서면 답변 · 2026-04-07 · 국회 15
진화하는 위협에 대한 현행 사이버 보안 대비 태세의 적정성 평가와 작전 보안 확보
샤라엘 타하(Sharael Taha) 의원은 지정학적 긴장 고조와 하이브리드 분쟁 수단으로서의 사이버 작전 증가를 배경으로, 싱가포르의 사이버 위협 노출이 높아졌다고 정부가 평가하는지, 그리고 작전 보안을 해치지 않으면서 핵심 정보 인프라·정부 시스템·기업·개인을 AI 기반 공격을 포함한 진화하는 위협으로부터 보호할 대비 태세를 어떻게 평가하는지 서면 질의했다. 조세핀 테오(Josephine Teo) 디지털개발정보부 장관은 금융 허브이자 디지털 경제인 싱가포르가 고가치 표적이라고 인정하며, 핵심 시스템은 사이버보안법에 따라 더 높은 기준을 적용받고, 사이버보안청(CSA)이 기준을 갱신하고 핵심 시스템 운영자에게 전용 위협 탐지 시스템을 제공해 고급 위협 행위자와 AI 기반 위협에 대응하며, GovTech는 핵심 시스템을 관리하는 정부 벤더에 Cyber Trust Mark 요건을 부과하고, 가정용 라우터 의무 기준을 사이버 라벨링 제도 1등급에서 2등급으로 상향하며 IP 카메라에도 유사 기준 도입을 검토한다고 답했다. 정부는 최선의 방어에도 AI 사이버 위협에 대한 경계가 필요하다고 인정했다.
핵심 요점
- • 핵심 시스템 운영자에게 AI 위협 대응용 전용 위협 탐지 시스템 제공
- • 핵심 시스템을 관리하는 정부 벤더에 Cyber Trust Mark 요건 의무화
- • 가정용 라우터 의무 기준을 사이버 라벨링 1등급에서 2등급으로 상향, IP 카메라 확대 검토
- • CSA의 CISO-as-a-Service가 중소기업에 사이버 보안 컨설턴트 지원
정부는 싱가포르가 견고하고 적응력 있는 사이버 보안 태세를 유지하고 있다고 보면서도, AI 기반 공격을 포함한 진화하는 위협에 맞서 기준·탐지 역량·벤더 의무를 지속적으로 강화해야 한다고 인정한다.
AI 기반 공격이 싱가포르 국가 사이버 방어의 위협 모델에 공식 편입되었으며, 규제 중심이 핵심 인프라에서 정부 공급망과 소비자 기기로 단계적으로 확장되고 있다.
“그러나 최선의 방어를 갖추더라도 AI 기반 사이버 위협을 포함한 진화하는 위협에 대해 경계심을 늦추지 말아야 한다.”
참여자 (2)
전문 번역(한국어)
Hansard 원문 · 2026-06-09
18번, Sharael Taha 의원이 디지털발전정보부장관에게 제출한 질문: 지정학적 긴장이 증가하고 사이버 행동이 하이브리드 분쟁의 도구로 점점 더 활용되고 있는 상황 속에서, (a) 정부가 싱가포르의 사이버 위협 노출이 악화되었다고 평가하는지, (b) 정부가 운영 보안을 손상시키지 않으면서 싱가포르의 핵심 정보 인프라, 정부 시스템, 기업 및 개인 주민들을 진화하는 위협(인공지능 기반 공격 포함)으로부터 보호하는 측면에서의 현재 전반적 사이버보안 준비 수준을 어떻게 평가하는지에 관하여
Josephine Teo 부인: 싱가포르는 주요 금융 중심지이자 디지털 경제체라는 지위로 인해 악의적 행위자들의 매력적인 목표가 되었습니다. 싱가포르 사이버보안청(CSA)은 SingCERT 공지 및 「싱가포르 사이버 경관」출판물 등의 방식으로 정기적으로 사이버보안 위협에 관해 공중에 알리고 있습니다.
다년간 정부는 우리의 사이버 방어를 강화하기 위한 조치들을 취해왔습니다.
핵심 시스템은 「사이버보안법」에 따라 더 높은 사이버보안 표준과 의무를 충족해야 합니다. 우리는 또한 역량 개발 측면에서 상당한 투자를 진행해왔습니다. CSA 사이버보안 발전 프로그램과 같은 이니셔티브들은 우리의 인재 저수지를 강화하는 데 도움이 되고 있으며, 사이버 스타 연습(Cyber Star Exercise) 같은 국가 훈련들은 공공 및 민간 부문 사이버 방어 인력의 운영 준비 수준을 높이는 데 도움이 되고 있습니다.
위협이 진화함에 따라 우리의 대응도 반드시 함께 진화해야 합니다. CSA는 보안 관제를 강화하기 위해 우리의 사이버보안 표준과 의무를 검토하고 업데이트할 것입니다. 정부는 또한 핵심 시스템 소유자들이 고급 위협 행위자들 및 인공지능 기반 위협을 포함하여 위협을 더욱 잘 탐지할 수 있도록 지원할 것입니다. 여기에는 그들에게 전용 위협 탐지 시스템을 갖춤이 포함됩니다. 우리는 또한 산업계와 협력하여 우리의 사이버 방어 인력의 역량을 심화시킬 것이며, 이를 통해 그들은 싱가포르를 더욱 잘 보호할 수 있게 될 것입니다.
