Implement Technology Risk Governance + Technology Risk Management Framework + Information Asset Management per MAS TRM Chapters 2 + 3 + 5. Chapter 2 Technology Risk Governance and Oversight - Board responsibility for technology risk + Senior Management implementation + Chief Information Officer (CIO) role + Chief Information Security Officer (CISO) role + Technology Risk Committee + Risk Appetite Statement for technology risk + Three Lines of Defence (1st line Technology + 2nd line Risk Management + 3rd line Internal Audit). MAS Notice 644 paragraph 4 binding Board and Senior Management responsibility. Chapter 3 Technology Risk Management Framework - risk identification + risk assessment + risk treatment + risk monitoring + risk reporting + ISO 31000 alignment + COSO ERM integration + risk taxonomy + risk register + Key Risk Indicators (KRIs) + Risk and Control Self-Assessment (RCSA) + risk acceptance criteria. Chapter 5 Information Asset Management - asset inventory (hardware + software + data + virtual assets) + asset classification (CIA triad + Public/Internal/Confidential/Restricted) + asset ownership + acceptable use policy + lifecycle management + Configuration Management Database (CMDB) + Software Asset Management (SAM) + IT Asset Management (ITAM) tooling integration. Risk assessment annually + ad-hoc upon material change. Risk reporting to Board and MAS upon request.
This control maps to 173 controls across 93 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 173 it maps to, and the evidence behind each claim, over MCP and REST.