビティログとアクセス権限管理方法を備えています。アクセス制御がシステム間で連携していないため、職員が別の部門に異動する際には、複数のシステムを手動で調整し、廃止された権限を取り消し、新しい権限を作成する必要があります。手動調整に依存することはエラーが発生しやすくなります。

スマートネーション・デジタルガバメント・グループ(SNDGG)は自動化システムを開発中であり、プロセスを簡素化し、エラーを削減します。2,000以上のシステムでの実装が必要であるため、完全な展開には時間が必要です。

まず、特権ユーザー活動のレビューの自動化を行っています。SNDGGはいくつかの機関とのパイロットを開始しており、このツールは2021年1月から段階的に展開される予定です。高優先度システムの完全な実装は2022年12月までに完了することが予想され、2023年12月までにすべてのシステムをカバーします。

次に、アカウントおよびユーザーアクセス権限管理の自動化を行っています。SNDGGは、機関職員の異動およびロール変更を通知できるソリューションスイートを提供しており、不要になったユーザーアカウントの手動削除を容易にしています。システムに接続されている38の機関のうち、5つが監査局長事務所の監査を受けており、アカウントとアクセス権限管理に関する過失は見つかりませんでした。

SNDGGはこのソリューションをアップグレード中です。将来、人事記録が職員の異動またはロール変更を更新すると、システムは不要なアカウントを自動的に削除し、アクセス権限をレビューします。このシステムは2023年12月までに800の高優先度システムをカバーし、2024年12月までにすべての残りのシステムをカバーすることが計画されています。

職員が煩雑な手動タスクから解放されると、機械では代替できないサイバーセキュリティとデータ保護業務により焦点を当てることができます。SNDGGは公務員の教育を強化し、強力なICTガバナンスとセキュリティ管理の重要性を強調し、正しい習慣と警戒心を育成しています。すべての公務員は毎年サイバーおよびデータセキュリティ意識トレーニングを受ける必要があります。

次に調達と契約管理について述べます。繰り返し発生する過失は、IT、建築などのより複雑な調達タイプ、および単一入札価格の妥当性評価や緊急契約変更管理などの直接的でない状況で多く発生します。これらの複雑な状況に対応するには、技術的なスキルだけでなく、経験と判断力が必要であり、これには長期的な蓄積が必要です。

このため、近年、調達管理における公務員の能力構築を強化しました。まず、入札評価および承認などの重要分野での訓練を強化し、訓練内容は監査意見の学習ポイントおよび良好な実践を含みます。次に、明年初めに承認権限に追加の指導を提供する予定です。第三に、2018年以来、調達プロセスに参加するすべての職員は強制的な電子学習モジュールを完了し、新しい政策と実践について定期的に再訓練と更新を受ける必要があります。

さらに、建築およびIT調達ならびに契約管理の能力構築を強化しています。これらの分野はより専門的であり、より深い技術知識が必要です。建設・都市開発庁(BCA)は能力フレームワークを策定中であり、公務員に建築契約管理の訓練を行っています。財務省とBCAは昨年、変更注文管理および詐欺的な入札価格の識別に関する実用的なアドバイスを提供する良好な実践ガイドラインを発表しました。ガバナンスを強化するため、治理指標のセットに基づいて機関の契約管理パフォーマンスを追跡します。同様に、GovTechはIT調達能力フレームワークを策定しており、電子学習モジュールを開発中であり、明年の完了が予想されています。

これらの業務をさらに推進するため、財務省と公務員学院は今年、公務員の財政、調達、契約管理スキルを向上させることを目的とした財政および調達学院を共同で設立しました。学院はBCA、GovTechなどの技術機関と協力し、正規の訓練を実施するだけでなく、実践者の共有およびメンタリングなどの非公式な学習も推進します。学院はまた、財政、調達、および契約管理の政策および実践の発展に追いつくため、職員の継続的な学習をサポートしています。

財政能力の開発において、財政職員は政府の財務手続きに関する基礎知識と治理および内部管理を含む就職課程に参加する必要があります。マイルストンプロジェクト、フォーラムおよび分享会を通じて、職業生涯全体にわたってこれらの知識を継続的に強化および更新します。同様のイニシアチブは、公共サービスのより広い範囲で認識を高めるためにも実施されており、例えば、財政以外の職員を対象とした財政コースに関連内容を含めることです。財務省はまた、公共の説明責任の重要性を強調し、定期的に機関の上級管理層にブリーフィングを行っています。

