Source Document

MAS Notice FSM-N06 (Cyber Hygiene)

MAS.CH.2024.Sec4.1.p3.OBL1

4 Cyber Security Requirements > Administrative Accounts > 4.1

Obligation Summary

Secure every administrative account against unauthorised access or use.

MUSThigh priorityobligationprocessrequirement
Source TextVerbatimView Evidence
A relevant entity must ensure that every administrative account in respect of any operating system, database, application, security appliance or network device, is secured to prevent any unauthorised access to or use of such account.

MAS Notice FSM-N06 (Cyber Hygiene), paragraph 4.1, p. 3 (2024) · Notice FSM-N06 on Cyber Hygiene · p. 3

In the Documentp. 3

4.1 Administrative Accounts: A relevant entity must ensure that every administrative account in respect of any operating system, database, application, security appliance or network device, is secured to prevent any unauthorised access to or use of such account.

4.2 Security Patches: * (a) A relevant entity must ensure that security patches are applied to address vulnerabilities to every system, and apply such security patches within a timeframe that is commensurate with the risks posed by each vulnerability.

Highlighted Text Is This Obligation

What This Requires.

ProfytAI Regulatory Intelligence

Type: requirement

Requires a relevant entity to secure every administrative account for any operating system, database, application, security appliance or network device so as to prevent any unauthorised access to or use of the account.

Relationship

This is a standalone provision under Section 4.1.p3 (Cyber Security Requirements): it states a complete duty in its own sentence rather than implementing a broader governing clause.

Why This Exists

Administrative accounts hold privileged control over systems, so compromising one is a direct route to compromising the institution. MAS mandates their protection as a baseline cyber defence.

Implementation Considerations

Typically involves an inventory of administrative accounts across all asset classes, privileged access management controls, and periodic review that access remains restricted to authorised users.

Interpretation Note · The scope words are broad, covering 'every administrative account' across the five listed asset classes with no materiality or criticality threshold. The standard is outcome-based, securing each account to prevent 'any unauthorised access to or use'. This is a binding notice requirement whose breach may attract supervisory and enforcement action, not guidance.

This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.

Evidence Capturep. 3

The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Captured source page for MAS.CH.2024.Sec4.1.p3.OBL1, MAS Notice FSM-N06 (Cyber Hygiene), paragraph 4.1, p. 3 (2024)