MDDI スピーチ · 2025-04-15
Tan Kiat How SMS による拡張されたサイバー・エッセンシャルズおよびサイバー・トラスト・マークのローンチでのオープニング・リマーク
要点
- • シンガポール・サイバーセキュリティー庁は、Cyber EssentialsおよびCyber Trustの認証マークを拡大し、クラウドセキュリティ、AIセキュリティ、および運用技術(OT)セキュリティのカバレッジを含めるようにしました。
- • クラウドセキュリティは、企業が「クラウド共有責任モデル」の下で保護措置を実装することが求められており、このモデルではクラウドサービスプロバイダーと企業の双方がそれぞれの責任を確保するようになっています。
- • 拡大されたCyber TrustおよびCyber Essentialsマークは、「シャドウAI」(IT部門の承認または監督なしに従業員によるAIツールの無認可使用)を含むAIセキュリティリスクに対応するようになっています。
- • 運用技術(OT)セキュリティは、Cyber EssentialsおよびCyber Trustに統合され、Industry 4.0および製造などのセクターにおけるITおよびOT環境の収束に対応するようになっています。
- • シンガポール政府は、機密政府データへのアクセス権を持つサイバーセキュリティベンダー(ペネトレーションテスト企業や監査企業など)が、政府契約の入札前にCyber Essentialsおよび/またはCyber Trust認証を取得することを義務付けるかどうかを評価しています。
- • 500以上の組織がCyber Essentials認証を取得しており、適格なSMEおよびCyber Security Agencyと契約するコンサルタントがCISO-as-a-Serviceサポートを提供するための政府資金が利用可能です。
全文翻訳
MDDI 英語原文の翻訳 · 翻訳日: 2026-07-04
2025年4月15日のサイバーエッセンシャルズおよびサイバートラスト・マークの拡張ローンチイベントでのデジタル開発・情報担当シニアミニスター Tan Kiat How による開会挨拶
著名なご来賓
皆様
こんにちは。本日、サイバースペースの保護とともに取り組める対策についての非常に重要なテーマのために、多くの皆様にお集まりいただき、大変嬉しく思います。
ご承知の通り、デジタル化は加速度を増しています。シンガポール企業は大企業も多くのSMEも含めて、デジタルトランスフォーメーションを推し進めています。大企業ではクラウドコンピューティングが主流になっており、中小企業(SME)の約3分の1がクラウドを利用しています。
人工知能(AI)は、企業が生産性を向上させたり、新しいビジネスモデルや製品のための新しい市場を創造したりするためにAIを採用している、エキサイティングなテクノロジー分野です。政府は、IMDAの GenAI サンドボックスおよびエンタープライズ向けの GenAI プレイブックを含む様々なイニシアティブを通じて、エンタープライズAI導入を支援しています。
新しいテクノロジーが企業をより生産的にする一方で、サイバー攻撃対象面も拡大させています。サイバー侵害と個人データ喪失の事例が増加しており、特にシンガポールのSMEに関わるものが増えています。
したがって、CSAがサイバーエッセンシャルズおよびサイバートラスト認証マークをクラウドセキュリティ、AIセキュリティ、および運用技術(OT)の対象を含むように更新することは時宜を得たものです。
サイバーエッセンシャルズはSMEを対象としています。より小規模な、またはデジタル化が進んでいない企業を対象に設計され、一般的なサイバーセキュリティ攻撃からの保護措置を提案しています。サイバートラストは、より大規模で、またはよりデジタル化された企業が、サイバーセキュリティ実装へのリスク・ベースアプローチを採用するのを支援します。
この更新により、サイバーエッセンシャルズおよびサイバートラストは、クラウドコンピューティング、AI、OTを導入している企業に対して、対象範囲と保護を提供します。主な更新内容を簡潔に説明させます。
まずクラウドコンピューティングについて、企業がクラウドコンピューティングを導入する際、サイバーセキュリティの責任はクラウドサービスプロバイダーと企業の間で共有されます。これは「クラウド共有責任モデル」と呼ばれています。
一方、クラウドサービスプロバイダーはデジタルインフラの重要なプロバイダーであり、強固なデジタルレジリエンスを備えていることを確保します。しかし他方では、企業も自らの役割を果たす必要があります。クラウドサービスプロバイダーに「任せる」ことではなく、企業もまたクラウド利用をセキュアにする必要があり、サイバーエッセンシャルズまたはサイバートラストのクラウドセキュリティコンテンツを参考にすることができます。
第二の領域、AIについて、企業がAIで実験および革新を行う際、AI利用に関連するリスクから身を守る必要があります。例には「シャドウAI」が含まれ、これはIT部門の承認または監視なしに従業員がAIツールを無許可で使用する場合、または情報の偶発的な漏洩および不適切な情報の出力を指しています。
世界経済フォーラム(WEF)の調査では、回答対象の組織の66%がAIがサイバーセキュリティに最も重大な影響を与えることを予想しています。AIユーザーを持つ企業は、サイバーエッセンシャルズおよびサイバートラストのAIセキュリティコンテンツを参照できるようになりました。
