- Data
- MAS
- Obligations
- MAS TRM Guidelines, Section 6.4.4, p. 21 (2021)
Source Document
MAS TRM Guidelines
MAS.TRM.2021.Sec6.4.4.p21.OBL1
6 Software Application Development and Management > 6.4 Application Programming Interface Development > 6.4.4
Obligation Summary
The FI should establish security standards for designing and developing secure APIs.
Security standards for designing and developing secure APIs should be established.
MAS TRM Guidelines, Section 6.4.4, p. 21 (2021) · Technology Risk Management Guidelines · p. 21
6.4.3 The FI should perform a risk assessment before allowing third parties to connect to its IT systems via APIs, and ensure the implementation for each API is commensurate with the sensitivity and business criticality of the data being exchanged, and the confidentiality and integrity requirements of the data.
6.4.4 Security standards for designing and developing secure APIs should be established. The standards should include the measures to protect the API keys or access tokens,<sup>10</sup> which are used to authorise access to APIs to exchange confidential data. A reasonable timeframe should be defined and enforced for access token expiry to reduce the risk of unauthorised access.
6.4.5 Strong encryption standards and key management controls should be adopted to secure transmission of sensitive data through APIs.
What This Requires.
ProfytAI Regulatory Intelligence
Type: requirementSecurity standards for designing and developing secure APIs should be established.
Relationship
First sentence of paragraph 6.4.4; the following sentences require the standards to include protection of API keys and access tokens and an enforced token expiry timeframe.
Why This Exists
A written standard makes API security repeatable across teams instead of dependent on individual developer judgment.
Implementation Considerations
An API security standard covering design and development requirements, referenced by development teams and checked during review and testing.
Interpretation Note · As TRM Guidelines guidance, SHOULD marks a MAS supervisory expectation rather than a binding notice requirement.
This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.
The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.
