- Data
- MAS
- Obligations
- MAS Notice FSM-N06 (Cyber Hygiene), paragraph 4.2(a), p. 3 (2024)
Source Document
MAS Notice FSM-N06 (Cyber Hygiene)
MAS.CH.2024.Sec4.2(a).p3.OBL1
4 Cyber Security Requirements > Security Patches > 4.2(a)
Obligation Summary
Apply security patches to every system within a risk-commensurate timeframe.
A relevant entity must ensure that security patches are applied to address vulnerabilities to every system, and apply such security patches within a timeframe that is commensurate with the risks posed by each vulnerability.
MAS Notice FSM-N06 (Cyber Hygiene), paragraph 4.2(a), p. 3 (2024) · Notice FSM-N06 on Cyber Hygiene · p. 3
4.1 Administrative Accounts: A relevant entity must ensure that every administrative account in respect of any operating system, database, application, security appliance or network device, is secured to prevent any unauthorised access to or use of such account.
* (a) A relevant entity must ensure that security patches are applied to address vulnerabilities to every system, and apply such security patches within a timeframe that is commensurate with the risks posed by each vulnerability.
(b) Where no security patch is available to address a vulnerability, the relevant entity must ensure that controls are instituted to reduce any risk posed by such vulnerability to such a system.
What This Requires.
ProfytAI Regulatory Intelligence
Type: requirementRequires a relevant entity to ensure security patches are applied to address vulnerabilities on every system, and to apply them within a timeframe commensurate with the risks each vulnerability poses.
Relationship
Sub-paragraph (a) of the paragraph 4.2 security patches requirement; sub-paragraph (b) supplies the fallback duty for cases where no security patch is available.
Why This Exists
Unpatched vulnerabilities are a primary attack vector. Requiring timely, risk-proportionate patching shrinks the exposure window in line with the severity of each flaw.
Implementation Considerations
Typically involves vulnerability identification, a risk-rating scheme mapping severity to patching deadlines, and tracking of patch deployment against those deadlines.
Interpretation Note · Two elements operate together, application of patches to 'every system' and a deadline 'commensurate with the risks posed by each vulnerability', which implies a per-vulnerability risk assessment rather than a single fixed patching window.
This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.
The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.
.p3.OBL1.png)