Monetary Authority of Singapore Technology Risk Management Guidelines
Project SDLC and Service Management - MAS TRM Chapters 4-6

Monetary Authority of Singapore Technology Risk Management Guidelines MAS-TRM-Project-SDLC-Service-Management-Chapters-4-5-6-IT-Project-Software-Lifecycle-Change-ITIL: MAS TRM Project + SDLC + Service Management + Chapters 4-6 + IT Project + Software Lifecycle + ITIL

Implement IT Project Management + Software Development Lifecycle + IT Service Management per MAS TRM Chapters 4 + 5 + 6. Chapter 4 IT Project Management - project initiation approval + business case + risk assessment + technology security review + steering committee + status reporting + change advisory + go/no-go gates + project close-out review + PMO programme management office governance. Chapter 5 Software Development Lifecycle (SDLC) - secure coding standards (OWASP Top 10 + OWASP ASVS + CWE Top 25 + CERT Secure Coding) + threat modelling (STRIDE + DREAD + PASTA) + secure design review + code review (static SAST + dynamic DAST + interactive IAST + software composition analysis SCA) + security testing + UAT + penetration testing prior to production + open-source license compliance + Software Bill of Materials (SBOM) + SDLC integration with DevSecOps + CI/CD pipeline security + Infrastructure as Code (IaC) security + container security + secret scanning. Chapter 6 IT Service Management - ITIL 4 alignment + ITIL Foundation/Practitioner/Expert + service catalogue + service level management + change management + release management + incident management + problem management + configuration management + capacity management + availability management + service continuity management + supplier management + IT financial management + portfolio management. Critical IT changes require risk assessment + Change Advisory Board (CAB) approval + back-out plan + post-implementation review. Emergency change procedures with abbreviated approval.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.