{
  "code": "MAS-TRM",
  "name": "MAS Technology Risk Management Guidelines",
  "version": "2021",
  "issuing_body": "Monetary Authority of Singapore",
  "description": "Guidelines on Technology Risk Management for financial institutions in Singapore",
  "regions": ["sg"],
  "industries": ["Financial Services"],
  "effective_date": "2021-01-18",
  "is_global": false,
  "requirements": [
    {
      "reference_code": "3",
      "title": "Board and Senior Management Responsibilities",
      "requirement_type": "mandatory",
      "category": "Governance",
      "children": [
        { "reference_code": "3.1", "title": "Board oversight of technology risk", "description": "The board is responsible for setting the tone and oversight of the FI's technology risk management.", "requirement_type": "mandatory" },
        { "reference_code": "3.2", "title": "Senior management responsibilities", "description": "Senior management is responsible for developing and implementing technology risk management framework.", "requirement_type": "mandatory" },
        { "reference_code": "3.3", "title": "Chief Information Officer responsibilities", "description": "The CIO is responsible for the overall management of technology functions and risks.", "requirement_type": "mandatory" },
        { "reference_code": "3.4", "title": "Chief Information Security Officer responsibilities", "description": "The CISO is responsible for the overall management of information security risks.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "4",
      "title": "Technology Risk Management Framework",
      "requirement_type": "mandatory",
      "category": "Risk Management",
      "children": [
        { "reference_code": "4.1", "title": "Technology risk appetite", "description": "Establish a technology risk appetite that is aligned with business strategies.", "requirement_type": "mandatory" },
        { "reference_code": "4.2", "title": "Technology risk management policies and procedures", "description": "Maintain comprehensive and robust technology risk management policies and procedures.", "requirement_type": "mandatory" },
        { "reference_code": "4.3", "title": "Technology risk identification and assessment", "description": "Establish processes to identify and assess technology risks in a timely and systematic manner.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "5",
      "title": "Cyber Resilience",
      "requirement_type": "mandatory",
      "category": "Cyber Security",
      "children": [
        { "reference_code": "5.1", "title": "Cybersecurity governance and oversight", "description": "Establish a robust cybersecurity governance framework.", "requirement_type": "mandatory" },
        { "reference_code": "5.2", "title": "Cyber risk assessment", "description": "Regularly conduct cyber risk assessments to identify and evaluate cyber risks.", "requirement_type": "mandatory" },
        { "reference_code": "5.3", "title": "Cyber security measures", "description": "Implement robust cyber security measures to protect systems and data.", "requirement_type": "mandatory" },
        { "reference_code": "5.4", "title": "Cyber incident management", "description": "Establish processes for effective management of cyber incidents.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "6",
      "title": "IT Infrastructure Management",
      "requirement_type": "mandatory",
      "category": "Infrastructure",
      "children": [
        { "reference_code": "6.1", "title": "IT infrastructure planning", "description": "Plan IT infrastructure capacity based on business requirements and projected growth.", "requirement_type": "mandatory" },
        { "reference_code": "6.2", "title": "IT infrastructure maintenance", "description": "Maintain IT infrastructure components in a secured and resilient manner.", "requirement_type": "mandatory" },
        { "reference_code": "6.3", "title": "Network management", "description": "Implement proper network segmentation and access controls.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "7",
      "title": "IT Project Management",
      "requirement_type": "mandatory",
      "category": "Change Management",
      "children": [
        { "reference_code": "7.1", "title": "Project governance", "description": "Establish a project governance framework for IT projects.", "requirement_type": "mandatory" },
        { "reference_code": "7.2", "title": "System testing", "description": "Conduct rigorous testing before implementing new or changed systems.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "8",
      "title": "Information Security",
      "requirement_type": "mandatory",
      "category": "Information Security",
      "children": [
        { "reference_code": "8.1", "title": "Access controls", "description": "Implement robust access control policies and procedures.", "requirement_type": "mandatory" },
        { "reference_code": "8.2", "title": "Cryptography", "description": "Apply cryptographic controls to protect the confidentiality and integrity of data.", "requirement_type": "mandatory" },
        { "reference_code": "8.3", "title": "Data leakage prevention", "description": "Implement data leakage prevention controls.", "requirement_type": "mandatory" }
      ]
    }
  ]
}
