Singapore Government Instruction Manual on ICT&SS Management (IM8)
Evidence request list. 44 controls, 44 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
AI Governance
Per IM8: AI and Algorithmic System Governance + ethics + risk + integration with SG AI Verify.
- IM8 evidence for SGIMEIGHT-3
- AI governance + cloud + audit partial
Awareness and Training
Deliver security awareness and role-specific training to public officers and contractors handling government data, with knowledge checks and refresher cycles aligned to IM8.
- Annual awareness curriculum and completion records
- Role-specific training for developers, administrators, and data handlers
- Phishing simulation programme outputs
- Refresh schedule and exception handling
- Awareness training completion measured at policy publication only, not actual completion
- Role-based training optional for senior officers
- Phishing simulations performed but failures not converted to targeted training
Cloud Services
Where cloud services are used, comply with IM8 requirements for government cloud adoption, including approved cloud service providers, data residency, sensitivity restrictions, and Government-on-Commercial-Cloud (GCC) usage where applicable.
- Approved cloud service provider list and contracts
- Data residency configuration evidence
- GCC tenant configuration and guardrails
- Cloud risk assessment per workload
- Workloads classified as Restricted deployed on non-approved cloud tiers
- Data residency configured at storage level but not at backup and analytics layers
- GCC guardrails disabled for development tenants without compensating controls
Agencies must follow prescribed governance processes when adopting cloud services for government workloads.
- cloud adoption policy
- cloud governance framework
- approval procedures
- exception register
- no cloud governance framework
- weak approval procedures
- missing exception register
Agencies must implement security controls for cloud environments covering access, encryption, and monitoring.
- cloud control matrix
- shared responsibility documentation
- control implementation evidence
- monitoring records
- unclear shared responsibility
- missing control matrix
- weak monitoring
Agencies must assess and validate the security posture of cloud service providers before engagement.
- CSP risk assessment reports
- MTCS certification records
- contract clauses
- ongoing monitoring records
- no CSP risk assessment
- weak contracts
- missing ongoing monitoring
Agencies must ensure government data stored in cloud environments meets data residency and sovereignty requirements.
- data residency mapping
- data location records
- transfer agreements
- regulatory compliance documentation
- no residency mapping
- weak transfer agreements
- missing compliance documentation
Cloud and Data
Per IM8: cloud + data + procurement + outsourcing controls per government context.
- IM8 evidence for SGIMEIGHT-4
- AI governance + cloud + audit partial
Data Management
Agencies must classify data according to sensitivity levels and apply appropriate handling and protection measures.
- data classification policy
- classification scheme
- labelling records
- review cadence
- no classification scheme
- weak labelling
- no review cadence
Agencies must implement controls to protect the confidentiality, integrity, and availability of government data.
- data protection policy
- encryption records
- access control documentation
- DLP configurations
- weak encryption
- no DLP
- missing access controls
Agencies must establish controls for secure data sharing and transfer between agencies and with external parties.
- data sharing agreements
- transfer impact assessments
- approval records
- monitoring logs
- no sharing agreements
- weak TIA
- missing monitoring
Agencies must implement policies for data retention schedules and secure disposal of data no longer required.
- retention schedule
- disposal procedures
- destruction certificates
- audit records
- no retention schedule
- weak disposal
- missing certificates
Decommission ICT and SS assets and dispose of government data in line with IM8 requirements, including secure data destruction, decommission records, and confirmation of asset disposal.
- Decommissioning plan per system
- Secure destruction certificates from approved providers
- Inventory updates reflecting disposal
- Confirmation of removal from backups and archives
- Production data destroyed but copies in backups and analytics not addressed
- Destruction certificates accepted from non-approved providers
- Inventory not updated post-decommissioning, leaving phantom assets
Digital Services and Secure Development
Apply secure software development practices to government ICT and SS, including secure coding standards, code review, automated security testing, and security gates within the development lifecycle.
- Secure development policy aligned with IM8
- Code review records and pull request templates referencing security checks
- SAST, DAST, and SCA tool configuration and findings
- Security gate evidence at build and release
- Secure development policy aligned to outdated IM8 revision
- Automated testing runs but findings not blocked at gates
- Third-party code integrated without SCA scanning
Digital services must be designed with user needs and accessibility requirements as primary considerations.
- user research records
- service blueprints
- usability test reports
- design standards documentation
- no user research
- weak usability testing
- missing design standards
Digital services must meet prescribed availability and performance standards for public-facing systems.
- SLA documentation
- uptime reports
- incident metrics
- reliability test results
- no SLA
- weak uptime tracking
- missing reliability tests
Agencies must adopt secure software development lifecycle practices for digital services.
