MTCS-Acquisition-Development-Maintenance-Supplier-Vulnerability-DevSecOps-SBOM-SDLC-SCA-API-Container | MTCS Acquisition + Development + Maintenance + Supplier + Vulnerability + DevSecOps + SBOM + SDLC + SCA | 72 |
MTCS-Asset-IAM-Cryptography-Multi-Tier-Asset-Inventory-RBAC-MFA-PAM-FIPS-HSM-Quantum-Safe | MTCS Asset Mgmt + IAM + Cryptography + Asset Inventory + RBAC + MFA + PAM + FIPS + HSM + Quantum-Safe | 51 |
MTCS-Governance-ISMS-Risk-HR-Lifecycle-Compliance-Cloud-Strategy-Roles-Responsibilities | MTCS Governance + ISMS + Risk Management + HR Security + Cloud Service Lifecycle + Compliance + Roles | 134 |
MTCS-Incident-Business-Continuity-CSC-Data-Protection-72-Hour-Notification-BCP-DR-PDPA | MTCS Incident + Business Continuity + CSC Data Protection + 72-Hour Notification + BCP + DR + PDPA | 63 |
MTCS-Logging-Monitoring-Compliance-Audit-SLA-Configuration-SIEM-SOAR-Cloud-Monitoring-CSPM | MTCS Logging + Monitoring + Compliance + Audit + SLA + Configuration + SIEM + SOAR + CSPM | 136 |
MTCS-Operations-Physical-Network-Tier-III-Data-Centre-Hardening-Patching-Network-Segmentation-DDoS | MTCS Operations + Physical + Network + Tier III Data Centre + Hardening + Patching + Segmentation + DDoS | 73 |
MTCS-Scope-SS-584-Singapore-Standards-Council-IMDA-SAC-3-Tier-2013-2015-2020-2024-Certification | MTCS Scope + SS 584 + Singapore Standards Council + IMDA + SAC + 3-Tier Framework + Certification | 36 |
MTCS-Tier-3-Additional-Controls-Critical-Systems-MAS-CCoP-Government-Classified-CII-Sovereign-Cloud | MTCS Tier 3 Additional Controls + Critical Systems + MAS + CCoP + Government Classified + CII + Sovereign Cloud | 0 |
10.1 | Legal and compliance controls | 0 |
10.2 | Compliance with regulatory and contractual requirements | 1 |
10.3 | Compliance with policies and standards | 1 |
10.4 | Prevention of misuse of cloud facilities | 1 |
10.5 | Use of compliant cryptographic controls | 1 |
10.6 | Third-party compliance | 1 |
10.7 | Continuous compliance monitoring | 1 |
11.1 | Incident management controls | 0 |
11.2 | Information security incident response plan and procedures | 1 |
11.3 | Information security incident response plan testing and updates | 1 |
11.4 | Information security incident reporting | 1 |
11.5 | Problem management | 1 |
12.1 | Data governance controls | 0 |
12.10 | Secure disposal verification of live instances and backups | 1 |
12.11 | Tracking of data | 1 |
12.12 | Production data | 1 |
12.2 | Data classification | 1 |
12.3 | Data ownership | 1 |
12.4 | Data integrity | 0 |
12.5 | Data labelling/handling | 1 |
12.6 | Data protection | 1 |
12.7 | Data retention | 1 |
12.8 | Data backups | 1 |
12.9 | Secure disposal and decommissioning of hardcopy, media and equipment | 1 |
13.1 | Audit logging and monitoring controls | 0 |
13.2 | Logging and monitoring process | 1 |
13.3 | Log review | 1 |
13.4 | Audit trails | 1 |
13.5 | Backup and retention of audit trails | 1 |
13.6 | Usage logs | 0 |
14.1 | Secure configuration controls | 0 |
14.10 | Enforcement checks | 1 |
14.2 | Server and network device configuration standards | 1 |
14.3 | Malicious code prevention | 1 |
14.4 | Portable code | 1 |
14.5 | Physical port protection | 1 |
14.6 | Restrictions to system utilities | 1 |
14.7 | System and network session management | 1 |
14.8 | Unnecessary services and protocols | 1 |
14.9 | Unauthorised software | 1 |
15.1 | Security testing and monitoring controls | 0 |
15.2 | Vulnerability scanning | 1 |
15.3 | Penetration testing | 1 |
15.4 | Security monitoring | 1 |
16.1 | System acquisitions and development controls | 0 |
16.2 | Development, acquisition and release management | 1 |
16.3 | Web application security | 1 |
16.4 | System testing | 1 |
16.5 | Source code security | 1 |
16.6 | Outsourced software development | 1 |
17.1 | Encryption controls | 0 |
17.2 | Encryption policies and procedures | 1 |
17.3 | Channel encryption | 1 |
17.4 | Key management | 1 |
17.5 | Electronic messaging security | 1 |
18.1 | Physical and environmental controls | 0 |
18.2 | Asset management | 1 |
18.3 | Off-site movement | 1 |
18.4 | Physical access | 1 |
18.5 | Visitors | 1 |
18.6 | Environmental threats and equipment power failures | 1 |
18.7 | Physical security review | 1 |
19.1 | Operations controls | 0 |
19.2 | Operations management policies and procedures | 1 |
