Certification
SIAS and other security frameworks
SIAS cross-references themes from four widely used frameworks so you can see where they overlap. The cross-references are for information. They are not equivalence.
What framework mappings mean
SecurityInspect certification is a proprietary, scope-limited assessment against the SecurityInspect Assurance Standard. Framework mappings indicate thematic alignment only. Certification does not constitute an HHS-recognized HIPAA certification, PCI DSS validation, a SOC 2 examination or report, or accredited ISO/IEC 27001 certification.
Which frameworks are cross-referenced
| Framework | What SIAS cites |
|---|---|
| HIPAA Security Rule (45 CFR Part 164, Subpart C) | Section numbers |
| PCI DSS v4.0.1 | Requirement numbers |
| AICPA Trust Services Criteria | Criterion identifiers |
| ISO/IEC 27001:2022 (including Amendment 1:2024) | Clause and Annex A control numbers |
Who issues each framework’s own outcomes
- HIPAAHHS has said it does not endorse or recognize private organizations’ certifications regarding the HIPAA Security Rule. A SIAS certificate does not change any HIPAA obligation.
- PCI DSSPCI DSS compliance is validated in the way a merchant’s or service provider’s acquirer or the payment brands require, using the PCI Security Standards Council’s assessment programs and forms. A SIAS certificate is not PCI DSS validation.
- SOC 2 and the Trust Services CriteriaSOC 2 examinations and reports are performed and issued by licensed CPA firms. SecurityInspect is not a CPA firm, and a SIAS certificate is not a SOC 2 report.
- ISO/IEC 27001Accredited ISO/IEC 27001 certification is issued by accredited certification bodies. SecurityInspect is not one, and a SIAS certificate is not ISO/IEC 27001 certification.
What a cross-reference tells you
A cross-reference means a SIAS control deals with a similar theme. It does not mean the SIAS control has the same wording, depth or evidence requirements as the other framework, or that meeting it counts toward that framework. SIAS requirements are SecurityInspect’s own. We cite identifiers only and don’t reproduce the other frameworks’ text.
How to use the mappings
If your organization also works toward one of these frameworks, the cross-references can help you see where evidence or effort may overlap. Any formal outcome under those frameworks still comes from the body or firm that program recognizes.
Compare the frameworks and who can issue each formal outcome
How current the mappings are
The mappings reflect each framework’s identifiers as checked on 2026-09-27 and are re-checked before each SIAS release.
Cross-references by control
Each row lists the identifiers a SIAS control cites. “No direct mapping” means no counterpart was found. The full requirement for each control is on its domain page in the standard.
GOV: Governance and security ownership
| Control | HIPAA Security Rule | PCI DSS v4.0.1 | Trust Services Criteria | ISO/IEC 27001:2022 |
|---|---|---|---|---|
| SIAS-GOV-01Security ownership and accountability | §164.308(a)(2) | 12.1, 12.4 | CC1.3, CC1.5 | 5.3; A.5.2, A.5.4 |
| SIAS-GOV-02Information security policy set | §164.316(a), §164.316(b)(2)(iii) | 12.1 | CC2.2, CC5.3 | 5.2; A.5.1, A.5.37 |
| SIAS-GOV-03System description and scope boundary | No direct mapping | 12.5 | No direct mapping | 4.3 |
| SIAS-GOV-04Security obligations register | No direct mapping | No direct mapping | No direct mapping | 4.1, 4.2 (incl. Amd 1:2024); A.5.31 |
