Source Document

MAS TRM

MAS.TRM.2021.ANNEX-C.1(a).p56.OBL1

Technology Risk Management Guidelines > Annex C: Mobile Application Security > C.1(a)

Obligation Summary

Data held by a mobile application should be kept in a protected and trusted area of the device rather than in general storage.

SHOULDrecommendationprocesscontrol
Source TextVerbatimView Evidence
Data should be stored in a protected and trusted area of the mobile device;

MAS TRM, Section C.1(a), p. 56 (2021) · Technology Risk Management Guidelines · p. 56

What This Requires.

ProfytAI Regulatory Intelligence

Type: control

Relationship

The first of Annex C's mobile application security measures, and the storage foundation the annex's other measures depend on.

Why This Exists

A mobile device is a shared, portable, frequently compromised environment. Application data written to general storage is reachable by other applications, by backups and by anyone with the unlocked handset, so where the data sits determines whether losing the phone means losing the data.

Watchouts

Application sandboxing is often assumed to be sufficient, since another app cannot normally read the container. Sandboxing is defeated on a rooted or jailbroken device and does not always cover backups, which is why the annex asks for a protected area specifically rather than for default application storage.

Interpretation Note · Protected and trusted are both qualifiers on the storage area, pointing at platform-provided secure storage rather than at application-level obfuscation. The annex frames these as measures that should be considered, so this is a recommendation rather than an absolute requirement.

This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.

Duties and Evidence Checklist1 duty

What the duty requires in practice, each with the condition that satisfies it and the evidence an examiner would expect. Derived by ProfytAI, anchored to the verbatim text above.

  1. 1

    Confirm that every location where the mobile application writes data on the device is within the platform's protected and trusted storage area.

    Done When

    A review record exists identifying every location the application writes data to on the device and showing, for each, that it lies within the platform's protected and trusted storage area.

    EvidenceMobile application storage review record
Evidence Capturep. 56

The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Captured source page for MAS.TRM.2021.ANNEX-C.1(a).p56.OBL1, MAS TRM, Section C.1(a), p. 56 (2021)

Reproduced from MAS Notices and Guidelines with permission, retrieved from mas.gov.sg. Refer to the MAS website for the latest available version. Highlighting and the verification stamp were added by ProfytAI. The stamp verifies ProfytAI's extraction only and does not represent approval or endorsement by the Monetary Authority of Singapore.