Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

Certification

SIAS and other security frameworks

SIAS cross-references themes from four widely used frameworks so you can see where they overlap. The cross-references are for information. They are not equivalence.

What framework mappings mean

SecurityInspect certification is a proprietary, scope-limited assessment against the SecurityInspect Assurance Standard. Framework mappings indicate thematic alignment only. Certification does not constitute an HHS-recognized HIPAA certification, PCI DSS validation, a SOC 2 examination or report, or accredited ISO/IEC 27001 certification.

Which frameworks are cross-referenced

Frameworks SIAS cross-references, and what it cites
FrameworkWhat SIAS cites
HIPAA Security Rule (45 CFR Part 164, Subpart C)Section numbers
PCI DSS v4.0.1Requirement numbers
AICPA Trust Services CriteriaCriterion identifiers
ISO/IEC 27001:2022 (including Amendment 1:2024)Clause and Annex A control numbers

Who issues each framework’s own outcomes

  • HIPAAHHS has said it does not endorse or recognize private organizations’ certifications regarding the HIPAA Security Rule. A SIAS certificate does not change any HIPAA obligation.
  • PCI DSSPCI DSS compliance is validated in the way a merchant’s or service provider’s acquirer or the payment brands require, using the PCI Security Standards Council’s assessment programs and forms. A SIAS certificate is not PCI DSS validation.
  • SOC 2 and the Trust Services CriteriaSOC 2 examinations and reports are performed and issued by licensed CPA firms. SecurityInspect is not a CPA firm, and a SIAS certificate is not a SOC 2 report.
  • ISO/IEC 27001Accredited ISO/IEC 27001 certification is issued by accredited certification bodies. SecurityInspect is not one, and a SIAS certificate is not ISO/IEC 27001 certification.

What a cross-reference tells you

A cross-reference means a SIAS control deals with a similar theme. It does not mean the SIAS control has the same wording, depth or evidence requirements as the other framework, or that meeting it counts toward that framework. SIAS requirements are SecurityInspect’s own. We cite identifiers only and don’t reproduce the other frameworks’ text.

How to use the mappings

If your organization also works toward one of these frameworks, the cross-references can help you see where evidence or effort may overlap. Any formal outcome under those frameworks still comes from the body or firm that program recognizes.

Compare the frameworks and who can issue each formal outcome

How current the mappings are

The mappings reflect each framework’s identifiers as checked on 2026-09-27 and are re-checked before each SIAS release.

Cross-references by control

Each row lists the identifiers a SIAS control cites. “No direct mapping” means no counterpart was found. The full requirement for each control is on its domain page in the standard.

GOV: Governance and security ownership

Framework cross-references for the GOV controls
ControlHIPAA Security RulePCI DSS v4.0.1Trust Services CriteriaISO/IEC 27001:2022
SIAS-GOV-01Security ownership and accountability§164.308(a)(2)12.1, 12.4CC1.3, CC1.55.3; A.5.2, A.5.4
SIAS-GOV-02Information security policy set§164.316(a), §164.316(b)(2)(iii)12.1CC2.2, CC5.35.2; A.5.1, A.5.37
SIAS-GOV-03System description and scope boundaryNo direct mapping12.5No direct mapping4.3
SIAS-GOV-04Security obligations registerNo direct mappingNo direct mappingNo direct mapping4.1, 4.2 (incl. Amd 1:2024); A.5.31
SIAS-GOV-05Management review and continual improvement§164.308(a)(8)12.4CC4.1, CC4.29.3, 10.1, 10.2; A.5.35, A.5.36

RSK: Risk management

Framework cross-references for the RSK controls
ControlHIPAA Security RulePCI DSS v4.0.1Trust Services CriteriaISO/IEC 27001:2022
SIAS-RSK-01Risk assessment of the in-scope environment§164.308(a)(1)(ii)(A)12.3CC3.1, CC3.2, CC3.36.1.2, 8.2
SIAS-RSK-02Risk treatment and accountable risk acceptance§164.308(a)(1)(ii)(B)12.3CC3.2, CC5.16.1.3, 8.3
SIAS-RSK-03Risk register and periodic review§164.308(a)(1)(ii)(B)12.3CC3.46.1.2, 8.2
SIAS-RSK-04Threat intelligence in risk decisionsNo direct mapping6.3CC3.2A.5.7

