MAS Technology Risk Management Guidelines
Mandatory technology risk management guidelines for financial institutions regulated by the Monetary Authority of Singapore. Covers 15 domains including technology risk governance, IT resilience, access control, cryptography, data and infrastructure security, cyber security operations, and IT audit.
AC (25) AU (2) CA (3) CM (6) CP (13) IA (12) IR (1) MP (7) PL (1) PM (8) PS (1) RA (6) SA (11) SC (12) SI (6) SR (4)
AC Access Control
| Control | Name | MAS TRM References |
|---|---|---|
| AC-01 | Policy and Procedures | 9 |
| AC-02 | Account Management | 9 |
| AC-03 | Access Enforcement | 915 |
| AC-04 | Information Flow Enforcement | 9 |
| AC-05 | Separation of Duties | 9 |
| AC-06 | Least Privilege | 9 |
| AC-07 | Unsuccessful Logon Attempts | 9 |
| AC-08 | System Use Notification | 9 |
| AC-09 | Previous Logon Notification | 9 |
| AC-10 | Concurrent Session Control | 9 |
| AC-11 | Device Lock | 9 |
| AC-12 | Session Termination | 9 |
| AC-13 | Supervision and Review — Access Control | 9 |
| AC-14 | Permitted Actions Without Identification or Authentication | 9 |
| AC-15 | Automated Marking | 9 |
| AC-16 | Security and Privacy Attributes | 9 |
| AC-17 | Remote Access | 914 |
| AC-18 | Wireless Access | 9 |
| AC-19 | Access Control for Mobile Devices | 9 |
| AC-20 | Use of External Systems | 9 |
| AC-21 | Information Sharing | 9 |
| AC-22 | Publicly Accessible Content | 9 |
| AC-23 | Data Mining Protection | 9 |
| AC-24 | Access Control Decisions | 9 |
| AC-25 | Reference Monitor | 9 |
AU Audit and Accountability
CA Security Assessment and Authorization
CM Configuration Management
CP Contingency Planning
| Control | Name | MAS TRM References |
|---|---|---|
| CP-01 | Policy and Procedures | 8 |
| CP-02 | Contingency Plan | 8 |
| CP-03 | Contingency Training | 8 |
| CP-04 | Contingency Plan Testing | 8 |
| CP-05 | Contingency Plan Update | 8 |
| CP-06 | Alternate Storage Site | 8 |
| CP-07 | Alternate Processing Site | 8 |
| CP-08 | Telecommunications Services | 8 |
| CP-09 | System Backup | 8 |
| CP-10 | System Recovery and Reconstitution | 8 |
| CP-11 | Alternate Communications Protocols | 8 |
| CP-12 | Safe Mode | 8 |
| CP-13 | Alternative Security Mechanisms | 8 |
IA Identification and Authentication
| Control | Name | MAS TRM References |
|---|---|---|
| IA-01 | Policy and Procedures | 9 |
| IA-02 | Identification and Authentication (Organizational Users) | 914 |
| IA-03 | Device Identification and Authentication | 9 |
| IA-04 | Identifier Management | 9 |
| IA-05 | Authenticator Management | 9 |
| IA-06 | Authentication Feedback | 9 |
| IA-07 | Cryptographic Module Authentication | 9 |
| IA-08 | Identification and Authentication (Non-organizational Users) | 9 |
| IA-09 | Service Identification and Authentication | 9 |
| IA-10 | Adaptive Authentication | 9 |
| IA-11 | Re-authentication | 9 |
| IA-12 | Identity Proofing | 9 |
IR Incident Response
| Control | Name | MAS TRM References |
|---|---|---|
| IR-04 | Incident Handling | 712 |
MP Media Protection
PL Planning
| Control | Name | MAS TRM References |
|---|---|---|
| PL-09 | Central Management | 4 |
PM Program Management
| Control | Name | MAS TRM References |
|---|---|---|
| PM-01 | Information Security Program Plan | 34 |
| PM-02 | Information Security Program Leadership Role | 3 |
| PM-03 | Information Security and Privacy Resources | 3 |
| PM-07 | Enterprise Architecture | 5 |
| PM-09 | Risk Management Strategy | 34 |
| PM-14 | Testing, Training, and Monitoring | 13 |
| PM-16 | Threat Awareness Program | 12 |
| PM-28 | Risk Framing | 4 |
PS Personnel Security
| Control | Name | MAS TRM References |
|---|---|---|
| PS-09 | Position Descriptions | 3 |
RA Risk Assessment
SA System and Services Acquisition
| Control | Name | MAS TRM References |
|---|---|---|
| SA-03 | System Development Life Cycle | 56 |
| SA-04 | Acquisition Process | 516 |
| SA-08 | Security and Privacy Engineering Principles | 56 |
| SA-09 | External System Services | 16 |
| SA-10 | Developer Configuration Management | 6 |
| SA-11 | Developer Testing and Evaluation | 6 |
| SA-15 | Development Process, Standards, and Tools | 56 |
| SA-16 | Developer-provided Training | 6 |
| SA-17 | Developer Security and Privacy Architecture and Design | 56 |
| SA-20 | Customized Development of Critical Components | 56 |
| SA-21 | Developer Screening | 616 |
SC System and Communications Protection
| Control | Name | MAS TRM References |
|---|---|---|
| SC-07 | Boundary Protection | 111415 |
| SC-08 | Transmission Confidentiality and Integrity | 1014 |
| SC-12 | Cryptographic Key Establishment and Management | 10 |
| SC-13 | Cryptographic Protection | 1014 |
| SC-23 | Session Authenticity | 14 |
| SC-24 | Fail in Known State | 8 |
| SC-26 | Decoys | 12 |
| SC-28 | Protection of Information at Rest | 1015 |
| SC-40 | Wireless Link Protection | 10 |
| SC-41 | Port and I/O Device Access | 11 |
| SC-44 | Detonation Chambers | 12 |
| SC-45 | System Time Synchronization | 14 |