|
Technology Risk Management GuidelinesMAS
|
Financial institutions within the guidelines’ scope |
Board technology oversight, risk assessment, secure operations, third-party risk, incident response, recovery and audit. |
|
Source
|
|
Guidelines on Business Continuity ManagementMAS
|
Financial institutions supervised by MAS |
Critical-business services, recovery objectives, dependency management, testing, crisis response and senior-management reporting. |
|
Source
|
|
Financial Institution Incident Reporting CircularMAS
|
Financial institutions within the circular’s reporting scope |
Consistent incident identification, classification, escalation, regulatory notification, updates and closure evidence. |
|
Source
|
|
Risk Management Guidelines on Internal ControlsMAS
|
Financial institutions within scope |
Control environment, risk assessment, control activities, information, monitoring and independent assurance. |
|
Source
|
|
Personal Data Protection ActPDPC
|
Private-sector organisations collecting, using or disclosing personal data |
Accountability, security arrangements, breach assessment, notification, retention and processor oversight. |
|
Source
|