AST: Asset inventory

Framework cross-references for the AST controls
ControlHIPAA Security RulePCI DSS v4.0.1Trust Services CriteriaISO/IEC 27001:2022
SIAS-AST-01Inventory of in-scope assets§164.310(d)(2)(iii)12.5CC6.1A.5.9
SIAS-AST-02Asset ownership and classification linkageNo direct mapping12.5CC6.1A.5.9, A.5.12
SIAS-AST-03Discovery and reconciliation of unmanaged assetsNo direct mapping12.5CC7.1A.5.9
SIAS-AST-04Unsupported and unauthorized technologyNo direct mapping6.3, 12.3CC7.1A.5.9, A.8.19

IAM: Identity, access and MFA

Framework cross-references for the IAM controls
ControlHIPAA Security RulePCI DSS v4.0.1Trust Services CriteriaISO/IEC 27001:2022
SIAS-IAM-01Unique identities and account lifecycle§164.308(a)(3)(ii)(C), §164.308(a)(4)(ii)(C), §164.312(a)(2)(i)8.2CC6.2A.5.16, A.5.18
SIAS-IAM-02Multi-factor authentication for remote, administrative and privileged access§164.312(d)8.4, 8.5CC6.1, CC6.6A.8.5
SIAS-IAM-03Least privilege and privileged access management§164.308(a)(4)(ii)(B), §164.312(a)(1)7.2, 7.3CC6.3A.5.15, A.8.2, A.8.3
SIAS-IAM-04Periodic access review§164.308(a)(4)(ii)(C)7.2CC6.2, CC6.3A.5.18
SIAS-IAM-05Authentication strength and credential protection§164.308(a)(5)(ii)(D), §164.312(d)8.3, 2.2CC6.1A.5.17, A.8.5
SIAS-IAM-06Non-human identities and workload credentials§164.312(a)(1)8.6CC6.1, CC6.2A.5.16, A.5.17, A.8.2

DAT: Data classification and protection

Framework cross-references for the DAT controls
ControlHIPAA Security RulePCI DSS v4.0.1Trust Services CriteriaISO/IEC 27001:2022
SIAS-DAT-01Data classification and handling rulesNo direct mappingNo direct mappingC1.1A.5.10, A.5.12, A.5.13
SIAS-DAT-02Sensitive data inventory and data-flow map§164.308(a)(1)(ii)(A)1.2, 12.5CC2.1, C1.1A.5.9, A.5.12, A.5.14
SIAS-DAT-03Data minimization, retention and secure deletion§164.310(d)(2)(i), §164.310(d)(2)(ii)3.2C1.2, P4 seriesA.5.33, A.8.10
SIAS-DAT-04Non-production data and data leakage preventionNo direct mapping3.4, 6.5CC6.7A.8.11, A.8.12, A.8.33

CRY: Encryption and key management

Framework cross-references for the CRY controls
ControlHIPAA Security RulePCI DSS v4.0.1Trust Services CriteriaISO/IEC 27001:2022
SIAS-CRY-01Encryption of data in transit§164.312(e)(1), §164.312(e)(2)(ii)4.2CC6.7A.5.14, A.8.24
SIAS-CRY-02Encryption of sensitive data at rest§164.312(a)(2)(iv)3.5CC6.1A.8.24
SIAS-CRY-03Cryptographic key and secret management§164.312(a)(2)(iv)3.6, 3.7CC6.1A.8.24
SIAS-CRY-04Certificate and algorithm lifecycle§164.312(e)(2)(ii)4.2CC6.7A.8.24

