- Data
- MAS
- Obligations
- MAS TRM, Section 6.1.4, p. 19 (2021)
Source Document
MAS TRM
MAS.TRM.2021.Sec6.1.4.p19.OBL1
Technology Risk Management Guidelines > 6 Software Application Development and Management > 6.1 Secure Coding, Source Code Review and Application Security Testing > 6.1.4
Obligation Summary
The FI should keep track of updates and reported vulnerabilities for third party and open-source code incorporated in its software, so that vulnerabilities can be remediated in a timely manner.
To facilitate the remediation of vulnerabilities in a timely manner, the FI should keep track of updates and reported vulnerabilities for third party and open-source software codes that are incorporated in the FI’s software.
MAS TRM, Section 6.1.4, p. 19 (2021) · Technology Risk Management Guidelines · p. 19
6.1.3 A policy and procedure on the use of third party and open-source software codes should be established to ensure these codes are subject to review and testing before they are integrated into the FI’s software.
6.1.4 To facilitate the remediation of vulnerabilities in a timely manner, the FI should keep track of updates and reported vulnerabilities for third party and open-source software codes that are incorporated in the FI’s software.
6.1.5 The FI should ensure its software developers are trained or have the necessary knowledge and skills to apply the secure coding and application security standards when developing applications.
What This Requires.
ProfytAI Regulatory Intelligence
Type: processRelationship
Follows directly from 6.1.3. Where the preceding paragraph controls external code at the point of entry, this one keeps it under watch for as long as it stays in the software.
Why This Exists
External components are only secure as at the day they were vetted. Vulnerabilities are disclosed after adoption, and a firm cannot patch what it does not know it is running.
Watchouts
Tracking updates is a separate limb from tracking reported vulnerabilities. A process that reacts only to published advisories misses the version drift the first limb covers.
Interpretation Note · Two things are tracked. Updates released for the component, and vulnerabilities reported against it. Scope is limited to code actually incorporated in the FI's software, which presupposes the firm knows what it has deployed. The opening clause explains the purpose, and "timely" is left undefined. No interval, severity scale or source of vulnerability information is specified. Guideline "should", so a supervisory expectation.
This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.
What the duty requires in practice, each with the condition that satisfies it and the evidence an examiner would expect. Derived by ProfytAI, anchored to the verbatim text above.
- 1
Maintain an inventory of the third party and open-source code components incorporated in the FI's software.
Done When
A component inventory exists listing each third party and open-source code component incorporated in the FI's software, and it can be reconciled to the software the FI runs.
EvidenceThird party and open-source component inventory - 2
Track updates and reported vulnerabilities for each inventoried component.
Done When
A tracking record exists showing, for each inventoried component, the updates and reported vulnerabilities identified and the date each was identified.
EvidenceUpdate and vulnerability tracking record
The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Reproduced from MAS Notices and Guidelines with permission, retrieved from mas.gov.sg. Refer to the MAS website for the latest available version. Highlighting and the verification stamp were added by ProfytAI. The stamp verifies ProfytAI's extraction only and does not represent approval or endorsement by the Monetary Authority of Singapore.