MTCS (Singapore)
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Acquisition Development Supplier and Vulnerability - MTCS SS 584
Implement Acquisition Development Maintenance + Supplier Relationships + Vulnerability Management per MTCS SS 584. Acquisition Development and Maintenance (ISO 27001 Annex A.14) - secure coding standards (OWASP Top 10 + OWASP ASVS + CWE Top 25 + CERT Secure Coding) + threat modelling (STRIDE + DREAD + PASTA) + secure design review + code review (SAST + DAST + IAST + SCA) + security testing + penetration testing prior to production + open-source license compliance + Software Bill of Materials (SBOM added 2024) + DevSecOps + CI/CD pipeline security + Infrastructure as Code (IaC) security + Terraform + Ansible + Pulumi + secret scanning + container security (image scanning + runtime protection + Falco + Aqua + Sysdig + Twistlock) + container orchestration (Kubernetes Pod Security + RBAC + Network Policies + Admission Controllers) + serverless security (function permissions + cold-start + se
- Secure SDLC documentation including OWASP + SAST + DAST + IAST + SCA + SBOM
- DevSecOps + CI/CD pipeline security + IaC security (Terraform + Ansible) evidence
- Container security (image scanning + runtime + Falco/Aqua/Sysdig)
- API security (OWASP API Top 10 + rate limiting + AuthN/AuthZ)
- Supplier risk register + SOC 2/ISO 27001 third-party reports
- Vulnerability scan results + CVSS prioritisation + SLA remediation tracking + KEV CISA monitoring
- DevSecOps shift-left not implemented for legacy apps
- Container runtime protection missing
- Supplier sub-outsourcing not flowed-down
- CISA KEV CVE remediation SLA exceeded
Asset Management IAM and Cryptography - MTCS SS 584
Implement Asset Management + Identity and Access Management + Cryptography per MTCS SS 584. Asset Management (ISO 27001 Annex A.8 alignment) - asset inventory (hardware + software + data + virtual + container + serverless) + asset classification + asset ownership + acceptable use + lifecycle + CMDB + ITAM + SAM + Software Bill of Materials (SBOM added 2024). Identity and Access Management (IAM) - identity lifecycle + provisioning + deprovisioning + role-based access control (RBAC) + attribute-based access control (ABAC) + Multi-Factor Authentication (MFA) mandatory for privileged + customer-facing + administrative access + Privileged Access Management (PAM) with session recording + just-in-time access + zero standing privileges + Federation (SAML + OAuth + OIDC) + Single Sign-On (SSO) + SCIM provisioning + LDAP/AD/Azure AD/Entra ID integration + Conditional Access policies. Cryptography
- Complete asset inventory + SBOM (2024 addition)
- RBAC/ABAC matrix + MFA enforcement evidence + PAM with session recording
- Federation + SSO + SCIM provisioning evidence
- FIPS 140-2/140-3 validated module inventory + HSM-backed KMS + Customer-Managed Keys
- Post-Quantum Cryptography (PQC) readiness roadmap (2024 addition)
- Tier 3 BYOK/HYOK implementation evidence
- SBOM not generated for in-house developed software
- MFA not enforced for all admin paths
- PAM session recording retention under 7 years
- PQC roadmap absent (2024 MTCS edition requires preparation)
Governance ISMS Risk HR and Lifecycle - MTCS SS 584
Implement governance + ISMS + risk + HR + lifecycle per MTCS SS 584 covering Information Security Management System (ISO/IEC 27001 alignment) + Risk Management (ISO 31000 + ISO/IEC 27005) + Human Resource Security (employment screening + training + termination + post-employment) + Cloud Service Lifecycle (acquisition + provisioning + operation + termination/exit + data return) + Regulatory Compliance (legal mapping + standards adherence) + Roles and Responsibilities including shared responsibility model (CSP responsibility vs CSC Cloud Service Customer responsibility) + Cloud Security Policy and Strategy + Risk Appetite Statement + Three Lines of Defence (1st line Operations + 2nd line Risk and Compliance + 3rd line Internal Audit) + CISO + Cloud Security Officer + Data Protection Officer per PDPA. Cloud Service Customer (CSC) data ownership + CSP custodial role + Tier 3 enhanced governa
- ISO 27001-certified ISMS + Statement of Applicability + Risk Treatment Plan
