Establish the scope of Singapore Multi-Tier Cloud Security Standard (MTCS) SS 584 - first issued 2013 (SS 584:2013 - world's first national cloud security standard) + revised 2015 + 2020 + current 2024 incorporating AI workload security + zero trust + data residency + supply chain. Issued by Singapore Standards Council (SSC) + administered by IMDA (Infocomm Media Development Authority) + certification scheme operated by SAC (Singapore Accreditation Council) under Enterprise Singapore + accredited CABs (BSI + DNV + LRQA + DQS + Coalfire + KPMG + EY + Deloitte + Setsco). **3 TIERS**: Tier 1 baseline ~35-50 controls equivalent to ISO 27001 for non-business critical + low-cost public cloud + SMEs; Tier 2 intermediate ~70-90 controls equivalent to ISO 27001 + 27017 + 27018 for sensitive workloads + financial + healthcare non-clinical + government; Tier 3 highest 100+ controls for critical/confidential workloads + systemically important systems + government classified + CII + MAS-regulated FIs + healthcare clinical. Aligned with ISO/IEC 27001 + 27002 + 27017 + 27018 + 27036 + NIST CSF + 800-53 + CSA CCM + SOC 2 + FedRAMP + STAR. Sectoral application via MAS Notice 658 + MOH NEHR + GovTech IM8 + CSA CCoP + PDPC PDPA + GCC. Annual surveillance + 3-year recertification.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.