Frameworks / Singapore Government Instruction Manual on ICT&SS Management (IM8) / DAT.2 Singapore Government Instruction Manual on ICT&SS Management (IM8)
Data Management
Singapore Government Instruction Manual on ICT&SS Management (IM8) DAT.2: Data Protection Agencies must implement controls to protect the confidentiality, integrity, and availability of government data.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 301 controls across 129 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CH-FADP-19 Transparency and proactive information CH-FADP-21 Data protection impact assessments FADP-16 FDPIC Independence and Functions FADP-7 Data Protection Impact Assessment (Articles 9-10) FADP-9 Data Protection Advisor (Articles 14-15) NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness NISTPF-6 Protect-P Data Security (PR.DS-P) NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NDPA-1 Applicability, Scope, and Carve-Outs NDPA-4 Sensitive Data Processing Consent and Childrens Protections NDPA-7 Data Protection Assessments and Processor Contracts NDPA-8 Nebraska Attorney General Enforcement, Permanent 30-Day Cure, and Penalties NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission NG-NDPA-4 Data Subject Rights and Automated Decision-Making NG-NDPA-7 Cross-Border Data Transfers and International Cooperation NG-NDPA-8 Enforcement, Penalties, Data Controllers of Major Importance (DCMI), and Compliance 4.3.2 Legal and Other Requirements 4.4.1 Resources, Roles, Responsibility, and Authority 4.4.2 Competence, Training, and Awareness AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction AT-DSG-12 Section 62 - Administrative penalties AT-DSG-7 Section 18 - Establishment of the Data Protection Authority FFIEC-11 Business continuity planning and testing FFIEC-12 Disaster recovery procedures FFIEC-14 Critical service identification NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations NIST-CSF-PR.IR-04 Adequate resource capacity to ensure availability is maintained SOC2-A1.1 Maintains capacity to meet availability commitments SOC2-A1.2 Environmental protections, data backups, and recovery infrastructure support availability SOC2-A1.3 Recovery plan procedures support system recovery from failures UGA-3 Accountability Principle UGA-6 Personal Data Protection Office UGA-7 Data Protection Officer CPS234-14 Definition of Information Security Roles and Responsibilities CPS234-15 Information Security Capability ASD37-20 Multi-factor authentication (Essential) ASD37-27 Outbound data loss prevention (Very Good) AZ-DPA-15 Article 17 - Dispute resolution AZ-DPA-6 Article 6 - State regulation in personal data protection BB-DPA-1 Section 1 - Short Title BB-DPA-4 Section 4 - Principles Relating to Processing 62351-12 Resilience and security recommendations for DER 62351-13 Cyber-physical generation and storage resilience NISTSP144-3 Data Classification, Handling, and Sovereignty NISTSP144-5 Identity and Access in Cloud, Federation, and Privileged Access NISTSP145-3 Rapid Elasticity Characteristic and Capacity Management NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition NISTSP146-6 Cloud Security and Privacy Recommendations NISTSP146-7 Service Level, Performance, Reliability, Interoperability, and Portability NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation NGCB-7 Patron and Employee Data Protection + Data Inventory + Vendor Management NHPA-7 Data Protection Assessments and Processor Contracts NHPA-8 AG Formella Enforcement, Permanent 60-Day Cure, and Penalties NJDPA-7 Data Protection Assessments and Processor Contracts NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security NGNDPR-6 Data Protection Officer, DPCOs, and Processor Obligations OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation OSFIB13-4 Third-Party Risk Management and Cloud OSFIB13-7 Incident Reporting to OSFI and Regulatory Coordination OPENBANK-4 Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices OREGONCPA-8 Cure Period, Attorney General Enforcement, Training, Compliance Monitoring PDPASG-1 Accountability, Records, DPO Appointment, and Training PDPASG-4 Children's Data, DPIA, and Privacy by Design PDPATH-4 DPIA, Privacy by Design, Children's Data PDPATH-7 DPO, Records of Processing, Retention, Marketing, Training POPIASA-4 Special Personal Information, Children, Information Quality, Documentation POPIASA-7 Information Officer, Records of Processing, Notification, Training NORWAY-4 DPIA, Privacy by Design, Records of Processing NORWAY-7 DPO, Cooperation with Datatilsynet, Retention, Marketing, Training NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design NZPRV-8 Privacy Officer, OPC Cooperation, Compliance Notices, Complaints, Training SOCI-S30BC Notification of critical cyber security incidents (12 hours) SOCI-S30BD Notification of other cyber security incidents (72 hours) UKAI-2 Sector-Specific Regulator Engagement UKAI-3 Bias Detection, Fairness, Validation CPG-3.C Strong and Agile Encryption RMD-1 Reference Data Management CAT-D5-4 Resilience planning and testing FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) 27007-5.4 Establishing the Programme Resources ITIL4-03 Capacity and availability management NATO-NCIRC-8 Cyberspace as Operational Domain + Cyber Defence Pledge + Annual Self-Assessment NIS2I-5 Cyber Hygiene, Training, Cryptography, and Human Resources Security NISTSP122-8 Continuous Monitoring, Training, and Privacy Programme Governance NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul OMANCS-4 Data Protection, Cryptography, and Privacy Alignment PSDTWO-2 SCA Exemptions and Risk-Based Authentication PARAGUAY-5 Security of Processing, Data Integrity, Information Security PERU-3 Data Subject Rights (ARCO), Habeas Data, Automated Decisions QATAR-7 DPO, Records, Retention, Marketing, Training SSAE18-A1.1 A1.1 - Availability Commitments and Requirements SAPAIA-2 Right of Access and Request Processes STUDPRV-2 Data Subject Rights for Students and Parents TEF-2 Openness and Transparency TISAXASS-3 Prototype Protection and Confidentiality D.1 Incident Response Planning UKOPRES-5 Third-Party Risk, Concentration Risk UNESCOAI-2 Principles 4-7: Sustainability, Privacy, Human Oversight, Transparency UNICEFAI-4 Transparency, Explanation, Adult Capacity CERT-1 RRA Certification to EPA Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Data Management Query this from an agent The graph holds this control, the 301 it maps to, and the evidence behind each claim, over MCP and REST.