SIAS-CMC-01 Continuous control monitoring
- Mandatory
- Yes
- Severity
- Medium
- Applies
- All scopes for SecurityInspect Certified (not part of any SecurityInspect Verified profile)
- SecurityInspect Verified profiles
- None
Control objective
The holder watches its own key controls between assessments, so that failures are noticed and fixed without waiting for the next assessment.
Testable requirement
- 1.The applicant must define control health indicators for the in-scope environment that cover at least: multi-factor authentication coverage (SIAS-IAM-02); the number of privileged accounts and changes to them (SIAS-IAM-03); endpoint protection coverage (SIAS-NET-03); vulnerability remediation against the SIAS-VPM-02 times; backup success and restore tests (SIAS-BCR-01, SIAS-BCR-02); log source health (SIAS-LOG-01); the status of open exceptions and remediation plans; and third-party review status (SIAS-TPR-03). Each indicator must have a defined source and threshold.
- 2.Indicators must be collected automatically wherever the source system supports it, and reviewed at least monthly by the security owner (SIAS-GOV-01). Deviations from thresholds must be recorded as tracked actions.
- 3.Failures of security control systems (for example, endpoint protection agents stopping, log sources going silent, backup jobs failing, or multi-factor enforcement being disabled) must be detected and alerted to a responsible person within 24 hours, and the response must be recorded: restored, or escalated with a risk decision.
- 4.Monitoring results must be kept for at least 12 months.
- 5.Findings from the applicant's own internal reviews (SIAS-GOV-05) should feed the same action tracking.
Applicability and scope
All scopes for SecurityInspect Certified (not part of any SecurityInspect Verified profile). Cannot be marked not applicable for a SecurityInspect Certified assessment. At the initial assessment it is tested over the 90-day look-back period; at surveillance and renewal, over the period since the last assessment. This control concerns the holder's own monitoring. SecurityInspect's weekly external surveillance is a separate program activity (see the SIAS renewal, suspension and revocation rules) and does not satisfy it.
Pass criteria
- 1.Every indicator in requirement 1 is defined, with a source and threshold, and has data for every month of the period.
- 2.A monthly review is recorded for every month of the period, and every deviation has a tracked action.
- 3.Every sampled control-system failure was alerted within 24 hours and has a recorded response.
- 4.No discrepancy of more than 5 percentage points between a reported coverage indicator and SecurityInspect's measurement is left unexplained.
Severity
Medium. Escalation to Critical applies only on the standard escalation triggers in the scoring model (§5.7).
Informative framework mappings
- HIPAA Security Rule
- §164.308(a)(8)
- PCI DSS v4.0.1
- 10.7, 12.4
- Trust Services Criteria
- CC4.1
- ISO/IEC 27001:2022
- 9.1; A.5.36
- Theme (SecurityInspect wording)
- the holder watching its own controls
SIAS-CMC-02 Material-change notification to SecurityInspect
- Mandatory
- Yes
- Severity
- High
- Applies
- All scopes
- SecurityInspect Verified profiles
- VP-EXT, VP-APP, VP-CLD
Control objective
SecurityInspect learns about material changes to the certified scope in time to decide whether the certificate still reflects reality.
Testable requirement
- 1.The applicant must maintain a documented procedure for identifying material changes to the certified scope and notifying SecurityInspect, and must name a responsible person and a deputy.
- 2.Definition of a material change (if it differs from the definition in the SIAS renewal, suspension and revocation rules, the lifecycle document prevails): a change of the certified legal entity, its ownership or control; adding, removing or replacing an in-scope website, product, system, domain, cloud account or hosting provider; a change of primary hosting region or data location; a change to the authentication or identity architecture of the scope; starting to store or process a new category of Restricted data in scope; outsourcing or bringing in-house a security function (for example, security monitoring or IT administration); a major architecture change affecting network boundaries or data flows; a change of the security owner (SIAS-GOV-01); and decommissioning all or part of the scope.
- 3.The applicant must notify SecurityInspect of each material change within 30 calendar days of it taking effect, and of planned major changes before they go live where practicable.
- 4.The change process (SIAS-SDC-03) must include a step that flags potential material changes to the responsible person.
- 5.Each notification must be sent through the channel named in the certification agreement and must state the change, its effective date, the scope elements affected and the security review performed.
- 6.At the initial assessment, the named responsible person must send one test notification, marked as a test, through that channel, so that SecurityInspect can confirm that the channel works and the content is complete.
Applicability and scope
All scopes (also in every SecurityInspect Verified profile); at initial assessment tested as documented procedure, named contact, a test notification received by SecurityInspect and an observed flagging step, and at surveillance and renewal tested as actual performance. Cannot be marked not applicable. SecurityInspect Verified profiles: VP-EXT, VP-APP and VP-CLD. In a SecurityInspect Verified profile, a material change is a change to the declared profile scope: for example, a new internet-facing domain or IP range (VP-EXT), a release that changes authentication or adds an API to the named application (VP-APP), or a new cloud account or region (VP-CLD).
Pass criteria
- 1.At every assessment: the procedure covers every category in requirement 2 (or the authoritative lifecycle definition) and names a responsible person and a deputy.
