← LEADERSHIP TERMINAL

PARLIAMENT OF SINGAPORE · FORMER

S Iswaran

Singapore

IN THEIR OWN WORDS

The Maritime and Port Authority of Singapore (MPA) has incorporated the requirements of the International Maritime Organization (IMO) 2020 regulation in its Prevention of Pollution of the Sea (Air) Regulations 2022. The Regulations are applicable to Singapore-registered ships and all other ships while they are in Singapore waters.

SINGAPORE'S ADOPTION OF IMO 2020 REGULATION - 2023-07-05 · READ THE OFFICIAL RECORD

The Maritime and Port Authority of Singapore (MPA) plans to progressively roll out the charging infrastructure for electric harbour craft operations in the Port of Singapore from 2025.

INSTALLATION OF ELECTRIC-CHARGING STATIONS FOR USE BY HARBOUR LAUNCHES AND HARBOUR CRAFT - 2023-07-04 · READ THE OFFICIAL RECORD

Since 2018, the Land Transport Authority (LTA) has imposed minimum bicycle parking provisions covering different types of developments. The requirements are determined by multiple factors, including the developments’ use, location and gross floor area (GFA).

PROVISION OF REQUIRED BICYCLE PARKING BY DEVELOPERS - 2023-07-04 · READ THE OFFICIAL RECORD

I had addressed similar Parliamentary Questions by Mr Gerald Giam on 29 November 2022 and 10 January 2023, as well as in my Ministerial Statement on 8 May 2023. The Member can refer to these past answers and statement as there has been no material change in the allocation of Certificates of Entitlement.

HOUSEHOLD OWNERSHIP OF CARS FROM ALLOCATION OF COES - 2023-07-04 · READ THE OFFICIAL RECORD

To encourage the uptake of electric cars, the Government has rolled out the Electric Vehicle Early Adoption Incentive and enhanced Vehicular Emissions Scheme. When taken together, it provides up to $45,000 off the Additional Registration Fee of an electric car upon registration.

ASSISTANCE TO PARALLEL IMPORTERS TO PROMOTE SALES OF ELECTRIC VEHICLES - 2023-07-04 · READ THE OFFICIAL RECORD

The Land Transport Authority studies all potential changes to the Certificate of Entitlement (COE) system carefully, including conducting sensitivity analysis where appropriate.

STUDY TO ASSESS IMPACT OF STABLE COE SUPPLY ON COE PRICES - 2023-07-04 · READ THE OFFICIAL RECORD

The complete record

Every one of 2,300 lines we hold for S Iswaran, in date order, each linked to its source. Free to read, in full, without an account. Page 20 of 46.

  1. A reliable and resilient telecommunication network is critical to our Smart Nation ambitions. That is why the Ministry of Communications and Information (MCI) and the Infocommunications Media Development Authority (IMDA) work with key telecommunication operators to ensure good service quality, including through IMDA's Quality of Service frameworks. Since 2016, the number of telecommunication outages has averaged 10 outages each year. These outages were mostly due to cable cuts by contractors, or faults in the telecommunication networks. MCI and IMDA have taken measures to minimise the risk of outages. IMDA requires key telecommunication operators to regularly audit their networks to ensure that they are on par with international best practices. IMDA also educates contractors to avoid cable cuts when carrying out earthworks. IMDA also penalises telecommunication operators which contribute to outages, or which fail to restore disrupted services quickly.

    TELECOMMUNICATION OUTAGES IN PAST THREE YEARS - 2018-11-20 · READ THE OFFICIAL RECORD

  2. All Singaporean Housing and Development Board (HDB) households who do not subscribe to Pay TV are eligible for the Digital TV Starter Kit (DSK). Singaporean HDB households who terminate their Pay TV subscriptions before analogue signals are switched off on 1 January 2019 are similarly eligible for the DSK. Singaporean households in private estates with financial difficulties can appeal to the Info-communications Media Development Authority (IMDA) for the DSK. The managing agents for public areas, such as senior citizen corners at void decks, can purchase the necessary Digital TV equipment from major retailers and Mediacorp's partners.

    REPLACEMENT OF ANALOGUE TV SIGNAL SYSTEMS WITH DIGITAL TV STARTER KIT AND EXTENSION OF ITS REDEMPTION PROGRAMME - 2018-11-19 · READ THE OFFICIAL RECORD

  3. Currently, some websites and online platforms track their users' behaviour by collecting data on their browsing habits and activities and use the data to serve targeted advertisements or improve browsing experiences. Organisations should ensure that their collection, use and disclosure of users' behavioural data comply with the Personal Data Protection Act 2012 (PDPA). In the event of a complaint, the Personal Data Protection Commission (PDPC) will investigate and take enforcement action if it assesses that there is a breach of the PDPA. As Singapore's Digital Economy develops, we envisage that businesses will increasingly leverage such data to offer better, more innovative products and services that are tailored to their users’ preferences. At the same time, we recognise public concerns over the widespread collection of personal data by online platforms, and the potential misuse of such data. There are tools and mechanisms already available today that provide a balanced and effective approach to prevent the unwanted tracking of individuals. For example, individuals who are concerned with tracking may block and delete cookies, or use plugins and browser extensions to prevent websites from profiling them. They may also request not to be tracked when browsing a website. Most modern browsers come with such functionalities. The Media Literacy Council also provides tips on basic ways in which users can guard against online tracking. The Ministry of Communications and Information and PDPC will continue to monitor developments on this issue and ensure that our policies continue to safeguard individuals' interests while allowing data-driven innovation in the Digital Economy.

    REGULATION ON COLLATION AND USE OF BEHAVIOURAL DATA AND PATTERNS BY ONLINE PLATFORMS - 2018-10-02 · READ THE OFFICIAL RECORD

  4. PDPC will review each complaint and take appropriate actions, such as directing non-complying organisations to dispose of the data and imposing financial penalties.

    INITIATIVES TO ENSURE COMPLIANCE WITH ADVISORY GUIDELINES FOR NRIC AND OTHER IDENTIFICATION NUMBERS - 2018-10-01 · READ THE OFFICIAL RECORD

  5. The Personal Data Protection Commission (PDPC), recently updated its Advisory Guidelines on the collection, use and disclosure of National Registration Identity Card and other national identification numbers. In summary, the Guidelines set out that organisations are allowed to do so only if it is required by the law, or if it is necessary to accurately establish or verify an individual's identity to a high degree of fidelity. PDPC, together with the Infocomm Media Development Authority (IMDA), is adopting a two-pronged approach to help organisations align their practices with the Guidelines. Firstly, PDPC is increasing awareness among organisations of the Guidelines through its outreach activities. For example, PDPC has briefed trade associations on the Guidelines. PDPC will also be carrying out additional briefings and producing collaterals for distribution to companies. Secondly, PDPC and IMDA are providing organisations with technical support to make the transition. These include a technical guide on alternatives to NRIC numbers for websites and public facing computer systems; a template to notify customers of the organisation's efforts and timeframe to comply with the Guidelines; and pre-approved solutions that organisations can adopt, such as visitor management and customer management systems. Organisations can reach out to PDPC or PDPC's panel of Data Protection Advisors for assistance. To allow organisations adequate time to review and refine their existing business practices and processes to comply with the Guidelines, they will take effect on 1 September 2019. Thereafter, individuals who encounter non-compliance can lodge a complaint with PDPC.