第三の領域、OTについて、インダストリー4.0の台頭に伴い、OT環境とIT環境の融合が起きています。これはシンガポール製造業などの主要産業に影響を及ぼしています。ITは情報の機密性、完全性、可用性に焦点を当てたデータ管理を優先する一方で、OTは産業環境における物理的プロセスと機器の実時間制御と安全性を優先しています。
IT環境をセキュアにするための実務は、投資サイクルが長く、レガシープロトコルと機器がまだ使用されている可能性があるOT環境では必ずしも実行可能ではありません。OT企業は、OT環境をセキュアにするために、サイバーエッセンシャルズおよびサイバートラストのOTセキュリティコンテンツを参照できるようになりました。IT環境とOT環境の両方をセキュアにするだけでなく、ますますIT境界とOT境界の交差点に目を向けています。より多くのグローバルシステムがより IT のようになり、より多くのシステムが自動化を促し、より多くの OT プロセスとプロトコルが使用されるようになるためです。CSAがこれらのエッセンシャルおよびトラストマークを更新するための措置を取り、クラウドコンピューティング、AI、OTを含めることになり、これらはすべてデジタル企業にとって非常に重要な領域です。大変嬉しく思います。
中国語で簡潔なご説明を申し上げたいと思います。
現在、中国語で重要内容を総括させていただきます。
新しいデジタルテクノロジーの使用は効率性を向上させることができますが、同時に攻撃面も拡大させます。サイバーセキュリティの脆弱性と個人データの漏洩事件が多く発生しており、特にシンガポールの中小企業に関わるものが増えています。
シンガポール・サイバーセキュリティ庁(CSA)が現在「ネットワークセキュリティ基本的能力標志」(Cyber Essentials)および「ネットワークセキュリティ信誉標志」(Cyber Trust)の認証範囲を拡張することは非常に時宜を得たもので、三つの大きな領域が新たに追加されます。
(一)クラウドセキュリティ
(二)人工知能セキュリティ
(三)運用技術セキュリティ。
政府はまた、国家レベルのネットワークセキュリティ標準を包括的に向上させることを計画しており、特に高リスク業界の機構を対象としています。ネットワークセキュリティ庁は評価を行っており、敏感データにアクセスする機構は、政府契約入札に参加する前に関連するネットワークセキュリティ認証を取得する必要があります。具体的な実装計画は、準備が完了した後、別途発表されます。
サイバーセキュリティの実装はSMEにとって課題になりうるというフィードバックを業界から受け取っています。SMEのサイバーセキュリティを簡素化するために、CSAはChief Information Security Officer【CISO as-a-Service】の役割を果たすサイバーセキュリティコンサルタントを活用しています。これらのコンサルタントは、SMEがサイバーエッセンシャルズマークに適合したサイバーセキュリティ衛生措置を実装するのを支援します。
適格なSMEに対して政府資金支援が利用可能です。500以上の組織がサイバーセキュリティの重要性に対応し、少なくともサイバーエッセンシャルズ認証を取得していることを見て、心強く感じています。
近年、サイバー脅威はより深刻になり、犯罪グループはますますオンラインで違法な利益を探すようになっています。基本的なサイバーセキュリティ標準を全国的に向上させ、より多くの組織、特に高リスク組織を保護するための、より体系的なアプローチが必要です。
本年度の省予算配分委員会討論で共有されたように、政府内の敏感データまたはシステムへのアクセスが許可される可能性のあるベンダー、特にそのようなベンダーに対して、より多くの対策が必要かどうかをCSAが評価しています。
このようなベンダーには、サイバーセキュリティペネトレーションテスティング企業およびサイバーセキュリティ監査人が含まれます。考えられる対策には、これらのベンダーとその下請業者が、ライセンスを取得するか政府が提供する契約に応札する前に、サイバーエッセンシャルズおよび/またはサイバートラストマークを取得することを要求することが含まれます。CSAは今後の方針について業界と協力する予定です。
サイバーエッセンシャルズおよびサイバートラストは、シンガポール企業のサイバーセキュリティ対応を向上させるために本来開発された国内マークです。
地域内の国からのご関心をいただいたことは喜ばしいことです。マレーシア、タイ、フィリピン、および中東の企業が認証を受けており、ブルネイの別の企業もこのプロセスを進めている可能性があることを理解しています。
企業のサイバーセキュリティ体勢の強化とデジタル経済の保護にとどまらず、シンガポールが知られている信頼と信頼性というブランドを基盤に、当社企業にとっての市場機会が存在します。
すべてのステークホルダーによる協力的な取り組みに期待しており、すべての企業と労働者に機会を提供する活気に満ちたデジタル経済を構築していきます。
ご清聴ありがとうございました。
英語原文
MDDI 公式サイト原文 · 取得日: 2026-07-04
Opening Remarks by Senior Minister of State for Digital Development and Information Tan Kiat How at the Launch Event for the Expanded Cyber Essentials and Cyber Trust Marks on 15 April 2025
