Source Document

MAS TRM Guidelines

MAS.TRM.2021.ANNEX-B.1.p55.OBL1

ANNEX-B > ANNEX-B.1

Obligation Summary

The FI should implement data loss prevention measures on personal computing or mobile devices that are used to access the FI's information assets.

SHOULDmedium priorityrecommendationprocessrequirement
Source TextVerbatimView Evidence
The FI should implement data loss prevention measures on personal computing or mobile devices that are used to access the FI’s information assets.

MAS TRM Guidelines, Section ANNEX-B.1, p. 55 (2021) · Technology Risk Management Guidelines · p. 55

In the Documentp. 55

B.1 The FI should implement data loss prevention measures on personal computing or mobile devices that are used to access the FI’s information assets. Two common ways to address BYOD security are the use of mobile device or application management, as well as virtualisation solutions. These solutions can be augmented with other security measures for personal devices to provide enhanced functionalities:

(a) Mobile Device or Application Management

Highlighted Text Is This Obligation

What This Requires.

ProfytAI Regulatory Intelligence

Type: requirement

The FI should implement data loss prevention measures on personal computing or mobile devices that are used to access the FI's information assets.

Relationship

Head obligation of Annex B paragraph B.1; Annex B is a TRM annex giving supplementary guidance on securing personal and mobile computing devices. The paragraph goes on to name mobile device or application management and virtualisation as two common ways to address BYOD security, elaborated in items (a) and (b).

Why This Exists

Personal devices sit outside the FI's managed environment, so information accessed from them can leak beyond the FI's control. This expectation extends the FI's data protection to the BYOD channel.

Implementation Considerations

Typically involves a BYOD policy backed by technical enforcement, such as enrolling personal devices in a device or application management solution or channelling access through a virtualised environment before FI information assets can be reached.

Interpretation Note · Scope is limited to personal devices used to access the FI's information assets, not every employee-owned device. The lead-in presents device or application management and virtualisation as two common solutions, so they are illustrative options rather than an exhaustive or mandated pair. As annex guidance to the TRM Guidelines, 'should' expresses an MAS expectation rather than a binding notice requirement.

This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.

Evidence Capturep. 55

The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Captured source page for MAS.TRM.2021.ANNEX-B.1.p55.OBL1, MAS TRM Guidelines, Section ANNEX-B.1, p. 55 (2021)