SIAS-AST-01 Inventory of in-scope assets
- Mandatory
- Yes
- Severity
- High
- Applies
- All scopes (hardware, software, cloud resources, domains, data stores)
- SecurityInspect Verified profiles
- VP-EXT, VP-CLD
Control objective
The applicant keeps a complete and current record of every asset in the stated scope, so that each one can be protected, monitored and recovered.
Testable requirement
- 1.The applicant must maintain an inventory of all in-scope assets. It must cover every one of these asset types that is present in scope: physical and virtual servers; network and security devices; endpoints used to access or administer in-scope systems; operating systems and installed software, with versions; cloud accounts, subscriptions and projects, and the resources in them (compute, storage, databases, serverless functions, container clusters, load balancers, gateways and managed services); domain names and DNS zones; public IP addresses and internet-facing services; SaaS applications; and data stores that hold in-scope data.
- 2.Each entry must record at least: a unique identifier; asset type; environment (production, staging, development or test); location, or hosting provider and region; whether it is internet-facing; lifecycle status (planned, active or retired); and the date it was last updated. SIAS-AST-02 adds the owner, classification and criticality attributes; SIAS-AST-04 adds version and support status.
- 3.The applicant must update the inventory whenever an asset is added, materially changed or retired. Retired assets must stay in the inventory with their retirement date; they must not be deleted.
- 4.The inventory should be populated or reconciled automatically from authoritative sources (cloud provider APIs, endpoint and device management, DNS zones, the identity provider) wherever such a source exists for the asset type. Where an asset type is recorded manually, the reason should be documented.
Applicability and scope
All scopes (hardware, software, cloud resources, domains, data stores). Cannot be marked not applicable. SecurityInspect Verified profiles: VP-EXT (the inventory and the pass criteria cover only the declared internet-facing domains, IP addresses and services) and VP-CLD (they cover only the named cloud tenants or accounts).
Pass criteria
- 1.An inventory exists and covers every asset type in requirement 1 that is present in scope.
- 2.Every internet-facing in-scope asset found by A1 or A2 is in the inventory, except assets created within the previous 7 days that have a change record.
- 3.At least 95% of the other in-scope assets found by A2, A3 and M3 are in the inventory, and no missing asset stores or processes Restricted data or provides administrative access to in-scope systems.
- 4.Every attribute in requirement 2 is populated for 100% of internet-facing entries and for at least 95% of all other entries.
- 5.No entry in the M3 existence sample refers to an asset that no longer exists without being marked retired.
- 6.Every sampled addition and retirement (E4, M5) is reflected in the inventory.
Severity
High. Escalate a finding to Critical when an asset missing from the inventory is internet-facing and exposes Restricted or other sensitive data or credentials to unauthenticated parties, allows authentication bypass, or has a vulnerability listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
Informative framework mappings
- HIPAA Security Rule
- §164.310(d)(2)(iii)
- PCI DSS v4.0.1
- 12.5
- Trust Services Criteria
- CC6.1
- ISO/IEC 27001:2022
- A.5.9
- Theme (SecurityInspect wording)
- a complete, current record of assets
SIAS-AST-02 Asset ownership and classification linkage
- Mandatory
- No
- Severity
- Medium
- Applies
- All scopes
- SecurityInspect Verified profiles
- None
Control objective
Every in-scope asset has an accountable owner and is linked to the sensitivity of the data it handles and to its business criticality, so that protection and recovery decisions are made by someone with authority and match the asset's importance.
Testable requirement
- 1.Each in-scope inventory entry must name an accountable owner, recorded as a role and a current named individual (or a team with a named lead).
- 2.Each entry must record the highest data classification, under the scheme in SIAS-DAT-01, of the data the asset stores, processes or transmits.
- 3.Each entry must record a business criticality rating on a scale the applicant defines. The rating must be consistent with the recovery priorities in SIAS-BCR-03.
- 4.Owners must confirm the accuracy of their entries at least every 12 months. Ownership must be reassigned before an owner leaves or changes role.
- 5.Where the applicant uses tags or labels in source systems to drive security controls (for example, a backup or encryption policy keyed to a classification tag), those tags must match the inventory.
Applicability and scope
All scopes. Cannot be marked not applicable. SecurityInspect Verified profiles: none.
Pass criteria
- 1.An owner is recorded for 100% of internet-facing entries and entries that hold Restricted data, and for at least 95% of all entries.
- 2.No owner in the M1 sample or flagged by A2 is disabled, departed or unknown.
- 3.A classification is recorded for 100% of data stores and for at least 95% of all entries.
- 4.No asset reviewed under M2 is classified lower than the highest classification of the data it holds or receives.
- 5.Criticality ratings are recorded and are consistent with SIAS-BCR-03 for every sampled asset.
- 6.An owner confirmation cycle covering all entries was completed within the last 12 months.
- 7.Tags that drive security controls match the inventory for every sampled resource.
Severity
Medium. Escalation to Critical applies only on the standard escalation triggers in the scoring model (§5.7).
