MTCS (Singapore)
6: Information security management – MTCS (Singapore)

MTCS (Singapore) 6.2: Information security management system (ISMS)

The CSP runs an ISMS for the cloud service. Level 1 (items a to k): (a) an ISMS scoped to the cloud environment and its assets; (b) risk assessment and treatment policies; (c) an approved security policy; (d) assigned security roles; (e) controls over authorised insiders and their access rights; (f) operations security with logging; (g) secure access to systems and applications; (h) secure acquisition and development; (i) treatment of cloud-specific risks and (j) protection of the virtualisation layer such as the hypervisor, the two items with no ISO/IEC 27001 counterpart; and (k) security event reporting with lessons learned. Level 2 adds backup and log protection (incremental) and measurement of the ISMS and its continuity controls; Level 3 adds maintaining the ISMS on ISO/IEC 27001 lines and its communication to interested parties.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in 6: Information security management – MTCS (Singapore)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.