| SIAS-GOV-05Management review and continual improvement | §164.308(a)(8) | 12.4 | CC4.1, CC4.2 | 9.3, 10.1, 10.2; A.5.35, A.5.36 |
RSK: Risk management
| Control | HIPAA Security Rule | PCI DSS v4.0.1 | Trust Services Criteria | ISO/IEC 27001:2022 |
|---|---|---|---|---|
| SIAS-RSK-01Risk assessment of the in-scope environment | §164.308(a)(1)(ii)(A) | 12.3 | CC3.1, CC3.2, CC3.3 | 6.1.2, 8.2 |
| SIAS-RSK-02Risk treatment and accountable risk acceptance | §164.308(a)(1)(ii)(B) | 12.3 | CC3.2, CC5.1 | 6.1.3, 8.3 |
| SIAS-RSK-03Risk register and periodic review | §164.308(a)(1)(ii)(B) | 12.3 | CC3.4 | 6.1.2, 8.2 |
| SIAS-RSK-04Threat intelligence in risk decisions | No direct mapping | 6.3 | CC3.2 | A.5.7 |
AST: Asset inventory
| Control | HIPAA Security Rule | PCI DSS v4.0.1 | Trust Services Criteria | ISO/IEC 27001:2022 |
|---|---|---|---|---|
| SIAS-AST-01Inventory of in-scope assets | §164.310(d)(2)(iii) | 12.5 | CC6.1 | A.5.9 |
| SIAS-AST-02Asset ownership and classification linkage | No direct mapping | 12.5 | CC6.1 | A.5.9, A.5.12 |
| SIAS-AST-03Discovery and reconciliation of unmanaged assets | No direct mapping | 12.5 | CC7.1 | A.5.9 |
| SIAS-AST-04Unsupported and unauthorized technology | No direct mapping | 6.3, 12.3 | CC7.1 | A.5.9, A.8.19 |
IAM: Identity, access and MFA
| Control | HIPAA Security Rule | PCI DSS v4.0.1 | Trust Services Criteria | ISO/IEC 27001:2022 |
|---|---|---|---|---|
| SIAS-IAM-01Unique identities and account lifecycle | §164.308(a)(3)(ii)(C), §164.308(a)(4)(ii)(C), §164.312(a)(2)(i) | 8.2 | CC6.2 | A.5.16, A.5.18 |
| SIAS-IAM-02Multi-factor authentication for remote, administrative and privileged access | §164.312(d) | 8.4, 8.5 | CC6.1, CC6.6 | A.8.5 |
| SIAS-IAM-03Least privilege and privileged access management | §164.308(a)(4)(ii)(B), §164.312(a)(1) | 7.2, 7.3 | CC6.3 | A.5.15, A.8.2, A.8.3 |
| SIAS-IAM-04Periodic access review | §164.308(a)(4)(ii)(C) | 7.2 | CC6.2, CC6.3 | A.5.18 |
| SIAS-IAM-05Authentication strength and credential protection | §164.308(a)(5)(ii)(D), §164.312(d) | 8.3, 2.2 | CC6.1 | A.5.17, A.8.5 |
| SIAS-IAM-06Non-human identities and workload credentials | §164.312(a)(1) | 8.6 | CC6.1, CC6.2 | A.5.16, A.5.17, A.8.2 |
DAT: Data classification and protection
| Control | HIPAA Security Rule | PCI DSS v4.0.1 | Trust Services Criteria | ISO/IEC 27001:2022 |
|---|---|---|---|---|
| SIAS-DAT-01Data classification and handling rules | No direct mapping | No direct mapping | C1.1 | A.5.10, A.5.12, A.5.13 |
| SIAS-DAT-02Sensitive data inventory and data-flow map | §164.308(a)(1)(ii)(A) | 1.2, 12.5 | CC2.1, C1.1 | A.5.9, A.5.12, A.5.14 |
| SIAS-DAT-03Data minimization, retention and secure deletion | §164.310(d)(2)(i), §164.310(d)(2)(ii) | 3.2 | C1.2, P4 series | A.5.33, A.8.10 |
| SIAS-DAT-04Non-production data and data leakage prevention | No direct mapping | 3.4, 6.5 | CC6.7 | A.8.11, A.8.12, A.8.33 |
CRY: Encryption and key management
| Control | HIPAA Security Rule | PCI DSS v4.0.1 | Trust Services Criteria | ISO/IEC 27001:2022 |
|---|---|---|---|---|
| SIAS-CRY-01Encryption of data in transit | §164.312(e)(1), §164.312(e)(2)(ii) | 4.2 | CC6.7 | A.5.14, A.8.24 |
| SIAS-CRY-02Encryption of sensitive data at rest | §164.312(a)(2)(iv) | 3.5 | CC6.1 | A.8.24 |
| SIAS-CRY-03Cryptographic key and secret management | §164.312(a)(2)(iv) | 3.6, 3.7 | CC6.1 | A.8.24 |
| SIAS-CRY-04Certificate and algorithm lifecycle | §164.312(e)(2)(ii) | 4.2 | CC6.7 | A.8.24 |
SDC: Secure development and change management
