Catalog / MAS TRM

MAS TRM Monetary Authority of Singapore

Technology Risk Management review for MAS-regulated institutions — governance, access, change, resilience, and the Cyber Hygiene measures.

9
domains
71
controls
71
tests the agent runs

Control catalog

Technology Risk Governance & Oversight

TRG · 9 controls
  • TRG-01

    Board & senior management oversight of technology risk

    The board and senior management are accountable for, and actively oversee, technology risk.

  • TRG-02

    Approved Technology Risk Management framework

    A documented TRM framework is approved and maintained.

  • TRG-03

    Technology risk appetite & tolerance

    Technology risk appetite is defined, approved, and monitored.

  • TRG-04

    Information security / CISO function

    A dedicated information security function with clear authority and resourcing exists.

  • TRG-05

    Technology risk identification & assessment

    Technology risks are identified and assessed on a structured, periodic basis.

  • TRG-06

    Technology risk register & treatment

    Identified risks are tracked with owners, treatment plans and monitoring.

  • TRG-07

    IT policies & standards

    IT and security policies are documented, approved and current.

  • TRG-08

    Technology risk reporting

    Technology risk is reported to management and the board with sufficient quality and frequency.

  • TRG-09

    Independent assurance / IT audit

    Independent assurance over technology risk is performed.

Access Control

AC · 9 controls
  • AC-01

    User access provisioning & authorisation

    Access is granted only on authorised, role-appropriate request.

  • AC-02

    Timely de-provisioning (leavers/transfers)

    Access is removed promptly when staff leave or change roles.

  • AC-03

    Periodic access recertification

    User access is periodically reviewed and recertified.

  • AC-04

    Privileged / administrative access management

    Privileged access is restricted, individually owned, and monitored.

  • AC-05

    Segregation of duties in access

    Conflicting duties are not concentrated in one individual.

  • AC-06

    Authentication & password standards

    Authentication enforces the security baseline (length, complexity, lockout, history).

  • AC-07

    Multi-factor authentication

    MFA is enforced for administrative, remote and critical-system access.

  • AC-08

    Remote access security

    Remote access to the network/systems is secured and controlled.

  • AC-09

    System / service account management

    Non-human (service) accounts are inventoried, least-privilege and rotated.

Change & Secure Development

CD · 9 controls
  • CD-01

    Change authorisation before deployment

    Production changes are authorised before deployment.

  • CD-02

    Testing & UAT before production

    Changes are tested and business-signed-off before release.

  • CD-03

    Segregation between development and deployment

    Developers cannot deploy their own changes to production.

  • CD-04

    Emergency change management

    Emergency changes receive timely retrospective approval and review.

  • CD-05

    Secure SDLC / security-by-design

    Security is built into the development lifecycle.

  • CD-06

    Source code management & review

    Source code is version-controlled and peer-reviewed.

  • CD-07

    API security & management

    APIs are securely designed, authenticated and managed.

  • CD-08

    Patch & vulnerability remediation

    Security patches are applied within risk-based timelines.

  • CD-09

    Production configuration & version control

    Production configuration is controlled and changes are traceable.

IT Resilience & Service Management

RS · 9 controls
  • RS-01

    Critical system availability (4-hour rule)

    Unscheduled downtime of a critical system does not exceed 4 hours within any 12-month period.

  • RS-02

    Recovery time objective (RTO ≤ 4h)

    Critical systems can be recovered within a 4-hour RTO.

  • RS-03

    Disaster recovery plan & testing

    A DR plan exists and is tested with successful results.

  • RS-04

    Data backup & restoration testing

    Backups run per schedule and restorability is demonstrated.

  • RS-05

    Business continuity management

    Business continuity plans exist and are tested.

  • RS-06

    Capacity & performance management

    Capacity is monitored to maintain performance and availability.

  • RS-07

    Batch / job scheduling & monitoring

    Scheduled jobs are monitored and failures resolved.

  • RS-08

    Problem management

    Recurring incidents are addressed through root-cause problem management.

