Source Document

MAS TRM Guidelines

MAS.TRM.2021.Sec9.3.2.p35.OBL1

9 Access Control > 9.3 Remote Access Management > 9.3.2

Obligation Summary

The FI should ensure remote access to its information assets is only allowed from devices that have been secured according to the FI's security standards.

SHOULDmedium priorityrecommendationprocessrequirement
Source TextVerbatimView Evidence
The FI should ensure remote access to the FI’s information assets is only allowed from devices that have been secured according to the FI’s security standards.

MAS TRM Guidelines, Section 9.3.2, p. 35 (2021) · Technology Risk Management Guidelines · p. 35

In the Documentp. 35

9.3.1 Remote access allows users to connect to the FI’s internal network via an external network to access the FI’s data and systems, such as emails and business applications. Remote connections should be encrypted to prevent data leakage through network sniffing and eavesdropping. Strong authentication, such as multi-factor authentication, should be implemented for users performing remote access to safeguard against unauthorised access to the FI’s IT environment.

9.3.2 The FI should ensure remote access to the FI’s information assets is only allowed from devices that have been secured according to the FI’s security standards.

Highlighted Text Is This Obligation

What This Requires.

ProfytAI Regulatory Intelligence

Type: requirement

Remote access to the FI's information assets should be allowed only from devices that have been secured to the FI's own security standards.

Relationship

This is a standalone provision under Section 9.3.2.p35 (Access Control): it states a complete duty in its own sentence rather than implementing a broader governing clause.

Why This Exists

Strong authentication does not help if the connecting endpoint is itself compromised. Conditioning access on device compliance keeps unmanaged or unsafe machines away from the FI's assets.

Implementation Considerations

Typically device posture or compliance checks tied to the remote access service, with managed device enrolment and blocking of non-compliant endpoints.

Interpretation Note · The benchmark is the FI's own security standards, which presupposes those standards exist, and 'only allowed from' makes this exclusionary rather than a preference. TRM is guidance, so this 'should' is a MAS supervisory expectation rather than a binding notice requirement.

This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.

Evidence Capturep. 35

The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Captured source page for MAS.TRM.2021.Sec9.3.2.p35.OBL1, MAS TRM Guidelines, Section 9.3.2, p. 35 (2021)