- secure SDLC documentation
- code review records
- SAST and DAST results
- developer training records
- no secure SDLC
- weak code review
- missing security testing
Governance
Per Singapore IM8: governance + Internal Audit and Independent Assurance + reporting to senior management + SmartNation Group + GovTech.
- IM8 evidence for SGIMEIGHT-1
- AI governance + cloud + audit partial
Governance and Risk Management
Classify government data and information products according to the IM8 sensitivity and security classification scheme (Official-Open, Official-Closed, Restricted, Confidential, Secret) and apply handling controls appropriate to each tier.
- Data classification policy aligned with IM8 scheme
- Inventory of datasets and information products with assigned classifications
- Handling instructions per classification including transmission, storage, and destruction
- Sample documents and systems with applied markings
- Classifications applied at dataset level but not at field level for mixed-sensitivity records
- Handling instructions not implemented in technical controls (DLP, labelling)
- Markings inconsistent between document templates and actual outputs
Ensure contractors who develop, operate, or maintain government ICT and SS comply with applicable IM8 instructions through contractual obligations, training, monitoring, and assurance.
- Standard government ICT contract clauses referencing IM8
- Contractor staff IM8 awareness training records
- Ongoing assurance reviews of contractor compliance
- Right-to-audit exercises performed and findings closed
- Older contracts predating current IM8 revisions not amended
- Training delivered to contractor leads only, not to engineering staff
- Right-to-audit clauses never exercised, leaving compliance unverified
Apply data protection and privacy by design principles to government services, including data minimisation, purpose limitation, retention controls, and Data Protection Trustmark or equivalent assurance where applicable.
- Privacy impact assessment per service
- Data minimisation analysis showing fields collected versus required
- Retention schedule per dataset
- Records of purpose limitation review when data is reused
- Privacy impact assessment performed for citizen-facing services only, omitting internal datasets
- Retention schedules documented but not implemented in storage layers
- Secondary use of data approved without revisiting privacy impact assessment
Conduct risk assessments for every ICT and SS initiative covering security, privacy, operational, and supplier dimensions, and refresh assessments at defined lifecycle gates.
- Risk assessment template aligned to IM8 dimensions
- Completed assessments per ICT and SS project
- Gate review records linking risk outcomes to approval decisions
- Refresh schedule per system criticality
- Assessments performed only at initiation, never refreshed when scope changes
- Risk treatment plans logged without ownership
- Supplier risk treated separately and not integrated into the initiative risk view
Incident
Per IM8: incident response + business continuity + cyber resilience.
- IM8 evidence for SGIMEIGHT-5
- AI governance + cloud + audit partial
Information Security
Protect government data across storage, transmission, and processing using encryption, data loss prevention, and approved transmission channels appropriate to the data classification.
- Encryption inventory mapped to data classification
- TLS configuration and certificate inventory
- DLP policy and event handling records
- Approved channel list for sensitive data exchange
- Encryption applied at storage layer but bypassed by direct database access
- Legacy transmission channels (FTP, unauthenticated email) still in operational use
- DLP alerts triaged inconsistently across business units
Apply identity, authentication, and privileged access controls in line with IM8 requirements, including strong authentication for sensitive access, role-based access control, and oversight of privileged accounts.
- Sign-In with Singpass or equivalent strong authentication evidence for sensitive transactions
- Role definitions and access matrices
- Privileged access management tool logs
- Periodic access review records
- Multi-factor authentication enforced for end users but not for system-to-system credentials
- Role definitions overlap creating implicit privilege accumulation
- Privileged session recording configured but recordings never reviewed
Generate and retain logs of security-relevant events from government ICT and SS systems, monitor them for indicators of compromise, and protect them from tampering.
- Log source inventory covering OS, application, database, network, and identity layers
- Retention configured to IM8 prescribed period
- SIEM ingestion and use-case catalogue
- Integrity controls for log storage
- Application logs sampled rather than complete
- Retention shortened to manage storage costs without authorisation
- No tamper evidence (hashing, immutability) on archived logs
Patch ICT and SS systems within the prescribed timeframes based on severity, and track unpatched vulnerabilities with documented risk acceptance.
- Patch deployment records meeting IM8 SLAs per severity
- Vulnerability tracker with status and aging
- Risk acceptance forms for deferred patches
- Reporting to senior accountable officer
- SLA tracked at fleet average rather than per asset
- Risk acceptance forms missing senior officer signature
- Reporting lacks trending over time, missing systemic patch debt
Agencies must adopt defence-in-depth security architecture principles for ICT systems design.