정부 시스템의 경우, GovTech는 민감한 데이터를 보유하고 중요한 정부 서비스를 제공하는 시스템을 보호하기 위한 기존의 내부 지침을 가지고 있습니다. 향후 GovTech는 정부 공급자들에게 더욱 엄격한 사이버보안 및 데이터 보호 의무를 도입할 것이며, 예를 들어 핵심 시스템 및 민감한 정부 데이터를 관리하는 정부 공급자들이 사이버트러스트마크 요구사항을 충족하도록 요구할 것입니다.
기업의 경우, CSA는 조직들이 방어를 강화할 수 있도록 지원하기 위해 다양한 이니셔티브를 추진했습니다. 예를 들어, CSA의 Chief Information Security Officer as a Service 프로그램은 중소기업들에게 사이버보안 자문가들과 협력할 수 있는 경로를 제공했으며, 이들 자문가들은 그들과 협력하여 사이버 위생을 개선할 수 있습니다.
정부는 또한 국민들을 악의적 행위자들의 피해로부터 보호하기 위한 조치들을 취했습니다. 예를 들어, 게이트웨이 기기(즉, 가정용 라우터)에 대해 강제적 사이버보안 요구사항을 도입했습니다. 가정용 라우터는 현재 사이버보안 표시 제도 1급 형태의 최소 사이버보안 요구사항을 충족해야 합니다. 이 요구사항은 더 높은 표준(즉, 사이버보안 표시 제도 2급)으로 상향될 것입니다. 우리는 또한 IP 카메라에 유사한 표준을 도입하는 것을 탐색할 것입니다. 이러한 조치들은 디지털 제품들이 침해되기 더욱 어렵게 만들 것입니다.
요약하면, 싱가포르는 강력하고도 적응력 있는 사이버보안 태세를 유지하고 있습니다. 그러나 최고의 방어를 갖추고 있더라도, 우리는 인공지능 기반 사이버 위협을 포함하여 계속 진화하는 위협에 대해 경계심 있고 신중해야 합니다. 정부는 싱가포르 국민들이 사이버 공간에서 계속해서 양호한 보호를 받을 수 있도록 우리의 정책과 이니셔티브를 지속적으로 검토할 것입니다.
영어 원문
SPRS Hansard 원본 기록 · 수집일: 2026-06-09
18 Mr Sharael Taha asked the Minister for Digital Development and Information in light of rising geopolitical tensions and the increasing use of cyber operations as part of hybrid conflict (a) whether the Government assesses that Singapore's cyber threat exposure has heightened; and (b) how the Government assesses Singapore's current overall cybersecurity readiness in safeguarding critical information infrastructure, Government systems, businesses and individual residents against evolving threats, including AI-enabled attacks, without compromising operational security.
Mrs Josephine Teo : Singapore's position as a major financial hub and digital economy makes us an attractive target for malicious actors. The Cyber Security Agency of Singapore (CSA) regularly updates the public on cybersecurity threats, such as through SingCERT advisories and the Singapore Cyber Landscape publication.
Over the years, the Government has taken steps to strengthen our cyber defenses.
Critical systems are held to higher cybersecurity standards and obligations under the Cybersecurity Act. We have also invested heavily in capability development. Initiatives like CSA's Cybersecurity Development Programme have helped to strengthen our talent pipeline while national exercises, such as Exercise Cyber Star, help enhance the operational readiness of cyber defenders across both public and private sectors.
As the threat evolves, so must our response. CSA will be reviewing and updating our cybersecurity standards and obligations to strengthen security controls. The Government will also be helping owners of critical systems better detect threats, including those from advanced threat actors and AI-enabled threats. This includes equipping them with proprietary threat detection systems. We will also partner the industry to deepen the capabilities of our cyber defenders so they can better protect Singapore.
For Government systems, GovTech has existing internal guidelines to safeguard systems that hold sensitive data and provide important Government services. Moving forward, GovTech will be introducing more stringent cybersecurity and data protection obligations for Government vendors, such as requiring Government vendors that manage critical systems and sensitive Government data to meet Cyber Trust Mark requirements.
For businesses, CSA has rolled out various initiatives to assist organisations in raising their defenses. For example, CSA's CISO-as-a-Service programme provides small and medium enterprises with access to cybersecurity consultants who can work with them to raise their cyber hygiene.
The Government has also put in place measures to protect our citizens against malicious actors, such as by introducing mandatory cybersecurity requirements for gateway devices (i.e., home routers). Home routers are currently required to meet minimum cybersecurity requirements in the form of the Cyber Labelling Scheme Level 1. This requirement will be raised to a higher standard (i.e., Cyber Labelling Scheme Level 2). We will also explore introducing similar standards for IP cameras. These will make digital products harder to compromise.
In summary, Singapore maintains a robust and adaptive cybersecurity posture. However, even with the best of defenses, we must remain vigilant and alert to evolving threats including AI-enabled cyber threats. The Government will continue to review our policies and initiatives to ensure that Singaporeans remain well protected in cyberspace.