- 2.At every assessment: the change process includes the material-change flagging step.
- 3.At every assessment: the responsible person can describe the obligation, the categories and the channel.
- 4.At surveillance and renewal: every material change in the period was notified within 30 days of taking effect.
- 5.At surveillance and renewal: every notification contains the content required by requirement 5.
- 6.At the initial assessment: the test notification (E5) was received through the agreed channel with the content required by requirement 5, and the flagging step was observed (E6).
Severity
High. Escalate a finding to Critical on the standard triggers, for example where an unreported change put an internet-facing asset with a KEV-listed vulnerability into the scope. Deliberate concealment of a change is an integrity failure. An unreported significant system change is also a suspension or revocation trigger under the SIAS renewal, suspension and revocation rules.
Informative framework mappings
- HIPAA Security Rule
- §164.308(a)(8)
- PCI DSS v4.0.1
- 6.5, 12.5
- Trust Services Criteria
- CC3.4
- ISO/IEC 27001:2022
- 6.3
- Theme (SecurityInspect wording)
- telling the assessor about significant change
SIAS-CMC-03 Serious security incident notification to SecurityInspect
- Mandatory
- Yes
- Severity
- High
- Applies
- All scopes for SecurityInspect Certified
- SecurityInspect Verified profiles
- None
Control objective
SecurityInspect learns promptly about serious security incidents that affect the certified scope, so that the certificate's status can be reviewed.
Testable requirement
- 1.The applicant's incident response plan (SIAS-INC-01) must include a step to notify SecurityInspect of any serious security incident affecting the certified scope, and must name the person responsible for sending the notice.
- 2.Definition of a serious security incident (if it differs from the definition in the SIAS renewal, suspension and revocation rules, the lifecycle document prevails): a confirmed incident affecting the certified scope that involves unauthorized access to or disclosure of Restricted data; unauthorized administrative or privileged access; ransomware or other destructive or extortion activity; loss of availability of an in-scope service beyond its recovery objective; or an incident that the applicant reports to a regulator, to law enforcement or to affected individuals.
- 3.The notice must reach SecurityInspect within 72 hours of the applicant confirming that the certified scope is affected, through the channel named in the certification agreement. It must state what is known: the date, the nature of the incident, the scope elements affected and the containment status. Details that are legally privileged or restricted may be withheld if the notice says that they are; the fact that the incident occurred may not.
- 4.The applicant must send an update when the incident is closed, stating the root cause and any corrective actions that affect SIAS controls.
- 5.This notice serves certification purposes only. It does not replace any notification the applicant owes under law or contract, and SecurityInspect does not provide incident response under SIAS.
- 6.At the initial assessment, the named person must prepare and send one test notice, marked as a test and containing no real incident details, through the channel named in the certification agreement, in a walkthrough that SecurityInspect observes.
Applicability and scope
All scopes for SecurityInspect Certified. Cannot be marked not applicable for a SecurityInspect Certified assessment. At the initial assessment it is tested as a documented step, a named person and an observed test notice received by SecurityInspect; at surveillance and renewal, as actual performance for incidents during the period. SecurityInspect Verified profiles: none.
Pass criteria
- 1.At every assessment: the incident response plan contains the notification step, the definition, the named person and the channel.
- 2.At every assessment: the named person can describe the step and the 72-hour window.
- 3.At surveillance and renewal: every serious security incident in the period was notified within 72 hours of scope confirmation.
- 4.At surveillance and renewal: every closed serious security incident has a closure update.
- 5.At the initial assessment: the observed walkthrough (I3) produced a test notice that was received through the agreed channel with the content required by requirement 3 (E5).
Severity
High. Escalation to Critical applies only on the standard escalation triggers in the scoring model (§5.7). Concealing a serious security incident is an integrity failure, and a serious security incident is itself a suspension or revocation trigger under the SIAS renewal, suspension and revocation rules.
Informative framework mappings
- HIPAA Security Rule
- No direct mapping
- PCI DSS v4.0.1
- No direct mapping
- Trust Services Criteria
- CC2.3
- ISO/IEC 27001:2022
- No direct mapping
- Theme (SecurityInspect wording)
- telling the assessor about serious incidents
SIAS-CMC-04 Surveillance cooperation and evidence refresh
- Mandatory
- Yes
- Severity
- High
- Applies
- All scopes for SecurityInspect Certified
- SecurityInspect Verified profiles
- None
Control objective
SecurityInspect can keep checking the certified scope between reassessments, so that the public status stays accurate.
Testable requirement
- 1.In the certification agreement, the applicant must authorize SecurityInspect's automated external surveillance of the declared internet-facing assets at least weekly for the validity period. The applicant must not selectively block SecurityInspect's declared testing sources in a way that stops SecurityInspect from seeing what any internet user can see. Protective controls that apply to all traffic, such as a web application firewall, are allowed.
- 2.The applicant must take part in the formal surveillance review at month 6 (plus or minus 30 days) and in any special review SecurityInspect starts under the SIAS renewal, suspension and revocation rules, for example after a material change or a serious security incident.
