Source Document

MAS TRM

MAS.TRM.2021.Sec10.2.2.p36.OBL2

Technology Risk Management Guidelines > 10 Cryptography > 10.2 Cryptographic Key Management > 10.2.2

Obligation Summary

Any cryptographic key or sensitive data used to generate or derive keys should be protected or securely destroyed once the key has been generated.

SHOULDrecommendationprocesscontrol
Source TextVerbatimView Evidence
Any cryptographic key or sensitive data used to generate or derive the keys should be also be protected or securely destroyed after the key is generated.

MAS TRM, Section 10.2.2, p. 36 (2021) · Technology Risk Management Guidelines · p. 36

In the Documentp. 36

10.2.1 Cryptographic key management policy, standards and procedures covering key generation, distribution, installation, renewal, revocation, recovery and expiry should be established.

10.2.2 The FI should ensure cryptographic keys are securely generated and protected from unauthorised disclosure. Any cryptographic key or sensitive data used to generate or derive the keys should be also be protected or securely destroyed after the key is generated.

10.2.3 The FI should determine the appropriate lifespan of each cryptographic key based on factors, such as the sensitivity of the data, the criticality of the system to be protected, and the threats and risks that the data or system may be exposed to. The cryptographic key should be securely replaced, before it expires at the end of its lifespan.

Highlighted Text Is This Obligation

What This Requires.

ProfytAI Regulatory Intelligence

Type: control

Relationship

It is the second sentence of 10.2.2, signalled as an addition by "also", and extends the confidentiality duty in the first sentence backwards to the material keys are made from.

Why This Exists

If the material a key was derived from survives unprotected, an attacker can reconstruct the key without ever touching the key itself. Closing off the generating material removes a back door that key protection alone would leave open.

Watchouts

Derivation inputs often survive in places nobody treats as a key store, including build scripts, ceremony notes, temporary files and screenshots. The obligation reaches them because it is written around what the material can do, not where it is kept.

Interpretation Note · This is a "should", so it is a supervisory expectation rather than a binding notice requirement. It offers a choice of two outcomes, protection or secure destruction, and either satisfies the expectation. The scope is broad, covering any cryptographic key or sensitive data used to generate or derive keys, so it reaches seed material, master keys and derivation inputs. The trigger point is stated as after the key is generated, which fixes when the decision has to be taken. The source does not define "securely destroyed" or prescribe a destruction method.

This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.

Duties and Evidence Checklist1 duty

What the duty requires in practice, each with the condition that satisfies it and the evidence an examiner would expect. Derived by ProfytAI, anchored to the verbatim text above.

  1. 1

    For each key generation process, record the input key material and sensitive data it uses and whether that material is retained under protection or securely destroyed.

    Done When

    A record exists for each key generation process naming its input key material and sensitive data and stating, for each item, either the protection applied to it or the destruction method used and the date.

Evidence Capturep. 36

The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Captured source page for MAS.TRM.2021.Sec10.2.2.p36.OBL2, MAS TRM, Section 10.2.2, p. 36 (2021)

Reproduced from MAS Notices and Guidelines with permission, retrieved from mas.gov.sg. Refer to the MAS website for the latest available version. Highlighting and the verification stamp were added by ProfytAI. The stamp verifies ProfytAI's extraction only and does not represent approval or endorsement by the Monetary Authority of Singapore.