- Data
- MAS
- Obligations
- MAS TRM, Section 13.2.1, p. 45 (2021)
Source Document
MAS TRM
MAS.TRM.2021.Sec13.2.1.p45.OBL2
Technology Risk Management Guidelines > 13 Cyber Security Assessment > 13.2 Penetration Testing > 13.2.1
Obligation Summary
For online financial services, penetration testing should combine blackbox and greybox approaches rather than using one alone.
A combination of blackbox and greybox testing should be conducted for online financial services.
MAS TRM, Section 13.2.1, p. 45 (2021) · Technology Risk Management Guidelines · p. 45
13.2 Penetration Testing
13.2.1 The FI should carry out penetration testing (PT) 28 to obtain an in-depth evaluation of its cyber security defences. A combination of blackbox and greybox testing should be conducted for online financial services.
13.2.2 A bug bounty programme is another means by which an FI could discover vulnerabilities in their IT systems by inviting and incentivising ethical or “white hat” hackers to conduct PT on their systems. The FI may consider conducting a bug bounty programme to test the security of its IT infrastructure to complement its PT.
What This Requires.
ProfytAI Regulatory Intelligence
Type: assessmentRelationship
Second sentence of 13.2.1. It qualifies how the PT duty in the first sentence is carried out for one category of service.
Why This Exists
Blackbox testing shows what an unauthenticated outsider can reach. Greybox testing shows what a logged-in customer can reach beyond their own entitlements. Running only one leaves either the perimeter or the authenticated attack surface unexamined.
Watchouts
Greybox as defined in the footnote is customer-level access, not administrator access. Giving testers privileged accounts changes the test and does not match the definition the guidance relies on.
Interpretation Note · "A combination" means both approaches, not a choice between them. Footnote 28 fixes the meanings. Blackbox is testing with no prior knowledge of the environment other than IP address ranges and known URLs. Greybox is testing with credentials, where the assessor is authenticated with the same rights as a normal customer. The trigger is the service being an online financial service, so the combination is not expected across the entire estate. It remains a guideline "should".
This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.
What the duty requires in practice, each with the condition that satisfies it and the evidence an examiner would expect. Derived by ProfytAI, anchored to the verbatim text above.
- 1
Identify the online financial services within penetration testing scope.
Done When
A list of the FI's online financial services exists and each entry is mapped to its most recent penetration test.
EvidenceOnline financial services inventory - 2
Confirm that both blackbox and greybox testing were performed for online financial services.
Done When
For each online financial service, the penetration test reports covering it state the method used, and both blackbox and greybox testing are evidenced.
The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Reproduced from MAS Notices and Guidelines with permission, retrieved from mas.gov.sg. Refer to the MAS website for the latest available version. Highlighting and the verification stamp were added by ProfytAI. The stamp verifies ProfytAI's extraction only and does not represent approval or endorsement by the Monetary Authority of Singapore.