Singapore

MTCS (Singapore)

175 controls. 169 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

175 controls 169 frameworks share controls with it Singapore verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
MTCS-Acquisition-Development-Maintenance-Supplier-Vulnerability-DevSecOps-SBOM-SDLC-SCA-API-ContainerMTCS Acquisition + Development + Maintenance + Supplier + Vulnerability + DevSecOps + SBOM + SDLC + SCA72
MTCS-Asset-IAM-Cryptography-Multi-Tier-Asset-Inventory-RBAC-MFA-PAM-FIPS-HSM-Quantum-SafeMTCS Asset Mgmt + IAM + Cryptography + Asset Inventory + RBAC + MFA + PAM + FIPS + HSM + Quantum-Safe51
MTCS-Governance-ISMS-Risk-HR-Lifecycle-Compliance-Cloud-Strategy-Roles-ResponsibilitiesMTCS Governance + ISMS + Risk Management + HR Security + Cloud Service Lifecycle + Compliance + Roles134
MTCS-Incident-Business-Continuity-CSC-Data-Protection-72-Hour-Notification-BCP-DR-PDPAMTCS Incident + Business Continuity + CSC Data Protection + 72-Hour Notification + BCP + DR + PDPA63
MTCS-Logging-Monitoring-Compliance-Audit-SLA-Configuration-SIEM-SOAR-Cloud-Monitoring-CSPMMTCS Logging + Monitoring + Compliance + Audit + SLA + Configuration + SIEM + SOAR + CSPM136
MTCS-Operations-Physical-Network-Tier-III-Data-Centre-Hardening-Patching-Network-Segmentation-DDoSMTCS Operations + Physical + Network + Tier III Data Centre + Hardening + Patching + Segmentation + DDoS73
MTCS-Scope-SS-584-Singapore-Standards-Council-IMDA-SAC-3-Tier-2013-2015-2020-2024-CertificationMTCS Scope + SS 584 + Singapore Standards Council + IMDA + SAC + 3-Tier Framework + Certification36
MTCS-Tier-3-Additional-Controls-Critical-Systems-MAS-CCoP-Government-Classified-CII-Sovereign-CloudMTCS Tier 3 Additional Controls + Critical Systems + MAS + CCoP + Government Classified + CII + Sovereign Cloud0
10.1Legal and compliance controls0
10.2Compliance with regulatory and contractual requirements1
10.3Compliance with policies and standards1
10.4Prevention of misuse of cloud facilities1
10.5Use of compliant cryptographic controls1
10.6Third-party compliance1
10.7Continuous compliance monitoring1
11.1Incident management controls0
11.2Information security incident response plan and procedures1
11.3Information security incident response plan testing and updates1
11.4Information security incident reporting1
11.5Problem management1
12.1Data governance controls0
12.10Secure disposal verification of live instances and backups1
12.11Tracking of data1
12.12Production data1
12.2Data classification1
12.3Data ownership1
12.4Data integrity0
12.5Data labelling/handling1
12.6Data protection1
12.7Data retention1
12.8Data backups1
12.9Secure disposal and decommissioning of hardcopy, media and equipment1
13.1Audit logging and monitoring controls0
13.2Logging and monitoring process1
13.3Log review1
13.4Audit trails1
13.5Backup and retention of audit trails1
13.6Usage logs0
14.1Secure configuration controls0
14.10Enforcement checks1
14.2Server and network device configuration standards1
14.3Malicious code prevention1
14.4Portable code1
14.5Physical port protection1
14.6Restrictions to system utilities1
14.7System and network session management1
14.8Unnecessary services and protocols1
14.9Unauthorised software1
15.1Security testing and monitoring controls0
15.2Vulnerability scanning1
15.3Penetration testing1
15.4Security monitoring1
16.1System acquisitions and development controls0
16.2Development, acquisition and release management1
16.3Web application security1
16.4System testing1
16.5Source code security1
16.6Outsourced software development1
17.1Encryption controls0
17.2Encryption policies and procedures1
17.3Channel encryption1
17.4Key management1
17.5Electronic messaging security1
18.1Physical and environmental controls0
18.2Asset management1
18.3Off-site movement1
18.4Physical access1
18.5Visitors1
18.6Environmental threats and equipment power failures1
