Implement Incident Management + Business Continuity + Cloud Service Customer Data Protection per MTCS SS 584. Incident Management (ISO 27001 Annex A.16 + ISO 27035) - incident response plan + 24x7 SOC + Computer Security Incident Response Team (CSIRT) + incident classification + containment + eradication + recovery + lessons learned + tabletop exercises + simulation exercises + SingCERT coordination + CSA SingCERT participation + Personal Data Protection Commission (PDPC) breach notification within 72 hours for material breaches + customer notification per Notice 644 / PDPA + Cybersecurity Act 2018 CII incident reporting + MAS-regulated entities 1-hour notification under MAS Notice 644 paragraph 6 + insurance sector reporting. Business Continuity (ISO 22301 BCMS) - Business Continuity Plan + Disaster Recovery Plan + Recovery Time Objective (RTO) defined and tested + Recovery Point Objective (RPO) defined and tested + tabletop exercises + simulation exercises + annual full-scale DR test + Maximum Tolerable Period of Disruption (MTPD) + cascading failure analysis + critical system identification + dependency mapping. Cloud Service Customer (CSC) Data Protection - data classification + tenant isolation + multi-tenancy controls + data residency (Singapore mandatory for Restricted/Sensitive/Confidential under government classifications + healthcare clinical data + financial sector regulated data) + data sovereignty + cross-border transfer controls + data ownership clauses + data return on termination + secure deletion (NIST 800-88 + crypto-erasure) + PDPA Personal Data Protection Act compliance + Personal Data Protection Commission (PDPC) requirements + Do Not Call Registry + cookies and tracking + consent management. Tier 3 requires data residency + multi-tenancy proof + isolation testing + customer-specific encryption keys (BYOK Bring Your Own Key + HYOK Hold Your Own Key).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.