SDC: Secure development and change management

Framework cross-references for the SDC controls
ControlHIPAA Security RulePCI DSS v4.0.1Trust Services CriteriaISO/IEC 27001:2022
SIAS-SDC-01Secure development lifecycleNo direct mapping6.2CC8.1A.8.25, A.8.27
SIAS-SDC-02Pre-release code review and security testingNo direct mapping6.2CC8.1A.8.28, A.8.29
SIAS-SDC-03Production change authorization, testing and rollbackNo direct mapping6.5CC8.1A.8.32
SIAS-SDC-04Environment separation and production accessNo direct mapping6.5CC8.1A.8.31
SIAS-SDC-05Third-party component and dependency managementNo direct mapping6.3CC7.1, CC8.1A.5.21, A.8.28, A.8.30
SIAS-SDC-06Source code, secret and pipeline integrityNo direct mapping6.2, 6.5CC8.1A.8.4, A.8.32

VPM: Vulnerability and patch management

Framework cross-references for the VPM controls
ControlHIPAA Security RulePCI DSS v4.0.1Trust Services CriteriaISO/IEC 27001:2022
SIAS-VPM-01Vulnerability identification and scanningNo direct mapping6.3, 11.3CC7.1A.8.8
SIAS-VPM-02Risk-based remediation within defined timelines§164.308(a)(1)(ii)(B)6.3, 11.3CC7.1A.8.8
SIAS-VPM-03Patch and update management§164.308(a)(1)(ii)(B)6.3CC7.1A.8.8, A.8.19
SIAS-VPM-04Periodic penetration testing§164.308(a)(8)11.4CC4.1A.8.8
SIAS-VPM-05Vulnerability exceptions and risk acceptance§164.308(a)(1)(ii)(B)6.3, 12.3CC3.26.1.3; A.8.8
SIAS-VPM-06Coordinated vulnerability disclosure intakeNo direct mapping6.3CC2.3A.8.8

CLD: Cloud and infrastructure security

Framework cross-references for the CLD controls
ControlHIPAA Security RulePCI DSS v4.0.1Trust Services CriteriaISO/IEC 27001:2022
SIAS-CLD-01Secure configuration baselines and drift detectionNo direct mapping2.2CC7.1A.8.9
SIAS-CLD-02Cloud account and tenant governanceNo direct mapping2.2, 7.2CC6.1A.5.23
SIAS-CLD-03Prevention of unintended public exposure of cloud resources§164.312(a)(1)1.3, 1.4CC6.6A.5.23, A.8.3
SIAS-CLD-04Infrastructure-as-code and configuration change controlNo direct mapping2.2, 6.5CC8.1A.8.9, A.8.32
SIAS-CLD-05Container, orchestration and serverless workload securityNo direct mapping2.2, 6.3CC6.8, CC7.1A.8.9, A.8.19

APP: Application and API security

Framework cross-references for the APP controls
ControlHIPAA Security RulePCI DSS v4.0.1Trust Services CriteriaISO/IEC 27001:2022
SIAS-APP-01Application security requirements and threat modelingNo direct mapping6.2CC8.1A.8.26, A.8.27
SIAS-APP-02Resistance to common web and API vulnerability classesNo direct mapping6.2, 6.4CC6.6A.8.26, A.8.28
SIAS-APP-03Application authentication, session management and authorization§164.312(a)(1), §164.312(a)(2)(iii), §164.312(d)6.2, 8.3CC6.1A.8.3, A.8.5
SIAS-APP-04API inventory, protection and abuse controlsNo direct mapping6.2, 6.4CC6.6A.8.26
SIAS-APP-05Browser security controls and third-party scriptsNo direct mapping6.4, 11.6CC6.8A.8.26

NET: Network and endpoint security

Framework cross-references for the NET controls
ControlHIPAA Security RulePCI DSS v4.0.1Trust Services CriteriaISO/IEC 27001:2022
SIAS-NET-01Network segmentation and boundary protectionNo direct mapping1.2, 1.3, 1.4CC6.6A.8.20, A.8.22
SIAS-NET-02Protection of administrative and remote-access services§164.312(d), §164.312(e)(1)1.4, 8.4CC6.6A.8.5, A.8.20
SIAS-NET-03Endpoint protection and hardening§164.308(a)(5)(ii)(B), §164.310(c), §164.312(a)(2)(iii)1.5, 5.2, 5.3CC6.8A.8.1, A.8.7
SIAS-NET-04Wireless and remote-work network safeguards§164.312(e)(1)2.3, 11.2CC6.6A.6.7, A.8.20
SIAS-NET-05Email and domain securityNo direct mapping5.4CC6.6A.5.14, A.8.21

