Source Document

MAS TRM

MAS.TRM.2021.Sec7.4.1.p24.OBL1

Technology Risk Management Guidelines > 7 IT Service Management > 7.4 Patch Management > 7.4.1

Obligation Summary

The FI should run a patch management process that gets applicable patches implemented within timeframes matched to how critical the patch and the affected IT systems are.

SHOULDrecommendationprocessprocess
Source TextVerbatimView Evidence
A patch management process should be established to ensure applicable functional and non-functional patches (e.g. fixes for security vulnerabilities and software bugs) are implemented within a timeframe that is commensurate with the criticality of the patches and the FI’s IT systems.

MAS TRM, Section 7.4.1, p. 24 (2021) · Technology Risk Management Guidelines · p. 24

In the Documentp. 24

7.4 Patch Management

7.4.1 A patch management process should be established to ensure applicable functional and non-functional patches (e.g. fixes for security vulnerabilities and software bugs) are implemented within a timeframe that is commensurate with the criticality of the patches and the FI’s IT systems.

7.4.2 Patches should be tested before they are applied to the FI’s IT systems in the production environment to ensure compatibility with existing IT systems or they do not introduce problems to the IT environment.

Highlighted Text Is This Obligation

What This Requires.

ProfytAI Regulatory Intelligence

Type: process

Relationship

A single sentence forming the whole of 7.4.1 and the opening provision of the patch management section. The pre-production testing gate in 7.4.2 follows it.

Why This Exists

Known but unpatched flaws are among the easiest routes into a system. What matters is not only whether patching happens but how long the window stays open, so the timeframe itself is the thing being controlled.

Watchouts

The wording names non-functional patches as well as functional ones. A process built only around security advisories would leave out part of what this sentence brings into scope.

Interpretation Note · Scope covers both functional and non-functional patches. The examples given, fixes for security vulnerabilities and software bugs, are introduced by "e.g." and are illustrative rather than exhaustive. "Applicable" limits the duty to patches relevant to the FI's own estate. No timeframe is fixed by MAS. It is derived from two variables read together, the criticality of the patch and the criticality of the FI's IT systems. This is a guideline "should", so a supervisory expectation rather than a binding requirement.

This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.

Duties and Evidence Checklist2 duties

What the duty requires in practice, each with the condition that satisfies it and the evidence an examiner would expect. Derived by ProfytAI, anchored to the verbatim text above.

  1. 1

    Document the patch management process, including the implementation timeframes by patch and system criticality.

    Done When

    A written patch process exists stating the criticality categories used for patches and for systems, and the implementation timeframe applying to each combination. The source states no figures.

    EvidencePatch management process document
  2. 2

    Track applicable patches against those timeframes.

    Done When

    A patch record shows, for each applicable patch, its criticality, the systems affected and the date implemented, so compliance with the stated timeframe can be checked.

    EvidencePatch deployment record
Evidence Capturep. 24

The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Captured source page for MAS.TRM.2021.Sec7.4.1.p24.OBL1, MAS TRM, Section 7.4.1, p. 24 (2021)

Reproduced from MAS Notices and Guidelines with permission, retrieved from mas.gov.sg. Refer to the MAS website for the latest available version. Highlighting and the verification stamp were added by ProfytAI. The stamp verifies ProfytAI's extraction only and does not represent approval or endorsement by the Monetary Authority of Singapore.