    INITIATIVES TO ENSURE COMPLIANCE WITH ADVISORY GUIDELINES FOR NRIC AND OTHER IDENTIFICATION NUMBERS - 2018-10-01 · READ THE OFFICIAL RECORD

  6. Premium Rate Services (PRS) are value-added services delivered over mobile telecommunication networks, and include third-party services provided to mobile customers. In 2017, the Infocommunications Media Development Authority (IMDA) received 91 PRS-related complaints. These complainants generally claimed that they were charged for PRS that they did not subscribe to. IMDA's investigations revealed that these end users had actually subscribed to the PRS without reading the terms and conditions carefully. IMDA has implemented several measures to protect consumers against accidentally subscribing to PRS. Currently, the Code of Practice for the Provision of Premium Rate Service (PRS Code) requires service providers to publish the terms and conditions of their services clearly and confirm end-users' purchases before activating the PRS. Since 2012, IMDA has required mobile operators to offer a PRS barring service for free. Consumers who activate this service will not receive or be billed for any chargeable PRS. Since the PRS barring service was introduced, the number of PRS-related complaints has dropped by approximately 80% from 483 complaints in 2012 to 91 complaints in 2017. IMDA has also stepped up our consumer education efforts, including giving talks at events targeting seniors, distributing brochures and uploading educational videos on YouTube. Where consumers, including seniors, have accidentally subscribed to PRS, IMDA will also step in to engage the service provider. In several cases, the service provider has waived the subscription charges incurred on a goodwill basis, and the mobile operator has thereafter activated its PRS barring service. Nevertheless, we urge consumers to also ensure that they fully understand the terms and conditions before activating any PRS.

    COMPLAINTS FROM MOBILE CUSTOMERS ABOUT BEING SUBSCRIBED TO THIRD-PARTY SERVICES WITHOUT THEIR CONSENT - 2018-09-10 · READ THE OFFICIAL RECORD

  7. Today, about four in five1 Singaporean households are receiving digital television (DTV) either over the air or through their Pay TV subscription. The Infocomm Media Development Authority (IMDA) is reaching out to the remaining households to get them DTV-ready before analogue TV signals are switched off on 31 December 2018. In April this year, IMDA launched the DTV Starter Kit to encourage more households to be DTV-ready. The DTV Starter Kit allows Singaporean Housing and Development Board (HDB) households without a Pay TV subscription to redeem an indoor DTV antenna and digital set-top box with free installation, or enjoy $100 off selected DTV equipment at participating electronics stores. As of 31 August 2018, more than 207,000 households have redeemed their DTV Starter Kits. I encourage all households which have not yet redeemed their DTV Starter Kits to do so right away. IMDA has also been working closely with community partners like the People's Association, the Silver Generation Office and voluntary welfare organisations to help households become DTV-ready. This includes organising roadshows in every town, deploying service counters in high-traffic areas, such as markets, hawker centres and community clubs, and conducting briefings at community events. Since June, Mediacorp has also run on-screen crawlers to inform those who are still viewing analogue channels to switch to DTV. Mediacorp will soon reduce the size of the screen area displaying content on analogue channels, which, we hope, will remind viewers to switch over to DTV early.

    UPDATE ON PROGRESS OF CONVERSION TO DIGITAL TV - 2018-09-10 · READ THE OFFICIAL RECORD

  8. All Public Service staff and contractors dealing with Government cybersecurity matters who require access to classified Government information, must undergo security screening by the authorities. Similarly, organisations in the Critical Information Infrastructure (CII) sectors, such as Banking and Finance as well as Land Transport, are required by their respective sectoral regulators to screen all staff and contractors with access to key infrastructure, such as information technology systems. Such measures go some way towards mitigating the "insider" risk, though they are not foolproof. The Cyber Security Agency (CSA) will also license organisations offering penetration testing and managed security operations centre monitoring services as well as individuals directly engaged for such services, to ensure they meet certain criteria, including that their key executive officers are fit and proper persons. Under the Cybersecurity Code of Practice issued by CSA, all CII owners must calibrate a vendor’s access to their CII, based on their organisations’ business needs and cybersecurity risk profile.

    APPROPRIATE SECURITY ASSESSMENT MEASURES IN PLACE FOR SCREENING OF CYBERSECURITY STAFF AND CONTRACTORS - 2018-09-10 · READ THE OFFICIAL RECORD

  9. In addition, the Library Consultative Panel (LCP), comprising citizens from a wide cross-section of our society, was established in 2015 to provide diverse community perspectives and recommendations to NLB on books which are being reviewed due to content concerns raised by members of the public.

    COMPLAINTS OVER LIBRARY BOOKS WITH HOMOSEXUAL CONTENT - 2018-09-10 · READ THE OFFICIAL RECORD

  10. Mr Speaker, Sir, since 2014, the National Library Board (NLB) has received 11 complaints from members of the public over titles with homosexual content. Eight of these titles were moved to sections for older readers, while three were assessed to be suitable to remain in the original collection for children and young adults. The NLB also received feedback on 23 titles due to race, religion and other topics. Of these, seven were moved to sections for older readers, and eight were retained in their original collection. A series of eight Malay children’s titles – Agama, Tamadun Dan Arkeologi (Religion, Civilisation and Archeology) – were withdrawn in June last year, due to controversial religious content. NLB brings in an average of 86,000 new titles for the 26 public libraries each year to ensure that library collections remain updated and relevant for Singaporeans of all ages. Titles are selected based on a collection policy which aims to provide age-appropriate and diverse reading material. The collection policy also takes reference from the Infocomm Media Development Authority's (IMDA's) general Content Guidelines for Imported Publications. The broad guidelines of the collection policy and selection criteria are available on NLB's website. NLB seeks to balance the need for a wide-ranging library collection with sensitivity towards our community norms. Beyond its team of book selectors, NLB also relies on pre-publication information from publishers and vendors, and reviews from library journals. In some instances, review copies are requested so that NLB can assess these books in greater detail.

    COMPLAINTS OVER LIBRARY BOOKS WITH HOMOSEXUAL CONTENT - 2018-09-10 · READ THE OFFICIAL RECORD

  11. The original Digital Television (DTV) Assistance Scheme, launched in September 2014, was aimed at helping low-income households transit from analogue free-to-air (FTA) TV to DTV, by providing and installing DTV equipment for them for free. In April 2018, the Government expanded the DTV Assistance Scheme to help more Singaporean households move to DTV before analogue FTA TV ceases on 31 December 2018. The expanded scheme is known as the DTV Starter Kit. It allows all Singaporean Housing and Development Board (HDB) households without a Pay TV subscription to redeem either DTV equipment with free installation, or a $100 voucher to offset the cost of purchasing selected DTV equipment. Singaporean households that have switched over to DTV on their own are not disadvantaged in any way because they can still enjoy the DTV Starter Kit by redeeming the DTV equipment for their TV sets, including as backup, or for their secondary TV sets, if any, as long as they meet the eligibility criteria as stated above. Ultimately, our objective is to assist as many Singaporean households as possible to continue to enjoy FTA TV after 31 December 2018.

