MTCS (Singapore)
14: Secure configuration – MTCS (Singapore)

MTCS (Singapore) 14.2: Server and network device configuration standards

Configuration standards covering every server, network device and system component, virtual images, snapshots and the hypervisor included, consistent with industry-accepted hardening standards. Level 1 (a to f): configuration files of network devices and servers kept secure and synchronised; vendor-supplied default settings changed before a system joins the network; hardened configurations for images, snapshots and hypervisors; periodic hypervisor log analysis and integrity checks, including self-checks at hypervisor boot; clipboard and file-sharing services disabled; and secure lifecycle management of images and applications at the CSP's edge nodes. Level 2 is the same; Level 3 deploys only systems and infrastructure independently tested and certified for security assurance (for example Common Criteria EAL4 or equivalent).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27002:2022 · 1 control

  • 8.9 Configuration management

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in 14: Secure configuration – MTCS (Singapore)

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.