| Control | HIPAA Security Rule | PCI DSS v4.0.1 | Trust Services Criteria | ISO/IEC 27001:2022 |
|---|---|---|---|---|
| SIAS-SDC-01Secure development lifecycle | No direct mapping | 6.2 | CC8.1 | A.8.25, A.8.27 |
| SIAS-SDC-02Pre-release code review and security testing | No direct mapping | 6.2 | CC8.1 | A.8.28, A.8.29 |
| SIAS-SDC-03Production change authorization, testing and rollback | No direct mapping | 6.5 | CC8.1 | A.8.32 |
| SIAS-SDC-04Environment separation and production access | No direct mapping | 6.5 | CC8.1 | A.8.31 |
| SIAS-SDC-05Third-party component and dependency management | No direct mapping | 6.3 | CC7.1, CC8.1 | A.5.21, A.8.28, A.8.30 |
| SIAS-SDC-06Source code, secret and pipeline integrity | No direct mapping | 6.2, 6.5 | CC8.1 | A.8.4, A.8.32 |
VPM: Vulnerability and patch management
| Control | HIPAA Security Rule | PCI DSS v4.0.1 | Trust Services Criteria | ISO/IEC 27001:2022 |
|---|---|---|---|---|
| SIAS-VPM-01Vulnerability identification and scanning | No direct mapping | 6.3, 11.3 | CC7.1 | A.8.8 |
| SIAS-VPM-02Risk-based remediation within defined timelines | §164.308(a)(1)(ii)(B) | 6.3, 11.3 | CC7.1 | A.8.8 |
| SIAS-VPM-03Patch and update management | §164.308(a)(1)(ii)(B) | 6.3 | CC7.1 | A.8.8, A.8.19 |
| SIAS-VPM-04Periodic penetration testing | §164.308(a)(8) | 11.4 | CC4.1 | A.8.8 |
| SIAS-VPM-05Vulnerability exceptions and risk acceptance | §164.308(a)(1)(ii)(B) | 6.3, 12.3 | CC3.2 | 6.1.3; A.8.8 |
| SIAS-VPM-06Coordinated vulnerability disclosure intake | No direct mapping | 6.3 | CC2.3 | A.8.8 |
CLD: Cloud and infrastructure security
| Control | HIPAA Security Rule | PCI DSS v4.0.1 | Trust Services Criteria | ISO/IEC 27001:2022 |
|---|---|---|---|---|
| SIAS-CLD-01Secure configuration baselines and drift detection | No direct mapping | 2.2 | CC7.1 | A.8.9 |
| SIAS-CLD-02Cloud account and tenant governance | No direct mapping | 2.2, 7.2 | CC6.1 | A.5.23 |
| SIAS-CLD-03Prevention of unintended public exposure of cloud resources | §164.312(a)(1) | 1.3, 1.4 | CC6.6 | A.5.23, A.8.3 |
| SIAS-CLD-04Infrastructure-as-code and configuration change control | No direct mapping | 2.2, 6.5 | CC8.1 | A.8.9, A.8.32 |
| SIAS-CLD-05Container, orchestration and serverless workload security | No direct mapping | 2.2, 6.3 | CC6.8, CC7.1 | A.8.9, A.8.19 |
APP: Application and API security
| Control | HIPAA Security Rule | PCI DSS v4.0.1 | Trust Services Criteria | ISO/IEC 27001:2022 |
|---|---|---|---|---|
| SIAS-APP-01Application security requirements and threat modeling | No direct mapping | 6.2 | CC8.1 | A.8.26, A.8.27 |
| SIAS-APP-02Resistance to common web and API vulnerability classes | No direct mapping | 6.2, 6.4 | CC6.6 | A.8.26, A.8.28 |
| SIAS-APP-03Application authentication, session management and authorization | §164.312(a)(1), §164.312(a)(2)(iii), §164.312(d) | 6.2, 8.3 | CC6.1 | A.8.3, A.8.5 |
| SIAS-APP-04API inventory, protection and abuse controls | No direct mapping | 6.2, 6.4 | CC6.6 | A.8.26 |
| SIAS-APP-05Browser security controls and third-party scripts | No direct mapping | 6.4, 11.6 | CC6.8 | A.8.26 |
NET: Network and endpoint security
| Control | HIPAA Security Rule | PCI DSS v4.0.1 | Trust Services Criteria | ISO/IEC 27001:2022 |
|---|---|---|---|---|
| SIAS-NET-01Network segmentation and boundary protection | No direct mapping | 1.2, 1.3, 1.4 | CC6.6 | A.8.20, A.8.22 |
| SIAS-NET-02Protection of administrative and remote-access services | §164.312(d), §164.312(e)(1) | 1.4, 8.4 | CC6.6 | A.8.5, A.8.20 |
