Score each MAS TRM domain.
Nine MAS TRM control domains. Mark each (0=None / 1=Partial / 2=Mostly / 3=Fully) and we'll surface a heat-map.
Board approves IT risk strategy; ITRC/TRMC committees meet ≥quarterly with documented minutes.
Documented TRM framework with risk identification, assessment, treatment, monitoring and reporting processes.
Defined roles (CIO/CISO), skills inventory, succession planning, ongoing training programme.
Secure SDLC with code review, threat modelling and penetration testing before production release.
Change management, problem management, capacity & availability management aligned to ITIL.
Critical systems with RTO ≤ 4 hours, annual DR drills, hot/warm/cold standby per criticality.
Tier-3+ data centres with multi-zone redundancy, environmental controls and physical access logs.
Segmentation, perimeter defence, secure remote access, encrypted traffic, monitored SOC.
Vendor risk tiering, due diligence, exit plans, concentration risk monitoring (esp. cloud).