Distinguished guests
Ladies and Gentlemen
Good afternoon. I am very glad to see many of you here today, for a very important topic about securing our cyberspace, and what steps we can take together.
As we all know, digitalisation is picking up pace. Enterprises in Singapore are pushing ahead with their digital transformation - large enterprises, and many SMEs as well. We see cloud computing become mainstream with large enterprises. About one-third of Small and Medium Enterprises (SMEs) are using cloud.
Artificial Intelligence (AI) is an exciting area of technology, where companies are adopting AI to improve productivity, create new business models or new markets for their products. The Government is supporting enterprise AI adoption through various initiatives, including the IMDA’s GenAI sandbox and the GenAI playbook for enterprises.
While such new technologies enable firms to be more productive, they also enlarge the cyber attack surface. We are seeing more cases of cyber breaches and loss of personal data, especially those involving SMEs in Singapore.
It is therefore timely for CSA to update the Cyber Essentials and Cyber Trust certification marks to include coverage of cloud security, AI security and Operational Technology, or OT.
Cyber Essentials is targeted towards SMEs. It is designed for smaller or less digital enterprises, proposing protection measures from common cybersecurity attacks. Cyber Trust helps larger or more digital enterprises to adopt a risk-based approach to implementing cybersecurity.
With the update, Cyber Essentials and Cyber Trust will provide coverage and protection for enterprises that are implementing cloud computing, AI and OT. Let me briefly outline the key updates.
First on cloud computing - when enterprises embrace cloud computing, the responsibility for cybersecurity is shared between the cloud service provider and the enterprise – this is referred to as the “cloud shared responsibility model”.
On one hand, cloud service providers are key providers of digital infrastructure, and we will ensure that they have robust digital resilience. But, on the other hand, enterprises also need to do their part. It is not a case of “leaving it” to the cloud service provider; the enterprise also needs to secure their cloud usage, and they can take reference from the cloud security content in Cyber Essentials or Cyber Trust.
