Singapore Government Instruction Manual on ICT&SS Management (IM8)
Data Management

Singapore Government Instruction Manual on ICT&SS Management (IM8) DAT.2: Data Protection

Agencies must implement controls to protect the confidentiality, integrity, and availability of government data.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 301 controls across 129 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CH-FADP-19 Transparency and proactive information
  • CH-FADP-21 Data protection impact assessments
  • FADP-16 FDPIC Independence and Functions
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • FADP-9 Data Protection Advisor (Articles 14-15)
  • NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness
  • NISTPF-6 Protect-P Data Security (PR.DS-P)
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-4 Sensitive Data Processing Consent and Childrens Protections
  • NDPA-7 Data Protection Assessments and Processor Contracts
  • NDPA-8 Nebraska Attorney General Enforcement, Permanent 30-Day Cure, and Penalties
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-4 Data Subject Rights and Automated Decision-Making
  • NG-NDPA-7 Cross-Border Data Transfers and International Cooperation
  • NG-NDPA-8 Enforcement, Penalties, Data Controllers of Major Importance (DCMI), and Compliance
  • 4.3.2 Legal and Other Requirements
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • 4.4.2 Competence, Training, and Awareness
  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority
  • FFIEC-11 Business continuity planning and testing
  • FFIEC-12 Disaster recovery procedures
  • FFIEC-14 Critical service identification

GDPR · 3 controls

ISO 13485 · 3 controls

ISO 27017 · 3 controls

ISO 27018 · 3 controls

ISO 27799 · 3 controls

ISO/IEC 27011:2024 · 3 controls

MTCS (Singapore) · 3 controls

  • NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected
  • NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
  • NIST-CSF-PR.IR-04 Adequate resource capacity to ensure availability is maintained

NIST SP 800-190 · 3 controls

PCI P2PE · 3 controls

PCI PIN Security · 3 controls

PCI SSF · 3 controls

SOC 2 · 3 controls

  • SOC2-A1.1 Maintains capacity to meet availability commitments
  • SOC2-A1.2 Environmental protections, data backups, and recovery infrastructure support availability
  • SOC2-A1.3 Recovery plan procedures support system recovery from failures
  • UGA-3 Accountability Principle
  • UGA-6 Personal Data Protection Office
  • UGA-7 Data Protection Officer

APRA CPS 234 · 2 controls

  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • CPS234-15 Information Security Capability
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-27 Outbound data loss prevention (Very Good)
  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection

Bahrain PDPL · 2 controls

  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-4 Section 4 - Principles Relating to Processing
  • 62351-12 Resilience and security recommendations for DER
  • 62351-13 Cyber-physical generation and storage resilience

ISO/IEC 27031:2011 · 2 controls

ISO/IEC 27400:2022 · 2 controls

Japan AI Guidelines · 2 controls

MARS-E · 2 controls

MDS2 (Medical Device) · 2 controls

Mauritius DPA · 2 controls

Mexico LFPDPPP · 2 controls

NIST SP 800-144 · 2 controls

  • NISTSP144-3 Data Classification, Handling, and Sovereignty
  • NISTSP144-5 Identity and Access in Cloud, Federation, and Privileged Access

NIST SP 800-145 · 2 controls

  • NISTSP145-3 Rapid Elasticity Characteristic and Capacity Management
  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 2 controls

  • NISTSP146-6 Cloud Security and Privacy Recommendations
  • NISTSP146-7 Service Level, Performance, Reliability, Interoperability, and Portability
  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation
  • NGCB-7 Patron and Employee Data Protection + Data Inventory + Vendor Management
  • NHPA-7 Data Protection Assessments and Processor Contracts
  • NHPA-8 AG Formella Enforcement, Permanent 60-Day Cure, and Penalties
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs
  • NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security
  • NGNDPR-6 Data Protection Officer, DPCOs, and Processor Obligations

