Singapore Government Instruction Manual on ICT&SS Management (IM8)
Singapore's Instruction Manual on ICT and Smart Systems Management (IM8), managed by the Government Technology Agency (GovTech), establishes ICT security policies and standards for Singapore Government agencies. IM8 covers data security classification, cloud security, application security, network security, endpoint security, and security operations. Mandatory for all government ICT systems. Complemented by the Government Commercial Cloud (GCC) framework for cloud adoption.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (27)
AI Governance
| Code | Title |
|---|---|
| IM8-AI | AI and Algorithmic System Governance |
Access Control
| Code | Title |
|---|---|
| IM8-IAM | Identity, Authentication, and Privileged Access |
Architecture and Security
| Code | Title |
|---|---|
| IM8-SEC.1 | Security Architecture Design |
| IM8-SEC.2 | Access Control |
| IM8-SEC.3 | Network Security |
| IM8-SEC.4 | Vulnerability Management |
Asset Disposal
| Code | Title |
|---|---|
| IM8-DEC | Decommissioning and Data Disposal |
Assurance
| Code | Title |
|---|---|
| IM8-AUD | Internal Audit and Independent Assurance |
Awareness
| Code | Title |
|---|---|
| IM8-AWR | Security Awareness and Training |
Cloud Adoption
| Code | Title |
|---|---|
| IM8-CLD | Use of Cloud Services and Government-on-Commercial-Cloud |
Cloud Security
| Code | Title |
|---|---|
| IM8-CLD.1 | Cloud Adoption Governance |
| IM8-CLD.2 | Cloud Security Controls |
| IM8-CLD.3 | Cloud Service Provider Assessment |
| IM8-CLD.4 | Cloud Data Sovereignty |
Contractor Compliance
| Code | Title |
|---|---|
| IM8-CON | Contractor Compliance and Flow-Down |
Data Classification
| Code | Title |
|---|---|
| IM8-CLF | Data Classification and Handling |
Data Management
| Code | Title |
|---|---|
| IM8-DAT.1 | Data Classification |
| IM8-DAT.2 | Data Protection |
| IM8-DAT.3 | Data Sharing and Transfer |
| IM8-DAT.4 | Data Retention and Disposal |
Data Protection
| Code | Title |
|---|---|
| IM8-DLP | Protection of Government Data Across Channels |
Digital Service Standards
| Code | Title |
|---|---|
| IM8-DSS.1 | User-Centric Design |
| IM8-DSS.2 | Service Reliability Standards |
| IM8-DSS.3 | Secure Development Practices |
Governance
| Code | Title |
|---|---|
| AASB-S2-5 | Governance Disclosure Objective |
| AASB-S2-6a | Governance Body Oversight |
| AASB-S2-6b | Management's Role in Governance |
| IM8-GOV | ICT and Smart Systems Governance Structure |
| IM8-GOV.1 | ICT Governance Framework |
| IM8-GOV.2 | Roles and Responsibilities |
| IM8-GOV.3 | Policy Compliance |
| IM8-GOV.4 | ICT Security Risk Management |
| TNFD-GOV-A | Board Oversight |
| TNFD-GOV-B | Management's Role |
| TNFD-GOV-C | Human Rights and Stakeholder Engagement |
Governance
Pillar A: Board and management oversight of nature-related issues
| Code | Title |
|---|---|
| AASB-S2-5 | Governance Disclosure Objective |
| AASB-S2-6a | Governance Body Oversight |
| AASB-S2-6b | Management's Role in Governance |
| IM8-GOV | ICT and Smart Systems Governance Structure |
| IM8-GOV.1 | ICT Governance Framework |
| IM8-GOV.2 | Roles and Responsibilities |
| IM8-GOV.3 | Policy Compliance |
| IM8-GOV.4 | ICT Security Risk Management |
| TNFD-GOV-A | Board Oversight |
| TNFD-GOV-B | Management's Role |
| TNFD-GOV-C | Human Rights and Stakeholder Engagement |
Incident Response
| Code | Title |
|---|---|
| IM8-IR | Cyber Incident Response and Reporting to GovTech |
Logging
| Code | Title |
|---|---|
| IM8-LOG | Logging, Monitoring, and Audit Trail |
Privacy
| Code | Title |
|---|---|
| IM8-DPP | Data Protection and Privacy by Design for Government Services |
Resilience
| Code | Title |
|---|---|