Informative framework mappings
- HIPAA Security Rule
- No direct mapping
- PCI DSS v4.0.1
- 12.5
- Trust Services Criteria
- CC6.1
- ISO/IEC 27001:2022
- A.5.9, A.5.12
- Theme (SecurityInspect wording)
- every asset owned and classified
SIAS-AST-03 Discovery and reconciliation of unmanaged assets
- Mandatory
- No
- Severity
- High
- Applies
- All scopes
- SecurityInspect Verified profiles
- VP-EXT, VP-CLD
Control objective
Assets that appear outside normal processes, such as forgotten test systems, unapproved SaaS or new subdomains, are found quickly and either brought under management or removed.
Testable requirement
- 1.The applicant must run automated discovery covering all in-scope internet-facing domains and IP ranges, all in-scope cloud accounts and enabled regions, and all in-scope internal network ranges. Frequency: continuously or at least weekly for internet-facing assets and cloud accounts, and at least monthly for internal networks.
- 2.Discovery must identify SaaS applications used with in-scope data or accounts, for example from identity-provider application registrations, OAuth consent grants, network records or purchasing records.
- 3.Each discovery run must be reconciled with the inventory. Every unmanaged asset found must be resolved, by adding it to the inventory and bringing it under the applicable SIAS controls or by removing or blocking it, within 7 days for internet-facing assets and 30 days for all others.
- 4.The applicant must monitor certificate transparency logs for certificates issued for in-scope domains and review any unexpected certificate within 7 days.
- 5.Discovery results and reconciliation decisions must be kept for at least 12 months, so that renewal can use a 12-month look-back.
Applicability and scope
All scopes. Cannot be marked not applicable. SecurityInspect Verified profiles: VP-EXT (limited to discovery of the declared internet-facing domains, IP ranges and services; requirement 2 does not apply) and VP-CLD (limited to the named cloud tenants or accounts).
Pass criteria
- 1.Discovery covers 100% of the declared internet-facing domains and IP ranges, cloud accounts and enabled regions, and in-scope internal network ranges.
- 2.During the look-back period, no gap between successful discovery runs exceeded twice the required interval.
- 3.Every sampled unmanaged asset was resolved within the deadline in requirement 3.
- 4.SecurityInspect's discovery (A4) finds no internet-facing unmanaged asset, older than 7 days, that the applicant's discovery missed or left unresolved.
- 5.Certificate transparency monitoring operated throughout the look-back period, and every unexpected certificate was reviewed within 7 days.
- 6.A SaaS discovery mechanism operates, and every SaaS application found by A6 that holds or accesses in-scope data is in the inventory.
Severity
High. Escalate a finding to Critical when an unmanaged internet-facing asset exposes Restricted or other sensitive data or credentials to unauthenticated parties, allows authentication bypass, or has a KEV-listed vulnerability.
Informative framework mappings
- HIPAA Security Rule
- No direct mapping
- PCI DSS v4.0.1
- 12.5
- Trust Services Criteria
- CC7.1
- ISO/IEC 27001:2022
- A.5.9
- Theme (SecurityInspect wording)
- finding assets that escaped normal processes
SIAS-AST-04 Unsupported and unauthorized technology
- Mandatory
- Yes
- Severity
- High
- Applies
- All scopes
- SecurityInspect Verified profiles
- None
Control objective
In-scope systems run only technology that the applicant has authorized and that still receives security updates, because software that is unknown or no longer supported cannot be kept patched.
Testable requirement
- 1.The applicant must record the version and supplier support status of every operating system, firmware, platform, runtime, database engine, application and framework in scope, as attributes of the SIAS-AST-01 inventory.
- 2.No in-scope component may be past its supplier's end of security support, unless it receives security updates under a paid extended-support arrangement, or is covered by a compensating control accepted under this control.
- 3.Every component that reaches end of security support within the next 180 days must have a recorded upgrade, replacement or retirement plan dated before its end of support.
- 4.The applicant must define which software may be installed or run on in-scope systems (an approved technology list, an allow-list, or a documented rule such as "only software deployed through the managed pipeline"), and must enforce or detect this technically on in-scope servers and endpoints.
- 5.Unauthorized software detected on in-scope systems must be removed, or formally authorized, within 30 days of detection. Unauthorized software with remote-access, tunneling or credential-harvesting capability must be investigated as a potential security incident under SIAS-INC-01 when detected.
Applicability and scope
All scopes. Cannot be marked not applicable. SecurityInspect Verified profiles: none.
Pass criteria
- 1.Version and support status are recorded for 100% of sampled components.
- 2.No unsupported component is in scope, other than components covered by an accepted compensating control.
- 3.Every component reaching end of security support within 180 days has a dated plan.
- 4.An approved-software definition exists and is enforced or detected on 100% of in-scope servers and on every endpoint within SIAS-NET-03.
- 5.Every sampled unauthorized-software detection was resolved within 30 days, and every sampled item with remote-access, tunneling or credential-harvesting capability was investigated.
- 6.The direct checks in M4 find no unauthorized software that the applicant's own enforcement or detection had not already flagged.
Severity
High. Escalate a finding to Critical when an unsupported or unauthorized component is internet-facing and has a KEV-listed vulnerability, or when unauthorized software shows evidence of active compromise.
Informative framework mappings
- HIPAA Security Rule
- No direct mapping
- PCI DSS v4.0.1
- 6.3, 12.3
- Trust Services Criteria
- CC7.1
- ISO/IEC 27001:2022
- A.5.9, A.8.19
- Theme (SecurityInspect wording)
- only supported, authorized technology in use