Security Questionnaire Mapper
Clause text

SIG (Shared Assessments): the clauses the register cites

The 12 SIG (Shared Assessments) clauses that questions are placed on, each with the evidence an assessor asks for and where answers usually fall short.

The text of this standard is not held in full here, so it is not quoted: each requirement carries a one-line statement of what it asks for, with its code and title, and the standard itself holds the wording.

12 clauses

the families they anchor
SIG domain A Risk Assessment and Treatment Program

What it asks for, in one line (the standard's own text is not quoted here):

Maintain a documented risk assessment and treatment program covering information security, operational, third party, and compliance risks, with defined ownership, frequency, and integration into business decision making.

Evidence an assessor expects: Risk management policy and procedure; Current risk register with owners; Treatment plans with target dates and approvals; Risk committee minutes
Where answers usually fall short: Risk register stale beyond annual cycle; No documented risk acceptance approvals at appropriate level
Source: SIG (Shared Assessments)
SIG domain B Information Security Policy Suite

What it asks for, in one line (the standard's own text is not quoted here):

Establish, approve, communicate, and periodically review a suite of information security policies that cover access control, acceptable use, data classification, encryption, vulnerability management, incident response, and supplier management.

Evidence an assessor expects: Approved policy library with version control; Executive or board approval records; Distribution and acknowledgement logs; Annual review evidence
Where answers usually fall short: Policies not reviewed annually; Acknowledgement coverage below 95 percent of workforce
Source: SIG (Shared Assessments)
SIG domain D Asset and Information Management

What it asks for, in one line (the standard's own text is not quoted here):

Maintain a complete and current inventory of information assets, data classification, ownership, and handling requirements throughout the asset lifecycle.

Evidence an assessor expects: Asset inventory with owner and classification; Data classification policy and labeling guide; Onboarding and decommissioning records; Data flow diagrams
Where answers usually fall short: Inventory missing cloud assets; Classification labels inconsistent across systems
Source: SIG (Shared Assessments)
SIG domain E Human Resources Security

What it asks for, in one line (the standard's own text is not quoted here):

Implement background screening, onboarding, training, awareness, sanctions, and termination procedures appropriate to data sensitivity and role risk.

Evidence an assessor expects: Background check policy and records; Annual security awareness training completion logs; Sanctions policy; Termination checklists and access removal records
Where answers usually fall short: Contractor screening not performed; Awareness training completion below threshold
Source: SIG (Shared Assessments)
SIG domain G IT Operations Management

What it asks for, in one line (the standard's own text is not quoted here):

Document and follow operational procedures for change management, capacity management, system hardening, backup, and operational monitoring for production systems.

Evidence an assessor expects: Operations procedure manual; Change advisory board minutes and tickets; Backup completion and restore test logs; Capacity reports
Where answers usually fall short: Backup restore not tested; Emergency changes routinely used to bypass CAB
Source: SIG (Shared Assessments)
SIG domain H Access Control

What it asks for, in one line (the standard's own text is not quoted here):

Implement formal access provisioning, periodic recertification, least privilege, separation of duties, and privileged access management across systems hosting in scope data.

Evidence an assessor expects: Access management policy; User access review reports; Privileged access management tool logs; Joiner mover leaver workflows
Where answers usually fall short: Privileged accounts shared; User reviews completed without manager attestation
Source: SIG (Shared Assessments)
SIG domain I Application Security

What it asks for, in one line (the standard's own text is not quoted here):

Apply secure software development lifecycle practices including secure coding standards, code review, vulnerability testing, dependency management, and pre release security gates.

Evidence an assessor expects: Secure SDLC policy; Static and dynamic analysis scan reports; Software composition analysis results; Pre release sign off records
Where answers usually fall short: No dependency scanning for open source components; Findings closed without retest
Source: SIG (Shared Assessments)
SIG domain J Cybersecurity Incident Management

What it asks for, in one line (the standard's own text is not quoted here):

Maintain an incident response capability with defined plans, classifications, escalation paths, communications protocols, evidence handling, lessons learned, and regulatory and customer notification procedures.

Evidence an assessor expects: Incident response plan and playbooks; Tabletop exercise reports; Notification templates and contact lists; Post incident review reports
Where answers usually fall short: No tabletop exercises within 12 months; Customer notification timelines not tracked
Source: SIG (Shared Assessments)
SIG domain K Business Resiliency

What it asks for, in one line (the standard's own text is not quoted here):

Maintain business continuity and disaster recovery programs including business impact analysis, recovery objectives, plans, periodic testing, and dependencies on third party providers.

Evidence an assessor expects: Business impact analysis with RTO and RPO; Approved BCP and DR plans; Annual test reports; Supplier dependency map
Where answers usually fall short: RTO and RPO not validated against tested recovery; Critical supplier failover untested
Source: SIG (Shared Assessments)
SIG domain O Privacy

What it asks for, in one line (the standard's own text is not quoted here):

Manage personal data in accordance with applicable privacy laws and contractual obligations, including data subject rights, lawful basis, cross border transfers, and breach notification.

Evidence an assessor expects: Privacy program policy; Data subject request handling procedure and metrics; Records of processing activities; Transfer impact assessments and standard contractual clauses
Where answers usually fall short: No transfer impact assessment for non adequacy jurisdictions; DSR metrics not tracked against statutory deadlines
Source: SIG (Shared Assessments)
SIG domain P Threat Management

What it asks for, in one line (the standard's own text is not quoted here):

Maintain threat intelligence, vulnerability management, penetration testing, and red team capabilities to identify and remediate weaknesses in a timely manner.

Evidence an assessor expects: Threat intelligence sources and feeds; Vulnerability scan reports with remediation timelines; Annual external penetration test report; Red team or purple team exercise reports
Where answers usually fall short: Critical vulnerabilities open beyond SLA; Penetration test scope omits new applications
Source: SIG (Shared Assessments)
SIG domain T Supply Chain Risk Management

What it asks for, in one line (the standard's own text is not quoted here):

Manage risk across the supply chain including subservice organizations, fourth parties, hardware and software providers, and concentration risk, with appropriate due diligence and continuous monitoring.

Evidence an assessor expects: Supplier inventory with risk tiering; Due diligence questionnaires and reports; Continuous monitoring tool outputs; Concentration risk analysis
Where answers usually fall short: No fourth party visibility; Continuous monitoring not actioned
Source: SIG (Shared Assessments)