Singapore Government Instruction Manual on ICT&SS Management (IM8)
Third Party and Supply Chain

Singapore Government Instruction Manual on ICT&SS Management (IM8) TPM.4: Supply Chain Risk Management

Agencies must manage supply chain risks associated with ICT products and services procurement.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 255 controls across 109 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

SASB Standards · 6 controls

  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • CPS230-37 Service Provider Management Policy
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement
  • CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing
  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained
  • NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition
  • AEO-2 Demonstrated Compliance with Customs Requirements
  • AEO-4 Financial Viability
  • P1-S2 Risk-Management Systems
  • P2-S1 Partnership

ISO 27019 · 4 controls

ISO/IEC 23894:2023 · 4 controls

ISO/IEC 27003:2017 · 4 controls

Solvency II · 4 controls

API 1164 · 3 controls

  • FFIEC-03 Risk appetite and tolerance for IT risk
  • FFIEC-18 Ongoing monitoring and assessment
  • FFIEC-20 Exit strategy and transition planning

IEC 62443 · 3 controls

ISO 27005 · 3 controls

ISO 31000 · 3 controls

Japan AI Guidelines · 3 controls

  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • NISTPF-2 Govern-P - Governance Policies, Risk Management Strategy, Awareness Training, and Monitoring
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 1800-32 · 3 controls

  • 3.16 System and Services Acquisition
  • 3.17 Supply Chain Risk Management
  • 3.5 Securely Dispose of Data

NIST SP 800-30 · 3 controls

  • NISTSP30-1 Risk Management Strategy and Risk Assessment Programme Establishment
  • NISTSP30-2 Three-Tier Risk Assessment Scoping (Organisation, Mission/Business, Information System)
  • NISTSP30-8 Risk Assessment Maintenance, Continuous Monitoring, and Integration with the RMF

NIST SP 800-53 Rev 5 · 3 controls

PCI P2PE · 3 controls

PCI PIN Security · 3 controls

PCI SSF · 3 controls

APRA CPS 234 · 2 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-20 Information Asset Classification
  • AS9100D-8.1 Operational Planning and Control
  • AS9100D-8.4 Control of Externally Provided Processes, Products, Services
  • CPG-6.A Vendor and Supplier Incident Reporting
  • CPG-6.B Supply Chain Incident Reporting
  • ICP-16 Enterprise Risk Management for Solvency Purposes
  • ICP-8 Risk Management and Internal Controls

NERC CIP · 2 controls

  • NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010)
  • NERCCIP-8 Supply Chain Risk Management (CIP-013)

NIST SP 800-37 · 2 controls

  • NISTSP37-1 RMF Prepare Step: Organisation-Level and System-Level Preparation
  • NISTSP37-7 RMF Monitor Step: Continuous Monitoring and Ongoing Authorisation

NIST SP 800-39 · 2 controls

  • NISTSP39-4 Risk Responding: Identify, Evaluate, Decide, Implement
  • NISTSP39-5 Risk Monitoring: Effectiveness, Changes, Compliance, and Reassessment Triggers
  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification
  • NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management
  • NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model

OECD AI Principles · 2 controls

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection
  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation

OSFI B-13 · 2 controls

  • OSFIB13-1 Governance, Risk Management, and Three Lines of Defense
  • OSFIB13-4 Third-Party Risk Management and Cloud
  • PICSGMP-1 Chapter 1: Pharmaceutical Quality System (PQS) and Quality Risk Management
  • PICSGMP-7 Chapter 7: Outsourced Activities and Supplier Management

PSD2 SCA · 2 controls

  • PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements
  • PSDTWO-3 Common and Secure Communication, API Access for AISPs and PISPs

South Korea ISMS-P · 2 controls

  • CFR211-J-184 Section 211.184 - Component, Drug Product Container, Closure, and Labeling Records
  • SPS220-28 Annual Board Risk Management Declaration
  • AS9100D-8.4 Control of Externally Provided Processes, Products, Services
  • 3.5 Securely Dispose of Data
  • CJIS-19 Supply Chain Risk Management

ISO 22316 · 1 control

ISO 22317 · 1 control

ISO 22318 · 1 control

ISO 22320:2018 · 1 control

ISO 26000:2010 · 1 control

ISO/IEC 27010:2015 · 1 control

ISO/IEC 27011:2024 · 1 control

  • 27011-5.6 Supplier relationships and telecom supply chain

MTCS (Singapore) · 1 control

  • NIS2I-2 Policy, Risk Management, and Roles + Responsibilities
  • NZISM-1 NZISM Governance, Documentation, and Classification System
  • ORANWG11-1 O-RAN Threat Model, Risk Management, and Security Architecture
  • OECDAI24-3 Frontier Model Risk Management, Capability Disclosure, and Independent Evaluation
  • OWASPLLM-4 Supply Chain and Vector/Embedding Weaknesses (LLM03 + LLM08)
  • OPENBANK-4 Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence
  • ORSA-S1 ORSA Manual Section 1: Description of Insurer's Risk Management Framework
  • PASONE-3 Personnel Security, Vetting, Awareness, and Training
  • PSPF-DIR-001-2024 Direction 001-2024: Foreign Ownership, Control or Influence - Technology Assets
  • SAEIGHT-7 Management System, Worker Engagement, Continuous Improvement
  • SECCLIM-2 Risk Management: Identification, Assessment, Integration
  • SSAE18-CC9.2 CC9.2 - Vendor and Business Partner Risk Management
  • AIGF-1.1 Risk Management and Internal Controls
  • UKAI-1 Risk-Based Approach and Pro-Innovation Principles
  • UKOPRES-5 Third-Party Risk, Concentration Risk

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Third Party and Supply Chain

Query this from an agent

The graph holds this control, the 255 it maps to, and the evidence behind each claim, over MCP and REST.