- Data
- MAS
- Obligations
- MAS TRM Guidelines, Section 12.3.2, p. 44 (2021)
Source Document
MAS TRM Guidelines
MAS.TRM.2021.Sec12.3.2.p44.OBL1
12 Cyber Security Operations > 12.3 Cyber Incident Response and Management > 12.3.2
Obligation Summary
As part of the cyber incident response and management plan, the FI should establish a process to investigate and identify the security or control deficiencies that resulted in the security breach.
As part of the plan, the FI should establish a process to investigate and identify the security or control deficiencies that resulted in the security breach.
MAS TRM Guidelines, Section 12.3.2, p. 44 (2021) · Technology Risk Management Guidelines · p. 44
12.3.1 The FI should establish a cyber incident response and management plan to swiftly isolate and neutralise a cyber threat and to securely resume affected services. The plan should describe communication, coordination and response procedures to address plausible cyber threat scenarios.
12.3.2 As part of the plan, the FI should establish a process to investigate and identify the security or control deficiencies that resulted in the security breach. The investigation should also evaluate the full extent of the impact to the FI.
12.3.3 Information from cyber intelligence and lessons learnt from cyber incidents should be used to enhance the existing controls or improve the cyber incident management plan.
What This Requires.
ProfytAI Regulatory Intelligence
Type: implementation stepAs part of its cyber incident response plan, the FI should establish a process to investigate and identify the security or control deficiencies that led to a security breach.
Relationship
Expressly framed as part of the plan, making it a component of the cyber incident response and management plan established in the preceding paragraph 12.3.1.
Why This Exists
Root cause investigation turns an incident into corrective action; without it the same deficiency remains exploitable after the incident closes.
Implementation Considerations
Typically post-incident investigation procedures, forensic capability or retainers, and a standard record for capturing identified control deficiencies.
Interpretation Note · The investigation targets the deficiencies that resulted in the breach, meaning causes rather than only incident symptoms. TRM is guidance; SHOULD signals a MAS expectation.
This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.
The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.