LOG: Logging, monitoring and alerting

Framework cross-references for the LOG controls
ControlHIPAA Security RulePCI DSS v4.0.1Trust Services CriteriaISO/IEC 27001:2022
SIAS-LOG-01Security event logging coverage§164.308(a)(1)(ii)(D), §164.312(b)10.2CC7.2A.8.15
SIAS-LOG-02Log protection, time synchronization and retention§164.312(b)10.3, 10.5, 10.6CC7.2A.8.15, A.8.17
SIAS-LOG-03Security alerting and triage§164.308(a)(1)(ii)(D), §164.308(a)(5)(ii)(C)10.4, 10.7CC7.2, CC7.3A.5.25, A.8.16
SIAS-LOG-04Monitoring effectiveness testing and log review§164.308(a)(1)(ii)(D)10.4CC4.1, CC7.2A.8.16

INC: Incident response

Framework cross-references for the INC controls
ControlHIPAA Security RulePCI DSS v4.0.1Trust Services CriteriaISO/IEC 27001:2022
SIAS-INC-01Incident response plan, roles and escalation§164.308(a)(6)(i), §164.308(a)(6)(ii)12.10CC7.3, CC7.4A.5.24, A.5.26, A.6.8
SIAS-INC-02Incident response exercisesNo direct mapping12.10CC7.4A.5.24
SIAS-INC-03Incident records, evidence preservation and lessons learned§164.308(a)(6)(ii)12.10CC7.4, CC7.5A.5.27, A.5.28
SIAS-INC-04Notification obligations and stakeholder communication§164.308(a)(6)(ii), §164.314(a)(2)(i)12.10CC2.3, CC7.4A.5.5, A.5.26

BCR: Backup, recovery and business continuity

Framework cross-references for the BCR controls
ControlHIPAA Security RulePCI DSS v4.0.1Trust Services CriteriaISO/IEC 27001:2022
SIAS-BCR-01Backup coverage, protection and isolation§164.308(a)(7)(ii)(A), §164.310(d)(2)(iv)No direct mappingCC9.1, A1.2A.8.13
SIAS-BCR-02Restore testing against recovery objectives§164.308(a)(7)(ii)(B), §164.308(a)(7)(ii)(D)No direct mappingA1.3A.5.30, A.8.13
SIAS-BCR-03Business impact analysis and recovery objectives§164.308(a)(7)(ii)(E)No direct mappingCC9.1A.5.30
SIAS-BCR-04Business continuity and disaster recovery plan§164.308(a)(7)(i), §164.308(a)(7)(ii)(B), §164.308(a)(7)(ii)(C)12.10CC9.1, A1.3A.5.29, A.5.30
SIAS-BCR-05Capacity and redundancy of critical servicesNo direct mappingNo direct mappingA1.1A.8.6, A.8.14

TPR: Third-party and supply-chain risk

Framework cross-references for the TPR controls
ControlHIPAA Security RulePCI DSS v4.0.1Trust Services CriteriaISO/IEC 27001:2022
SIAS-TPR-01Third-party inventory and criticality tiering§164.308(b)(1)12.8CC9.2A.5.19
SIAS-TPR-02Security due diligence and contractual security terms§164.308(b)(1), §164.308(b)(3), §164.314(a)12.8CC9.2A.5.19, A.5.20, A.5.21
SIAS-TPR-03Ongoing monitoring of critical third parties§164.308(b)(1)12.8CC9.2A.5.22
SIAS-TPR-04Third-party access control and offboarding§164.308(a)(4)(ii)(B)8.2, 8.4CC6.2, CC9.2A.5.19, A.5.20
SIAS-TPR-05Shared-responsibility mapping for service providers§164.308(b)(1)12.8, 12.9CC9.2A.5.19, A.5.23

