Source Document

MAS TRM

MAS.TRM.2021.Sec13.2.1.p45.OBL2

Technology Risk Management Guidelines > 13 Cyber Security Assessment > 13.2 Penetration Testing > 13.2.1

Obligation Summary

For online financial services, penetration testing should combine blackbox and greybox approaches rather than using one alone.

SHOULDrecommendationprocessassessment
Source TextVerbatimView Evidence
A combination of blackbox and greybox testing should be conducted for online financial services.

MAS TRM, Section 13.2.1, p. 45 (2021) · Technology Risk Management Guidelines · p. 45

In the Documentp. 45

13.2 Penetration Testing

13.2.1 The FI should carry out penetration testing (PT) 28 to obtain an in-depth evaluation of its cyber security defences. A combination of blackbox and greybox testing should be conducted for online financial services.

13.2.2 A bug bounty programme is another means by which an FI could discover vulnerabilities in their IT systems by inviting and incentivising ethical or “white hat” hackers to conduct PT on their systems. The FI may consider conducting a bug bounty programme to test the security of its IT infrastructure to complement its PT.

Highlighted Text Is This Obligation

What This Requires.

ProfytAI Regulatory Intelligence

Type: assessment

Relationship

Second sentence of 13.2.1. It qualifies how the PT duty in the first sentence is carried out for one category of service.

Why This Exists

Blackbox testing shows what an unauthenticated outsider can reach. Greybox testing shows what a logged-in customer can reach beyond their own entitlements. Running only one leaves either the perimeter or the authenticated attack surface unexamined.

Watchouts

Greybox as defined in the footnote is customer-level access, not administrator access. Giving testers privileged accounts changes the test and does not match the definition the guidance relies on.

Interpretation Note · "A combination" means both approaches, not a choice between them. Footnote 28 fixes the meanings. Blackbox is testing with no prior knowledge of the environment other than IP address ranges and known URLs. Greybox is testing with credentials, where the assessor is authenticated with the same rights as a normal customer. The trigger is the service being an online financial service, so the combination is not expected across the entire estate. It remains a guideline "should".

This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.

Duties and Evidence Checklist2 duties

What the duty requires in practice, each with the condition that satisfies it and the evidence an examiner would expect. Derived by ProfytAI, anchored to the verbatim text above.

  1. 1

    Identify the online financial services within penetration testing scope.

    Done When

    A list of the FI's online financial services exists and each entry is mapped to its most recent penetration test.

    EvidenceOnline financial services inventory
  2. 2

    Confirm that both blackbox and greybox testing were performed for online financial services.

    Done When

    For each online financial service, the penetration test reports covering it state the method used, and both blackbox and greybox testing are evidenced.

Evidence Capturep. 45

The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Captured source page for MAS.TRM.2021.Sec13.2.1.p45.OBL2, MAS TRM, Section 13.2.1, p. 45 (2021)

Reproduced from MAS Notices and Guidelines with permission, retrieved from mas.gov.sg. Refer to the MAS website for the latest available version. Highlighting and the verification stamp were added by ProfytAI. The stamp verifies ProfytAI's extraction only and does not represent approval or endorsement by the Monetary Authority of Singapore.