- security architecture documents
- reference architectures
- design review records
- approval logs
- no security architecture
- weak design reviews
- missing approvals
Agencies must implement access control mechanisms based on least privilege and need-to-know principles.
- access control policy
- RBAC documentation
- access review reports
- privileged access logs
- weak access control
- no reviews
- missing privileged access controls
Agencies must implement network segmentation, firewalls, and intrusion detection to protect government networks.
- network architecture diagrams
- firewall rule reviews
- segmentation documentation
- monitoring records
- flat network
- stale rules
- weak segmentation
Agencies must conduct regular vulnerability assessments and penetration testing of ICT systems.
- vulnerability scan reports
- remediation tracking
- patching records
- exception register
- scanning gaps
- remediation past SLA
- missing patches
Conduct vulnerability assessment and penetration testing (VAPT) on ICT and SS systems prior to go-live and at defined intervals thereafter, using approved testers and addressing identified findings within prescribed timeframes.
- VAPT schedule aligned to IM8 frequencies
- Engagement records with approved testers
- VAPT reports with severity-ranked findings
- Remediation tracker meeting prescribed SLA
- Penetration testing performed pre-launch but not refreshed post material change
- Remediation extensions granted without revisiting risk acceptance
- Test scope limited to surface assets, omitting internal lateral paths
Per IM8: information security + classification + access control + encryption + cybersecurity baseline.
- IM8 evidence for SGIMEIGHT-2
- AI governance + cloud + audit partial
Resilience and Incident Response
Maintain business continuity and disaster recovery plans for government ICT and SS aligned to service criticality, with regular testing and senior officer sign-off on residual risk.
- BCP covering essential government services
- DR test plans and results
- Service criticality matrix linking RTO and RPO to citizen impact
- Senior officer sign-off on residual risk
- BCPs static after first publication, not refreshed for service changes
- DR tests performed without independent observation
- Criticality matrix not aligned with whole-of-government service classifications
Maintain a cyber incident response capability and report incidents affecting government ICT and SS to GovTech (the lead agency) and other authorities within prescribed timelines, including incidents at contractors.
- IR plan referencing GovTech notification obligations
- Incident reporting log with timestamps
- Contractor notification clauses and operational evidence
- Post-incident review reports
- Reporting starts from confirmation rather than detection
- Contractor incidents notified to procuring agency only, not escalated as required
- Post-incident reviews completed but findings not fed into baseline improvements
Agencies must develop and maintain business continuity plans for critical ICT systems and services.
- BCP documentation
- BIA records
- BCP testing reports
- executive sign-off
- no BCP
- weak BIA
- missing testing
Agencies must establish disaster recovery procedures and infrastructure to restore critical systems within defined timeframes.
- DR plan
- DR test reports
- RTO and RPO documentation
- failover records
- no DR plan
- untested DR
- missing RTO and RPO
Agencies must implement incident response procedures to detect, contain, and recover from cybersecurity incidents.
- incident response plan
- Playbooks
- exercise reports
- lessons learned register
- no IR plan
- weak playbooks
- missing exercises
Agencies must conduct regular testing of business continuity and disaster recovery plans to ensure effectiveness.
- resilience test plan
- exercise reports
- scenario documentation
- improvement tracking
- no resilience testing
- weak scenarios
- missing improvement tracking
Third Party and Supply Chain
Manage supply chain and vendor risks for government ICT and SS, including third-party security assessments, contractual security obligations, and ongoing monitoring of vendor performance.
- Vendor risk assessment records
- Contract clauses referencing IM8 obligations, audit rights, and incident reporting
- Quarterly or annual vendor performance reviews
- Sub-contractor flow-down evidence
- Due diligence performed at award with no refresh
- Contracts lack flow-down clauses to sub-contractors
- Performance reviews track delivery only, omitting security KPIs
Agencies must assess the security posture of third-party vendors before granting access to government systems.
- vendor risk assessments
- security questionnaires
- due diligence records
- approval logs
- no vendor assessment
- weak questionnaires
- missing approvals
Agencies must include security requirements in contracts with third-party ICT service providers.
- contract security clauses
- DPA records
- right-to-audit clauses
- contract review logs
- missing clauses
- no DPA
- no audit rights
Agencies must monitor third-party compliance with security requirements throughout the engagement period.
- vendor monitoring records
- performance reports
- compliance dashboards
- review cadence
- no ongoing monitoring
- weak dashboards
- missing review cadence
Agencies must manage supply chain risks associated with ICT products and services procurement.
- supply chain risk register
- subcontractor inventory
- concentration analyses
- executive reports
- no supply chain register
- weak subcontractor visibility
- missing concentration analyses
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.