- Data
- MAS
- Obligations
- MAS TRM Guidelines, Section 10.2.2, p. 36 (2021)
Source Document
MAS TRM Guidelines
MAS.TRM.2021.Sec10.2.2.p36.OBL1
10 Cryptography > 10.2 Cryptographic Key Management > 10.2.2
Obligation Summary
The FI should ensure cryptographic keys are securely generated and protected from unauthorised disclosure.
The FI should ensure cryptographic keys are securely generated and protected from unauthorised disclosure.
MAS TRM Guidelines, Section 10.2.2, p. 36 (2021) · Technology Risk Management Guidelines · p. 36
10.2.1 Cryptographic key management policy, standards and procedures covering key generation, distribution, installation, renewal, revocation, recovery and expiry should be established.
10.2.2 The FI should ensure cryptographic keys are securely generated and protected from unauthorised disclosure. Any cryptographic key or sensitive data used to generate or derive the keys should be also be protected or securely destroyed after the key is generated.
10.2.3 The FI should determine the appropriate lifespan of each cryptographic key based on factors, such as the sensitivity of the data, the criticality of the system to be
What This Requires.
ProfytAI Regulatory Intelligence
Type: requirementThe FI should ensure cryptographic keys are securely generated and protected from unauthorised disclosure.
Relationship
This is a standalone provision under Section 10.2.2.p36 (Cryptography): it states a complete duty in its own sentence rather than implementing a broader governing clause.
Why This Exists
A disclosed key silently defeats every control built on it, so protection of the key material itself is the foundation the rest of the cryptographic regime stands on.
Implementation Considerations
Typically secure generation ceremonies or modules, restricted key stores, and access controls limiting which people and processes can read key material.
Interpretation Note · Two aspects travel together, secure generation and continuing protection from disclosure; both attach to the key across its life, not only at creation.
This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.
The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.