    PROVISION OF FREE DIGITAL TV STARTER KITS - 2018-08-06 · READ THE OFFICIAL RECORD

  12. I thank the Members for their questions. I have addressed them in my Ministerial Statement at the 6 August 2018 Parliament Sitting. [Please refer to ​"Cyberattack on SingHealth's IT System", Official Report, 6 August 2018, Vol 94, Issue 81, Ministerial Statements section.]

    SAFEGUARDING RECORDS AND PERSONAL PARTICULARS AGAINST CYBERATTACKS - 2018-08-06 · READ THE OFFICIAL RECORD

  13. PDPC is making Singapore a training hub for data protection professionals in the region by anchoring data protection-related events here, such as the annual Personal Data Protection Seminar hosted by PDPC. PDPC is also encouraging the formation of more communities of practice, such as AsiaDPO and the Law Society's Cybersecurity and Data Protection Committee. While we continue to grow and deepen the pool of DPOs, organisations must also do their part by appointing and supporting their DPOs. By doing so, organisations will not just comply with the PDPA but, more importantly, build consumer trust in their ability to use and safeguard personal data responsibly.

    PROJECTED NUMBER OF DATA PROTECTION OFFICERS NEEDED - 2018-08-06 · READ THE OFFICIAL RECORD

  14. It is mandatory under the Personal Data Protection Act (PDPA), for all private-sector organisations to designate one or more individuals as a Data Protection Officer (DPO). The DPO is responsible for ensuring that the organisation complies with the PDPA. According to a 2018 survey commissioned by the Personal Data Protection Commission (PDPC), close to 60% of private sector organisations in Singapore have appointed at least one DPO. This represents a six percentage point increase from the previous year. PDPC is studying this issue closely, with a view to increasing both the numbers and capabilities of DPOs. There are two parts to my Ministry and PDPC's plan to train and deploy more DPOs. Firstly, we are developing and supporting training programmes for DPOs. For example, since 2014, PDPC has developed an e-learning programme for DPOs to learn about the fundamentals of the PDPA. PDPC is supplementing this by rolling out more advanced training programmes to enhance DPOs' skills. These include the Professional Conversion Programme for DPOs, which started last month, and the Practitioner Certificate for Personal Data Protection Preparatory Course, which starts in October this year. In addition, PDPC has supported the development of personal data protection-related courses to be taught at the National University of Singapore and Singapore Management University starting this academic year, through which graduates can attain professional, internationally recognised certification. The second part of our strategy is to foster a collaborative environment where DPOs can learn best practices.

    PROJECTED NUMBER OF DATA PROTECTION OFFICERS NEEDED - 2018-08-06 · READ THE OFFICIAL RECORD

  15. Let me say this. First of all, I think we should not create the impression that we are helpless or that we are at the mercy of these potential perpetrators. If that was the case, then why have this strong robust response? Because we have conviction that we can deter, and we have the capability. And where we do not, we will build it, and we will find ways to strengthen our systems so that we can resist such attacks. And as far as this effort is concerned, it is also important that even as we do this, it is important that, psychologically, not just this House, but Singaporeans at large, understand that it cannot be foolproof. And so, we must have that resilience that when it happens, we will pick ourselves up again and we will learn from it, grow stronger and we will carry on. I think that is the most important aspect of the way we can deter such attacks.

    CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2018-08-06 · READ THE OFFICIAL RECORD

  16. I thank the Member for the questions. First, have other countries been victims of cyberattacks? In my Statement, I highlighted a couple, both of which are in the context of the US. But there have also been other incidents in Europe. And I think many of these may not even be reported in the public domain, but we know that they are occurring. So, the truth of the matter is that this is a universal challenge; we are not an exception. In fact, every country is facing this challenge and the greater their connectivity and the use of digital technologies, the greater their challenge as well. So, that is an important point that all of us need to understand and appreciate. The second point is on the contemporaneous Police investigation. So, the COI is doing its work. It will be aided by CSA, which leads a team of investigators, and they will also have the AGC leading evidence. The Police report was lodged because there was suspicion of a crime being committed. And so, the Police will investigate this incident in that context. But the Police will also take reference from any deliberations that take place in the COI. And I would add that there is a third stream, because there was also a report lodged with the Personal Data Protection Commission. And they, too, are conducting their own investigations. And again, they too, will take reference from what is being conducted within the COI hearing process as well.

    CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2018-08-06 · READ THE OFFICIAL RECORD

  17. I understand where the Member is coming from. Let me say this: we are aware of the range of possible ways to harness talent, and we have to use them in a judicious way in order to ensure that we have our fair share of the talent that is needed for the kind of challenges that we face.

    CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2018-08-06 · READ THE OFFICIAL RECORD

  18. The answer is certainly yes. In fact, that is the objective of the exercise. We want to make sure that whatever the findings are, we are able to extract the lessons and recommendations which can then be used not just within the public sector or within the CII sectors but for other private sector operators because there is a general concern about security. But the qualifier I will make is that what we can share is constrained by the considerations I had pointed out earlier. Secondly, it is also about having a risk-adjusted approach because, in certain types of companies and certain types of operations, their risk profiles are different and are at a lesser level and, therefore, they may not need to do everything. But they do need to take up certain basic measures for cybersecurity purposes. So, it has been a differentiated approach. But the larger point about drawing lessons which can then be shared, this is something that we certainly intend to do.

    CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2018-08-06 · READ THE OFFICIAL RECORD

  19. I thank the Member for the question. I think our existing legislative framework provides us with sufficient scope, because if you can demonstrate and prove a criminal act, then you can take action under the Penal Code or appropriate legislation. If we can find a specific actor or individual who has posed a threat to our national security, then we also have legislation that allows us to take action against such individuals. So, the legislative levers are adequate. But this is a domain where the nature of the crime and specific attribution can be quite challenging at times.

    CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2018-08-06 · READ THE OFFICIAL RECORD

  20. And where they have got some accounts, it is well worth using this opportunity to look at resetting passwords.

    CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2018-08-06 · READ THE OFFICIAL RECORD

  21. Mr Speaker, I thank the Member for her question which I think is a genuine true reflection of some of the concerns on the ground. That is why, in my Statement, I try to explain why Singaporeans in general and elderly residents, in particular, can draw some comfort from the fact that transactions that involve banks, financial institutions and those involved in sensitive Government e-transactions all have 2FAs. So, it is not just about the ID, although in some cases, and I think, in many cases, the IC number is used as the ID. And this might be an opportunity for us to review that and see whether we can use other IDs which are more robust. And then, in addition to ID, you need the password as well as the one-time password. So, what we can explain to our residents in general is that the system that is in place is a secure one. But what might be prudent for them to do is, where they have got accounts, where they have already set them up and they have used their IC number particularly as an ID, or in some cases, people even use their NRIC as the password, they should reset and ensure that they have thoroughly reviewed this kind of exposure. On the point the Member made about alerting them to any other kind of activity which can have financial implications, typically, in all of these transactions, you would have to not just put in your IC number or name. If you are going to, for example, buy something online, you need either credit card data or some other kind of financial information. That information has not been taken in this instance and, therefore, that link is broken. Hence, the consumers and the general residents can be comforted by that. But we should not get complacent and we should review this.

    CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2018-08-06 · READ THE OFFICIAL RECORD

  22. Mr Speaker, let me state it for the third time for the Member's reference. The attack fits the profile of certain known APT groups, but, for national security reasons, we will not be making any specific public attribution. The Member asked whether we are prepared to share the names, if we know specifically who, and whether we are able to then share that. I would put to the Member that, first, I have explained why we have a larger set of concerns around this matter. Secondly, in this sort of matter, whilst one can have a high level of technical confidence, one may not be able to have the certainty that you might need in order to specifically assign responsibility. And this is the kind of evidentiary threshold that may not stand up in a Court of law but, at the operational level, the agencies that are involved have a high level of confidence in their findings. Having said that, we do not think it serves our national interest, nor is it a productive exercise for us to be making specific public attribution. What is essential is that we diagnose the problem clearly and take the appropriate steps. And if, in the process of the COI deliberations, specific attribution can be made in a manner where action can subsequently be taken up in a Court of law, we will certainly consider that course of action.

    CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2018-08-06 · READ THE OFFICIAL RECORD

  23. We have various platforms to do that in because there are, generally, various education sessions that Government agencies conduct to heighten awareness of cybersecurity and the measures that can be taken. We also have the frameworks of the Personal Data Protection Act and the Personal Data Protection Commission which are actively involved not just in following up on complaints or reports of personal data breaches but also in terms of raising awareness and education and sharing best practices, so that the general private sector can also continue to harden itself against cyberattacks.

    CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2018-08-06 · READ THE OFFICIAL RECORD

  24. I thank the Member for the clarification. First, we have to be clear. The COI's Terms of Reference have been scoped to focus on this incident because if we scope it too wide, then you will lose the value of setting up such a Committee, which is really to go deep, understand what the issues were and then to come up with valuable insights and recommendations which we can apply across the public sector and, specifically, in the healthcare system. The Member then asked whether there are issues around databases and IT systems that reside outside the public sector. Sir, I want to bring Members back to the point I made earlier, which is that the CSA will be designating computer systems in 11 sectors as CIIs. Some of these sectors the Member highlighted are banking, telecommunications. There are others like energy, water and so on. And each of these sectors has computer systems that may be within the public sector or in the private sector, but by virtue of the functions they perform, the databases they hold, they are deemed to be CIIs and, therefore, they will be designated and governed as such by CSA, by the rules and provisions under the Cyber Security Act. And that is where, as I mentioned in my earlier Statement, CSA will ensure that there are certain minimum requirements that are implemented. But beyond that, there may also be certain advisory guidelines on what else they can do to further strengthen cybersecurity. But ultimately, the regulators and owners of those CIIs will have to make the judgement call and be accountable for the uninterrupted essential services they provide. On the point of the private sector, what we learned from this incident will be shared.

    CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2018-08-06 · READ THE OFFICIAL RECORD

  25. Mr Speaker, the COI has been asked, as elaborated in the Terms of Reference, to study what were the factors that led to the incident and how were the relevant players involved in the response, in order to derive the lessons that can be used and applied in the context of our public sector ICT systems and databases and also specifically for the health system. In that process, I imagine that they would be looking at what could have been done, what should have been done and then, make their recommendations accordingly. I would urge Members to refrain from going down the path of allocating blame at this stage. Our resolute focus should be on ensuring that the system in SingHealth is secure and patient data is protected. And for this, we need all parties who are involved to be working together in order to achieve that objective. The COI will conduct its due process and, when we have the outcome of that and we know the recommendations and findings, then we can take appropriate action.

    CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2018-08-06 · READ THE OFFICIAL RECORD

  26. So, we have to also ensure that we are able to do so. This is why we are investing in cybersecurity, not only in terms of building our capabilities within CSA, but also in the broader system. We have many efforts in the broader ecosystem – the ICT ecosystem – and cybersecurity is one of the focal points for that. And the final point I would make is that as part of our overall defence, if you will, cyber defence, this is not just a battle we fight alone. We have allies from around the world. All of them face similar challenges, they are all investing in their capabilities, and the cooperation with our allies helps to strengthen our own capabilities in resisting such attacks.

    CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2018-08-06 · READ THE OFFICIAL RECORD

  27. Mr Speaker, I thank the Member for her clarification. The Member is absolutely right. We should be very clear that our challenges with cybersecurity are in no way different from our challenges with terrorism. We have raised our awareness about terrorism. We have a systematic effort for that. But when it comes to cybersecurity and defences, perhaps the level of awareness is not as palpable. The reason is probably also because many of us, all of us, use digital devices as part and parcel of everyday life and we do not pause to think sometimes what the implications are of having this hyper-connectivity and the kind of data that flows through our devices and the connections that we have with the Internet and the wider Internet community. So, in terms of the specific question, what are we doing? First, we have to use this opportunity to reinforce the message and the importance of cybersecurity to the general public and the measures that they can take at a personal level, which is what we have just outlined, but also to organisations, public and private organisations, because often the investment in cybersecurity is seen as a cost, without an obvious payoff and value. This sort of instances helps to crystallise why cybersecurity must be taken seriously at the top management level, and you put in place systems and make the judgement in terms of what kind of resources should be allocated for this. As far as the Government itself is concerned, we are very clear that we have to continue to invest in our ability and capabilities to prevent, detect and respond to any kind of cyberattack. As I said earlier, the reality is that this is going to be a ceaseless battle because the perpetrators or the potential perpetrators are constantly developing their own capabilities.

    CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2018-08-06 · READ THE OFFICIAL RECORD

  28. Speaker, I thank the Member for his question. First, I do not think we should speculate on the motives of the attacker. I think it does not detract from the fact that this is an illegal criminal act and we have the responsibility to get to the bottom of it. Having said that, can we be sure that there is no remnant malicious malware in the system? As I had said earlier, our agencies –CSA working with their counterparts in IHiS and SingHealth – have done everything they can to secure the system and to detect and eliminate the risk. In fact, as we also elaborated, even as we were doing the work to contain the challenge, as late as on 19 July, there was evidence of some residual risk which had to be dealt with. At midnight on 19 July, Internet Surfing separation was then imposed. The short answer is that we have done everything in our means to secure the system, to detect any residual risk and eliminate it. But as I have said several times in the course of my Statement, one can never be sure that we have fully eliminated that risk.

    CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2018-08-06 · READ THE OFFICIAL RECORD

  29. Mr Speaker, to conclude, I would like to emphasise that this was a well-planned and targeted cyberattack by an APT group. We will get to the bottom of this incident, learn from it and further strengthen Government IT systems. But I caution the House: we cannot completely eliminate the risk of another cyberattack breaking through our defences. Ensuring cybersecurity is a ceaseless battle, like our battle against terrorism. It involves changing technology and sophisticated perpetrators who are constantly developing new techniques and probing for fresh weaknesses. Therefore, even as we do our best to strengthen our IT systems, it is crucial that our people and systems remain resilient, that we are able to respond robustly and decisively to an incident, and that we constantly learn and reinforce our system. Despite this incident, or any others like it, we must press on with our plans for a Smart Nation, after learning and applying the lessons from this incident. We must adapt ourselves to operate effectively and securely in the digital age, to deliver better public services, enhance our economic competitiveness, and create good jobs and opportunities for Singaporeans. The Government takes with utmost seriousness its responsibility of ensuring the security of public sector IT systems and databases. We will learn from this cyberattack, implement measures to better secure our IT systems and databases, and uphold public trust in our systems.

    CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2018-08-06 · READ THE OFFICIAL RECORD

  30. To log in, the account holder has to input his/her Personal Identification Number (PIN) and a one-time-password (OTP), received via SMS or the bank’s authentication token. An additional authentication layer – commonly known as "transaction signing" – protects higher-risk transactions, such as adding a third party payee or transferring large sums of money. Unless the attacker has access to all authentication information, it would not be possible for fraudulent transactions or identity theft to occur. To address any residual risk, the Monetary Authority of Singapore (MAS) has directed all financial institutions to take further measures, as announced in its press statement on 24 July. Similarly, since July 2016, all sensitive Government e-transactions have been protected by SingPass 2FA. The account holder would need to input his/her SingPass username and password, and an OTP. Since the SingHealth cyberattack, agencies have taken further measures, such as heightened monitoring of their IT systems, and strengthening of the identity authentication process. Individuals can also do their part by practising good personal data protection and cybersecurity habits. They should ensure that their passwords, user IDs and security questions are not based on personal data, use strong passwords, enable 2FA for online transactions, and watch out for fraudulent transactions and suspicious requests for personal data. SingCERT has published online the precautions that individuals can take in view of the SingHealth incident. Individuals may also contact SingCERT to report a cybersecurity incident, and the Personal Data Protection Commission to lodge reports of personal data breaches under the Personal Data Protection Act.

    CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2018-08-06 · READ THE OFFICIAL RECORD

  31. The Government had taken the added precaution of calling for a pause in the introduction of new Information and Communications Technology (ICT) systems, although there was no evidence that Government ICT systems had been compromised in this cyberattack. The Smart Nation and Digital Government Group (SNDGG) was directed to review the cybersecurity measures of all existing and upcoming Government systems. SNDGG has completed its review and will implement additional security safeguards where necessary. The pause on new systems was lifted on 3 August, just Friday last week. Cybersecurity is the foundation of our Smart Nation and Digital Government drive, and the Government is resolute in its commitment to strengthen our cyber defence, as well as our detection and response capabilities, in the face of the evolving cybersecurity threat. All organisations – not just CII operators – should take this incident as a warning to review their cybersecurity system and ensure the protection of their IT systems and databases, including personal data. There have been concerns that the data stolen through the SingHealth cyberattack could be used for fraudulent transactions or identity theft. I want to emphasise that there are multiple safeguards in place to mitigate such risks, especially for financial transactions and sensitive Government e-transactions. Let me elaborate. Financial institutions generally do not rely solely on personal information, like those stolen in the SingHealth cyberattack, to verify customer identity. All banks and insurance companies in Singapore already have two-factor authentication (2FA) for online financial services, such as making fund transfers or accessing account details.

    CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2018-08-06 · READ THE OFFICIAL RECORD

  32. As the COI will be addressing these issues, I seek Members' understanding to allow the Committee to conduct a thorough investigation and to complete its work without pre-empting its findings. Meanwhile, the Government has taken additional measures to strengthen our cybersecurity defences. CSA's forensic investigations team has analysed the compromised computers and extracted Indicators of Compromise. These are pieces of forensic data used to identify malicious activity on a network. CSA then instructed owners and regulators of CII to scan for these Indicators and advise on possible measures to mitigate a similar incident. CSA has also instructed CII sectors to strengthen the security around their network connectivity gateways. In addition, the Cybersecurity Act passed by this House in February this year gives the Government additional levers to strengthen the protection of CII against cyberattacks and to respond to national cybersecurity threats and incidents. CSA is currently implementing the provisions of the Act and will designate all CII by the end of 2018. Notwithstanding these measures, we must recognise that a balance must be struck between cybersecurity on the one hand, and operational efficiency and service quality on the other. This is a dynamic balance, one that will change as the threat landscape evolves. CSA will direct CII owners on the essential security measures they must adopt to meet a required standard. Beyond this, CSA will also render its professional advice on what CII system owners could do to further strengthen their defences. Ultimately, owners and regulators of CII are responsible for ensuring the security and uninterrupted operations of the essential services they provide.

    CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2018-08-06 · READ THE OFFICIAL RECORD

  33. As the notes are being distributed, let me summarise. The COI will establish the events and contributing factors leading to the cyberattack and the incident response. It will also recommend measures to safeguard public sector IT systems containing large databases of personal data, including those in the public healthcare clusters, against similar cyberattacks. The COI will submit its report by 31 December 2018. The Chairman and members of the Committee have the legal, technical and operational expertise to conduct a thorough and rigorous inquiry. The Chairman, Mr Richard Magnus, was formerly the Senior District Judge, and he has chaired two other COIs before; Mr Lee Fook Sun is the former president of ST Electronics and currently Executive Chairman of Quann World, a cybersecurity company; Mr T K Udairam was formerly Chief Executive Officer (CEO) of Changi General Hospital and he has decades of experience in healthcare administration; Ms Cham Hui Fong is a former Nominated Member of Parliament and Assistant Secretary General at the National Trades Union Congress. The COI has already started its work. The Committee has had preparatory meetings and will soon hold its first pre-Inquiry conference. The Attorney-General's Chambers (AGC) will lead evidence and CSA will lead a team to conduct the investigations. After receiving CSA's investigation report, the COI will conduct the Inquiry hearings. As some aspects of the Inquiry have security implications, the COI will decide which part of its hearings can be held in public. Some Members have asked whether the SingHealth cyberattack could have been prevented and what are the lessons learnt.

    CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2018-08-06 · READ THE OFFICIAL RECORD

  34. Some recent examples of cyberattacks by APT groups include the hacking of the US Democratic National Committee in 2016, and the theft of more than 20 million personnel records from the US Office of Personnel Management in 2014. Singapore has also been the target of APT attacks, such as that on the National University of Singapore (NUS) and Nanyang Technological University (NTU) last year. The cyberattack on SingHealth had characteristics that are typical of an APT attack. The attacker used advanced and sophisticated tools, including customised malware that was able to evade SingHealth's anti-virus software and security tools. After establishing a foothold in the network, the attacker took steps to remain in the system undetected before stealing the patients' information. The attack fits the profile of certain known APT groups but, as I have said earlier, for national security reasons, we will not be making any specific public attribution. Let me now turn to the COI. Mr Speaker, may I have your permission for the distribution of the note on the COI's composition and terms of reference, please?

    CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2018-08-06 · READ THE OFFICIAL RECORD

  35. CSA subsequently established that the attackers had obtained a foothold in SingHealth's network by infecting a frontend computer with malicious software, or what is called malware. The attackers had evaded detection by the SingHealth network security tools, moved stealthily through the system, eventually gained access to the database servers storing SingHealth's patient records, and copied the data to servers hosted overseas on 27 June to 4 July. No further data loss has been detected since 4 July. Based on the logs, two types of data were illegally accessed – personal particulars, including the name, NRIC number, address, gender, race and date of birth of 1.5 million patients, and the outpatient dispensed medication records of 160,000 patients. The attackers also repeatedly and specifically tried to steal the medical records and data of Prime Minister Lee Hsien Loong. Prime Minister Lee's personal particulars and outpatient dispensed medication records were stolen. However, to reinforce the point that Minister Gan Kim Yong made, no telephone numbers, passwords or credit card information were accessed or stolen. Neither were other medical records, such as diagnoses, test results or doctor's notes. They were not illegally accessed. The data that was illegally copied was not tampered with, nor was it deleted. CSA has done a detailed analysis of the SingHealth cyberattack and has determined that it is the work of an APT group. An APT group refers to a class of sophisticated, usually state-linked cyberattackers who conduct extended and carefully planned cyber campaigns to steal information or disrupt operations.

    CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2018-08-06 · READ THE OFFICIAL RECORD

  36. This is an ongoing battle, with potential cyberattackers who are constantly developing their capabilities and seeking out new vulnerabilities. We should not let this incident or any others like it derail our Smart Nation initiatives. In fact, we must pursue these initiatives for they will bring benefits and opportunities for Singaporeans. What matters most is that our people and systems remain resilient, that we are able to respond swiftly and effectively to a cyberattack and that we strengthen our defences and harden our systems. I want to thank Members who have raised a range of questions on the cyberattack, our response and the COI, and I will now address them in detail. Let me start by adding CSA's perspective to the Minister for Health's detailed account of this incident and subsequent response. On 10 July 2018, CSA was notified that an unauthorised network intrusion had occurred at SingHealth. CSA immediately deployed members of its National Incident Response Team (NIRT) to investigate the incident. The CSA team conducted forensic investigations on suspected compromised computers and supported IHiS in implementing measures to contain the attack. This included blocking unauthorised connections to prevent access by the attacker, resetting servers, enforcing mandatory password resets for all SingHealth users, heightened monitoring across all public healthcare IT systems, and implementing Internet Surfing Separation. CSA's investigations ascertained that on 4 July, IHiS system administrators had discovered unusual activity on one of SingHealth's IT databases which triggered follow-up investigations by IHiS' IT team.

    CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2018-08-06 · READ THE OFFICIAL RECORD

  37. Thank you, Mr Speaker, Sir. Let me start by reiterating the key facts. First, SingHealth's IT system was the target of a deliberate and well-planned cyberattack. Second, this attack caused the most serious breach of personal data in Singapore's experience. Third, the personal particulars of 1.5 million patients, including the outpatient dispensed medication records of 160,000 patients, were illegally accessed and copied. Fourth, Prime Minister Lee Hsien Loong's records were specifically and repeatedly targeted. SingHealth and IHiS are private companies. They are not Statutory Boards. However, their patient databases are part of our Critical Information Infrastructure (CII). A cyberattack on any CII can disrupt essential services and affect public welfare and confidence. We have done a detailed analysis of this attack and have determined that it is the work of an Advanced Persistent Threat (APT) group. This refers to a class of sophisticated cyberattackers, typically state-linked, who conduct extended, carefully planned cyber campaigns, to steal information or disrupt operations. The APT group that attacked SingHealth was persistent in its efforts to penetrate and anchor itself in the network, bypass the security measures, and illegally access and exfiltrate data. The attack fits the profile of certain known APT groups. But for national security reasons, we will not be making any specific public attribution. Given the serious implications of this incident for public health and safety, I have convened a COI to get to the bottom of this incident, learn from it, and implement stronger safeguards. We will do our utmost to strengthen our cybersecurity. But it is impossible to completely eliminate the risk of another cyberattack.

    CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2018-08-06 · READ THE OFFICIAL RECORD

  38. oBike, like any other business in Singapore, is required to comply with the data protection obligations under the Personal Data Protection Act (PDPA). If a business has no legal or business purpose for the personal data in its possession or control, PDPA requires it to stop retaining such data. PDPA continues to apply to a company undergoing liquidation. Where a liquidator is appointed, the liquidator will also have to ensure that the company undergoing liquidation continues to comply with PDPA. This includes the obligations to protect customer data during liquidation and expunging customer data at the end of the winding-up process if there is no legal or business purpose to retain it. The personal data of customers in Singapore cannot be treated as assets and sold without their consent. In winding up a company, the company's liquidator may sell the whole or part of the company, its assets or business. If such a sale takes place, customer data that is directly relevant to the transaction may be transferred to the acquirer. However, under PDPA, customers must be notified that their personal data has been transferred. If customers do not wish for the acquiring company to use their personal data, they can approach the acquiring company to withdraw their consent, whereupon the acquiring company shall then delete the personal data once there is no legal or business purpose to retain it. The Personal Data Protection Commission (PDPC) expects oBike and its liquidators to continue complying with PDPA even as it prepares to exit the market in Singapore. PDPC has reminded oBike of its obligations under the PDPA and is monitoring the situation closely. PDPC will not hesitate to take further action to safeguard consumers' interests if necessary.

    REGULATION TO ENSURE DELETION OF PERSONAL DATA COLLECTED BY OBIKE - 2018-07-10 · READ THE OFFICIAL RECORD

  39. All 64 FIFA World Cup 2018 matches will be screened for free across various public venues, such as community centres and the Singapore Sports Hub. An estimated 100,000 members of the public have already enjoyed these free screenings. Nine FIFA World Cup 2018 matches are also being broadcast "live" on Mediacorp's Okto channel for free. Six of these matches have already been broadcast, as will the two Semi-Finals and the Final in the coming days. It is becoming more challenging to provide such "live" broadcasts of international sports events for free. Broadcast rights for international sports events, such as the FIFA World Cup, are commercially negotiated. Over the years, the cost of these broadcast rights has grown significantly. For the FIFA World Cup 2018, broadcasters in the region paid an estimated 25% to 75% more this year compared to 2014. Broadcasters find it difficult to recoup the escalating cost of broadcast rights, because there are other options for viewers to watch such sports events "live". Hence, commercial sponsorship is important and we welcome more sponsors to partner our broadcasters to make "live" broadcasts of such international sports events more accessible to Singaporean viewers.

