- Data
- MAS
- Obligations
- MAS TRM, Section 10.2.2, p. 36 (2021)
Source Document
MAS TRM
MAS.TRM.2021.Sec10.2.2.p36.OBL2
Technology Risk Management Guidelines > 10 Cryptography > 10.2 Cryptographic Key Management > 10.2.2
Obligation Summary
Any cryptographic key or sensitive data used to generate or derive keys should be protected or securely destroyed once the key has been generated.
Any cryptographic key or sensitive data used to generate or derive the keys should be also be protected or securely destroyed after the key is generated.
MAS TRM, Section 10.2.2, p. 36 (2021) · Technology Risk Management Guidelines · p. 36
10.2.1 Cryptographic key management policy, standards and procedures covering key generation, distribution, installation, renewal, revocation, recovery and expiry should be established.
10.2.2 The FI should ensure cryptographic keys are securely generated and protected from unauthorised disclosure. Any cryptographic key or sensitive data used to generate or derive the keys should be also be protected or securely destroyed after the key is generated.
10.2.3 The FI should determine the appropriate lifespan of each cryptographic key based on factors, such as the sensitivity of the data, the criticality of the system to be protected, and the threats and risks that the data or system may be exposed to. The cryptographic key should be securely replaced, before it expires at the end of its lifespan.
What This Requires.
ProfytAI Regulatory Intelligence
Type: controlRelationship
It is the second sentence of 10.2.2, signalled as an addition by "also", and extends the confidentiality duty in the first sentence backwards to the material keys are made from.
Why This Exists
If the material a key was derived from survives unprotected, an attacker can reconstruct the key without ever touching the key itself. Closing off the generating material removes a back door that key protection alone would leave open.
Watchouts
Derivation inputs often survive in places nobody treats as a key store, including build scripts, ceremony notes, temporary files and screenshots. The obligation reaches them because it is written around what the material can do, not where it is kept.
Interpretation Note · This is a "should", so it is a supervisory expectation rather than a binding notice requirement. It offers a choice of two outcomes, protection or secure destruction, and either satisfies the expectation. The scope is broad, covering any cryptographic key or sensitive data used to generate or derive keys, so it reaches seed material, master keys and derivation inputs. The trigger point is stated as after the key is generated, which fixes when the decision has to be taken. The source does not define "securely destroyed" or prescribe a destruction method.
This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.
What the duty requires in practice, each with the condition that satisfies it and the evidence an examiner would expect. Derived by ProfytAI, anchored to the verbatim text above.
- 1
For each key generation process, record the input key material and sensitive data it uses and whether that material is retained under protection or securely destroyed.
Done When
A record exists for each key generation process naming its input key material and sensitive data and stating, for each item, either the protection applied to it or the destruction method used and the date.
The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Reproduced from MAS Notices and Guidelines with permission, retrieved from mas.gov.sg. Refer to the MAS website for the latest available version. Highlighting and the verification stamp were added by ProfytAI. The stamp verifies ProfytAI's extraction only and does not represent approval or endorsement by the Monetary Authority of Singapore.