- Data
- MAS
- Obligations
- MAS TRM Guidelines, Section 9.3.2, p. 35 (2021)
Source Document
MAS TRM Guidelines
MAS.TRM.2021.Sec9.3.2.p35.OBL1
9 Access Control > 9.3 Remote Access Management > 9.3.2
Obligation Summary
The FI should ensure remote access to its information assets is only allowed from devices that have been secured according to the FI's security standards.
The FI should ensure remote access to the FI’s information assets is only allowed from devices that have been secured according to the FI’s security standards.
MAS TRM Guidelines, Section 9.3.2, p. 35 (2021) · Technology Risk Management Guidelines · p. 35
9.3.1 Remote access allows users to connect to the FI’s internal network via an external network to access the FI’s data and systems, such as emails and business applications. Remote connections should be encrypted to prevent data leakage through network sniffing and eavesdropping. Strong authentication, such as multi-factor authentication, should be implemented for users performing remote access to safeguard against unauthorised access to the FI’s IT environment.
9.3.2 The FI should ensure remote access to the FI’s information assets is only allowed from devices that have been secured according to the FI’s security standards.
What This Requires.
ProfytAI Regulatory Intelligence
Type: requirementRemote access to the FI's information assets should be allowed only from devices that have been secured to the FI's own security standards.
Relationship
This is a standalone provision under Section 9.3.2.p35 (Access Control): it states a complete duty in its own sentence rather than implementing a broader governing clause.
Why This Exists
Strong authentication does not help if the connecting endpoint is itself compromised. Conditioning access on device compliance keeps unmanaged or unsafe machines away from the FI's assets.
Implementation Considerations
Typically device posture or compliance checks tied to the remote access service, with managed device enrolment and blocking of non-compliant endpoints.
Interpretation Note · The benchmark is the FI's own security standards, which presupposes those standards exist, and 'only allowed from' makes this exclusionary rather than a preference. TRM is guidance, so this 'should' is a MAS supervisory expectation rather than a binding notice requirement.
This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.
The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.