要約すると、公務員は自らの行為と決定に対して責任を持つ必要があり、職務遂行の過程で高い基準の遵守を維持することを含みます。公共サービスの上級領導層に大きな期待を寄せており、彼らは公共資源の管理者としての責務が与えられており、各組織内で強力なガバナンスと問責を維持する必要があります。これらの期待は、各省庁および法定機関の上級領導に対して、リーダーシップと責任の形式で明確に伝達されます。パフォーマンス評価では、これらの期待に基づいてリーダーを評価し、表現不十分な者は低い評価を受けます。イベントの性質と原因に応じて、適切な規律処分が講じられる可能性があります。

最後に、公共の説明責任は依然として政府の最優先事項であることを、議員の皆様にお約束申し上げます。監査局長報告書で言及された機関は、過失について詳細な調査を進めています。公共サービスの上級領導は、発見された問題の解決、根本原因の根絶、および将来の再発防止に取り組む責務を負っています。

議長:秩序。質問時間は終了しました。運輸大臣Josephine Teoからの説明。

午後1時31分です。

[議事規則第22(3)条によれば、議程第29-32、41-60、63-68、70-84、86-90、92-106および108号の質問に対する書面回答は附録に記載されています。第27-28、33-40、61-62、69、85、91および107号の質問は、2020年10月6日の議会会議での討議に延期されています。]

英語原文

SPRS Hansard 原本記録 · 取得日:2026-05-02

25 Mr Alex Yam asked the Deputy Prime Minister and Minister for Finance in view of the weak links highlighted annually in the Auditor-General's Reports (a) how does the Civil Service ensure that officers are adequately trained and supervised to meet the Government's procurement processes; and (b) whether officers handling tenders have to attend regular refresher courses to stay abreast with new regulations and processes.

26 Mr Liang Eng Hwa asked the Deputy Prime Minister and Minister for Finance in view of the recurring lapses in IT controls highlighted in the latest Auditor-General's Report, whether there are inherent systemic issues within the public service and what effective measures will be taken to address the weaknesses.

The Second Minister for Finance (Ms Indranee Rajah) (for the Deputy Prime Minister and Minister for Finance) : Mr Speaker, Sir, may I have your permission to answer Question Nos 25 and 26 together, in my response?

Mr Speaker : Yes, please.

Ms Indranee Rajah : Let me first assure Members that, as mentioned in the Auditor-General’s reports, all the agencies take the audit observations seriously and are committed to making improvements. Actions have been taken at the whole-of-Government level to address the gaps identified.

Mr Speaker, the Auditor-General’s Report for FY 2019/2020 highlighted weaknesses in IT controls, specifically in the areas of: first, review of privileged users’ activities; and second, management of account and user access rights. These observations were raised in previous Reports.

To provide some context, I should first explain that the Government IT systems were built over time, beginning from when we first built IT systems in Ministries back in 1980s and eventually extending to all Ministries and also new Ministries and programme offices.

Since then, the IT systems have been upgraded, refreshed or replaced to be more effective and efficient to cater to the requirements over the years. Consequently, we now have more than 2,000 Government IT systems built over the years, by different vendors and using different technologies. Each system has its way of logging user activities and of managing who can access the system. As the access controls are not linked across systems, when an officer moves to another portfolio, it requires a chain of manual adjustments to different systems, to remove obsolete access rights and create new access rights for the officer. The reliance on manual adjustments is prone to human errors.

The Smart Nation and Digital Government Group or SNDGG is developing systems that will automate the processes involved and minimise errors. It will take some time to fully implement the solutions across the whole-of-Government because we need to implement the automated process in more than 2,000 IT systems.

First, we are automating the review of privileged users’ activities. SNDGG has started a pilot with some agencies and the tool will be progressively deployed from January 2021. This will be fully implemented for high-priority systems by December 2022 and all remaining systems by December 2023.

Second, we are automating the management of account and user access rights. SNDGG has made available a solution which can alert agencies to staff movements and role changes so that they can manually remove the user accounts that are no longer required. Five of the 38 agencies that have onboarded this system were audited by AGO and no lapses pertaining to account and user access rights management were found.

