Singapore
Asia-Pacific
Singapore's IMDA (Infocomm Media Development Authority) issues the Telecommunications Cybersecurity Code (TCC) as binding regulation. CII operators fall additionally under the Cybersecurity Act enforced by CSA.
Regulator: IMDA + CSA
Primary frameworks: IMDA TCC, Cybersecurity Act 2018, CII designation, IMDA 5G security requirements
TCC domains
The TCC covers governance, risk management, technical controls, incident response, business continuity, and testing. Signaling firewall deployment falls under technical controls.
CII obligations
Designated telecom CII operators must comply with the Cybersecurity Act — including CSA notification of incidents within 2 hours of detection.
5G nationwide security
IMDA required security-by-design in the 5G award. Operators submitted network security plans as part of the licence.
Key takeaways
- The TCC is unusually explicit for a country its size; assume audit-grade evidence is expected.
- CII 2-hour reporting is one of the tightest globally alongside CERT-In's 6-hour rule.
- IMDA reviews technical implementation, not just governance artefacts.