The second area, AI - as enterprises experiment with and innovate with AI, we need to protect ourselves from the risks associated with the use of AI. Examples include “shadow AI”, which refers to the unsanctioned use of AI tools by employees without approval or oversight of the IT department, or accidental leakage of information, and the output of inappropriate information.
In a World Economic Forum (WEF) survey, 66% of organisations polled expect AI to have the most significant impact on cybersecurity. Enterprises that have AI users can now refer to the AI security content in Cyber Essentials and Cyber Trust.
The third area, OT - with the rise of Industry 4.0, we are seeing a convergence of the OT environment and the IT environment. This has an impact on key sectors in Singapore, such as manufacturing. While IT prioritises data management, focusing on the confidentiality, integrity and availability of information, OT prioritises real-time control and safety of physical processes and equipment in industrial settings.
The practices to secure an IT environment are not necessarily feasible in an OT environment, where the investment cycle is long, and legacy protocols and equipment may still be in use. OT enterprises can now refer to the OT security content in Cyber Essentials and Cyber Trust to secure their OT environment. We are not just looking at securing your IT environment and OT environment, but increasingly, at the nexus of the IT and OT boundaries, as more global systems become more IT-like, and more systems invite automation and more OT processes and protocols. I am very glad that CSA is taking these steps to update these Essential and Trust marks, to include computing, AI and OT – all very important areas for digital enterprises.
Let me make a few brief remarks in Mandarin.
现在,请允许我用华语总结关键内容:
虽然使用新兴数字技术可以提升效率,却也可扩大攻击面。我们看到了很多网安漏洞及个人数据泄露事件的发生,尤其涉及到新加坡的中小企业。
新加坡网安局(CSA)此时扩展 "网络安全 基本能力 标志"(Cyber Essentials)和 "网络安全 信誉 标志"(Cyber Trust)的认证范围 非常及时,新增三大领域:
(一)云 安全
(二)人工智能 安全
(三)运营技术 安全。
政府还在计划全面提升国家网络安全标准,特别是针对高风险的行业机构。网安局正在评估,要求接触敏感数据的机构必须取得相关网络安全认证才可以参与政府合同竞标。具体实施方案将在筹备完成后另外公报。
We have received industry feedback that implementing cybersecurity can be challenging for SMEs. To simplify cybersecurity for SMEs, CSA taps on cybersecurity consultants that play the role of their Chief Information Security Officer [(CISO) as-a-Service]. These consultants help SMEs to implement cyber hygiene measures aligned to the Cyber Essentials mark.
Government funding support is available for eligible SMEs. We are heartened to see more than 500 organisations acting on the importance of cybersecurity by attaining at least Cyber Essentials certification.
In recent years, cyber threats have become more severe, and criminal groups are increasingly going online to look for illicit gains. We need a more systematic approach to raise baseline cybersecurity standards nationally and protect more organisations, especially those of higher risk.
As shared at our Ministry’s Committee of Supply Debate this year, CSA is assessing if more measures are needed, particularly for vendors that may be given access to sensitive data or systems within Government.
Such vendors include cybersecurity penetration testing firms, and cybersecurity auditors. Possible measures include requiring these vendors and their subcontractors to obtain their Cyber Essentials and/or Cyber Trust marks before they can be licensed or bid for contracts offered by Government. CSA will be engaging the industry on the way ahead.
Cyber Essentials and Cyber Trust are domestic marks, originally developed to uplift the cybersecurity posture of enterprises in Singapore.
We are glad that there has been interest from countries in the region. We understand that there are enterprises in Malaysia, Thailand, Philippines and the Middle East, who have been certified, with possibly another firm in Brunei going through the process.
Beyond raising the cybersecurity posture of our enterprises and securing our digital economy, there are market opportunities for our firms, building on the brand of trust and reliability that Singapore is known for.
I look forward to the collective effort of all stakeholders in this effort as we build a vibrant digital economy that provides opportunities for all enterprises and our workers.
Thank you.