구두 답변 · 2026-04-08 · 국회 15
핵심 정보 기반시설 인원의 강제 정부 보안 심사
Workers' Party의 Gerald Giam이 디지털발전뉴스부에 주요 정보기반시설(CII) 접근 인원(외국인 기술 전문가 포함)을 대상으로 정부 차원의 강제적 중앙집중식 보안 심사 도입 여부를 질문했습니다. 이는 내부 위협과 국가급 사이버 공격에 대응하기 위함입니다. 장관 유방달은 다음 세 가지로 긍정적으로 응답했습니다: (1) 개인 프로필(국적/민족)을 바탕으로 누가 더 신뢰할 수 있는지 미리 설정해서는 안 됩니다. 그렇지 않으면 오히려 위험을 놓칩니다; (2) 보안 심사는 만능약이 아닙니다. 의도적인 nefarious actor는 알려진 심사 절차를 특별히 우회합니다; (3) 현재 「영 신뢰」 아키텍처와 「최소 권한」 원칙을 시행 중입니다——access control / 지속 검증 / 이상 모니터링의 다층 심층 방어가 핵심입니다. Giam이 공무원급(G50) 보안 심사를 CII super user / admin으로 확대할 수 있는지 추가로 질문했을 때, 장관은 다음과 같이 응답했습니다: 일부 시나리오에서는 이미 해당 조치가 마련되어 있지만, 보안상의 이유로 구체적인 요구사항을 공개하지 않습니다. 악의적 행위자의 역공학을 방지하기 위함입니다.
핵심 요점
- • WP calls for mandatory CII personnel security vetting
- • Minister: zero-trust + least-privileged access is the model
- • Profile-based trust assumptions rejected as a vulnerability
- • Specific vetting requirements kept confidential by design
심층 방어와 영 신뢰 아키텍처 유지, 단일 심사 의존에 반대
G50 공무원급 보안 심사를 CII super user / admin으로 확대할 것을 주장
CII 내부 위협 대응: 아키텍처 차원의 다층 방어가 인원 심사보다 우선
“Security by design means that you have all these multiple layers of defences in order to be able to guard against the cyber risk.”
참여자 (2)
영어 원문
SPRS Hansard · Fetched: 2026-05-03
18 Mr Gerald Giam Yean Song asked the Minister for Digital Development and Information (a) whether the Ministry will introduce mandatory, centralised government security vetting for personnel with access to Singapore’s critical information infrastructure to mitigate insider threats; and (b) if not, how the Ministry ensures that current employer-led vetting of personnel, including foreign nationals, in sensitive technical roles is sufficiently robust against sophisticated state-sponsored cyber threats. The Minister for Digital Development and Information (Mrs Josephine Teo) : Mr Speaker, insider threats are just one of a multitude of threats facing our critical information infrastructure (CIIs). Under the Cybersecurity Act, owners of CIIs are required to put in place access management controls and processes to monitor for anomalies and suspicious activities in these systems. Upon detection of any unauthorised activity, CII owners are required to investigate such anomalies. These controls mitigate potential insider threats or any other threats. The Government takes the cybersecurity of our CIIs very seriously.
We will continue to review the standards we require and consider further enhancements that could be effective. Mr Speaker : Mr Gerald Giam. Mr Gerald Giam Yean Song (Aljunied) : I thank the Minister for the reply. I am asking more in terms of dealing with the issue upstream, in terms of vetting personnel. And given that many technical experts in our telco and energy sectors are foreign nationals, what specific assistance does the Cyber Security Agency provide to private CII owners to verify the backgrounds of such individuals? And could the Ministry introduce a tiered vetting system, where personnel with super user or administrator access rights to our sensitive core areas of our CII must undergo Government-led G50 security clearance, just like public servants and vendors who access our Government systems? Mrs Josephine Teo : Mr Speaker, if we are serious about mitigating against insider threats, we should not assume that any particular profile of someone who is able to access the system is more or less likely to commit nefarious activities. This is the first point I want to put across.
You do not want to have a preconceived idea that this profile would necessarily be safer than another profile. If you want to be able to defend against as many insider threats as possible, you have to assume that every single person that has access to the system could pose an insider threat. Second, we also do not assume that security vetting is a silver bullet. If a nefarious actor is determined to infiltrate the system and they know that there is a vetting process of some sort, then clearly, it would be an effort on their part to overcome whatever it is that would stand in the way of them clearing a vetting system. So, a vetting system is also not a silver bullet. Thirdly, in cybersecurity, today we operate with the concept of zero trust, meaning that you decide in terms of how you architect the access controls, and you provide what is known as least privileged access, for every single one who has access to the system, you design the access controls in such a way that they only access what they are supposed to access in order to get the job done.
Then, you need to put in place a robust system so that you never trust, you always verify whether a user is accessing the part of the system that they should access. Then, you need the system to monitor, to look at suspicious behaviour, whether there was a user that attempted to go beyond the access privileges that were granted. And you are very careful about who you provide more access to. That is the approach that we take, rather than to think that just because we have done security vetting upstream, other controls are not as important; or since they have cleared vetting, then it is safe. We do not make that sort of assumption. Security by design means that you have all these multiple layers of defences in order to be able to guard against the cyber risk. Mr Speaker : Mr Gerald Giam. Mr Gerald Giam Yean Song : I thank the Minister for her reply. I agree that we should not assume any of these things and we should not assume that just because someone is security cleared, therefore they are safe to continue using the systems.
But in this age of cybersecurity threats and Advanced Persistent Threats (APTs), should we not consider that aligning the security clearance of our CII personnel, especially those with access to sensitive systems, with public servants? Because our all public servants have to go through this standard security vetting. Why not we extend that to CII personnel as well? Mrs Josephine Teo : Mr Speaker, I think I addressed the Member's question, which is that where it is useful and relevant to do so for certain types of cybersecurity accesses, yes, we do have measures in place to ensure that the persons accessing them fit the right conditions and we have no concerns. But we do not publicly reveal all the requirements that we put in place, and that is for obvious security reasons. Because if it was so plain, if you state it so clearly that there is this particular process and once you clear it, that is it. Then, that becomes the easiest thing to overcome. So, I take the Member's point. It is not the case that there is no vetting. It depends on what the activity is.