Monetary Authority of Singapore Technology Risk Management Guidelines
Access Control Cryptography Network - MAS TRM Chapters 9-10

Monetary Authority of Singapore Technology Risk Management Guidelines MAS-TRM-Access-Cryptography-Network-Security-Chapters-9-10-MFA-PKI-Encryption-Network-Segmentation: MAS TRM Access Control + Cryptography + Network + Chapters 9-10 + MFA + PKI + Encryption + Network Segmentation

Implement Access Control + Cryptography + Network and Infrastructure Security per MAS TRM Chapters 9 + 10. Chapter 9 Access Control + Cryptography - access control policy + user identification + authentication (Multi-Factor Authentication MFA required for privileged access per Notice 655 + biometric + smart cards + soft tokens) + authorisation (Role-Based Access Control RBAC + Attribute-Based Access Control ABAC + Mandatory Access Control MAC) + accountability (audit logging + monitoring) + least privilege + separation of duties + privileged access management (PAM) with session recording + just-in-time access + service accounts management + machine identities + Cryptography per ISO/IEC 18033 + FIPS 140-2/140-3 validated modules + key management (key generation + storage + rotation + destruction) + Hardware Security Module (HSM) for key storage + Public Key Infrastructure (PKI) + Certificate Authority (CA) + Certificate Lifecycle Management + algorithm strength (AES-256 + RSA-3072+ + ECC P-256+ + SHA-256+) + Post-Quantum Cryptography (PQC) preparation per NIST PQC. Chapter 10 Network and Infrastructure Security - network segmentation (perimeter + DMZ + internal + management + critical systems + customer-facing) + firewall + IDS/IPS + DDoS protection + WAF + network access control (NAC) + 802.1X + secure remote access + VPN + bastion host + jump server + privileged access workstation (PAW) + endpoint protection (EPP + EDR + XDR) + email security (S/MIME + DKIM + DMARC + SPF + ATP) + DNS security + zero trust architecture (NIST SP 800-207 + CISA Zero Trust Maturity Model). MAS Notice 655 baseline: administrative accounts + security patching + security standards + network perimeter + malware protection + MFA.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.