- Data
- MAS
- Obligations
- MAS Notice FSM-N06 (Cyber Hygiene), paragraph 4.4, p. 4 (2024)
Source Document
MAS Notice FSM-N06 (Cyber Hygiene)
MAS.CH.2024.Sec4.4.p4.OBL1
4 Cyber Security Requirements > Network Perimeter Defence > 4.4
Obligation Summary
Implement network-perimeter controls to restrict unauthorised traffic.
A relevant entity must implement controls at its network perimeter to restrict all unauthorised network traffic.
MAS Notice FSM-N06 (Cyber Hygiene), paragraph 4.4, p. 4 (2024) · Notice FSM-N06 on Cyber Hygiene · p. 4
4.3 Security Standards: (a) A relevant entity must ensure that there is a written set of security standards for every system. (b) Subject to sub-paragraph (c), a relevant entity must ensure that every system conforms to the set of security standards. (c) Where the system is unable to conform to the set of security standards, the relevant entity must ensure that controls are instituted to reduce any risk posed by such non- conformity.
4.4 Network Perimeter Defence: A relevant entity must implement controls at its network perimeter to restrict all unauthorised network traffic.
4.5 Malware protection: A relevant entity must ensure that one or more malware protection measures are implemented on every system, to mitigate the risk of malware infection, where such malware protection measures are available and can be implemented.
What This Requires.
ProfytAI Regulatory Intelligence
Type: requirementRequires a relevant entity to implement controls at its network perimeter to restrict all unauthorised network traffic.
Relationship
This is a standalone provision under Section 4.4.p4 (Cyber Security Requirements): it states a complete duty in its own sentence rather than implementing a broader governing clause.
Why This Exists
The network perimeter is the first line of defence. Restricting unauthorised traffic there cuts the attack surface before threats reach internal systems.
Implementation Considerations
Typically involves perimeter controls such as firewalls or gateway filtering with defined rulesets, plus periodic rule reviews to confirm only authorised traffic is permitted.
Interpretation Note · The duty targets 'all unauthorised network traffic' at the perimeter, which presupposes the entity can distinguish authorised from unauthorised traffic; the provision mandates the control outcome without prescribing particular technologies.
This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.
The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.
