Home Audit Threat and Vulnerability Risk Assessment (TVRA): What Financial Institutions Need to Know?

Threat and Vulnerability Risk Assessment (TVRA): What Financial Institutions Need to Know?

TVRA untuk Financial Institutions dalam Technology Risk Management MAS

Written By

CBQA Global

Follow us:

Financial Institutions are increasingly dependent on technology to deliver services and support daily operations. Therefore, technology risk management plays an important role in maintaining resilience and service continuity.

Under the Technology Risk Management Guidelines (January 2021), the Monetary Authority of Singapore (MAS) provides principles and practices to help Financial Institutions establish technology risk governance and oversight. The guidelines also support organizations in maintaining IT and cyber resilience.

One aspect specifically addressed by the guidelines is Threat and Vulnerability Risk Assessment (TVRA) for Data Centres, as covered in Section 8.5 on Data Centre Resilience.

Official source: Monetary Authority of Singapore (MAS), Technology Risk Management Guidelines (January 2021)

What Is the Role of TVRA in MAS Technology Risk Management?

According to Section 8.5.1 of the MAS TRM Guidelines, a Financial Institution (FI) must conduct a Threat and Vulnerability Risk Assessment (TVRA) for its data centres (DCs) to identify potential vulnerabilities and weaknesses, as well as the protective measures required to safeguard the DCs against physical and environmental threats.

The TVRA must also take into account the political and economic climate of the country where the data centre is located. In doing so, the TVRA helps align data centre conditions and risks with a comprehensive technology risk management approach.

Examples of physical and environmental threats cited by MAS include flooding, fire, natural disasters, acts of terrorism, power surges, electromagnetic and electrical interference, and the like.

Why Is TVRA Important for Financial Institutions?

For financial institutions, disruptions to data centers can impact critical systems and the services that rely on that infrastructure. Consequently, risks must be understood in terms of potential vulnerabilities, weaknesses, and the necessary protective measures.

The MAS Technology Risk Management Guidelines emphasize the importance of IT and cyber resilience. TVRA provides a specific perspective on physical and environmental threats within the data center environment, complementing the processes of risk identification, assessment, treatment, monitoring, review, and reporting.

What Should Be Considered in TVRA?

TVRA for Data Centres is not limited to physical security. Instead, the assessment should consider various conditions that may affect the resilience of the facility, in line with Section 8.5 of the MAS Guidelines.

Area (MAS Section 8.5)Assessment Focus / Expectations
TVRA (8.5.1)Identify potential vulnerabilities and weaknesses; establish protection against physical and environmental threats; consider the political and economic climate.
Redundancy (8.5.2)Power, network connectivity, cooling, electrical, and mechanical systems to eliminate a single point of failure.
Environmental Controls (8.5.3)Fire detection and suppression, including smoke/heat detectors, inert gas, and wet/dry sprinkler systems.
Geographic Separation (8.5.4)Secondary/DR Data Centre geographically separated from the primary/production Data Centre.
Monitoring & Response (8.5.5)24×7 monitoring of physical security and environmental controls, with tested escalation and response plans.
Physical Access Controls (8.5.6)Need-to-have access, visitor escort, secured access points, restricted rack access, key control, and segregation of areas.

Factors such as criticality of the DC, location, multi-tenancy, type of tenant, and the political and economic climate are also considered when assessing Data Centre risks.

Related article : What Is TVRA? Understanding Threat and Vulnerability Risk Assessment for Data Centres

When Should TVRA Be Reviewed?

Section 8.5.1 of the MAS Guidelines explicitly states:

The TVRA should be reviewed whenever there is a significant change in the threat landscape or when there is a material change in the DC’s environment.

TVRA should not be viewed as an assessment that is performed only once. A significant change in the threat landscape or a material change in the Data Centre environment can affect the level of risk.

Therefore, regular reviews help ensure that assessment results remain relevant to current conditions.

How Does TVRA Support Data Centre Resilience?

TVRA helps Financial Institutions understand vulnerabilities and weaknesses that may affect Data Centre resilience. The assessment results can then provide a basis for determining appropriate control improvements and risk mitigation measures.

MAS emphasizes the importance of:

  • Adequate redundancy for power, network connectivity, cooling, electrical, and mechanical systems to eliminate a single point of failure (Section 8.5.2).
  • Fire detection and suppression devices/systems as part of environmental controls (Section 8.5.3).
  • Geographic separation between the primary/production Data Centre and the secondary/disaster recovery Data Centre to reduce the risk of both facilities being affected by the same infrastructure disruption (Section 8.5.4).
  • 24×7 monitoring of physical security and environmental controls, together with the establishment and testing of escalation and response plans (Section 8.5.5).
  • Adequate physical access controls, including need-to-have access, visitor management, secured access points, restricted rack access, key control, and segregation of delivery/common areas (Section 8.5.6).

As a result, Threat and Vulnerability Risk Assessment helps Financial Institutions connect risk identification with stronger controls. This supports greater Data Centre resilience and more structured technology risk management.

Conclusion

TVRA plays an important role in the context of MAS Technology Risk Management, particularly when assessing risks that may affect Data Centres under Section 8.5.

For Financial Institutions, TVRA helps identify potential vulnerabilities and weaknesses and determine appropriate protection against physical and environmental threats. The assessment also considers the political and economic climate of the Data Centre’s location.

When combined with redundancy requirements, environmental controls, geographic separation, continuous monitoring, physical access controls, risk treatment, and monitoring, TVRA supports a structured approach to strengthening Data Centre resilience and technology risk management in line with MAS expectations.

Strengthen Your Data Centre Audit and Risk Assessment

Understanding Data Centre risks helps organizations determine appropriate controls and mitigation measures in line with the MAS Technology Risk Management Guidelines.

CBQA Global provides Audit and Assessment services to help organizations evaluate risks, controls, compliance, and Data Centre resilience based on business and regulatory requirements.

Contact CBQA Global to discuss your organization’s audit and assessment requirements.

Email: info@cbqaglobal.com
Marketing Email: marketing.cbqaglobal@gmail.com
WhatsApp: 08118468777
Phone: +62 21 2781 4200

CBQA Global. We Inspire in Trust.
Certification | Audit | Training | Sustainability

More CBQA Global News

Ready to Strengthen Compliance, Trust, and Business Resilience?

Get expert support for your ISO certification and compliance needs through structured services in Certification, Audit, Training, Verification, Validation, Sustainability, and Professional Training to strengthen governance, reduce risk, and improve performance.

Apply for This Opportunity

Name
Drag & Drop Files, Choose Files to Upload