  • RS-09

    IT incident / service management (operational)

    Operational incidents are managed, prioritised and resolved per SLA.

Data Security & Cryptography

DS · 9 controls
  • DS-01

    Data classification & handling

    Data is classified and handled per its sensitivity.

  • DS-02

    Encryption of data at rest

    Sensitive data at rest is encrypted per the baseline.

  • DS-03

    Encryption of data in transit

    Sensitive data in transit is encrypted.

  • DS-04

    Cryptographic key management

    Cryptographic keys are securely generated, stored, rotated and retired.

  • DS-05

    Data loss prevention

    Controls detect and prevent unauthorised data exfiltration.

  • DS-06

    Data retention & secure disposal

    Data is retained and disposed per policy.

  • DS-07

    Database security & monitoring

    Databases are hardened, access-controlled and monitored.

  • DS-08

    Network security & segmentation

    Networks are segmented and protected.

  • DS-09

    Endpoint security

    Endpoints are protected and managed.

Cyber Security Operations & Monitoring

CO · 8 controls
  • CO-01

    Security event logging & monitoring

    Security-relevant events are logged and monitored centrally.

  • CO-02

    Security operations / threat detection

    Security alerts are triaged and responded to on a timely basis.

  • CO-03

    Incident response plan & handling

    Security incidents are handled per a defined response plan.

  • CO-04

    MAS incident notification (≤ 1 hour)

    Relevant incidents are notified to MAS within 1 hour of discovery.

  • CO-05

    Incident root-cause analysis & 14-day reporting

    Root-cause analysis is submitted to MAS within 14 days for relevant incidents.

  • CO-06

    Threat intelligence & information sharing

    Threat intelligence is used and shared to improve defences.

  • CO-07

    Malware protection

    Malware protection is deployed and current across the estate.

  • CO-08

    Vulnerability remediation within SLA

    Identified vulnerabilities are remediated within risk-based SLAs.

Cyber Security Assessment

CA · 5 controls
  • CA-01

    Vulnerability assessment cadence

    Vulnerability assessments are performed on a defined cadence.

  • CA-02

    Penetration testing

    Penetration tests are performed periodically and findings remediated.

  • CA-03

    Adversarial attack simulation (red teaming)

    Scenario-based / red-team exercises test detection and response.

  • CA-04

    Assessment findings remediation tracking

    Findings from assessments are tracked to closure within SLA.

  • CA-05

    Security review of new / changed systems

    New or significantly changed systems undergo security review before go-live.

Third-Party & Outsourcing Risk

TP · 7 controls
  • TP-01

    Third-party risk assessment

    Third parties are risk-assessed before and during engagement.

  • TP-02

    Material outsourcing register & due diligence

    Material outsourcing arrangements are identified, registered and diligenced.

  • TP-03

    Outsourcing agreements & MAS audit/access rights

    Agreements include required clauses incl. MAS audit/inspection and access rights.

  • TP-04

    Ongoing service-provider monitoring

    Service providers are monitored on an ongoing basis.

  • TP-05

    Cloud outsourcing risk management

    Cloud services are governed with appropriate controls.

  • TP-06

    Concentration & sub-contracting risk

    Concentration and sub-contracting (4th-party) risks are managed.

  • TP-07

    Outsourcing exit & access revocation

    On termination, provider access is revoked and data returned/destroyed.

Cyber Hygiene (Mandatory Baseline)

CH · 6 controls
  • CH-01

    Administrative accounts secured

    Administrative accounts are secured and not used for daily activities.

  • CH-02

    Security patches applied

    Security patches are applied to address known vulnerabilities.

  • CH-03

    Baseline security standards / hardening

    Systems are configured to written security standards.

  • CH-04

    Network perimeter defence

    Network perimeter defences restrict unauthorised access.

  • CH-05

    Malware protection deployed

    Malware protection is in place on systems that support it.

  • CH-06

    Multi-factor authentication (admin/critical)

    MFA secures administrative access and access to critical systems.

See MAS TRM tested against your evidence.