Source Document

MAS TRM

MAS.TRM.2021.Sec12.2.1.p43.OBL1

Technology Risk Management Guidelines > 12 Cyber Security Operations > 12.2 Cyber Event Monitoring and Detection > 12.2.1

Obligation Summary

The FI should either establish a security operations centre or acquire managed security services, so that cyber events are monitored and analysed continuously and cyber incidents are detected and responded to promptly.

SHOULDrecommendationprocessprocess
Source TextVerbatimView Evidence
To facilitate continuous monitoring and analysis of cyber events;26 as well as prompt detection and response to cyber incidents, the FI should establish a security operations centre or acquire managed security services.

MAS TRM, Section 12.2.1, p. 43 (2021) · Technology Risk Management Guidelines · p. 43

In the Documentp. 43

12.2 Cyber Event Monitoring and Detection

12.2.1 To facilitate continuous monitoring and analysis of cyber events;26 as well as prompt detection and response to cyber incidents, the FI should establish a security operations centre or acquire managed security services. The processes, roles and responsibilities for security operations should be defined.

12.2.2 A process to collect, process, review and retain system logs 27 should be established to facilitate the FI’s security monitoring operations. These logs should be protected against unauthorised access.

Highlighted Text Is This Obligation

What This Requires.

ProfytAI Regulatory Intelligence

Type: process

Relationship

Opening sentence of 12.2.1 and the substantive duty. The following sentence in the same paragraph expects the processes, roles and responsibilities to be defined, which applies whichever option is chosen.

Why This Exists

Continuous coverage is the point. Attacks do not respect office hours, and detecting an intrusion days later removes most of the options for containing it.

Watchouts

"Prompt detection and response" sits in the same sentence as monitoring. A capability that raises alerts but has no authority or path to act on them out of hours meets only half of what the sentence describes.

Interpretation Note · The "or" is a genuine choice. An in-house centre and bought-in managed services are presented as alternatives and the text does not favour either. What is fixed is the outcome, being continuous monitoring and analysis plus prompt detection and response. "Cyber events" is defined by footnote 26 and covers exploits on system vulnerabilities, system intrusions, privilege escalation, unauthorised system access, data exfiltration and attempts to establish Internet connections to Command and Control servers. It is a "should", so a supervisory expectation. No staffing model, hours or tooling is stated.

This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.

Duties and Evidence Checklist2 duties

What the duty requires in practice, each with the condition that satisfies it and the evidence an examiner would expect. Derived by ProfytAI, anchored to the verbatim text above.

  1. 1

    Record whether security operations are run in-house or supplied as a managed service.

    Done When

    A dated record or contract identifies the operating model in force and, where a provider is used, names the provider and the services supplied.

    EvidenceSecurity operations mandate or service contract
  2. 2

    Confirm the security operations capability monitors the cyber event types described in the Guidelines.

    Done When

    A coverage mapping shows each cyber event type described in the accompanying footnote is covered by a monitoring or detection rule in use.

    EvidenceMonitoring coverage mapping
Evidence Capturep. 43

The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Captured source page for MAS.TRM.2021.Sec12.2.1.p43.OBL1, MAS TRM, Section 12.2.1, p. 43 (2021)

Reproduced from MAS Notices and Guidelines with permission, retrieved from mas.gov.sg. Refer to the MAS website for the latest available version. Highlighting and the verification stamp were added by ProfytAI. The stamp verifies ProfytAI's extraction only and does not represent approval or endorsement by the Monetary Authority of Singapore.