    FREE LIVE BROADCASTS OF WORLD CUP 2018 IN SINGAPORE - 2018-07-10 · READ THE OFFICIAL RECORD

  40. (proc text)] [(proc text) The House immediately resolved itself into a Committee on the Bill. – [Mr S Iswaran.] (proc text)] [(proc text) Bill considered in Committee; reported without amendment; read a Third time and passed. (proc text)]

    NATIONAL LIBRARY BOARD (AMENDMENT) BILL - 2018-07-09 · READ THE OFFICIAL RECORD

  41. As Mr Darryl David has pointed out, there is a large amount of information collected via Legal Deposit and Web Harvesting which NLB needs to ensure is stored securely while remaining publicly accessible. On this point, I want to highlight that NLB has a secure digital infrastructure that is protected in accordance with robust Government standards. There are regular reviews of the security and resilience of our system, including the necessary firewalls and antivirus software, to protect against malicious cyber activities. Alongside this, NLB’s digitisation and preservation policies will ensure that deposited content is preserved. This includes the migration of content to updated formats from time to time, which will prevent content from being corrupted or lost when formats become obsolete. Mr Speaker, Sir, I believe I have addressed substantively the points that have been raised by the Members. I want to reiterate that the proposed amendments to the Act will be an important step forward in allowing NLB to preserve the materials which document Singapore's history and culture, so that these can be made available to our future generations. These amendments are especially crucial in this digital era, given that more and more valuable materials are now residing online and available in electronic formats. We must focus our collection efforts on such materials now so that we do not lose important pieces of our culture, heritage and history. On this note, I want to once again thank all three Members who have spoken in support of the Bill. Sir, I beg to move. [(proc text) Question put, and agreed to. (proc text)] [(proc text) Bill accordingly read a Second time and committed to a Committee of the whole House.

    NATIONAL LIBRARY BOARD (AMENDMENT) BILL - 2018-07-09 · READ THE OFFICIAL RECORD

  42. In time to come, we hope to be able to share a greater collection of materials on NLB's digital platforms through the support of content creators and publishers as they join us in our efforts to make our nation's published heritage accessible in more ways. I want to assure all Members that under the proposed amendments, the copyright of digital content continues to reside with the content creators and publishers. In the event that members of the public or researchers wish to use the content beyond just research and study, they will still have to approach the copyright owners for permission. Mr Louis Ng has asked if there was a grace period after publication before content will be made available in the National Library. As there are several steps involved in the processing of material, which includes quality check and cataloguing, it may take one to six months from the date of collection – depending on the type of material collected – before it is made accessible to the public. For instance, in the case of websites, it may take up to six months from the last archiving exercise before a website is ready for public viewing. The online material collected via web-harvesting will also be made available in an easily accessible form. Mr Louis Ng asked if NLB will be making indices and abstracts of archives available online for citizens and researchers to have greater access. I am very happy to share with him that NLB is at present already cataloguing and indexing websites for which they have obtained permission to archive. Archived websites can be found on NLB's digital platform One Search, and their Web Archives Singapore has an alphabetical and subject listing of all archived websites to date.

    NATIONAL LIBRARY BOARD (AMENDMENT) BILL - 2018-07-09 · READ THE OFFICIAL RECORD

  43. We have also heard these concerns from stakeholders, like book publishers, in our consultations. To strike a balance as we embark on this new scheme, NLB will, for a start, provide public access to the collected electronic publications and websites at the Lee Kong Chian Reference Library located at the National Library Building. These materials can only be viewed at the computer terminals with no downloading, copying or printing allowed. Two concurrent users will be able to view each item in the collections at any one time. This approach mirrors that of NLB's current Legal Deposit policy for physical materials, which requires two copies to be deposited. We think this strikes a good starting balance between safeguarding publishers' IP interests and giving public access to these materials. There are, however, instances where the content of the collected electronic materials or websites are made available to the public beyond the library's premises. This is now done where express permission has already been given by the copyright owner or when the copyright has expired, and the content will be made accessible via NLB's digital services and websites, such as BookSG and Web Archives Singapore. For example, the archived websites of the W!ld Rice Theatre Company (www.wildrice.com.sg), the Eurasian Association Singapore (www.eurasians.org.sg) and Singapore National Olympic Council (www.singaporeolympics.sg) are made available online as prior consent has been given, while the digitised copy of Hikayat Abdullah (Stories of Abdullah), published by the Mission Press in 1849, is also available online as the copyright has expired.

    NATIONAL LIBRARY BOARD (AMENDMENT) BILL - 2018-07-09 · READ THE OFFICIAL RECORD

  44. In general, if you are publishing content on a website, one assumes that you want it to be read, and it is counter-intuitive to then say that "I want it to be published but I do not want it to be archived". In fact, our public consultation with website owners last year showed that they were generally receptive and supportive of the web-harvesting initiative as they understood that the intent is for us to retain the collective memories of our nation. Furthermore, this will allow them to have their content captured and stored for posterity. So, I think it is an alignment of interest. We recognise that website owners have the right to choose the platforms on which they distribute their materials, but we hope that they will join us in our efforts to keep a part of our history alive. Several Members, Mr Louis Ng in particular, had also asked how NLB would be ensuring that publishers' rights and content creators' copyrights and IP are protected, while making collected material easily accessible to people. This is an important point. How do we strike that balance? All three Members asked whether we can consider making access to digital archived content more accessible, so that more people can benefit from them. Indeed, it is important that we ensure that the nation's published heritage is accessible to future and current generations of Singaporeans, and for all the good reasons that we have emphasised. But at the same time, we also share their concerns regarding the protection of commercial interests of publishers of electronic materials, and they have asked how we will ensure that these interests will not be compromised in any way through the amendments to this Act. These are valid concerns.

    NATIONAL LIBRARY BOARD (AMENDMENT) BILL - 2018-07-09 · READ THE OFFICIAL RECORD

  45. Mr Ong Teng Koon has also asked if an annual web-harvesting exercise would be sufficient, given that the content on the Internet changes so quickly and frequently. We do not intend to emulate Google, I assure Mr Ong, but the proposed frequency of harvesting the .sg domain websites is generally in line with international practices. However, as I mentioned earlier, there will be instances where some websites will be archived more frequently. So, it becomes a judgement call in terms of the currency and relevance. But by and large, an automated annual exercise should suffice to provide that snapshot that is being sought. On the specific issue of whether NLB will be web-harvesting objectionable material, such as content which could pose a threat to Singapore’s national security, to be clear, what NLB endeavours to do is to preserve a comprehensive record of Singapore-related websites through web-harvesting. As these are important resources that chart Singapore's cultural and social changes over time, it is essential that we capture them as they are so that they can accurately reflect the cultural and social landscape of our nation at different points in time. If the websites archived are found to contain content that is found to be objectionable under the relevant laws or codes, then NLB may block access to that content. In other words, NLB will still archive the content, but may not allow access to it. Mr Ong Teng Koon has also asked if website owners could decline to be web-harvested. He also pointed out that some website owners might post their content on non .sg sites to avoid being archived.