| SIAS-NET-03Endpoint protection and hardening | §164.308(a)(5)(ii)(B), §164.310(c), §164.312(a)(2)(iii) | 1.5, 5.2, 5.3 | CC6.8 | A.8.1, A.8.7 |
| SIAS-NET-04Wireless and remote-work network safeguards | §164.312(e)(1) | 2.3, 11.2 | CC6.6 | A.6.7, A.8.20 |
| SIAS-NET-05Email and domain security | No direct mapping | 5.4 | CC6.6 | A.5.14, A.8.21 |
LOG: Logging, monitoring and alerting
| Control | HIPAA Security Rule | PCI DSS v4.0.1 | Trust Services Criteria | ISO/IEC 27001:2022 |
|---|---|---|---|---|
| SIAS-LOG-01Security event logging coverage | §164.308(a)(1)(ii)(D), §164.312(b) | 10.2 | CC7.2 | A.8.15 |
| SIAS-LOG-02Log protection, time synchronization and retention | §164.312(b) | 10.3, 10.5, 10.6 | CC7.2 | A.8.15, A.8.17 |
| SIAS-LOG-03Security alerting and triage | §164.308(a)(1)(ii)(D), §164.308(a)(5)(ii)(C) | 10.4, 10.7 | CC7.2, CC7.3 | A.5.25, A.8.16 |
| SIAS-LOG-04Monitoring effectiveness testing and log review | §164.308(a)(1)(ii)(D) | 10.4 | CC4.1, CC7.2 | A.8.16 |
INC: Incident response
| Control | HIPAA Security Rule | PCI DSS v4.0.1 | Trust Services Criteria | ISO/IEC 27001:2022 |
|---|---|---|---|---|
| SIAS-INC-01Incident response plan, roles and escalation | §164.308(a)(6)(i), §164.308(a)(6)(ii) | 12.10 | CC7.3, CC7.4 | A.5.24, A.5.26, A.6.8 |
| SIAS-INC-02Incident response exercises | No direct mapping | 12.10 | CC7.4 | A.5.24 |
| SIAS-INC-03Incident records, evidence preservation and lessons learned | §164.308(a)(6)(ii) | 12.10 | CC7.4, CC7.5 | A.5.27, A.5.28 |
| SIAS-INC-04Notification obligations and stakeholder communication | §164.308(a)(6)(ii), §164.314(a)(2)(i) | 12.10 | CC2.3, CC7.4 | A.5.5, A.5.26 |
BCR: Backup, recovery and business continuity
| Control | HIPAA Security Rule | PCI DSS v4.0.1 | Trust Services Criteria | ISO/IEC 27001:2022 |
|---|---|---|---|---|
| SIAS-BCR-01Backup coverage, protection and isolation | §164.308(a)(7)(ii)(A), §164.310(d)(2)(iv) | No direct mapping | CC9.1, A1.2 | A.8.13 |
| SIAS-BCR-02Restore testing against recovery objectives | §164.308(a)(7)(ii)(B), §164.308(a)(7)(ii)(D) | No direct mapping | A1.3 | A.5.30, A.8.13 |
| SIAS-BCR-03Business impact analysis and recovery objectives | §164.308(a)(7)(ii)(E) | No direct mapping | CC9.1 | A.5.30 |
| SIAS-BCR-04Business continuity and disaster recovery plan | §164.308(a)(7)(i), §164.308(a)(7)(ii)(B), §164.308(a)(7)(ii)(C) | 12.10 | CC9.1, A1.3 | A.5.29, A.5.30 |
| SIAS-BCR-05Capacity and redundancy of critical services | No direct mapping | No direct mapping | A1.1 | A.8.6, A.8.14 |
TPR: Third-party and supply-chain risk
| Control | HIPAA Security Rule | PCI DSS v4.0.1 | Trust Services Criteria | ISO/IEC 27001:2022 |
|---|---|---|---|---|
| SIAS-TPR-01Third-party inventory and criticality tiering | §164.308(b)(1) | 12.8 | CC9.2 | A.5.19 |
| SIAS-TPR-02Security due diligence and contractual security terms | §164.308(b)(1), §164.308(b)(3), §164.314(a) | 12.8 | CC9.2 | A.5.19, A.5.20, A.5.21 |
| SIAS-TPR-03Ongoing monitoring of critical third parties | §164.308(b)(1) | 12.8 | CC9.2 | A.5.22 |
| SIAS-TPR-04Third-party access control and offboarding | §164.308(a)(4)(ii)(B) | 8.2, 8.4 | CC6.2, CC9.2 | A.5.19, A.5.20 |
| SIAS-TPR-05Shared-responsibility mapping for service providers | §164.308(b)(1) | 12.8, 12.9 | CC9.2 | A.5.19, A.5.23 |
WFS: Workforce security
| Control | HIPAA Security Rule | PCI DSS v4.0.1 | Trust Services Criteria | ISO/IEC 27001:2022 |
|---|---|---|---|---|
| SIAS-WFS-01Role-appropriate screening | §164.308(a)(3)(ii)(B) | 12.7 | CC1.4 | A.6.1 |
