Singapore Government Instruction Manual on ICT&SS Management (IM8)
Resilience and Incident Response

Singapore Government Instruction Manual on ICT&SS Management (IM8) IM8-RES.2: Disaster Recovery

Agencies must establish disaster recovery procedures and infrastructure to restore critical systems within defined timeframes.

What else in your programme already covers this

This control maps to 419 controls across 166 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 27031:2011 · 7 controls

ISO 22316 · 5 controls

  • ISO22316-01 Organizational resilience and security - business continuity policy for building security and resilience
  • ISO22316-08 Recovery time and point objectives
  • ISO22316-12 Recovery strategy for critical activities
  • ISO22316-14 Supply chain continuity
  • ISO22316-15 Communication strategy during disruption

ISO 22317 · 5 controls

ISO 22318 · 5 controls

  • NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied
  • NRC7354-2 Critical Digital Asset (CDA) Identification, Scope, and Boundary
  • NRC7354-4 Security Controls Implementation per NRC RG 5.71 Appendix B/C
  • RG5.71-C.3 Cyber Security Training
  • RG5.71-C.5 Recovery and Restoration
  • RG5.71-C.6 Configuration Management
  • DA-1 Enterprise Data Architecture
  • DIQ-1 Data Integration and Interoperability
  • DIQ-2 Data Quality Management
  • RMD-1 Reference Data Management

ISO 22320:2018 · 4 controls

ISO/IEC 27011:2024 · 4 controls

SOC 2 · 4 controls

  • SOC2-A1.2 Environmental protections, data backups, and recovery infrastructure support availability
  • SOC2-A1.3 Recovery plan procedures support system recovery from failures
  • SOC2-CC4.2 COSO principle 17: Evaluates and communicates deficiencies in a timely manner
  • SOC2-CC7.4 Responds to identified security incidents through defined procedures

API 1164 · 3 controls

  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)
  • 1.2 Operating System Privileged Account Control
  • 1.3 Virtualisation Platform Protection
  • 3.3 Configure Data Access Control Lists
  • FFIEC-05 Roles and responsibilities definition
  • FFIEC-11 Business continuity planning and testing
  • FFIEC-12 Disaster recovery procedures

IEC 62443 · 3 controls

ISO 27019 · 3 controls

ISO/IEC 23894:2023 · 3 controls

ISO/IEC 27004:2016 · 3 controls

ISO/IEC 27014:2020 · 3 controls

ISO/IEC 27400:2022 · 3 controls

ISO/IEC 29100:2024 · 3 controls

ISO/IEC 29134:2023 · 3 controls

ISO/IEC 29147:2018 · 3 controls

ISO/IEC 30111:2019 · 3 controls

MTCS (Singapore) · 3 controls

NIST SP 1800-32 · 3 controls

  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles
  • NG-NDPA-5 Security of Processing, Breach Notification, and DPIA
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul
  • ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management
  • ORANWG11-6 Security Test Specifications, Certification, and Conformance

PCI P2PE · 3 controls

PCI PIN Security · 3 controls

PCI SSF · 3 controls

  • PICSGMP-2 Chapter 2: Personnel - Qualified Personnel, Key Responsibilities, Training
  • PICSGMP-5 Chapter 5: Production Operations and Material Management
  • PICSGMP-7 Chapter 7: Outsourced Activities and Supplier Management

South Korea ISMS-P · 3 controls

UK Bribery Act 2010 · 3 controls

  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • 4.4.8 Business Continuity and Recovery
  • AT-DSG-2 Section 2 - Scope and application
  • AT-DSG-8 Section 22 - Functions and powers of the DPA
  • MLE.1 Machine Learning Requirements Analysis
  • MLE.3 Machine Learning Training
  • FDBR-702 Definitions (§501.702)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)

ISMAP (Japan) · 2 controls

ISO 19011 · 2 controls

  • 6.5 Preparing and Distributing Audit Report
  • 6.7 Conducting Audit Follow-up

ISO 27017 · 2 controls

ISO 27018 · 2 controls

ISO 27043 · 2 controls

ISO 56002 · 2 controls

ISO/SAE 21434 · 2 controls

MITRE ATT&CK · 2 controls

  • STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • NISTSP115-1 Scope, Methodology, and Assessment Planning
  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-123 · 2 controls

  • NISTSP123-5 Server Operations - Patching, Malware, Logging, Backup
  • NISTSP123-8 Governance, Policies, and ISMS Integration

NIST SP 800-137 · 2 controls

  • NISTSP137-1 ISCM Strategy, Governance, and Volatility Assessment
  • NISTSP137-7 Incident Response Integration and Ongoing Authorization

NIST SP 800-144 · 2 controls

  • NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation
  • NISTSP144-6 Availability, Resilience, BCP/DR, and SLA Management

