Singapore Government Instruction Manual on ICT&SS Management (IM8)
Singapore's Instruction Manual on ICT and Smart Systems Management (IM8), managed by the Government Technology Agency (GovTech), establishes ICT security policies and standards for Singapore Government agencies. IM8 covers data security classification, cloud security, application security, network security, endpoint security, and security operations. Mandatory for all government ICT systems. Complemented by the Government Commercial Cloud (GCC) framework for cloud adoption.
Singapore Government Instruction Manual on ICT&SS Management (IM8) is a compliance framework from Singapore (GovTech) with 12 domains and 44 controls that map to 294 other frameworks. The largest domains are Information Security (10 controls), Resilience and Incident Response (6 controls), Cloud Services (5 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (12)
AI Governance
| Code | Title |
|---|---|
| SGIMEIGHT-3 | AI and Algorithmic System Governance |
Awareness and Training
Awareness and Training
| Code | Title |
|---|---|
| IM8-AWR | Security Awareness and Training |
Cloud Services
Cloud Services
| Code | Title |
|---|---|
| IM8-CLD | Use of Cloud Services and Government-on-Commercial-Cloud |
| IM8-CLD.1 | Cloud Adoption Governance |
| IM8-CLD.2 | Cloud Security Controls |
| IM8-CLD.3 | Cloud Service Provider Assessment |
| IM8-CLD.4 | Cloud Data Sovereignty |
Cloud and Data
| Code | Title |
|---|---|
| SGIMEIGHT-4 | Cloud, Data, Procurement, Outsourcing |
Data Management
Data Management
Digital Services and Secure Development
Digital Services and Secure Development
| Code | Title |
|---|---|
| IM8-DEV | Secure Software Development for Government Systems |
| IM8-DSS.1 | User-Centric Design |
| IM8-DSS.2 | Service Reliability Standards |
| IM8-DSS.3 | Secure Development Practices |
Governance
| Code | Title |
|---|---|
| SGIMEIGHT-1 | Governance, Audit, Independent Assurance |
Governance and Risk Management
Governance and Risk Management
| Code | Title |
|---|---|
| IM8-CLF | Data Classification and Handling |
| IM8-CON | Contractor Compliance and Flow-Down |
| IM8-DPP | Data Protection and Privacy by Design for Government Services |
| IM8-RA | Risk Assessment for ICT and SS Initiatives |
Incident
| Code | Title |
|---|---|
| SGIMEIGHT-5 | Incident Response and Continuity |
Information Security
| Code | Title |
|---|---|
| IM8-DLP | Protection of Government Data Across Channels |
| IM8-IAM | Identity, Authentication, and Privileged Access |
| IM8-LOG | Logging, Monitoring, and Audit Trail |
| IM8-PATCH | Patching and Vulnerability Remediation |
| IM8-SEC.1 | Security Architecture Design |
| IM8-SEC.2 | Access Control |
| IM8-SEC.3 | Network Security |
| IM8-SEC.4 | Vulnerability Management |
| IM8-VAPT | Vulnerability Assessment and Penetration Testing |
| SGIMEIGHT-2 | Information Security, Classification, Access |
Resilience and Incident Response
Resilience and Incident Response
| Code | Title |
|---|---|
| IM8-BCM | Business Continuity and Disaster Recovery |
| IM8-IR | Cyber Incident Response and Reporting to GovTech |
| IM8-RES.1 | Business Continuity Planning |
| IM8-RES.2 | Disaster Recovery |
| IM8-RES.3 | Incident Response |
| IM8-RES.4 | Resilience Testing |
Third Party and Supply Chain
Third Party and Supply Chain
| Code | Title |
|---|---|
| IM8-SCM | Supply Chain and Vendor Management |
| IM8-TPM.1 | Vendor Security Assessment |
| IM8-TPM.2 | Contractual Security Requirements |
| IM8-TPM.3 | Third-Party Monitoring |
| IM8-TPM.4 | Supply Chain Risk Management |
Your Compliance Coverage
If you comply with Singapore Government Instruction Manual on ICT&SS Management (IM8), you already cover:
Maps to 294 other frameworks
What is Singapore Government Instruction Manual on ICT&SS Management (IM8) and who does it apply to?
Singapore Government Instruction Manual on ICT&SS Management (IM8) is a compliance framework from Singapore (GovTech) with 12 domains and 44 controls. Singapore's Instruction Manual on ICT and Smart Systems Management (IM8), managed by the Government Technology Agency (GovTech), establishes ICT security policies and standards for Singapore Government agencies. IM8 covers data security classification, cloud security, application security, network security, endpoint security, and security operations. Mandatory for all government ICT systems. Complemented by the Government Commercial Cloud (GCC) framework for cloud adoption. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does Singapore Government Instruction Manual on ICT&SS Management (IM8) actually require?
Singapore Government Instruction Manual on ICT&SS Management (IM8) has 44 controls organised across 12 domains. The largest domains are Information Security (10 controls), Resilience and Incident Response (6 controls), Cloud Services (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of Singapore Government Instruction Manual on ICT&SS Management (IM8) do I already cover?
Singapore Government Instruction Manual on ICT&SS Management (IM8) maps to 294 other compliance frameworks. The top mapping partners are MTCS (Singapore) (30% coverage), NIST Privacy Framework (25% coverage), SOC for Cybersecurity - Cybersecurity Risk Management Examination (25% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement Singapore Government Instruction Manual on ICT&SS Management (IM8)?
Start your Singapore Government Instruction Manual on ICT&SS Management (IM8) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Singapore Government Instruction Manual on ICT&SS Management (IM8) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 44 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required