| SIAS-WFS-02Security terms, acceptable use and sanctions | §164.308(a)(1)(ii)(C), §164.310(b) | 12.2 | CC1.1, CC1.5 | A.5.10, A.6.2, A.6.4, A.6.6 |
| SIAS-WFS-03Security awareness and phishing training | §164.308(a)(5)(i), §164.308(a)(5)(ii)(A) | 12.6 | CC1.4, CC2.2 | A.6.3 |
| SIAS-WFS-04Role-based security training for technical and privileged staff | §164.308(a)(5)(i) | 6.2, 12.6, 12.10 | CC1.4 | 7.2; A.6.3 |
| SIAS-WFS-05Offboarding and role change | §164.308(a)(3)(ii)(C) | 8.2 | CC6.2 | A.5.11, A.6.5 |
PHY: Physical safeguards
| Control | HIPAA Security Rule | PCI DSS v4.0.1 | Trust Services Criteria | ISO/IEC 27001:2022 |
|---|---|---|---|---|
| SIAS-PHY-01Physical access control for applicant-operated facilities | §164.310(a)(1), §164.310(a)(2)(ii), §164.310(a)(2)(iii), §164.310(a)(2)(iv) | 9.2, 9.3 | CC6.4 | A.7.1, A.7.2, A.7.3, A.7.4 |
| SIAS-PHY-02Workstation and portable device physical protection | §164.310(b), §164.310(c) | No direct mapping | CC6.4 | A.7.7, A.7.8, A.7.9 |
| SIAS-PHY-03Physical media and equipment disposal | §164.310(d)(1), §164.310(d)(2)(i), §164.310(d)(2)(ii) | 9.4 | CC6.5 | A.7.10, A.7.14 |
| SIAS-PHY-04Environmental and utility protection | No direct mapping | No direct mapping | A1.2 | A.7.5, A.7.11, A.7.12, A.7.13 |
| SIAS-PHY-05Hosting provider physical assurance | §164.310(a)(1) | 12.8 | CC6.4, CC9.2 | A.5.19, A.5.22 |
PRV: Privacy-related security safeguards
| Control | HIPAA Security Rule | PCI DSS v4.0.1 | Trust Services Criteria | ISO/IEC 27001:2022 |
|---|---|---|---|---|
| SIAS-PRV-01Personal information categories and security requirements | §164.306(a) | No direct mapping | C1.1, P3 series | A.5.12, A.5.34 |
| SIAS-PRV-02Restricted and logged access to personal information | §164.308(a)(4)(ii)(B), §164.312(a)(1), §164.312(b) | 7.2, 10.2 | CC6.1, CC6.3 | A.5.34, A.8.3 |
| SIAS-PRV-03Tracking technologies and outbound data sharing match declared practices | No direct mapping | 6.4, 11.6 | P1 series, P6 series | A.5.14, A.5.34 |
| SIAS-PRV-04Secure handling of privacy requests | No direct mapping | No direct mapping | P5 series | A.5.34 |
| SIAS-PRV-05Personal-information impact in incident handling | §164.308(a)(6)(ii) | 12.10 | CC7.4, P6 series | A.5.26, A.5.34 |
CMC: Continuous monitoring and material-change reporting
| Control | HIPAA Security Rule | PCI DSS v4.0.1 | Trust Services Criteria | ISO/IEC 27001:2022 |
|---|---|---|---|---|
| SIAS-CMC-01Continuous control monitoring | §164.308(a)(8) | 10.7, 12.4 | CC4.1 | 9.1; A.5.36 |
| SIAS-CMC-02Material-change notification to SecurityInspect | §164.308(a)(8) | 6.5, 12.5 | CC3.4 | 6.3 |
| SIAS-CMC-03Serious security incident notification to SecurityInspect | No direct mapping | No direct mapping | CC2.3 | No direct mapping |
| SIAS-CMC-04Surveillance cooperation and evidence refresh | §164.308(a)(8) | No direct mapping | CC4.1 | A.5.35 |
| SIAS-CMC-05Accurate representation of certification and badge use | No direct mapping | No direct mapping | CC2.3 | No direct mapping. This is a SIAS program rule with no framework counterpart |
HIPAA is a U.S. federal law. PCI DSS, SOC 2, Trust Services Criteria and ISO/IEC 27001 are names or marks of their respective owners, used here only to identify their frameworks. No endorsement is implied.
Where our work stops
Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.
Talk to us about a SIAS assessment
Tell us what you want assessed, and we’ll start with the scope.