← Frameworks / MAS TRM / Control Mappings

MAS Technology Risk Management Guidelines

Mandatory technology risk management guidelines for financial institutions regulated by the Monetary Authority of Singapore. Covers 15 domains including technology risk governance, IT resilience, access control, cryptography, data and infrastructure security, cyber security operations, and IT audit.

AC Access Control

Control Name MAS TRM References
AC-01 Policy and Procedures
9
AC-02 Account Management
9
AC-03 Access Enforcement
915
AC-04 Information Flow Enforcement
9
AC-05 Separation of Duties
9
AC-06 Least Privilege
9
AC-07 Unsuccessful Logon Attempts
9
AC-08 System Use Notification
9
AC-09 Previous Logon Notification
9
AC-10 Concurrent Session Control
9
AC-11 Device Lock
9
AC-12 Session Termination
9
AC-13 Supervision and Review — Access Control
9
AC-14 Permitted Actions Without Identification or Authentication
9
AC-15 Automated Marking
9
AC-16 Security and Privacy Attributes
9
AC-17 Remote Access
914
AC-18 Wireless Access
9
AC-19 Access Control for Mobile Devices
9
AC-20 Use of External Systems
9
AC-21 Information Sharing
9
AC-22 Publicly Accessible Content
9
AC-23 Data Mining Protection
9
AC-24 Access Control Decisions
9
AC-25 Reference Monitor
9

AU Audit and Accountability

Control Name MAS TRM References
AU-02 Event Logging
15
AU-06 Audit Record Review, Analysis, and Reporting
12

CA Security Assessment and Authorization

Control Name MAS TRM References
CA-02 Control Assessments
13
CA-07 Continuous Monitoring
712
CA-08 Penetration Testing
13

CM Configuration Management

Control Name MAS TRM References
CM-02 Baseline Configuration
11
CM-03 Configuration Change Control
7
CM-06 Configuration Settings
11
CM-07 Least Functionality
11
CM-12 Information Location
11
CM-14 Signed Components
6

CP Contingency Planning

Control Name MAS TRM References
CP-01 Policy and Procedures
8
CP-02 Contingency Plan
8
CP-03 Contingency Training
8
CP-04 Contingency Plan Testing
8
CP-05 Contingency Plan Update
8
CP-06 Alternate Storage Site
8
CP-07 Alternate Processing Site
8
CP-08 Telecommunications Services
8
CP-09 System Backup
8
CP-10 System Recovery and Reconstitution
8
CP-11 Alternate Communications Protocols
8
CP-12 Safe Mode
8
CP-13 Alternative Security Mechanisms
8

IA Identification and Authentication

Control Name MAS TRM References
IA-01 Policy and Procedures
9
IA-02 Identification and Authentication (Organizational Users)
914
IA-03 Device Identification and Authentication
9
IA-04 Identifier Management
9
IA-05 Authenticator Management
9
IA-06 Authentication Feedback
9
IA-07 Cryptographic Module Authentication
9
IA-08 Identification and Authentication (Non-organizational Users)
9
IA-09 Service Identification and Authentication
9
IA-10 Adaptive Authentication
9
IA-11 Re-authentication
9
IA-12 Identity Proofing
9

IR Incident Response

Control Name MAS TRM References
IR-04 Incident Handling
712

MP Media Protection

Control Name MAS TRM References
MP-01 Policy and Procedures
11
MP-02 Media Access
11
MP-03 Media Marking
11
MP-04 Media Storage
11
MP-05 Media Transport
11
MP-06 Media Sanitization
11
MP-07 Media Use
11

PL Planning

Control Name MAS TRM References
PL-09 Central Management
4

PM Program Management

Control Name MAS TRM References
PM-01 Information Security Program Plan
34
PM-02 Information Security Program Leadership Role
3
PM-03 Information Security and Privacy Resources
3
PM-07 Enterprise Architecture
5
PM-09 Risk Management Strategy
34
PM-14 Testing, Training, and Monitoring
13
PM-16 Threat Awareness Program
12
PM-28 Risk Framing
4

PS Personnel Security

Control Name MAS TRM References
PS-09 Position Descriptions
3

RA Risk Assessment

Control Name MAS TRM References
RA-01 Policy and Procedures
4
RA-03 Risk Assessment
4
RA-05 Vulnerability Monitoring and Scanning
13
RA-07 Risk Response
4
RA-09 Criticality Analysis
413
RA-10 Threat Hunting
12

SA System and Services Acquisition

Control Name MAS TRM References
SA-03 System Development Life Cycle
56
SA-04 Acquisition Process
516
SA-08 Security and Privacy Engineering Principles
56
SA-09 External System Services
16
SA-10 Developer Configuration Management
6
SA-11 Developer Testing and Evaluation
6
SA-15 Development Process, Standards, and Tools
56
SA-16 Developer-provided Training
6
SA-17 Developer Security and Privacy Architecture and Design
56
SA-20 Customized Development of Critical Components
56
SA-21 Developer Screening
616

SC System and Communications Protection

Control Name MAS TRM References
SC-07 Boundary Protection
111415
SC-08 Transmission Confidentiality and Integrity
1014
SC-12 Cryptographic Key Establishment and Management
10
SC-13 Cryptographic Protection
1014
SC-23 Session Authenticity
14
SC-24 Fail in Known State
8
SC-26 Decoys
12
SC-28 Protection of Information at Rest
1015
SC-40 Wireless Link Protection
10
SC-41 Port and I/O Device Access
11
SC-44 Detonation Chambers
12
SC-45 System Time Synchronization
14

SI System and Information Integrity

Control Name MAS TRM References
SI-02 Flaw Remediation
7
SI-03 Malicious Code Protection
11
SI-04 System Monitoring
1112
SI-13 Predictable Failure Prevention
7
SI-16 Memory Protection
11
SI-17 Fail-safe Procedures
8

SR Supply Chain Risk Management

Control Name MAS TRM References
SR-01 Policy and Procedures
16
SR-02 Supply Chain Risk Management Plan
16
SR-03 Supply Chain Controls and Processes
16
SR-06 Supplier Assessments and Reviews
16