NIST SP 800-145 · 2 controls

  • NISTSP145-3 Rapid Elasticity Characteristic and Capacity Management
  • NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition

NIST SP 800-146 · 2 controls

  • NISTSP146-1 Cloud Adoption Strategy, Workload Suitability, and Decision Framework
  • NISTSP146-7 Service Level, Performance, Reliability, Interoperability, and Portability

NIST SP 800-190 · 2 controls

NIST SP 800-53 Rev 5 · 2 controls

NIST SP 800-61 · 2 controls

  • NISTSP61-2 Computer Security Incident Response Team (CSIRT) Structure and Staffing
  • NISTSP61-5 Containment, Eradication, and Recovery

NIST SP 800-63-4 · 2 controls

  • NISTSP63R4-1 Digital Identity Risk Management and IAL/AAL/FAL Assurance Level Selection
  • NISTSP63R4-4 Authenticator Lifecycle: Binding, Recovery, Replacement, Suspension, Revocation
  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity

NIST SP 800-88 · 2 controls

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework
  • NISTSP88-5 Media Inventory, Tracking, Chain of Custody, and Sanitization Records

NIST SP 800-92 · 2 controls

  • NISTSP92-1 Log Management Programme, Policy, Roles, and Operational Runbooks
  • NISTSP92-6 Log Retention: Policy, Tiered Storage, Backup, Secure Disposal, Legal Hold

OSFI B-13 · 2 controls

  • OSFIB13-1 Governance, Risk Management, and Three Lines of Defense
  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery

OWASP MASVS · 2 controls

  • OWASPMASVS-7 MASVS-RESILIENCE: Resilience Against Reverse Engineering
  • OWASPMASVS-8 MASVS-PRIVACY: Privacy and Data Protection

OWASP SAMM · 2 controls

  • OWASPSAMM-1 Governance: Strategy, Policy, Compliance, Education, Champions
  • OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management

Open Banking Security · 2 controls

  • OPENBANK-2 Strong Customer Authentication (SCA), Consent Lifecycle, and Customer UX
  • OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM

OpenSSF Scorecard · 2 controls

  • OSSFSC-1 Branch Protection, Code Review, and Repository Governance
  • OSSFSC-8 Project Maintenance, Sustainability, Integration with Supply Chain Security

PSD2 SCA · 2 controls

  • PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements
  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication

PTES · 2 controls

SLSA · 2 controls

  • SUPCHAIN-1 Build Integrity - Source, Build, Provenance
  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • C1 Organizational Boundary
  • C3 Scope 1 and 2 Coverage
  • CPS230-26 Critical Operations Register, Continuity Plan and Activation
  • CPG-6.B Supply Chain Incident Reporting

COBIT 2019 · 1 control

  • QMSR-ISO13485-Sec5 Management responsibility (ISO 13485:2016 Section 5 - incorporated via §820.10)

FedRAMP High · 1 control

  • CA-9 Internal System Connections

FedRAMP Moderate · 1 control

  • CA-9 Internal System Connections
  • ICP-1 Objectives, Powers and Responsibilities of the Supervisor

ISO 31000:2018 · 1 control

  • 6.7 Conducting Audit Follow-up

ISO/IEC 27003:2017 · 1 control

ISO/IEC 27007:2020 · 1 control

ISO/IEC 27010:2015 · 1 control

  • NAIC-5 Third Party Service Provider Oversight - Section 4(F)(3) and Section 5

NERC CIP · 1 control

  • NERCCIP-6 Incident Reporting and Response Planning + Recovery Plans (CIP-008 + CIP-009)
  • NIS2I-3 Incident Handling Policy, Reporting Significance Criteria, and Business Continuity
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • CA-9 Internal System Connections
  • CA-9 Internal System Connections
  • CA-9 Internal System Connections
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation
  • AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold
  • OMANCS-7 Business Continuity, Disaster Recovery, and Resilience

PCI DSS 4.0 · 1 control

  • 2.2.2 Vendor default accounts are managed as follows: • If the vendor default account(s) will be used, the default password is changed per Requirement 8.3.6. • If the vendor default account(s) will not be used,
  • PHILCC-1 Computer Crime Offences (Illegal Access, Interference, Misuse of Devices)
  • RCEPEC-1 Online Personal Information Protection (12.13)
  • SCA-S2 Interpretation and Definitions

South Korea PIPA · 1 control

  • TSAPIPE-2 OT/IT Network Segmentation and Access Control
  • UKGDPRREG-1 Subject Matter, Scope, Principles (Articles 1-11)

WCAG 2.2 · 1 control

  • SO2.2 Digital health architecture blueprint

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Resilience and Incident Response

Query this from an agent

The graph holds this control, the 419 it maps to, and the evidence behind each claim, over MCP and REST.