Skip to main content

Public advisory of scammers impersonating CSA and the SPF

Cyber Security Agency of Singapore
  1. Home
  2. Frequently Asked Questions
  3. Cybersecurity Audit for CII

Cybersecurity Audit for CII

Explains cybersecurity audit requirements for Critical Information Infrastructure (CII), detailing compliance, processes, and roles under Singapore’s Cybersecurity Act.

Last updated 20 January 2025
How often must the Critical Information Infrastructure owners (CIIOs) carry out the cybersecurity audit?
Which approach (compliance or risk-based) should the auditor adopt to conduct cybersecurity audit of the CII?
Will Critical Information Infrastructure owners (CIIOs) be given a grace period to comply with the Operation Technology (OT) Systems Requirements in Cybersecurity Code of Practice (CCoP) addendum?
What is the process for seeking approval from the Commissioner to appoint an auditor to conduct an audit of the Critical Information Infrastructure?
Where a waiver of the Code of Practice (“CoP”) is granted to a CII, will the waived CoP clause(s) be subjected to the cybersecurity audit?