Data Centres are critical infrastructure for organizations that rely on technology-based services. Any disruption to facilities, infrastructure, or supporting systems can affect service availability and business operations.
One approach outlined in the Monetary Authority of Singapore (MAS) Technology Risk Management Guidelines is Threat and Vulnerability Risk Assessment (TVRA). In the context of Data Centres, TVRA helps Financial Institutions (FIs) identify potential vulnerabilities and weaknesses and determine the protection needed to safeguard Data Centres against physical and environmental threats.
Official source: Monetary Authority of Singapore (MAS), Technology Risk Management Guidelines (January 2021)
What Is TVRA According to MAS?
According to Section 8.5.1 of the MAS Technology Risk Management Guidelines (January 2021), Financial Institutions should conduct a Threat and Vulnerability Risk Assessment (TVRA) for its data centres (DCs).
The assessment aims to identify potential vulnerabilities and weaknesses and determine the protection needed to safeguard Data Centres against physical and environmental threats.
MAS identifies various examples of physical and environmental threats. These include flooding, fire, natural disasters, acts of terrorism, electricity surge, electromagnetic and electrical interference, and other threats.
In addition, TVRA should also consider the political and economic climate of the country where the Data Centre is located.
Why Is TVRA Important for Data Centres?
Data Centre risks do not come from technology alone. Facilities also face physical, environmental, infrastructure, and operational threats.
Therefore, MAS emphasizes that TVRA is an integral part of Data Centre Resilience. Through TVRA, organizations can gain a more comprehensive view of potential risks.
As a result, controls and protection measures can be aligned with the level of risk identified.
TVRA Areas and Example Controls
| Area (MAS Section 8.5) | Example Focus / Controls |
|---|---|
| Physical & Environmental Threats | Flooding, fire, natural disasters, terrorism, electricity surge, EMI |
| Physical Security Controls | Access control, visitor management, rack access, key control, segregation |
| Environmental Controls | Fire detection & suppression, including smoke/heat detectors, inert gas, and sprinkler |
| Infrastructure Redundancy | Power, network connectivity, cooling, electrical and mechanical systems |
| Monitoring & Response | 24×7 monitoring, escalation, and response plans for physical and environmental incidents |
| Geographic Separation | Secondary/DR Data Centre geographically separated from the primary Data Centre |
What Is Assessed in TVRA?
According to the MAS Guidelines, TVRA covers the identification of potential vulnerabilities and weaknesses and the protection that should be established.
Therefore, several factors should be considered, including:
- Data Centre location and geographical conditions.
- Political and economic climate of the country where the Data Centre is located.
- Physical security controls, including access, perimeter, visitor, rack, and key controls.
- Environmental threats and controls, including fire, flood, and natural disasters.
- Infrastructure supporting systems, including power, cooling, network connectivity, and electrical and mechanical systems.
- Redundancy to eliminate single points of failure.
- 24×7 monitoring, including escalation and response procedures.
With this risk-based approach, organizations can identify higher-risk areas. These areas can then become priorities for further mitigation and control improvements.
How Does TVRA Support Data Centre Resilience?
Data Centre resilience refers to the ability of a facility to maintain services when disruptions occur.
Therefore, TVRA results can provide a basis for understanding vulnerabilities and determining the controls that need to be strengthened.
Under Section 8.5.2, MAS states that FIs should ensure adequate redundancy for the power, network connectivity, and cooling, electrical and mechanical systems of the DC to eliminate any single point of failure.
MAS provides several considerations, including:
- Diversification of data communications and network paths.
- Deployment of power equipment, such as UPS and backup diesel generators with fuel tanks.
- Implementation of redundant cooling equipment, such as cooling towers, chilled water supply, and CRAC units to control temperature and humidity.
In addition, MAS emphasizes the following areas:
- Fire detection and suppression systems under Section 8.5.3.
- Geographic separation between the primary/production DC and the secondary/disaster recovery DC under Section 8.5.4.
- 24×7 monitoring of physical security and environmental controls, together with the establishment and testing of escalation and response plans under Section 8.5.5.
- Adequate physical access controls, including need-to-have access, visitor escort, secured access points, restricted rack access, key control, and segregation of delivery/common areas under Section 8.5.6.
As a result, TVRA helps organizations connect risk identification with stronger controls and improved Data Centre resilience.
Read Also : What Is PCI DSS? Definition, Objectives, and Benefits for Businesses
When Should TVRA Be Reviewed?
According to Section 8.5.1 of the MAS Technology Risk Management Guidelines:
The TVRA should be reviewed whenever there is a significant change in the threat landscape or when there is a material change in the DC’s environment.
This means that TVRA is not an assessment that should only be performed once.
When the threat landscape changes or there is a material change in the Data Centre environment, the level of risk may also change. Therefore, organizations need to ensure that TVRA results remain relevant to current conditions.
Regular reviews also help organizations ensure that protection, controls, and mitigation measures remain appropriate for the risks they face.
Conclusion
Threat and Vulnerability Risk Assessment (TVRA) is part of the MAS Technology Risk Management Guidelines, specifically Section 8.5 on Data Centre Resilience.
In this context, Financial Institutions need to identify potential vulnerabilities and weaknesses and determine protection against physical and environmental threats affecting their Data Centres.
With a structured assessment aligned with the MAS Guidelines, organizations can evaluate several critical areas. These include redundancy, environmental controls, geographic separation, 24×7 monitoring, and physical access controls.
Ultimately, TVRA provides a stronger basis for improving Data Centre resilience, risk management, and operational security.
Strengthen Your Data Centre Audit and Risk Assessment
Understanding Data Centre risks helps organizations determine appropriate controls and mitigation measures in line with the expectations of the MAS Technology Risk Management Guidelines.
CBQA Global provides Audit and Assessment services to help organizations evaluate risks, controls, compliance, and Data Centre resilience based on business and regulatory requirements.
Contact CBQA Global to discuss your audit and assessment requirements.
Contact Us
Email:
info@cbqaglobal.com
Marketing Email:
marketing.cbqaglobal@gmail.com
WhatsApp:
08118468777
Phone:
+62 21 2781 4200
CBQA Global. We Inspire in Trust.