Source Document

MAS TRM

MAS.TRM.2021.Sec9.1.5.p34.OBL1

Technology Risk Management Guidelines > 9 Access Control > 9.1 User Access Management > 9.1.5

Obligation Summary

Multi-factor authentication should be implemented for users who have access to sensitive system functions.

SHOULDrecommendationprocesscontrol
Source TextVerbatimView Evidence
Multi-factor authentication21 should be implemented for users with access to sensitive system functions to safeguard the systems and data from unauthorised access.

MAS TRM, Section 9.1.5, p. 34 (2021) · Technology Risk Management Guidelines · p. 34

In the Documentp. 34

9.1.4 The FI should establish a password policy and a process to enforce strong password controls20 for users’ access to IT systems.

9.1.5 Multi-factor authentication21 should be implemented for users with access to sensitive system functions to safeguard the systems and data from unauthorised access.

9.1.6 The FI should ensure appropriate parties such as information asset owners perform periodic user access review to verify the appropriateness of privileges that are granted to users. The user access review should be used to identify dormant and redundant user accounts, as well as inappropriate access rights. Exceptions noted from the user access review should be resolved as soon as practicable.

Highlighted Text Is This Obligation

What This Requires.

ProfytAI Regulatory Intelligence

Type: control

Relationship

Paragraph 9.1.5 is a single standalone sentence sitting between the password controls in 9.1.4 and the access review duty in 9.1.6. It strengthens authentication for the higher risk subset of users.

Why This Exists

A single credential can be stolen, guessed or reused without the holder knowing. Where the function reached by that credential can cause real damage, one factor is not a proportionate gate.

Watchouts

Two secrets of the same category are not two factors. A password plus a security question both fall under something the user knows, which does not meet the footnote 21 definition.

Interpretation Note · This is a guideline "should", so it is an expectation rather than a binding requirement. The trigger is access to sensitive system functions, not all access, so the firm has to decide which functions are sensitive before it can define the population. Footnote 21 defines multi-factor authentication as two or more factors verifying a claimed identity and gives three factor categories as examples, something the user knows, something the user has, and something the user is. The list is expressly not exhaustive. Nothing in the provision endorses a particular method, token type or vendor. The stated purpose, safeguarding systems and data from unauthorised access, frames how the control should be judged.

This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.

Duties and Evidence Checklist2 duties

What the duty requires in practice, each with the condition that satisfies it and the evidence an examiner would expect. Derived by ProfytAI, anchored to the verbatim text above.

  1. 1

    Identify the sensitive system functions and the users who can access them.

    Done When

    A dated record lists the system functions assessed as sensitive and, for each, the users or roles able to access it.

    EvidenceSensitive system function and access inventory
  2. 2

    Confirm multi-factor authentication is in force for each of those users.

    Done When

    For each user on the in-scope list, a configuration or authentication record shows more than one factor is required at logon, with the date checked.

    EvidenceAuthentication configuration record
Evidence Capturep. 34

The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Captured source page for MAS.TRM.2021.Sec9.1.5.p34.OBL1, MAS TRM, Section 9.1.5, p. 34 (2021)

Reproduced from MAS Notices and Guidelines with permission, retrieved from mas.gov.sg. Refer to the MAS website for the latest available version. Highlighting and the verification stamp were added by ProfytAI. The stamp verifies ProfytAI's extraction only and does not represent approval or endorsement by the Monetary Authority of Singapore.