MAS Technology Risk Management Guidelines
Mandatory technology risk management guidelines for financial institutions regulated by the Monetary Authority of Singapore. Covers 15 domains including technology risk governance, IT resilience, access control, cryptography, data and infrastructure security, cyber security operations, and IT audit.
| Clause | Title | SP 800-53 Controls |
|---|---|---|
| 3 | Board and Senior Management Oversight | |
| 4 | Technology Risk Management Framework | |
| 5 | IT Project Management and Security-by-Design | |
| 6 | Software Application Development and Management | |
| 7 | IT Service Management | |
| 8 | IT Resilience | |
| 9 | Access Control | |
| 10 | Cryptography | |
| 11 | Data and Infrastructure Security | |
| 12 | Cyber Security Operations | |
| 13 | Cyber Security Assessment | |
| 14 | Online Financial Services | |
| 15 | Payment Card Security | |
| 16 | Technology Risk Arising from Third Party Arrangements |