- Data
- MAS
- Obligations
- MAS TRM, Section 12.2.1, p. 43 (2021)
Source Document
MAS TRM
MAS.TRM.2021.Sec12.2.1.p43.OBL1
Technology Risk Management Guidelines > 12 Cyber Security Operations > 12.2 Cyber Event Monitoring and Detection > 12.2.1
Obligation Summary
The FI should either establish a security operations centre or acquire managed security services, so that cyber events are monitored and analysed continuously and cyber incidents are detected and responded to promptly.
To facilitate continuous monitoring and analysis of cyber events;26 as well as prompt detection and response to cyber incidents, the FI should establish a security operations centre or acquire managed security services.
MAS TRM, Section 12.2.1, p. 43 (2021) · Technology Risk Management Guidelines · p. 43
12.2 Cyber Event Monitoring and Detection
12.2.1 To facilitate continuous monitoring and analysis of cyber events;26 as well as prompt detection and response to cyber incidents, the FI should establish a security operations centre or acquire managed security services. The processes, roles and responsibilities for security operations should be defined.
12.2.2 A process to collect, process, review and retain system logs 27 should be established to facilitate the FI’s security monitoring operations. These logs should be protected against unauthorised access.
What This Requires.
ProfytAI Regulatory Intelligence
Type: processRelationship
Opening sentence of 12.2.1 and the substantive duty. The following sentence in the same paragraph expects the processes, roles and responsibilities to be defined, which applies whichever option is chosen.
Why This Exists
Continuous coverage is the point. Attacks do not respect office hours, and detecting an intrusion days later removes most of the options for containing it.
Watchouts
"Prompt detection and response" sits in the same sentence as monitoring. A capability that raises alerts but has no authority or path to act on them out of hours meets only half of what the sentence describes.
Interpretation Note · The "or" is a genuine choice. An in-house centre and bought-in managed services are presented as alternatives and the text does not favour either. What is fixed is the outcome, being continuous monitoring and analysis plus prompt detection and response. "Cyber events" is defined by footnote 26 and covers exploits on system vulnerabilities, system intrusions, privilege escalation, unauthorised system access, data exfiltration and attempts to establish Internet connections to Command and Control servers. It is a "should", so a supervisory expectation. No staffing model, hours or tooling is stated.
This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.
What the duty requires in practice, each with the condition that satisfies it and the evidence an examiner would expect. Derived by ProfytAI, anchored to the verbatim text above.
- 1
Record whether security operations are run in-house or supplied as a managed service.
Done When
A dated record or contract identifies the operating model in force and, where a provider is used, names the provider and the services supplied.
EvidenceSecurity operations mandate or service contract - 2
Confirm the security operations capability monitors the cyber event types described in the Guidelines.
Done When
A coverage mapping shows each cyber event type described in the accompanying footnote is covered by a monitoring or detection rule in use.
EvidenceMonitoring coverage mapping
The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Reproduced from MAS Notices and Guidelines with permission, retrieved from mas.gov.sg. Refer to the MAS website for the latest available version. Highlighting and the verification stamp were added by ProfytAI. The stamp verifies ProfytAI's extraction only and does not represent approval or endorsement by the Monetary Authority of Singapore.