- Cloud Risk Register + Risk Appetite Statement + KRIs
- HR Security policies + screening + training + termination procedures
- Cloud Service Lifecycle documentation including exit and data return
- Shared Responsibility Model documentation
- Three Lines of Defence structure + Board reporting
- Shared Responsibility Model misaligned between CSP and CSC
- Cloud risk register not refreshed for AI/serverless workloads
- Exit strategy lacks tested data return procedure
- Tier 3 Board reporting frequency below quarterly
Incident Business Continuity and CSC Data Protection - MTCS SS 584
Implement Incident Management + Business Continuity + Cloud Service Customer Data Protection per MTCS SS 584. Incident Management (ISO 27001 Annex A.16 + ISO 27035) - incident response plan + 24x7 SOC + Computer Security Incident Response Team (CSIRT) + incident classification + containment + eradication + recovery + lessons learned + tabletop exercises + simulation exercises + SingCERT coordination + CSA SingCERT participation + Personal Data Protection Commission (PDPC) breach notification within 72 hours for material breaches + customer notification per Notice 644 / PDPA + Cybersecurity Act 2018 CII incident reporting + MAS-regulated entities 1-hour notification under MAS Notice 644 paragraph 6 + insurance sector reporting. Business Continuity (ISO 22301 BCMS) - Business Continuity Plan + Disaster Recovery Plan + Recovery Time Objective (RTO) defined and tested + Recovery Point Object
- Incident response plan + 24x7 SOC + CSIRT structure
- 72-hour PDPC breach notification preparedness + 1-hour MAS notification capability + Cybersecurity Act CII reporting
- ISO 22301 BCMS + annual full-scale DR test + RTO/RPO tested evidence
- Tenant isolation proof + multi-tenancy controls + data residency Singapore + BYOK/HYOK for Tier 3
- PDPA compliance + PDPC requirements + Do Not Call + cookies/consent
- 1-hour MAS notification not capable
- Annual DR test partial only (not full-scale)
- Tenant isolation not independently validated
- Data residency leaks via metadata or logs
Logging Monitoring Compliance Audit and SLA - MTCS SS 584
Implement Logging and Monitoring + Compliance and Audit + Cloud Configuration Management + Cloud Security Monitoring + SLA Management per MTCS SS 584. Logging and Monitoring (ISO 27001 Annex A.12.4) - centralised logging + audit logging + log retention (90 days online + 7 years offline for regulated + 3 years for unregulated) + log integrity protection (cryptographic hashing + WORM Write Once Read Many storage + immutable storage) + log analysis + Security Information and Event Management (SIEM) integration (Splunk + Sentinel + QRadar + Chronicle + Elastic + Sumo Logic + Devo + LogRhythm) + SOAR (Splunk Phantom + Microsoft Sentinel + Cortex XSOAR + Tines) + UEBA + cloud-native logging (AWS CloudTrail + Azure Activity Log + GCP Cloud Audit Logs + Container audit logs + Kubernetes audit logs). Compliance and Audit (ISO 27001 Annex A.18) - independent audit + internal audit + external audit
- Centralised logging + audit logs with cryptographic hashing + WORM storage + 7-year retention for regulated
- SIEM + SOAR integration evidence
- CSPM + CWPP + CNAPP deployed
- MTCS surveillance audit reports + recertification readiness
- SLA evidence (99.9% Tier 1 / 99.95% Tier 2 / 99.99% Tier 3)
- Monthly SLA reporting + Quarterly Business Review
- Log retention under 7 years for regulated workloads
- CSPM not integrated with SIEM for unified view
- SLA breaches not service-credit-tracked
- MTCS surveillance audit lapsed
Operations Physical and Network Security - MTCS SS 584
Implement Operations Security + Physical/Environmental Security + Communications and Network Security per MTCS SS 584. Operations Security (ISO 27001 Annex A.12 alignment) - documented operating procedures + capacity management + separation of dev/test/prod + change management + patch management (security patching baseline + emergency patching) + clock synchronisation NTP + system hardening (CIS Benchmarks + DISA STIG + Microsoft Security Baselines + Apple Security + Linux/CIS) + secure configuration baselines + drift detection + container image scanning + serverless function scanning. Physical and Environmental Security (ISO 27001 Annex A.11) - Tier III+ data centre (Uptime Institute or TIA-942 Tier III/IV) + geographic separation primary + secondary + power redundancy (UPS + generators + 2N or N+1) + cooling redundancy + fire suppression + physical access controls (multi-factor + biome