SNDGG is in the midst of enhancing this solution, so that it can trigger automatic removal of unneeded user accounts and review of user access rights, once the staff movement or role change is updated in the HR records. This system will be implemented for 800 high-priority systems by December 2023 and all remaining systems by December 2024.

When officers are freed up from manual tasks, they are better able to focus on aspects of cyber-security and data protection that cannot be replicated by a machine. SNDGG has stepped up efforts to educate public officers on the importance of strong ICT governance and security controls, and to have the right habits and instincts. All public officers are required to undergo annual cyber and data security awareness training.

Next, on procurement and contract management, the recurrent lapses tend to be for more complex types of procurement – such as IT and construction, and in less straightforward cases, such as assessing price reasonableness for single bids and managing urgent contract variations. Navigating these complexities require not only technical skills but experience and judgment which require long-term efforts to build up.

To address this, we have been stepping up efforts in recent years to strengthen the competencies and capabilities of Public Officers in managing the procurement process. First, we are stepping up training of officers in key areas such as evaluation and approval of tenders. The training covers learning points from audit observations and good practices. Second, we will be providing additional guidance to approving authorities, which will be available from early next year. Third, since 2018, we have required all officers who are involved in procurement processes to complete a compulsory e-learning module. These are supplemented with regular refreshers and updates on new policies and practices.

In addition, we are also stepping up efforts to strengthen construction and IT procurement and contract management capabilities, which are more specialised areas requiring deeper technical know-how. The Building and Construction Authority or BCA is developing a competency framework to train public officers in managing construction contracts. MOF and BCA issued a good practice guide last year, containing practical advice on the management of variation orders and how to spot fraudulent quotes. To enhance governance, we will track agencies’ performance in contract management, based on a set of governance indicators. Similarly, GovTech is working on a competency framework for IT procurement and developing an e-learning module that will be ready next year.

To take these efforts forward further, MOF and the Civil Service College jointly established the Finance and Procurement Academy this year to better equip Public Officers with finance, procurement and contract management skills. The academy will work with technical agencies such as BCA and GovTech to not only conduct formal training, but also promote informal learning such as through practitioner sharing and mentorships. It will also support officers in continual learning to keep abreast of developments in finance, procurement and contract management policies and practices.

In the area of developing finance capabilities, finance officers today are required to attend induction courses that cover the fundamentals of Government financial procedures, including on governance and internal controls. These are reinforced and refreshed at milestone programmes, forums and sharing sessions throughout the officers’ career. Similar efforts are also undertaken to raise awareness of these concepts more widely across the Public Service. For example, they are incorporated into finance courses targeted at non-finance officers. MOF also conducts regular briefings to agencies’ senior management to emphasise the importance of public accountability.

In conclusion, let me say public officers are expected to be accountable for their actions and decisions, and this includes maintaining high standards of compliance with guidelines and procedures as they perform their duties. We place high expectations on the senior leadership of the Public Service, who are entrusted to be stewards of public resources. They must uphold strong governance and accountability in their organisations. These expectations are spelt out in the form of leadership competencies and responsibilities, which are conveyed to all senior Public Service leaders in Ministries and Statutory Boards. We evaluate our leaders against these expectations as part of their performance reviews and those who fall short will be rated less favourably. Depending on the nature and cause of the incident, appropriate disciplinary action may be taken as well.

So, finally, let me assure Members that public accountability remains a top priority for the Government. Where warranted, agencies mentioned in the Auditor-General’s report are conducting further investigation into the lapses. The senior leadership of the Public Service is accountable and committed to addressing the lapses identified, resolving the problem at the root and preventing future recurrence.

Mr Speaker : Order. End of Question Time. Clarification by Minister Josephine Teo.

1.31 pm

[Pursuant to Standing Order No 22(3), Written Answers to Question Nos 29-32, 41-60, 63-68, 70-84, 86-90, 92-106 and 108 on the Order Paper are reproduced in the Appendix. Question Nos 27-28, 33-40, 61-62, 69, 85, 91, and 107 have been postponed to the sitting of Parliament on 6 October 2020.]

この記録を引用

シンガポール AI 観測. 公共調達訓練とIT脆弱性への対応. 取得日 2026-08-20, https://sgai.md/ja/debates/oral-answer-2283/

同じテーマの続き