Source Document

MAS TRM Guidelines

MAS.TRM.2021.Sec5.4.1.p16.OBL2

5 IT Project Management and Security-by-Design > 5.4 System Development Life Cycle and Security-By-Design > 5.4.1

Obligation Summary

The framework should clearly define the processes, procedures and controls in each phase of the life cycle, such as initiation/planning, requirements analysis, design, implementation, testing and acceptance.

SHOULDmedium priorityrecommendationprocessrequirement
Source TextVerbatimView Evidence
The framework<sup>6</sup> should clearly define the processes, procedures and controls in each phase of the life cycle, such as initiation/planning, requirements analysis, design, implementation, testing and acceptance.

MAS TRM Guidelines, Section 5.4.1, p. 16 (2021) · Technology Risk Management Guidelines · p. 16

In the Documentp. 16

5.4 System Development Life Cycle and Security-By-Design

5.4.1 The FI should establish a framework to manage its system development life cycle (SDLC). <sup>5</sup> The framework<sup>6</sup> should clearly define the processes, procedures and controls in each phase of the life cycle, such as initiation/planning, requirements analysis, design, implementation, testing and acceptance. Standards and procedures for the different phases of the SDLC should be maintained.

5.4.2 The security-by-design approach refers to building security in every phase of the SDLC in order to minimise system vulnerabilities and reduce the attack surface. The FI should incorporate security specifications in the system design, perform continuous security evaluation, and adhere to security practices throughout the SDLC.

Highlighted Text Is This Obligation

What This Requires.

ProfytAI Regulatory Intelligence

Type: requirement

The SDLC framework should clearly define the processes, procedures and controls in each phase of the life cycle, such as initiation and planning, requirements analysis, design, implementation, testing and acceptance.

Relationship

Second expectation from paragraph 5.4.1; it prescribes the content of the SDLC framework required by the first extracted obligation (OBL1).

Why This Exists

Phase-level definition is what makes an SDLC enforceable; without it, controls exist in principle but no one can say what must happen at which stage.

Implementation Considerations

Typically involves documenting entry and exit criteria, activities and control points for every SDLC phase in the methodology.

Interpretation Note · The phase list is introduced with 'such as' and is illustrative, not exhaustive; definition is expected 'in each phase', whatever phases the FI's methodology uses. The verbatim carries a footnote marker on 'framework'. As guidance, 'should' is a MAS expectation.

This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.

Evidence Capturep. 16

The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Captured source page for MAS.TRM.2021.Sec5.4.1.p16.OBL2, MAS TRM Guidelines, Section 5.4.1, p. 16 (2021)