- Data
- MAS
- Obligations
- MAS Notice FSM-N06 (Cyber Hygiene), paragraph 4.1, p. 3 (2024)
Source Document
MAS Notice FSM-N06 (Cyber Hygiene)
MAS.CH.2024.Sec4.1.p3.OBL1
4 Cyber Security Requirements > Administrative Accounts > 4.1
Obligation Summary
Secure every administrative account against unauthorised access or use.
A relevant entity must ensure that every administrative account in respect of any operating system, database, application, security appliance or network device, is secured to prevent any unauthorised access to or use of such account.
MAS Notice FSM-N06 (Cyber Hygiene), paragraph 4.1, p. 3 (2024) · Notice FSM-N06 on Cyber Hygiene · p. 3
4.1 Administrative Accounts: A relevant entity must ensure that every administrative account in respect of any operating system, database, application, security appliance or network device, is secured to prevent any unauthorised access to or use of such account.
4.2 Security Patches: * (a) A relevant entity must ensure that security patches are applied to address vulnerabilities to every system, and apply such security patches within a timeframe that is commensurate with the risks posed by each vulnerability.
What This Requires.
ProfytAI Regulatory Intelligence
Type: requirementRequires a relevant entity to secure every administrative account for any operating system, database, application, security appliance or network device so as to prevent any unauthorised access to or use of the account.
Relationship
This is a standalone provision under Section 4.1.p3 (Cyber Security Requirements): it states a complete duty in its own sentence rather than implementing a broader governing clause.
Why This Exists
Administrative accounts hold privileged control over systems, so compromising one is a direct route to compromising the institution. MAS mandates their protection as a baseline cyber defence.
Implementation Considerations
Typically involves an inventory of administrative accounts across all asset classes, privileged access management controls, and periodic review that access remains restricted to authorised users.
Interpretation Note · The scope words are broad, covering 'every administrative account' across the five listed asset classes with no materiality or criticality threshold. The standard is outcome-based, securing each account to prevent 'any unauthorised access to or use'. This is a binding notice requirement whose breach may attract supervisory and enforcement action, not guidance.
This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.
The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.
