Monetary Authority of Singapore Technology Risk Management Guidelines
Systems Reliability and Data Centre - MAS TRM Chapters 7-8

Monetary Authority of Singapore Technology Risk Management Guidelines MAS-TRM-Reliability-Data-Centre-Chapters-7-8-RTO-RPO-BCP-DR-System-Availability-4-Hours-12-Months: MAS TRM Reliability + Data Centre + Chapters 7-8 + RTO + RPO + BCP + DR + System Availability 4 Hours 12 Months

Implement Systems Reliability Availability and Recoverability + Data Centre Resilience per MAS TRM Chapters 7 + 8. Chapter 7 Systems Reliability + Availability + Recoverability - Recovery Time Objective (RTO) definition + testing + Recovery Point Objective (RPO) definition + testing + system downtime tracking + Business Continuity Plan (BCP) + Disaster Recovery Plan (DRP) + crisis management + tabletop exercises + simulation exercises + full-scale annual DR test + Maximum Tolerable Period of Disruption (MTPD) + Maximum Tolerable Data Loss (MTDL) + critical system identification + system criticality categorisation + dependency mapping + cascading failure analysis. **MAS NOTICE 644 PARAGRAPH 5 BINDING REQUIREMENT**: System downtime no more than 4 hours within any 12-month period for systemically-important systems (systemically-important systems = systems supporting essential financial services + critical business functions + supporting D-SIB operations). Chapter 8 Data Centre Resilience - Tier III or higher data centre + geographically separated primary and secondary + active-active or active-passive configuration + power resilience (UPS + generators + 2N + N+1) + cooling redundancy + fire suppression + physical security + environmental monitoring + Service Organization Control (SOC 2 Type 2) + ISO 22301 BCMS alignment + cloud DR alternatives + multi-region cloud architecture. Annual DR test mandatory + reported to Board + remediation tracked + lessons learned.

What else in your programme already covers this

This control maps to 106 controls across 48 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 27031:2011 · 7 controls

ISO 22316 · 5 controls

  • ISO22316-01 Organizational resilience and security - business continuity policy for building security and resilience
  • ISO22316-08 Recovery time and point objectives
  • ISO22316-12 Recovery strategy for critical activities
  • ISO22316-14 Supply chain continuity
  • ISO22316-15 Communication strategy during disruption

ISO 22317 · 5 controls

ISO 22318 · 5 controls

  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)
  • 4.3.2 Legal and Other Requirements
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • 4.4.2 Competence, Training, and Awareness
  • 4.4.8 Business Continuity and Recovery

API 1164 · 3 controls

  • FFIEC-11 Business continuity planning and testing
  • FFIEC-12 Disaster recovery procedures
  • FFIEC-14 Critical service identification

IEC 62443 · 3 controls

ISO 27019 · 3 controls

APRA CPS 234 · 2 controls

  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • CPS234-15 Information Security Capability
  • 62351-12 Resilience and security recommendations for DER
  • 62351-13 Cyber-physical generation and storage resilience
  • NISTSP34-2 Business Impact Analysis (BIA): Critical Resources, Recovery Priorities
  • NISTSP34-4 Information System Contingency Plan (ISCP) Development

South Korea ISMS-P · 2 controls

  • CPS230-26 Critical Operations Register, Continuity Plan and Activation

COBIT 2019 · 1 control

  • DIQ-1 Data Integration and Interoperability
  • CAT-D5-4 Resilience planning and testing

ISO 20000-1 · 1 control

ISO 22320:2018 · 1 control

ISO 27017 · 1 control

ISO 27018 · 1 control

ISO 27043 · 1 control

ISO/IEC 27007:2020 · 1 control

  • 27007-5.4 Establishing the Programme Resources

ISO/IEC 27010:2015 · 1 control

ISO/IEC 27011:2024 · 1 control

ISO/SAE 21434 · 1 control

ITIL 4 · 1 control

  • ITIL4-03 Capacity and availability management

MITRE ATT&CK · 1 control

  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation

OWASP ASVS · 1 control

  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • KRCSAP-1 CSAP Certification Tiers (IaaS, SaaS, DaaS, AI)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 106 it maps to, and the evidence behind each claim, over MCP and REST.