Implement Cyber Resilience per MAS TRM Chapter 11 including Cyber Threat Intelligence + Penetration Testing + Vulnerability Assessment + Cyber Incident Response and Notification. Cyber Threat Intelligence (CTI) programme - subscription to commercial feeds (CrowdStrike + Microsoft + Mandiant + Recorded Future + Anomali + Intel 471 + Flashpoint) + open-source intelligence (OSINT) + dark web monitoring + ISAC participation (FS-ISAC + ABS Cybersecurity Standards + IMDA SingCERT) + government sharing (CSA NCSC ASEAN CSO) + STIX 2.x/TAXII 2.x exchange + Indicators of Compromise (IOCs) + Indicators of Attack (IOAs) + ATT&CK mapping + threat hunt programmes. Penetration Testing - critical systems triennial penetration testing per Notice 644 + Singapore Cyber Resilience Framework (CRF) + Red Team exercises + Purple Team exercises + Bug Bounty programmes + CREST/OSCP certified testers + ATT&CK-aligned objectives. Vulnerability Assessment - vulnerability management programme + monthly external + weekly internal scans + container scanning + cloud configuration scanning + CVSS prioritisation + remediation SLA (critical 24-48 hours + high 7 days + medium 30 days + low 90 days). Cyber Incident Response - 24x7 SOC + Computer Security Incident Response Team (CSIRT) + incident classification + containment + eradication + recovery + lessons learned + tabletop exercises + simulation exercises. **MAS NOTICE 644 PARAGRAPH 6 BINDING REQUIREMENT**: Relevant Incident Notification within 1 HOUR of discovery to MAS Technology Risk and Cybersecurity Department + follow-up root cause analysis within 14 days + remediation plan + customer notification per Notice 644 paragraph 7. CSA SingCERT coordination + CCoP for CII compliance.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.