OECD AI Principles · 2 controls

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection
  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation

OSFI B-13 · 2 controls

  • OSFIB13-4 Third-Party Risk Management and Cloud
  • OSFIB13-7 Incident Reporting to OSFI and Regulatory Coordination

Open Banking Security · 2 controls

  • OPENBANK-4 Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence
  • OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • OREGONCPA-8 Cure Period, Attorney General Enforcement, Training, Compliance Monitoring

PDPA Singapore · 2 controls

  • PDPASG-1 Accountability, Records, DPO Appointment, and Training
  • PDPASG-4 Children's Data, DPIA, and Privacy by Design

PDPA Thailand · 2 controls

  • PDPATH-4 DPIA, Privacy by Design, Children's Data
  • PDPATH-7 DPO, Records of Processing, Retention, Marketing, Training

POPIA · 2 controls

  • POPIASA-4 Special Personal Information, Children, Information Quality, Documentation
  • POPIASA-7 Information Officer, Records of Processing, Notification, Training
  • NORWAY-4 DPIA, Privacy by Design, Records of Processing
  • NORWAY-7 DPO, Cooperation with Datatilsynet, Retention, Marketing, Training

Privacy Act 2020 · 2 controls

  • NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design
  • NZPRV-8 Privacy Officer, OPC Cooperation, Compliance Notices, Complaints, Training

SASB Standards · 2 controls

Saudi Arabia PDPL · 2 controls

  • SOCI-S30BC Notification of critical cyber security incidents (12 hours)
  • SOCI-S30BD Notification of other cyber security incidents (72 hours)
  • UKAI-2 Sector-Specific Regulator Engagement
  • UKAI-3 Bias Detection, Fairness, Validation

Uruguay DPL · 2 controls

COBIT 2019 · 1 control

  • CAT-D5-4 Resilience planning and testing
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))

ISMAP (Japan) · 1 control

ISO 20000-1 · 1 control

ISO 26000:2010 · 1 control

ISO/IEC 23894:2023 · 1 control

ISO/IEC 27007:2020 · 1 control

  • 27007-5.4 Establishing the Programme Resources

ITIL 4 · 1 control

  • ITIL4-03 Capacity and availability management

LGPD · 1 control

Liechtenstein DPA · 1 control

Malaysia PDPA 2010 · 1 control

  • NATO-NCIRC-8 Cyberspace as Operational Domain + Cyber Defence Pledge + Annual Self-Assessment
  • NIS2I-5 Cyber Hygiene, Training, Cryptography, and Human Resources Security

NIST SP 800-122 · 1 control

  • NISTSP122-8 Continuous Monitoring, Training, and Privacy Programme Governance

NIST SP 800-66 · 1 control

  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication
  • NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment

PSD2 SCA · 1 control

  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication
  • PARAGUAY-5 Security of Processing, Data Integrity, Information Security

Peru DPL · 1 control

  • PERU-3 Data Subject Rights (ARCO), Habeas Data, Automated Decisions

Qatar DPL · 1 control

  • QATAR-7 DPO, Records, Retention, Marketing, Training
  • SSAE18-A1.1 A1.1 - Availability Commitments and Requirements
  • SAPAIA-2 Right of Access and Request Processes

South Korea PIPA · 1 control

  • STUDPRV-2 Data Subject Rights for Students and Parents
  • TISAXASS-3 Prototype Protection and Confidentiality

Taiwan PDPA · 1 control

Turkey KVKK · 1 control

  • UKOPRES-5 Third-Party Risk, Concentration Risk
  • UNESCOAI-2 Principles 4-7: Sustainability, Privacy, Human Oversight, Transparency
  • UNICEFAI-4 Transparency, Explanation, Adult Capacity

Vietnam PDPD · 1 control

Virginia CDPA · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Data Management

Query this from an agent

The graph holds this control, the 301 it maps to, and the evidence behind each claim, over MCP and REST.