Skip to main content
A Singapore Government Agency Website How to identify
Official website links end with .gov.sg
Government agencies communicate via .gov.sg websites (e.g. go.gov.sg/open). Trusted websites
Secure websites use HTTPS
Look for a lock () or https:// as an added precaution. Share sensitive information only on official, secure websites.

Security Programme Management

Controls to implement cybersecurity governance, risk, and compliance processes and policies.

Last updated 24 March 2026

PM-1: Cybersecurity Incident Management Plan

Control Statement

Control Recommendations

Risk Statement

PM-2: Risk Assessment

Control Statement

Control Recommendations

Risk Statement

Parameters

PM-3: System Security Plan (SSP) Development

Control Statement

Control Recommendations

Risk Statement

PM-4: Approval of Residual Risks

Control Statement

Control Recommendations

Risk Statement

Parameters

PM-5: Central Submission of Approved System Security Plan (SSP)

Control Statement

Control Recommendations

Risk Statement

PM-6: System Documentation

Control Statement

Control Recommendations

Risk Statement

PM-7: Certification

Control Statement

Control Recommendations

Risk Statement

Parameters

PM-8: SaaS Whitelisting

Control Statement

Control Recommendations

Risk Statement

Parameters

PM-9: Cybersecurity Incident Response Testing

Control Statement

Control Recommendations

Risk Statement

Parameters

PM-10: Cybersecurity Leadership and Oversight

Control Statement

Control Recommendations

Risk Statement