Source Document

MAS TRM

MAS.TRM.2021.Sec8.2.3.p29.OBL1

Technology Risk Management Guidelines > 8 IT Resilience > 8.2 System Recoverability > 8.2.3

Obligation Summary

During recovery the FI should follow its established disaster recovery plan, and that plan should already have been tested and approved by management.

SHOULDrecommendationprocesscontrol
Source TextVerbatimView Evidence
During the recovery process, the FI should follow the established disaster recovery plan that has been tested and approved by management.

MAS TRM, Section 8.2.3, p. 29 (2021) · Technology Risk Management Guidelines · p. 29

In the Documentp. 29

8.2.2 The FI’s disaster recovery plan should include procedures to recover systems from various disaster scenarios, as well as the roles and responsibilities of relevant personnel in the recovery process. The disaster recovery plan should be reviewed at least annually and updated when there are material changes to business operations, information assets or environmental factors.

8.2.3 During the recovery process, the FI should follow the established disaster recovery plan that has been tested and approved by management. The FI should avoid deviating from the plan as untested recovery measures could exacerbate the incident and prolong the recovery process. In exceptional circumstances where untested recovery measures need to be used, the FI should perform a risk assessment and ensure adequate controls are in place, as well as obtain approval from senior management.

8.2.4 The FI should endeavour to operate from its recovery, secondary or alternate site periodically so as to have the assurance that its infrastructure and systems at these sites are able to support business needs for an extended period of time when production systems failover from the primary or production site.

Highlighted Text Is This Obligation

What This Requires.

ProfytAI Regulatory Intelligence

Type: control

Relationship

Opening sentence of 8.2.3. It states the governing rule, and the two sentences that follow deal with deviation and the exception route.

Why This Exists

An incident is the worst moment to discover that a recovery route does not work. Prior testing and management approval mean the steps executed under pressure have been proven and owned in advance.

Watchouts

Testing and approval have to precede the incident. A plan revised since the last test is, on this wording, not the tested plan.

Interpretation Note · Two conditions attach to the plan being followed. It has been tested, and it has been approved by management. Note that this approval sits with "management", a lower bar than the "senior management" approval the same paragraph attaches to the exception route. Guideline "should", so a supervisory expectation rather than a binding notice requirement.

This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.

Duties and Evidence Checklist2 duties

What the duty requires in practice, each with the condition that satisfies it and the evidence an examiner would expect. Derived by ProfytAI, anchored to the verbatim text above.

  1. 1

    Show that the recovery actions taken during an event matched the established plan.

    Done When

    For each recovery event, a record maps the actions performed to the corresponding steps of the approved plan and identifies any step not followed.

    EvidenceIncident recovery record
  2. 2

    Confirm the plan version in use has been tested and carries management approval.

    Done When

    The current plan version carries a dated management approval and a test record that post-dates that version.

    EvidenceApproved and tested disaster recovery plan
Evidence Capturep. 29

The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Captured source page for MAS.TRM.2021.Sec8.2.3.p29.OBL1, MAS TRM, Section 8.2.3, p. 29 (2021)

Reproduced from MAS Notices and Guidelines with permission, retrieved from mas.gov.sg. Refer to the MAS website for the latest available version. Highlighting and the verification stamp were added by ProfytAI. The stamp verifies ProfytAI's extraction only and does not represent approval or endorsement by the Monetary Authority of Singapore.