My bookmarksSign up free

Cybersecurity Act 2018 PART 2 — ADMINISTRATION

s 4–s 6A · 4 sections

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Appointment of Commissioner of Cybersecurity and other officers

s 4

4.—(1) The Minister may appoint, from public officers or employees of a statutory body under the charge of the Minister —(a) a Commissioner of Cybersecurity; and (b) a Deputy Commissioner and one or more Assistant Commissioners of Cybersecurity, to assist the Commissioner in the discharge of the Commissioner’s duties and functions. (2) The Minister may appoint as an Assistant Commissioner under subsection (1)(b) in respect of a provider‑owned critical information infrastructure or a system of temporary cybersecurity concern —(a) a public officer of another Ministry; or (b) an employee of a statutory body under the charge of another Minister, where that other Ministry or statutory body has supervisory or regulatory responsibility over an industry or a sector to which the owner of the provider‑owned critical information infrastructure or the system of temporary cybersecurity concern (as the case may be) belongs. [Act 19 of 2024 wef 31/10/2025] (2A) The Minister may appoint as an Assistant Commissioner under subsection (1)(b) in respect of a designated provider responsible for third‑party‑owned critical information infrastructure, an entity of special cybersecurity interest or a major foundational digital infrastructure service provider —(a) a public officer of another Ministry; or (b) an employee of a statutory body under the charge of another Minister, where that other Ministry or statutory body has supervisory or regulatory responsibility over an industry or a sector to which the designated provider responsible for third‑party‑owned critical information infrastructure, entity of special cybersecurity interest or major foundational digital infrastructure service provider (as the case may be) belongs. [Act 19 of 2024 wef 31/10/2025] (3) The Commissioner may in writing appoint such number of public officers as cybersecurity officers as the Commissioner thinks necessary for carrying this Act into effect. (4) Subject to any general or special directions of the Minister, the Commissioner is responsible for the administration of this Act, and has and may perform such duties and functions as are imposed, and exercise such powers as are conferred, upon the Commissioner by this Act. (5) The Deputy Commissioner has and may exercise all the powers, duties and functions of the Commissioner except those exercisable under section 7, 9, 9A, 16A, 16C, 16D, 17, 17B, 17C, 18, 18B, 18C, 18G, 18I or 18J.[Act 19 of 2024 wef 31/10/2025] (6) Subject to such conditions or limitations as the Commissioner may specify, an Assistant Commissioner or a cybersecurity officer has and may exercise all the powers, duties and functions of the Commissioner as may be delegated to that Assistant Commissioner or cybersecurity officer in writing, except —(a) in the case of an Assistant Commissioner, those powers, duties or functions exercisable under this subsection, or section 6, 7, 9, 9A, 16A, 16C, 16D, 17, 17B, 17C, 18, 18B, 18C, 18G, 18I, 18J, 20(5), 37A or 37C; and[Act 19 of 2024 wef 31/10/2025] (b) in the case of a cybersecurity officer, those powers, duties or functions exercisable under this subsection, or section 6, 6A, 7, 9, 9A, 12, 16A, 16C, 16D, 16G, 17, 17B, 17C, 17E, 18, 18B, 18C, 18E, 18G, 18I, 18J, 18L, 20(5), 35A, 37A or 37C.[Act 19 of 2024 wef 31/10/2025]

