Source Document

MAS Notice FSM-N06 (Cyber Hygiene)

MAS.CH.2024.Sec4.4.p4.OBL1

4 Cyber Security Requirements > Network Perimeter Defence > 4.4

Obligation Summary

Implement network-perimeter controls to restrict unauthorised traffic.

MUSThigh priorityobligationprocessrequirement
Source TextVerbatimView Evidence
A relevant entity must implement controls at its network perimeter to restrict all unauthorised network traffic.

MAS Notice FSM-N06 (Cyber Hygiene), paragraph 4.4, p. 4 (2024) · Notice FSM-N06 on Cyber Hygiene · p. 4

In the Documentp. 4

4.3 Security Standards: (a) A relevant entity must ensure that there is a written set of security standards for every system. (b) Subject to sub-paragraph (c), a relevant entity must ensure that every system conforms to the set of security standards. (c) Where the system is unable to conform to the set of security standards, the relevant entity must ensure that controls are instituted to reduce any risk posed by such non- conformity.

4.4 Network Perimeter Defence: A relevant entity must implement controls at its network perimeter to restrict all unauthorised network traffic.

4.5 Malware protection: A relevant entity must ensure that one or more malware protection measures are implemented on every system, to mitigate the risk of malware infection, where such malware protection measures are available and can be implemented.

Highlighted Text Is This Obligation

What This Requires.

ProfytAI Regulatory Intelligence

Type: requirement

Requires a relevant entity to implement controls at its network perimeter to restrict all unauthorised network traffic.

Relationship

This is a standalone provision under Section 4.4.p4 (Cyber Security Requirements): it states a complete duty in its own sentence rather than implementing a broader governing clause.

Why This Exists

The network perimeter is the first line of defence. Restricting unauthorised traffic there cuts the attack surface before threats reach internal systems.

Implementation Considerations

Typically involves perimeter controls such as firewalls or gateway filtering with defined rulesets, plus periodic rule reviews to confirm only authorised traffic is permitted.

Interpretation Note · The duty targets 'all unauthorised network traffic' at the perimeter, which presupposes the entity can distinguish authorised from unauthorised traffic; the provision mandates the control outcome without prescribing particular technologies.

This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.

Evidence Capturep. 4

The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Captured source page for MAS.CH.2024.Sec4.4.p4.OBL1, MAS Notice FSM-N06 (Cyber Hygiene), paragraph 4.4, p. 4 (2024)