- 3.The applicant must supply evidence requested for surveillance within 10 business days of the request, unless SecurityInspect agrees an extension in writing, and must keep the read-only access arrangements agreed for surveillance working.
- 4.The applicant must name a surveillance contact and keep the contact details current.
- 5.The applicant must make personnel available for surveillance interviews and allow observation where the surveillance plan requires it.
- 6.The applicant must keep the evidence that SIAS controls rely on for at least 12 months, so that renewal can use a 12-month look-back.
Applicability and scope
All scopes for SecurityInspect Certified. Cannot be marked not applicable for a SecurityInspect Certified assessment. At the initial assessment it is tested as a signed authorization, a named contact, agreed access arrangements and a baseline surveillance run; at surveillance and renewal, as actual cooperation. SecurityInspect Verified profiles: none.
Pass criteria
- 1.At every assessment: a signed authorization covers weekly external surveillance and the month-6 review.
- 2.At every assessment: a surveillance contact is named and current.
- 3.At every assessment: the agreed read-only access arrangements work.
- 4.At surveillance and renewal: no surveillance run was prevented by selective blocking of SecurityInspect's declared sources.
- 5.At surveillance and renewal: every evidence request was answered within 10 business days or within an agreed extension.
- 6.At surveillance and renewal: the month-6 surveillance review was completed within its window.
- 7.At renewal: 12 months of evidence is available for the controls that rely on it.
Severity
High. Escalation to Critical applies only on the standard escalation triggers in the scoring model (§5.7). Refusing to cooperate with reassessment is a revocation trigger under the SIAS renewal, suspension and revocation rules.
Informative framework mappings
- HIPAA Security Rule
- §164.308(a)(8)
- PCI DSS v4.0.1
- No direct mapping
- Trust Services Criteria
- CC4.1
- ISO/IEC 27001:2022
- A.5.35
- Theme (SecurityInspect wording)
- supporting independent checks between assessments
SIAS-CMC-05 Accurate representation of certification and badge use
- Mandatory
- Yes
- Severity
- High
- Applies
- All scopes
- SecurityInspect Verified profiles
- VP-EXT, VP-APP, VP-CLD
Control objective
What the holder says about its SIAS result matches the verification record, so that no one is misled about what was assessed.
Testable requirement
- 1.The applicant must accept the badge license (the badge license) as part of the certification agreement and follow the badge and mark policy.
- 2.The applicant must not state or imply that it holds any SIAS level before SecurityInspect issues it, or after the certificate becomes Suspended, Expired, Revoked or Withdrawn.
- 3.Every display of a SIAS badge must link to the certificate's verification page (https://securityinspect.com/verify/<certificate-id>), use unaltered artwork, and carry the defined alternative text: "SecurityInspect Certified — independently assessed against SIAS v1.0. Select to verify current status." Badges may appear only on the bound domains or in materials that identify the certified scope.
- 4.Public statements must match the level and scope on the verification record. A SecurityInspect Verified result must not be presented as organizational certification. A SecurityInspect Reviewed result must not be presented as a pass. The certified scope must not be presented as covering other products, systems or legal entities.
- 5.Statements about SIAS must not claim or imply that SIAS is equivalent to, endorsed by, or a substitute for HIPAA, PCI DSS, SOC 2 or the AICPA Trust Services Criteria, or ISO/IEC 27001, and must not describe the holder as secure, compliant or protected against breaches on the basis of its SIAS result. The full wording rules are in the SIAS claims rules.
- 6.The applicant must name a person responsible for public statements about SIAS, and must have a review step for marketing, sales and proposal materials that mention SecurityInspect or SIAS.
- 7.Misuse found by the holder or notified by SecurityInspect must be corrected within 10 business days.
Applicability and scope
All scopes (also in every SecurityInspect Verified profile). Cannot be marked not applicable. At the initial assessment it is tested as accepted license terms, a named responsible person, a review step, and the absence of premature claims; at surveillance and renewal, as actual use. SecurityInspect Verified profiles: VP-EXT, VP-APP and VP-CLD.
Pass criteria
- 1.At every assessment: the badge license terms are accepted, a responsible person is named and the review step is documented.
- 2.At the initial assessment: no claim of a SIAS level made before issuance is found.
- 3.At surveillance and renewal: every badge display links to the correct verification page, uses unaltered artwork and carries the defined alternative text.
- 4.At surveillance and renewal: no statement misrepresents the level, the scope or the relationship between SIAS and any framework.
- 5.At surveillance and renewal: every misuse notified during the period was corrected within 10 business days.
Severity
High. Escalation to Critical applies only on the standard escalation triggers in the scoring model (§5.7). Deliberate misrepresentation, and use of a badge after suspension, expiry, revocation or withdrawal, are badge misuse under the SIAS renewal, suspension and revocation rules (a suspension or revocation trigger), in addition to any finding under this control.
Informative framework mappings
- HIPAA Security Rule
- No direct mapping
- PCI DSS v4.0.1
- No direct mapping
- Trust Services Criteria
- CC2.3
- ISO/IEC 27001:2022
- No direct mapping. This is a SIAS program rule with no framework counterpart
- Theme (SecurityInspect wording)
- honest statements about the SIAS result