Duties and functions of Commissioner

s 5

5.—(1) The Commissioner has the following duties and functions:(a) to oversee and promote the cybersecurity of computers and computer systems in Singapore; (b) to advise the Government or any other public authority on national needs and policies in respect of cybersecurity matters generally; (c) to monitor cybersecurity threats, whether such cybersecurity threats occur in or outside Singapore; (d) to respond to cybersecurity incidents that threaten the national security, defence, economy, foreign relations, public health, public order or public safety, or any essential services, of Singapore, whether such cybersecurity incidents occur in or outside Singapore; (e) to identify and designate provider‑owned critical information infrastructure or systems of temporary cybersecurity concern, and to regulate owners of provider‑owned critical information infrastructure or systems of temporary cybersecurity concern with regard to the cybersecurity of the provider‑owned critical information infrastructure or systems of temporary cybersecurity concern;[Act 19 of 2024 wef 31/10/2025] (ea) to identify and designate designated providers responsible for third‑party‑owned critical information infrastructure, entities of special cybersecurity interest or major foundational digital infrastructure service providers, and to regulate those providers or entities with regard to the cybersecurity of the third‑party‑owned critical information infrastructure, system of special cybersecurity interest or major foundational digital infrastructure;[Act 19 of 2024 wef 31/10/2025] (f) to establish cybersecurity codes of practice and standards of performance for implementation by owners of provider‑owned critical information infrastructure or systems of temporary cybersecurity concern, or by designated providers responsible for third‑party‑owned critical information infrastructure, entities of special cybersecurity interest or major foundational digital infrastructure service providers;[Act 19 of 2024 wef 31/10/2025] (g) to represent the Government on cybersecurity issues internationally; (h) to cooperate with computer emergency response teams (CERTs) of other countries or territories on cybersecurity incidents; (i) to develop and promote the cybersecurity services industry in Singapore; (j) to license and establish standards in relation to cybersecurity service providers; (k) to establish standards within Singapore in relation to cybersecurity products or services, and the recommended level of cybersecurity of computer hardware or software, including certification or accreditation schemes or international certification schemes;[Act 19 of 2024 wef 31/10/2025] (l) to promote, develop, maintain and improve competencies and professional standards of persons working in the field of cybersecurity; (m) to support the advancement of technology, and research and development relating to cybersecurity; (n) to promote awareness of the need for and the importance of cybersecurity in Singapore; (o) to perform such other functions and discharge such other duties as may be conferred on the Commissioner under any other written law.[Act 19 of 2024 wef 31/10/2025] (2) The office of the Commissioner is to be known as the Cyber Security Agency of Singapore.[Act 19 of 2024 wef 31/10/2025]

Appointment of authorised officers

s 6

6.—(1) The Commissioner may, after consulting the Minister, in writing appoint any of the following as an authorised officer to assist the Commissioner in exercising the powers under Part 4:(a) a public officer of another Ministry; (b) an employee of any statutory body; (c) an auxiliary police officer appointed under the Police Force Act 2004. (2) In exercising any of the powers of enforcement under Part 4, an authorised officer must, on demand, produce to the person against whom the authorised officer is acting the authority issued to the authorised officer by the Commissioner. (3) Every authorised officer appointed under subsection (1)(b) or (c) is deemed to be a public servant for the purpose of the Penal Code 1871.

Cyber Security Agency of Singapore’s symbols, etc.

s 6A

6A.—(1) The Commissioner has the exclusive right to the use of one or more symbols or representations of the Cyber Security Agency of Singapore as the Commissioner may select or devise (each called in this section the Cyber Security Agency of Singapore’s symbol or representation), and to display or exhibit those symbols or representations in connection with the Cyber Security Agency of Singapore’s activities or affairs. (2) The Commissioner must publish any symbol or representation mentioned in subsection (1) in the Gazette. (3) A person who —(a) uses, without the Commissioner’s prior written permission, a symbol or representation that is identical to the Cyber Security Agency of Singapore’s symbol or representation; or (b) uses a symbol or representation that so resembles the Cyber Security Agency of Singapore’s symbol or representation as to deceive or cause confusion, or to be likely to deceive or to cause confusion, shall be guilty of an offence and shall be liable on conviction to a fine not exceeding $5,000 or to imprisonment for a term not exceeding 6 months or to both. [Act 19 of 2024 wef 31/10/2025]

Back to Cybersecurity Act 2018 — full text

Provisions on this page are reproduced verbatim from official open data. See the attribution line.

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. Read the official text ↗

Source: Singapore Statutes Online (Attorney-General's Chambers), © Government of Singapore.

The Singapore legislation on this platform is subject to copyright of the Singapore Government and is used/reproduced for the purposes of this platform with the permission of the Attorney-General's Chambers. Users of this platform may check Singapore Statutes Online for the latest version of the Singapore legislation.

What to look at next