- Documented operating procedures + capacity + change + patch management evidence
- Tier III+ data centre certification (Uptime Institute or TIA-942 Tier III/IV)
- Network segmentation + microsegmentation + Zero Trust architecture evidence (NIST SP 800-207)
- DDoS protection (volumetric + protocol + application)
- Container + Kubernetes security (Pod Security + RBAC + Network Policies + Admission Controllers)
- Patch SLA breached for critical/high
- Data centre Tier II only (Tier III required for MTCS Tier 2/3)
- Zero Trust architecture in planning only (not implemented)
- Container/Kubernetes security gaps
Scope and Tier Framework - MTCS SS 584
Establish the scope of Singapore Multi-Tier Cloud Security Standard (MTCS) SS 584 - first issued 2013 (SS 584:2013 - world's first national cloud security standard) + revised 2015 + 2020 + current 2024 incorporating AI workload security + zero trust + data residency + supply chain. Issued by Singapore Standards Council (SSC) + administered by IMDA (Infocomm Media Development Authority) + certification scheme operated by SAC (Singapore Accreditation Council) under Enterprise Singapore + accredited CABs (BSI + DNV + LRQA + DQS + Coalfire + KPMG + EY + Deloitte + Setsco). **3 TIERS**: Tier 1 baseline ~35-50 controls equivalent to ISO 27001 for non-business critical + low-cost public cloud + SMEs; Tier 2 intermediate ~70-90 controls equivalent to ISO 27001 + 27017 + 27018 for sensitive workloads + financial + healthcare non-clinical + government; Tier 3 highest 100+ controls for critical/con
- MTCS SS 584 version + tier (1/2/3) determination evidence
- Sectoral mapping (MAS Notice 658 + MOH NEHR + GovTech IM8 + CSA CCoP + PDPC PDPA)
- SAC-accredited CAB selection records + Stage 1 + Stage 2 audit reports
- 3-year certificate validity + annual surveillance audits + recertification plan
- ISO 27001 + 27017 + 27018 cross-walk evidence
- MTCS 2024 edition AI/PQC/sovereign requirements not addressed
- Tier selection too low for actual workload sensitivity
- Annual surveillance audit overdue
- Sectoral mapping incomplete (especially MAS/MOH/GovTech specifics)
Tier 3 Additional Controls - MTCS SS 584
Implement Tier 3 Additional Controls per MTCS SS 584 for highest sensitivity workloads (critical systems + government classified + Critical Information Infrastructure CII + MAS-regulated systemically-important systems + healthcare clinical data + Restricted/Sensitive/Confidential government data). Enhanced governance: Board-level oversight + monthly Risk Committee + quarterly Board reporting + annual independent risk assessment. Enhanced data residency: Singapore mandatory + restrictions on data egress + cross-border transfer requires MAS approval (financial) or specific approval (government) + Sovereign Cloud requirements + multi-tenant isolation proof. Enhanced encryption: Customer-Managed Keys (CMK) mandatory + Bring Your Own Key (BYOK) + Hold Your Own Key (HYOK) + Hardware Security Module (HSM) integration + Post-Quantum Cryptography (PQC) readiness + algorithm rotation policies. Enh
- Board-level oversight + monthly Risk Committee + quarterly Board reporting + annual independent risk assessment
- Singapore data residency proof + no egress + Sovereign Cloud where applicable
- Customer-Managed Keys (CMK + BYOK + HYOK + HSM) for Tier 3 workloads
- Zero standing privileges + JIT + PAW + dual-person controls
- 1-hour MAS / sectoral notification SLA + dedicated incident commander
- Sectoral mapping evidence (MAS Notice 658 + GovTech IM8 + MOH NEHR + CSA CCoP)
- Customer-Managed Keys not adopted (CSP-managed keys only)
- Data residency monitored but not enforceable (metadata + logs leak)
- Tier 3 Board reporting frequency below quarterly
- Sectoral mapping claimed without operationalisation
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the MTCS (Singapore) framework page.