SIG (Shared Assessments): the clauses the register cites
The 12 SIG (Shared Assessments) clauses that questions are placed on, each with the evidence an assessor asks for and where answers usually fall short.
The text of this standard is not held in full here, so it is not quoted: each requirement carries a one-line statement of what it asks for, with its code and title, and the standard itself holds the wording.
12 clauses
the families they anchorSIG domain A Risk Assessment and Treatment ProgramWhat it asks for, in one line (the standard's own text is not quoted here):
Maintain a documented risk assessment and treatment program covering information security, operational, third party, and compliance risks, with defined ownership, frequency, and integration into business decision making.
Where answers usually fall short: Risk register stale beyond annual cycle; No documented risk acceptance approvals at appropriate level
Source: SIG (Shared Assessments)
SIG domain B Information Security Policy SuiteWhat it asks for, in one line (the standard's own text is not quoted here):
Establish, approve, communicate, and periodically review a suite of information security policies that cover access control, acceptable use, data classification, encryption, vulnerability management, incident response, and supplier management.
Where answers usually fall short: Policies not reviewed annually; Acknowledgement coverage below 95 percent of workforce
Source: SIG (Shared Assessments)
SIG domain D Asset and Information ManagementWhat it asks for, in one line (the standard's own text is not quoted here):
Maintain a complete and current inventory of information assets, data classification, ownership, and handling requirements throughout the asset lifecycle.
Where answers usually fall short: Inventory missing cloud assets; Classification labels inconsistent across systems
Source: SIG (Shared Assessments)
SIG domain E Human Resources SecurityWhat it asks for, in one line (the standard's own text is not quoted here):
Implement background screening, onboarding, training, awareness, sanctions, and termination procedures appropriate to data sensitivity and role risk.
Where answers usually fall short: Contractor screening not performed; Awareness training completion below threshold
Source: SIG (Shared Assessments)
SIG domain G IT Operations ManagementWhat it asks for, in one line (the standard's own text is not quoted here):
Document and follow operational procedures for change management, capacity management, system hardening, backup, and operational monitoring for production systems.
Where answers usually fall short: Backup restore not tested; Emergency changes routinely used to bypass CAB
Source: SIG (Shared Assessments)
SIG domain H Access ControlWhat it asks for, in one line (the standard's own text is not quoted here):
Implement formal access provisioning, periodic recertification, least privilege, separation of duties, and privileged access management across systems hosting in scope data.
Where answers usually fall short: Privileged accounts shared; User reviews completed without manager attestation
Source: SIG (Shared Assessments)
SIG domain I Application SecurityWhat it asks for, in one line (the standard's own text is not quoted here):
Apply secure software development lifecycle practices including secure coding standards, code review, vulnerability testing, dependency management, and pre release security gates.
Where answers usually fall short: No dependency scanning for open source components; Findings closed without retest
Source: SIG (Shared Assessments)
SIG domain J Cybersecurity Incident ManagementWhat it asks for, in one line (the standard's own text is not quoted here):
Maintain an incident response capability with defined plans, classifications, escalation paths, communications protocols, evidence handling, lessons learned, and regulatory and customer notification procedures.
Where answers usually fall short: No tabletop exercises within 12 months; Customer notification timelines not tracked
Source: SIG (Shared Assessments)
SIG domain K Business ResiliencyWhat it asks for, in one line (the standard's own text is not quoted here):
Maintain business continuity and disaster recovery programs including business impact analysis, recovery objectives, plans, periodic testing, and dependencies on third party providers.
Where answers usually fall short: RTO and RPO not validated against tested recovery; Critical supplier failover untested
Source: SIG (Shared Assessments)
SIG domain O PrivacyWhat it asks for, in one line (the standard's own text is not quoted here):
Manage personal data in accordance with applicable privacy laws and contractual obligations, including data subject rights, lawful basis, cross border transfers, and breach notification.
Where answers usually fall short: No transfer impact assessment for non adequacy jurisdictions; DSR metrics not tracked against statutory deadlines
Source: SIG (Shared Assessments)
SIG domain P Threat ManagementWhat it asks for, in one line (the standard's own text is not quoted here):
Maintain threat intelligence, vulnerability management, penetration testing, and red team capabilities to identify and remediate weaknesses in a timely manner.
Where answers usually fall short: Critical vulnerabilities open beyond SLA; Penetration test scope omits new applications
Source: SIG (Shared Assessments)
SIG domain T Supply Chain Risk ManagementWhat it asks for, in one line (the standard's own text is not quoted here):
Manage risk across the supply chain including subservice organizations, fourth parties, hardware and software providers, and concentration risk, with appropriate due diligence and continuous monitoring.
Where answers usually fall short: No fourth party visibility; Continuous monitoring not actioned
Source: SIG (Shared Assessments)