| IM8-BCM | Business Continuity and Disaster Recovery |
| IM8-RES.1 | Business Continuity Planning |
| IM8-RES.2 | Disaster Recovery |
| IM8-RES.3 | Incident Response |
| IM8-RES.4 | Resilience Testing |
Resilience
| Code | Title |
|---|---|
| IM8-BCM | Business Continuity and Disaster Recovery |
| IM8-RES.1 | Business Continuity Planning |
| IM8-RES.2 | Disaster Recovery |
| IM8-RES.3 | Incident Response |
| IM8-RES.4 | Resilience Testing |
Risk Assessment
| Code | Title |
|---|---|
| IM8-RA | Risk Assessment for ICT and SS Initiatives |
Secure Development
| Code | Title |
|---|---|
| IM8-DEV | Secure Software Development for Government Systems |
Security Controls
| Code | Title |
|---|---|
| IM8-SEC | Baseline Security Controls for Government ICT Systems |
Security Testing
| Code | Title |
|---|---|
| IM8-VAPT | Vulnerability Assessment and Penetration Testing |
Supply Chain
| Code | Title |
|---|---|
| IM8-SCM | Supply Chain and Vendor Management |
Third-Party Management
| Code | Title |
|---|---|
| IM8-TPM.1 | Vendor Security Assessment |
| IM8-TPM.2 | Contractual Security Requirements |
| IM8-TPM.3 | Third-Party Monitoring |
| IM8-TPM.4 | Supply Chain Risk Management |
Vulnerability Management
| Code | Title |
|---|---|
| IM8-PATCH | Patching and Vulnerability Remediation |
Your Compliance Coverage
If you comply with Singapore Government Instruction Manual on ICT&SS Management (IM8), you already cover:
CFTC System Safeguards (17 CFR 37, 38, 39, 49)
30%
16 controls mapped
Compare →Defence Security Principles Framework (DSPF)
30%
16 controls mapped
Compare →Protective Security Policy Framework (PSPF) Release 2024
30%
16 controls mapped
Compare →+ 666 more: DORA (30%), CSA CCM v4 (30%)
See all 669 mapped frameworks ↓Maps to 669 other frameworks
Frequently Asked Questions
What is Singapore Government Instruction Manual on ICT&SS Management (IM8)?
Singapore Government Instruction Manual on ICT&SS Management (IM8) is a compliance framework from Singapore (GovTech) with 27 domains and 53 controls. Singapore's Instruction Manual on ICT and Smart Systems Management (IM8), managed by the Government Technology Agency (GovTech), establishes ICT security policies and standards for Singapore Government agencies. IM8 covers data security classification, cloud security, application security, network security, endpoint security, and security operations. Mandatory for all government ICT systems. Complemented by the Government Commercial Cloud (GCC) framework for cloud adoption. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Singapore Government Instruction Manual on ICT&SS Management (IM8) have?
Singapore Government Instruction Manual on ICT&SS Management (IM8) has 53 controls organised across 27 domains. The largest domains are Governance (10 controls), Architecture and Security (4 controls), Cloud Security (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Singapore Government Instruction Manual on ICT&SS Management (IM8) map to?
Singapore Government Instruction Manual on ICT&SS Management (IM8) maps to 669 other compliance frameworks. The top mapping partners are CFTC System Safeguards (17 CFR 37, 38, 39, 49) (30% coverage), Defence Security Principles Framework (DSPF) (30% coverage), Protective Security Policy Framework (PSPF) Release 2024 (30% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Singapore Government Instruction Manual on ICT&SS Management (IM8) compliance?
Start your Singapore Government Instruction Manual on ICT&SS Management (IM8) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Singapore Government Instruction Manual on ICT&SS Management (IM8) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 53 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required