18.7Physical security review1
19.1Operations controls0
19.2Operations management policies and procedures1
19.3Documentation of service operations and external dependencies1
19.4Capacity management1
19.5Service levels0
19.6Reliability and resiliency1
19.7Recoverability1
20.1Change management controls0
20.2Change management process1
20.3Backup procedures1
20.4Back-out or rollback procedures1
20.5Separation of environment1
20.6Patch management procedures1
21.1Business continuity planning (BCP) and disaster recovery (DR) controls0
21.2BCP framework1
21.3BCP and DR plans1
21.4BCP and DR testing1
22.1Cloud services administration controls0
22.10Session management1
22.11Segregation of duties1
22.12Secure transmission of access credentials1
22.13Third party administrative access1
22.14Service and application accounts1
22.2Privilege account creation1
22.3Generation of administrator passwords1
22.4Administrator access review and revocation1
22.5Account lockout1
22.6Password change1
22.7Password reset and first logon1
22.8Administrator access security1
22.9Administrator access logs1
23.1Cloud user access controls0
23.10Self-service portal creation and management of user accounts1
23.11Communication with cloud users1
23.2User access registration1
23.3User access security1
23.4User access password1
23.5User account lockout1
23.6User password reset and first logon change1
23.7Password protection1
23.8User session management1
23.9Change of cloud user's administrator details notification1
24.1Tenancy and customer isolation controls0
24.2Multi tenancy1
24.3Supporting infrastructure segmentation1
24.4Network protection1
24.5Virtualisation1
24.6Storage area networks (SAN)1
24.7Data segregation1
4Cloud computing fundamentals0
5.1Applicability and compensatory controls0
5.2Cloud service provider disclosure0
5.3Considerations of emerging technologies0
6.1Information security management controls0
6.2Information security management system (ISMS)0
6.3Management of information security1
6.4Management oversight of information security0
6.5Information security policy1
6.6Review of information security policy1
6.7Information security audits1
6.8Information security liaisons (ISL)1
6.9Acceptable usage1
7.1Human resources controls0
7.2Background screening1
7.3Continuous personnel evaluation1
7.4Employment and contract terms and conditions1
7.5Disciplinary process1
7.6Asset returns1
7.7Information security training and awareness1
8.1Risk management controls0
8.2Risk management programme0
8.3Risk assessment0
8.4Risk management0
8.5Risk register0
9.1Third-party controls0
9.2Third-party due diligence1
9.3Identification of risks related to third parties1
9.4Third-party agreement1
9.5Third-party delivery management1
A.1Disclosure: Right to audit1
A.10Disclosure: Liability0
A.11Disclosure: Shared responsibility1
A.12Disclosure: Change management1
A.13Disclosure: Self-service provisioning and management portal0
A.14Disclosure: Incident and problem management1
A.15Disclosure: Billing0
A.16Disclosure: Data portability1
A.17Disclosure: Interoperability0
A.18Disclosure: Access0
A.19Disclosure: User management1
A.2Disclosure: Compliance1
A.20Disclosure: Lifecycle0
A.21Disclosure: Security configuration enforcement checks1
A.22Disclosure: Multi-tenancy1
A.23Disclosure: Hybrid cloud provision0
A.24Disclosure: Capacity elasticity1
A.25Disclosure: Network resiliency and elasticity1
A.26Disclosure: Storage redundancy and elasticity1
A.3Disclosure: Data ownership1
A.4Disclosure: Data retention1
A.5Disclosure: Data sovereignty1
A.6Disclosure: Non-disclosure1
A.7Disclosure: Availability1
A.8Disclosure: Third-party dependency1
A.9Disclosure: BCP / DR1

Tell me when MTCS (Singapore) files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What this page is

A control-level reference for MTCS (Singapore), drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition