Home Audit What Is TVRA? Understanding Threat and Vulnerability Risk Assessment for Data Centres

What Is TVRA? Understanding Threat and Vulnerability Risk Assessment for Data Centres

Threat and Vulnerability Risk Assessment (TVRA) untuk Data Centre berdasarkan MAS Technology Risk Management Guidelines

Written By

CBQA Global

Follow us:

Data Centres are critical infrastructure for organizations that rely on technology-based services. Any disruption to facilities, infrastructure, or supporting systems can affect service availability and business operations.

One approach outlined in the Monetary Authority of Singapore (MAS) Technology Risk Management Guidelines is Threat and Vulnerability Risk Assessment (TVRA). In the context of Data Centres, TVRA helps Financial Institutions (FIs) identify potential vulnerabilities and weaknesses and determine the protection needed to safeguard Data Centres against physical and environmental threats.

Official source: Monetary Authority of Singapore (MAS), Technology Risk Management Guidelines (January 2021)

What Is TVRA According to MAS?

According to Section 8.5.1 of the MAS Technology Risk Management Guidelines (January 2021), Financial Institutions should conduct a Threat and Vulnerability Risk Assessment (TVRA) for its data centres (DCs).

The assessment aims to identify potential vulnerabilities and weaknesses and determine the protection needed to safeguard Data Centres against physical and environmental threats.

MAS identifies various examples of physical and environmental threats. These include flooding, fire, natural disasters, acts of terrorism, electricity surge, electromagnetic and electrical interference, and other threats.

In addition, TVRA should also consider the political and economic climate of the country where the Data Centre is located.

Why Is TVRA Important for Data Centres?

Data Centre risks do not come from technology alone. Facilities also face physical, environmental, infrastructure, and operational threats.

Therefore, MAS emphasizes that TVRA is an integral part of Data Centre Resilience. Through TVRA, organizations can gain a more comprehensive view of potential risks.

As a result, controls and protection measures can be aligned with the level of risk identified.

TVRA Areas and Example Controls

Area (MAS Section 8.5)Example Focus / Controls
Physical & Environmental ThreatsFlooding, fire, natural disasters, terrorism, electricity surge, EMI
Physical Security ControlsAccess control, visitor management, rack access, key control, segregation
Environmental ControlsFire detection & suppression, including smoke/heat detectors, inert gas, and sprinkler
Infrastructure RedundancyPower, network connectivity, cooling, electrical and mechanical systems
Monitoring & Response24×7 monitoring, escalation, and response plans for physical and environmental incidents
Geographic SeparationSecondary/DR Data Centre geographically separated from the primary Data Centre

What Is Assessed in TVRA?

According to the MAS Guidelines, TVRA covers the identification of potential vulnerabilities and weaknesses and the protection that should be established.

Therefore, several factors should be considered, including:

  • Data Centre location and geographical conditions.
  • Political and economic climate of the country where the Data Centre is located.
  • Physical security controls, including access, perimeter, visitor, rack, and key controls.
  • Environmental threats and controls, including fire, flood, and natural disasters.
  • Infrastructure supporting systems, including power, cooling, network connectivity, and electrical and mechanical systems.
  • Redundancy to eliminate single points of failure.
  • 24×7 monitoring, including escalation and response procedures.

With this risk-based approach, organizations can identify higher-risk areas. These areas can then become priorities for further mitigation and control improvements.

How Does TVRA Support Data Centre Resilience?

Data Centre resilience refers to the ability of a facility to maintain services when disruptions occur.

Therefore, TVRA results can provide a basis for understanding vulnerabilities and determining the controls that need to be strengthened.

Under Section 8.5.2, MAS states that FIs should ensure adequate redundancy for the power, network connectivity, and cooling, electrical and mechanical systems of the DC to eliminate any single point of failure.

MAS provides several considerations, including:

  • Diversification of data communications and network paths.
  • Deployment of power equipment, such as UPS and backup diesel generators with fuel tanks.
  • Implementation of redundant cooling equipment, such as cooling towers, chilled water supply, and CRAC units to control temperature and humidity.

In addition, MAS emphasizes the following areas:

  • Fire detection and suppression systems under Section 8.5.3.
  • Geographic separation between the primary/production DC and the secondary/disaster recovery DC under Section 8.5.4.
  • 24×7 monitoring of physical security and environmental controls, together with the establishment and testing of escalation and response plans under Section 8.5.5.
  • Adequate physical access controls, including need-to-have access, visitor escort, secured access points, restricted rack access, key control, and segregation of delivery/common areas under Section 8.5.6.

As a result, TVRA helps organizations connect risk identification with stronger controls and improved Data Centre resilience.

Read Also : What Is PCI DSS? Definition, Objectives, and Benefits for Businesses

When Should TVRA Be Reviewed?

According to Section 8.5.1 of the MAS Technology Risk Management Guidelines:

The TVRA should be reviewed whenever there is a significant change in the threat landscape or when there is a material change in the DC’s environment.

This means that TVRA is not an assessment that should only be performed once.

When the threat landscape changes or there is a material change in the Data Centre environment, the level of risk may also change. Therefore, organizations need to ensure that TVRA results remain relevant to current conditions.

Regular reviews also help organizations ensure that protection, controls, and mitigation measures remain appropriate for the risks they face.

Conclusion

Threat and Vulnerability Risk Assessment (TVRA) is part of the MAS Technology Risk Management Guidelines, specifically Section 8.5 on Data Centre Resilience.

In this context, Financial Institutions need to identify potential vulnerabilities and weaknesses and determine protection against physical and environmental threats affecting their Data Centres.

With a structured assessment aligned with the MAS Guidelines, organizations can evaluate several critical areas. These include redundancy, environmental controls, geographic separation, 24×7 monitoring, and physical access controls.

Ultimately, TVRA provides a stronger basis for improving Data Centre resilience, risk management, and operational security.

Strengthen Your Data Centre Audit and Risk Assessment

Understanding Data Centre risks helps organizations determine appropriate controls and mitigation measures in line with the expectations of the MAS Technology Risk Management Guidelines.

CBQA Global provides Audit and Assessment services to help organizations evaluate risks, controls, compliance, and Data Centre resilience based on business and regulatory requirements.

Contact CBQA Global to discuss your audit and assessment requirements.

Contact Us

Email:
info@cbqaglobal.com

Marketing Email:
marketing.cbqaglobal@gmail.com

WhatsApp:
08118468777

Phone:
+62 21 2781 4200

CBQA Global. We Inspire in Trust.

Certification | Audit | Training | Sustainability

More CBQA Global News

Ready to Strengthen Compliance, Trust, and Business Resilience?

Get expert support for your ISO certification and compliance needs through structured services in Certification, Audit, Training, Verification, Validation, Sustainability, and Professional Training to strengthen governance, reduce risk, and improve performance.

Apply for This Opportunity

Name
Drag & Drop Files, Choose Files to Upload