Catalog / MAS TRM
MAS TRM Monetary Authority of Singapore
Technology Risk Management review for MAS-regulated institutions — governance, access, change, resilience, and the Cyber Hygiene measures.
- 9
- domains
- 71
- controls
- 71
- tests the agent runs
Control catalog
Technology Risk Governance & Oversight
-
TRG-01Board & senior management oversight of technology risk
The board and senior management are accountable for, and actively oversee, technology risk.
-
TRG-02Approved Technology Risk Management framework
A documented TRM framework is approved and maintained.
-
TRG-03Technology risk appetite & tolerance
Technology risk appetite is defined, approved, and monitored.
-
TRG-04Information security / CISO function
A dedicated information security function with clear authority and resourcing exists.
-
TRG-05Technology risk identification & assessment
Technology risks are identified and assessed on a structured, periodic basis.
-
TRG-06Technology risk register & treatment
Identified risks are tracked with owners, treatment plans and monitoring.
-
TRG-07IT policies & standards
IT and security policies are documented, approved and current.
-
TRG-08Technology risk reporting
Technology risk is reported to management and the board with sufficient quality and frequency.
-
TRG-09Independent assurance / IT audit
Independent assurance over technology risk is performed.
Access Control
-
AC-01User access provisioning & authorisation
Access is granted only on authorised, role-appropriate request.
-
AC-02Timely de-provisioning (leavers/transfers)
Access is removed promptly when staff leave or change roles.
-
AC-03Periodic access recertification
User access is periodically reviewed and recertified.
-
AC-04Privileged / administrative access management
Privileged access is restricted, individually owned, and monitored.
-
AC-05Segregation of duties in access
Conflicting duties are not concentrated in one individual.
-
AC-06Authentication & password standards
Authentication enforces the security baseline (length, complexity, lockout, history).
-
AC-07Multi-factor authentication
MFA is enforced for administrative, remote and critical-system access.
-
AC-08Remote access security
Remote access to the network/systems is secured and controlled.
-
AC-09System / service account management
Non-human (service) accounts are inventoried, least-privilege and rotated.
Change & Secure Development
-
CD-01Change authorisation before deployment
Production changes are authorised before deployment.
-
CD-02Testing & UAT before production
Changes are tested and business-signed-off before release.
-
CD-03Segregation between development and deployment
Developers cannot deploy their own changes to production.
-
CD-04Emergency change management
Emergency changes receive timely retrospective approval and review.
-
CD-05Secure SDLC / security-by-design
Security is built into the development lifecycle.
-
CD-06Source code management & review
Source code is version-controlled and peer-reviewed.
-
CD-07API security & management
APIs are securely designed, authenticated and managed.
-
CD-08Patch & vulnerability remediation
Security patches are applied within risk-based timelines.
-
CD-09Production configuration & version control
Production configuration is controlled and changes are traceable.
IT Resilience & Service Management
-
RS-01Critical system availability (4-hour rule)
Unscheduled downtime of a critical system does not exceed 4 hours within any 12-month period.
-
RS-02Recovery time objective (RTO ≤ 4h)
Critical systems can be recovered within a 4-hour RTO.
-
RS-03Disaster recovery plan & testing
A DR plan exists and is tested with successful results.
-
RS-04Data backup & restoration testing
Backups run per schedule and restorability is demonstrated.
-
RS-05Business continuity management
Business continuity plans exist and are tested.
-
RS-06Capacity & performance management
Capacity is monitored to maintain performance and availability.
-
RS-07Batch / job scheduling & monitoring
Scheduled jobs are monitored and failures resolved.
-
RS-08Problem management
Recurring incidents are addressed through root-cause problem management.
-
RS-09IT incident / service management (operational)
Operational incidents are managed, prioritised and resolved per SLA.
Data Security & Cryptography
-
DS-01Data classification & handling
Data is classified and handled per its sensitivity.
-
DS-02Encryption of data at rest
Sensitive data at rest is encrypted per the baseline.
-
DS-03Encryption of data in transit
Sensitive data in transit is encrypted.
-
DS-04Cryptographic key management
Cryptographic keys are securely generated, stored, rotated and retired.
-
DS-05Data loss prevention
Controls detect and prevent unauthorised data exfiltration.
-
DS-06Data retention & secure disposal
Data is retained and disposed per policy.
-
DS-07Database security & monitoring
Databases are hardened, access-controlled and monitored.
-
DS-08Network security & segmentation
Networks are segmented and protected.
-
DS-09Endpoint security
Endpoints are protected and managed.
Cyber Security Operations & Monitoring
-
CO-01Security event logging & monitoring
Security-relevant events are logged and monitored centrally.
-
CO-02Security operations / threat detection
Security alerts are triaged and responded to on a timely basis.
-
CO-03Incident response plan & handling
Security incidents are handled per a defined response plan.
-
CO-04MAS incident notification (≤ 1 hour)
Relevant incidents are notified to MAS within 1 hour of discovery.
-
CO-05Incident root-cause analysis & 14-day reporting
Root-cause analysis is submitted to MAS within 14 days for relevant incidents.
-
CO-06Threat intelligence & information sharing
Threat intelligence is used and shared to improve defences.
-
CO-07Malware protection
Malware protection is deployed and current across the estate.
-
CO-08Vulnerability remediation within SLA
Identified vulnerabilities are remediated within risk-based SLAs.
Cyber Security Assessment
-
CA-01Vulnerability assessment cadence
Vulnerability assessments are performed on a defined cadence.
-
CA-02Penetration testing
Penetration tests are performed periodically and findings remediated.
-
CA-03Adversarial attack simulation (red teaming)
Scenario-based / red-team exercises test detection and response.
-
CA-04Assessment findings remediation tracking
Findings from assessments are tracked to closure within SLA.
-
CA-05Security review of new / changed systems
New or significantly changed systems undergo security review before go-live.
Third-Party & Outsourcing Risk
-
TP-01Third-party risk assessment
Third parties are risk-assessed before and during engagement.
-
TP-02Material outsourcing register & due diligence
Material outsourcing arrangements are identified, registered and diligenced.
-
TP-03Outsourcing agreements & MAS audit/access rights
Agreements include required clauses incl. MAS audit/inspection and access rights.
-
TP-04Ongoing service-provider monitoring
Service providers are monitored on an ongoing basis.
-
TP-05Cloud outsourcing risk management
Cloud services are governed with appropriate controls.
-
TP-06Concentration & sub-contracting risk
Concentration and sub-contracting (4th-party) risks are managed.
-
TP-07Outsourcing exit & access revocation
On termination, provider access is revoked and data returned/destroyed.
Cyber Hygiene (Mandatory Baseline)
-
CH-01Administrative accounts secured
Administrative accounts are secured and not used for daily activities.
-
CH-02Security patches applied
Security patches are applied to address known vulnerabilities.
-
CH-03Baseline security standards / hardening
Systems are configured to written security standards.
-
CH-04Network perimeter defence
Network perimeter defences restrict unauthorised access.
-
CH-05Malware protection deployed
Malware protection is in place on systems that support it.
-
CH-06Multi-factor authentication (admin/critical)
MFA secures administrative access and access to critical systems.