    NATIONAL LIBRARY BOARD (AMENDMENT) BILL - 2018-07-09 · READ THE OFFICIAL RECORD

  46. Thank you, Mr Speaker. Let me, first, thank the Members Mr Louis Ng, Mr Darryl David and Mr Ong Teng Koon who have all spoken in support of the National Library Board (Amendment) Bill. They have raised several valid questions. Let me now endeavour to address them in some detail. Mr Ong Teng Koon has asked about the scope of online material which may be web-harvested, and whether it would be clear to website owners which elements of their websites would be web-harvested. The intent of this amendment is to ensure that Singapore-related content, which is increasingly found online, is collected and preserved for future generations so that they can better understand the evolution of events here. So, in the first instance, NLB will collect material from all .sg domain websites. This means that NLB will not be collecting material residing in social media, such as Facebook, Twitter and Instagram, that are not within the .sg domain. For .sg websites, NLB will archive all the pages within the websites, including images, portable document format (PDF) documents, audio files and video files, that are hosted within the websites themselves. However, content hosted on external websites, such as links to videos hosted on YouTube, will not be archived. In addition to .sg domain websites, we also recognise that there are other non.sg websites which may also contain valuable content about Singapore. For such websites, NLB will proactively approach the site owners for permission to archive the sites. Mr Speaker, I want to reiterate here that NLB will only be collecting material that is publicly available; it will not collect material that is behind a paywall or open only to subscribers or members.

    NATIONAL LIBRARY BOARD (AMENDMENT) BILL - 2018-07-09 · READ THE OFFICIAL RECORD

  47. The Copyright Act will also be amended, via an expansion of section 45(7A) and a new section 113B, to allow the web-harvested content of Singapore websites to be made available on computer terminals within the premises of libraries and archives in Singapore. This is to make the preserved content accessible for research and reference within libraries and archives, where there are safeguards to prevent users from further copying or distributing the work. Mr Speaker, in summary, the proposed amendments will allow NLB to more effectively fulfil its mandate to collect, preserve and make accessible our nation’s published heritage in both print and electronic forms. This is important so that today’s Singapore stories will be kept alive for future generations of Singaporeans. Mr Speaker, I beg to move. [(proc text) Question proposed. (proc text)]

    NATIONAL LIBRARY BOARD (AMENDMENT) BILL - 2018-07-09 · READ THE OFFICIAL RECORD

  48. The third set of amendments provides for an electronic legal deposit. The current legal deposit scheme requires publishers to deposit with NLB two physical copies of library materials that are published in Singapore. Going forward, section 10 will be amended to require publishers of library materials in electronic form to also deposit a copy of these with NLB within four weeks of the date of first publication. The copy deposited must be free of any technological protection or access restrictions, such as password protection, to enable NLB to digitally preserve the content for posterity and provide access to researchers at the library premises. With the proposed amendments to the NLB Act, there will be consequential amendments to the Copyright Act to permit NLB to copy any online material made available on a Singapore website, for the purpose of performing NLB’s statutory function of acquiring and maintaining a comprehensive collection of library materials relating to Singapore. Although the content is already available to the public on Singapore websites, current copyright laws generally require obtaining the consent of the copyright owner of the content on the website prior to copying the content. A new section 49A will, therefore, be created in the Copyright Act to allow NLB to make copies of online literary, dramatic, musical and artistic works. A new section 113A and an expanded section 116 will provide likewise for online sound recordings and cinematograph films, and published editions of literary, dramatic, musical and/or artistic works, respectively. These amendments are necessary to make clear that NLB is not infringing any copyright laws while web-harvesting Singapore websites to collect and preserve them.

    NATIONAL LIBRARY BOARD (AMENDMENT) BILL - 2018-07-09 · READ THE OFFICIAL RECORD

  49. At present, NLB has to seek the written consent of website owners before making copies of online content that is of historical value to Singapore. This is cumbersome, and typically only a small percentage of website owners respond, perhaps because they are unaware of their websites’ significance to Singapore’s history and heritage. To address this, section 7 of the NLB Act will be amended to empower NLB to make copies of any online material published on a Singapore website through automated web-harvesting, without requiring NLB to seek written consent from the owners or producers. In line with international practice, NLB will only collect material from websites that are publicly accessible; material will not be collected from websites that are password-protected or restricted to members or subscribers. Most websites will be web-harvested once a year, although Government sites will be archived more regularly in order to capture major developments in national policies or programmes. Other selected sites may be harvested more frequently, during periods in which they showcase events of significance to Singapore, such as official websites for National Day or the Southeast Asian Games. NLB will also archive more frequently websites which contain content on current affairs and are read by many Singaporeans, such as Mothership.sg. These amendments are similar to web-harvesting legislation in the UK, Australia and New Zealand. In the UK, the British Library is empowered to harvest online works available to the public through websites with domain names relating to the UK or to a place within the UK or works which have been created or published within the UK. The national libraries of New Zealand and Australia have similar powers.

    NATIONAL LIBRARY BOARD (AMENDMENT) BILL - 2018-07-09 · READ THE OFFICIAL RECORD

  50. The United Kingdom (UK), Australia, New Zealand, Japan and South Korea are examples of countries that have amended their legislation to allow their national libraries to collect and preserve electronic materials and websites. In preparing this Bill, NLB conducted a public consultation last year to gather feedback on the amendments. In addition, NLB consulted publishers, academics, researchers, writers, librarians and bloggers through various stakeholder engagement sessions. Overall, there was broad support for the proposed amendments. Mr Speaker, Sir, let me now elaborate on the proposed amendments to the Act. The first set of amendments expands the definition of "library materials" beyond the printed form to include electronic and online material. The definition of “library materials” in section 2 of the NLB Act will be amended to include materials in the electronic form, such as e-books. The definition of “library materials” relating to films, videos, sound recordings and other similar materials will also be broadened to include electronic forms, including streamed content. The expanded definition of "library materials" will also include any online material that is made available on what is called a "Singapore website", which is defined as a website under the .sg domain. A Singapore website or electronic service that is not under the .sg domain can also be included in this definition, if it is determined by NLB to be associated with Singapore; for example, where there are non .sg sites that have content that is considered to hold significant cultural or heritage value. The second set of amendments pertains to web-harvesting.

    NATIONAL LIBRARY BOARD (AMENDMENT) BILL - 2018-07-09 · READ THE OFFICIAL RECORD