Galexia

  Projects

Singapore iDA


[ Galexia Dots ]

Singapore iDA - A Study of Singapore’s Certification Authority Scheme

Related Galexia services and solutions

  • Identity Management and Authentication - Strategic Consulting. Read more »
  • Identity Management and Authentication - Technical Consulting. Read more »
  • Issues Management: Public and Stakeholder Consultations. Read more »

Galexia successfully joined a consortium to review the compliance auditing framework for Certification Authority (CA) candidates for the Singapore Infocomm Development Authority (iDA).

The existing framework consists of audit standards and updated security management best practice guidelines. The objective was to update the guidelines to align them with international best practices, and to provide clarity for CAs and auditors on security audit requirements for CAs. The project also provided a ‘gap analysis’ of the present set of guidelines and audit requirements concerning internationally recognised security standards and best practices.

The proposed changes are currently the subject of consideration by Singapore iDA.



[ Galexia Dots ]

Singapore iDA - Singapore National Authentication Framework (NAF)

The Infocomm Development Authority of Singapore (iDA) is also spearheading a National Authentication Framework (NAF) programme under their 10 year Intelligent Nation Masterplan. NAF aims to implement a nationwide infrastructure for strong authentication through the development of appropriate business, technical and operational frameworks. A NAF steering committee and four NAF sub-committees (Finance, Telecommunications, Government and Technical) comprising of industry captains and government will provide sponsorship and inputs to the developmental works under NAF.

Galexia has been chosen as part of a consortium (also including KPMG, Baker & McKenzie, Wong & Leow and Biometix) to drive and guide the establishment of the NAF. As such Galexia’s work entails the proposal of a model to deploy the NAF, and to develop 4 supporting components that are needed to realise the deployments:

  • Governance Framework and Regulatory Requirements;
  • Accreditation Audit Criteria for Authentication Operators (‘AOs’);
  • Reference Business Agreement; and
  • Reference Technical Standards and Protocols.


[ Galexia Dots ]