WFS: Workforce security

Framework cross-references for the WFS controls
ControlHIPAA Security RulePCI DSS v4.0.1Trust Services CriteriaISO/IEC 27001:2022
SIAS-WFS-01Role-appropriate screening§164.308(a)(3)(ii)(B)12.7CC1.4A.6.1
SIAS-WFS-02Security terms, acceptable use and sanctions§164.308(a)(1)(ii)(C), §164.310(b)12.2CC1.1, CC1.5A.5.10, A.6.2, A.6.4, A.6.6
SIAS-WFS-03Security awareness and phishing training§164.308(a)(5)(i), §164.308(a)(5)(ii)(A)12.6CC1.4, CC2.2A.6.3
SIAS-WFS-04Role-based security training for technical and privileged staff§164.308(a)(5)(i)6.2, 12.6, 12.10CC1.47.2; A.6.3
SIAS-WFS-05Offboarding and role change§164.308(a)(3)(ii)(C)8.2CC6.2A.5.11, A.6.5

PHY: Physical safeguards

Framework cross-references for the PHY controls
ControlHIPAA Security RulePCI DSS v4.0.1Trust Services CriteriaISO/IEC 27001:2022
SIAS-PHY-01Physical access control for applicant-operated facilities§164.310(a)(1), §164.310(a)(2)(ii), §164.310(a)(2)(iii), §164.310(a)(2)(iv)9.2, 9.3CC6.4A.7.1, A.7.2, A.7.3, A.7.4
SIAS-PHY-02Workstation and portable device physical protection§164.310(b), §164.310(c)No direct mappingCC6.4A.7.7, A.7.8, A.7.9
SIAS-PHY-03Physical media and equipment disposal§164.310(d)(1), §164.310(d)(2)(i), §164.310(d)(2)(ii)9.4CC6.5A.7.10, A.7.14
SIAS-PHY-04Environmental and utility protectionNo direct mappingNo direct mappingA1.2A.7.5, A.7.11, A.7.12, A.7.13
SIAS-PHY-05Hosting provider physical assurance§164.310(a)(1)12.8CC6.4, CC9.2A.5.19, A.5.22

PRV: Privacy-related security safeguards

Framework cross-references for the PRV controls
ControlHIPAA Security RulePCI DSS v4.0.1Trust Services CriteriaISO/IEC 27001:2022
SIAS-PRV-01Personal information categories and security requirements§164.306(a)No direct mappingC1.1, P3 seriesA.5.12, A.5.34
SIAS-PRV-02Restricted and logged access to personal information§164.308(a)(4)(ii)(B), §164.312(a)(1), §164.312(b)7.2, 10.2CC6.1, CC6.3A.5.34, A.8.3
SIAS-PRV-03Tracking technologies and outbound data sharing match declared practicesNo direct mapping6.4, 11.6P1 series, P6 seriesA.5.14, A.5.34
SIAS-PRV-04Secure handling of privacy requestsNo direct mappingNo direct mappingP5 seriesA.5.34
SIAS-PRV-05Personal-information impact in incident handling§164.308(a)(6)(ii)12.10CC7.4, P6 seriesA.5.26, A.5.34

CMC: Continuous monitoring and material-change reporting

Framework cross-references for the CMC controls
ControlHIPAA Security RulePCI DSS v4.0.1Trust Services CriteriaISO/IEC 27001:2022
SIAS-CMC-01Continuous control monitoring§164.308(a)(8)10.7, 12.4CC4.19.1; A.5.36
SIAS-CMC-02Material-change notification to SecurityInspect§164.308(a)(8)6.5, 12.5CC3.46.3
SIAS-CMC-03Serious security incident notification to SecurityInspectNo direct mappingNo direct mappingCC2.3No direct mapping
SIAS-CMC-04Surveillance cooperation and evidence refresh§164.308(a)(8)No direct mappingCC4.1A.5.35
SIAS-CMC-05Accurate representation of certification and badge useNo direct mappingNo direct mappingCC2.3No direct mapping. This is a SIAS program rule with no framework counterpart

HIPAA is a U.S. federal law. PCI DSS, SOC 2, Trust Services Criteria and ISO/IEC 27001 are names or marks of their respective owners, used here only to identify their frameworks. No endorsement is implied.

Where our work stops

Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.

Talk to us about a SIAS assessment

Tell us what you want assessed, and we’ll start with the scope.