MAS.CH.2024.Sec4.1.p3.OBL1
p.3MAS Cyber Hygiene
A relevant entity must ensure that every administrative account in respect of any operating system, database, application, security appliance or network device, is secured to prevent any unauthorised access to or use of such account.
Secure every administrative account against unauthorised access or use.
The clauses around this duty, as written in the source
Notice FSM-N06 on Cyber Hygiene › 4 Cyber Security Requirements › Administrative Accounts › 4.1
Administrative Accounts: A relevant entity must ensure that every administrative account in respect of any operating system, database, application, security appliance or network device, is secured to prevent any unauthorised access to or use of such account.
Security Patches: (a) A relevant entity must ensure that security patches are applied to address vulnerabilities to every system, and apply such security patches within a timeframe that is commensurate with the risks posed by each vulnerability.
Deontic
obligation
Type
Process
Strength
Mandatory
Frequency
Ongoing
Status
In Force
Sanction
supervisory
Marker
4.1
Amendment
New · First Edition
MAS Notice FSM-N06 (Cyber Hygiene), paragraph 4.1, p. 3 (2024)
Consequence. Non-compliance with this Notice may attract MAS supervisory and enforcement action; a MAS notice imposes legally binding requirements on the relevant entities.