Security Questionnaire Mapper
Framework

SIG (Shared Assessments): what it anchors in a questionnaire

The Shared Assessments questionnaire banks and insurers send. Its ids name a domain letter (A to U); a SIG reference in a question places its domain.

The text of this standard is not held in full here, so it is not quoted: each requirement carries a one-line statement of what it asks for, with its code and title, and the standard itself holds the wording. Ticked by default for bank and other customer customers.

Families anchored here

24 families, 12 clauses cited
FamilyClause
Information security policydomain B
Risk assessmentdomain A
Background checksdomain E
Security awareness trainingdomain E
Confidentiality terms and leaversdomain E
Multi-factor authenticationdomain H
Password policydomain H
Access provisioning and reviewdomain H
Privileged accessdomain H
Encryption at restdomain D
Data retention and secure deletiondomain D
Logging and monitoringdomain G
Vulnerability and patch managementdomain P
Penetration testingdomain P
Secure development and changedomain I
Incident response plandomain J
Notifying the customer of an incidentdomain J
Business continuity plandomain K
Backup and disaster recoverydomain K
Subcontractors and subprocessorsdomain T
Assessing your own suppliersdomain T
Data subject requestsdomain O
Lawful basis, consent and privacy noticedomain O
Data processing agreementdomain O

Every SIG clause the register cites, with its text and evidence