19.3 | Documentation of service operations and external dependencies | 1 |
19.4 | Capacity management | 1 |
19.5 | Service levels | 0 |
19.6 | Reliability and resiliency | 1 |
19.7 | Recoverability | 1 |
20.1 | Change management controls | 0 |
20.2 | Change management process | 1 |
20.3 | Backup procedures | 1 |
20.4 | Back-out or rollback procedures | 1 |
20.5 | Separation of environment | 1 |
20.6 | Patch management procedures | 1 |
21.1 | Business continuity planning (BCP) and disaster recovery (DR) controls | 0 |
21.2 | BCP framework | 1 |
21.3 | BCP and DR plans | 1 |
21.4 | BCP and DR testing | 1 |
22.1 | Cloud services administration controls | 0 |
22.10 | Session management | 1 |
22.11 | Segregation of duties | 1 |
22.12 | Secure transmission of access credentials | 1 |
22.13 | Third party administrative access | 1 |
22.14 | Service and application accounts | 1 |
22.2 | Privilege account creation | 1 |
22.3 | Generation of administrator passwords | 1 |
22.4 | Administrator access review and revocation | 1 |
22.5 | Account lockout | 1 |
22.6 | Password change | 1 |
22.7 | Password reset and first logon | 1 |
22.8 | Administrator access security | 1 |
22.9 | Administrator access logs | 1 |
23.1 | Cloud user access controls | 0 |
23.10 | Self-service portal creation and management of user accounts | 1 |
23.11 | Communication with cloud users | 1 |
23.2 | User access registration | 1 |
23.3 | User access security | 1 |
23.4 | User access password | 1 |
23.5 | User account lockout | 1 |
23.6 | User password reset and first logon change | 1 |
23.7 | Password protection | 1 |
23.8 | User session management | 1 |
23.9 | Change of cloud user's administrator details notification | 1 |
24.1 | Tenancy and customer isolation controls | 0 |
24.2 | Multi tenancy | 1 |
24.3 | Supporting infrastructure segmentation | 1 |
24.4 | Network protection | 1 |
24.5 | Virtualisation | 1 |
24.6 | Storage area networks (SAN) | 1 |
24.7 | Data segregation | 1 |
4 | Cloud computing fundamentals | 0 |
5.1 | Applicability and compensatory controls | 0 |
5.2 | Cloud service provider disclosure | 0 |
5.3 | Considerations of emerging technologies | 0 |
6.1 | Information security management controls | 0 |
6.2 | Information security management system (ISMS) | 0 |
6.3 | Management of information security | 1 |
6.4 | Management oversight of information security | 0 |
6.5 | Information security policy | 1 |
6.6 | Review of information security policy | 1 |
6.7 | Information security audits | 1 |
6.8 | Information security liaisons (ISL) | 1 |
6.9 | Acceptable usage | 1 |
7.1 | Human resources controls | 0 |
7.2 | Background screening | 1 |
7.3 | Continuous personnel evaluation | 1 |
7.4 | Employment and contract terms and conditions | 1 |
7.5 | Disciplinary process | 1 |
7.6 | Asset returns | 1 |
7.7 | Information security training and awareness | 1 |
8.1 | Risk management controls | 0 |
8.2 | Risk management programme | 0 |
8.3 | Risk assessment | 0 |
8.4 | Risk management | 0 |
8.5 | Risk register | 0 |
9.1 | Third-party controls | 0 |
9.2 | Third-party due diligence | 1 |
9.3 | Identification of risks related to third parties | 1 |
9.4 | Third-party agreement | 1 |
9.5 | Third-party delivery management | 1 |
A.1 | Disclosure: Right to audit | 1 |
A.10 | Disclosure: Liability | 0 |
A.11 | Disclosure: Shared responsibility | 1 |
A.12 | Disclosure: Change management | 1 |
A.13 | Disclosure: Self-service provisioning and management portal | 0 |
A.14 | Disclosure: Incident and problem management | 1 |
A.15 | Disclosure: Billing | 0 |
A.16 | Disclosure: Data portability | 1 |
A.17 | Disclosure: Interoperability | 0 |
A.18 | Disclosure: Access | 0 |
A.19 | Disclosure: User management | 1 |
A.2 | Disclosure: Compliance | 1 |
A.20 | Disclosure: Lifecycle | 0 |
A.21 | Disclosure: Security configuration enforcement checks | 1 |
A.22 | Disclosure: Multi-tenancy | 1 |
A.23 | Disclosure: Hybrid cloud provision | 0 |
A.24 | Disclosure: Capacity elasticity | 1 |
A.25 | Disclosure: Network resiliency and elasticity | 1 |
A.26 | Disclosure: Storage redundancy and elasticity | 1 |
A.3 | Disclosure: Data ownership | 1 |
A.4 | Disclosure: Data retention | 1 |
A.5 | Disclosure: Data sovereignty | 1 |
A.6 | Disclosure: Non-disclosure | 1 |
A.7 | Disclosure: Availability | 1 |
A.8 | Disclosure: Third-party dependency | 1 |
A.9 | Disclosure: BCP / DR | 1 |