Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

SIAS v1.0 · Domain 19 of 19

CMC: Continuous monitoring and material-change reporting

This domain keeps a certificate accurate after it is issued. It checks that the holder monitors its own controls between assessments, tells SecurityInspect about material changes and serious security incidents affecting the certified scope, cooperates with surveillance, and describes its SIAS result accurately. All five controls are mandatory. Most of them have two testing modes: at the initial assessment SecurityInspect tests that the procedure, the named people and the commitments exist, and at surveillance and renewal it tests what actually happened during the period. The lifecycle consequences of failures (special reviews, suspension and revocation) are set out in the SIAS renewal, suspension and revocation rules. SIAS-CMC-02 and SIAS-CMC-03 each include an item that SecurityInspect obtains itself at the initial assessment (a test notice received in its register), so that they can meet the evidence-sufficiency rule in §5.2 before any real notice has been sent. For SecurityInspect Verified holders, SIAS-CMC-03 and SIAS-CMC-04 are not assessed, but the incident-notification and surveillance-cooperation duties still apply under the certification agreement (the SIAS renewal, suspension and revocation rules).

Controls in this domain

5 controls, 5 of them mandatory.

Controls in the CMC domain
ControlTitleMandatorySeverityApplies
SIAS-CMC-01Continuous control monitoringYesMediumAll scopes for SecurityInspect Certified (not part of any SecurityInspect Verified profile)
SIAS-CMC-02Material-change notification to SecurityInspectYesHighAll scopes
SIAS-CMC-03Serious security incident notification to SecurityInspectYesHighAll scopes for SecurityInspect Certified
SIAS-CMC-04Surveillance cooperation and evidence refreshYesHighAll scopes for SecurityInspect Certified
SIAS-CMC-05Accurate representation of certification and badge useYesHighAll scopes

SIAS-CMC-01 Continuous control monitoring

Mandatory
Yes
Severity
Medium
Applies
All scopes for SecurityInspect Certified (not part of any SecurityInspect Verified profile)
SecurityInspect Verified profiles
None

Control objective

The holder watches its own key controls between assessments, so that failures are noticed and fixed without waiting for the next assessment.

Testable requirement

  • 1.The applicant must define control health indicators for the in-scope environment that cover at least: multi-factor authentication coverage (SIAS-IAM-02); the number of privileged accounts and changes to them (SIAS-IAM-03); endpoint protection coverage (SIAS-NET-03); vulnerability remediation against the SIAS-VPM-02 times; backup success and restore tests (SIAS-BCR-01, SIAS-BCR-02); log source health (SIAS-LOG-01); the status of open exceptions and remediation plans; and third-party review status (SIAS-TPR-03). Each indicator must have a defined source and threshold.
  • 2.Indicators must be collected automatically wherever the source system supports it, and reviewed at least monthly by the security owner (SIAS-GOV-01). Deviations from thresholds must be recorded as tracked actions.
  • 3.Failures of security control systems (for example, endpoint protection agents stopping, log sources going silent, backup jobs failing, or multi-factor enforcement being disabled) must be detected and alerted to a responsible person within 24 hours, and the response must be recorded: restored, or escalated with a risk decision.
  • 4.Monitoring results must be kept for at least 12 months.
  • 5.Findings from the applicant's own internal reviews (SIAS-GOV-05) should feed the same action tracking.

Applicability and scope

All scopes for SecurityInspect Certified (not part of any SecurityInspect Verified profile). Cannot be marked not applicable for a SecurityInspect Certified assessment. At the initial assessment it is tested over the 90-day look-back period; at surveillance and renewal, over the period since the last assessment. This control concerns the holder's own monitoring. SecurityInspect's weekly external surveillance is a separate program activity (see the SIAS renewal, suspension and revocation rules) and does not satisfy it.

Pass criteria

  • 1.Every indicator in requirement 1 is defined, with a source and threshold, and has data for every month of the period.
  • 2.A monthly review is recorded for every month of the period, and every deviation has a tracked action.
  • 3.Every sampled control-system failure was alerted within 24 hours and has a recorded response.
  • 4.No discrepancy of more than 5 percentage points between a reported coverage indicator and SecurityInspect's measurement is left unexplained.

Severity

Medium. Escalation to Critical applies only on the standard escalation triggers in the scoring model (§5.7).

Informative framework mappings

HIPAA Security Rule
§164.308(a)(8)
PCI DSS v4.0.1
10.7, 12.4
Trust Services Criteria
CC4.1
ISO/IEC 27001:2022
9.1; A.5.36
Theme (SecurityInspect wording)
the holder watching its own controls

SIAS-CMC-02 Material-change notification to SecurityInspect

Mandatory
Yes
Severity
High
Applies
All scopes
SecurityInspect Verified profiles
VP-EXT, VP-APP, VP-CLD

Control objective

SecurityInspect learns about material changes to the certified scope in time to decide whether the certificate still reflects reality.

Testable requirement

  • 1.The applicant must maintain a documented procedure for identifying material changes to the certified scope and notifying SecurityInspect, and must name a responsible person and a deputy.
  • 2.Definition of a material change (if it differs from the definition in the SIAS renewal, suspension and revocation rules, the lifecycle document prevails): a change of the certified legal entity, its ownership or control; adding, removing or replacing an in-scope website, product, system, domain, cloud account or hosting provider; a change of primary hosting region or data location; a change to the authentication or identity architecture of the scope; starting to store or process a new category of Restricted data in scope; outsourcing or bringing in-house a security function (for example, security monitoring or IT administration); a major architecture change affecting network boundaries or data flows; a change of the security owner (SIAS-GOV-01); and decommissioning all or part of the scope.
  • 3.The applicant must notify SecurityInspect of each material change within 30 calendar days of it taking effect, and of planned major changes before they go live where practicable.
  • 4.The change process (SIAS-SDC-03) must include a step that flags potential material changes to the responsible person.
  • 5.Each notification must be sent through the channel named in the certification agreement and must state the change, its effective date, the scope elements affected and the security review performed.
  • 6.At the initial assessment, the named responsible person must send one test notification, marked as a test, through that channel, so that SecurityInspect can confirm that the channel works and the content is complete.

Applicability and scope

All scopes (also in every SecurityInspect Verified profile); at initial assessment tested as documented procedure, named contact, a test notification received by SecurityInspect and an observed flagging step, and at surveillance and renewal tested as actual performance. Cannot be marked not applicable. SecurityInspect Verified profiles: VP-EXT, VP-APP and VP-CLD. In a SecurityInspect Verified profile, a material change is a change to the declared profile scope: for example, a new internet-facing domain or IP range (VP-EXT), a release that changes authentication or adds an API to the named application (VP-APP), or a new cloud account or region (VP-CLD).

Pass criteria

  • 1.At every assessment: the procedure covers every category in requirement 2 (or the authoritative lifecycle definition) and names a responsible person and a deputy.
  • 2.At every assessment: the change process includes the material-change flagging step.
  • 3.At every assessment: the responsible person can describe the obligation, the categories and the channel.
  • 4.At surveillance and renewal: every material change in the period was notified within 30 days of taking effect.
  • 5.At surveillance and renewal: every notification contains the content required by requirement 5.
  • 6.At the initial assessment: the test notification (E5) was received through the agreed channel with the content required by requirement 5, and the flagging step was observed (E6).

Severity

High. Escalate a finding to Critical on the standard triggers, for example where an unreported change put an internet-facing asset with a KEV-listed vulnerability into the scope. Deliberate concealment of a change is an integrity failure. An unreported significant system change is also a suspension or revocation trigger under the SIAS renewal, suspension and revocation rules.

Informative framework mappings

HIPAA Security Rule
§164.308(a)(8)
PCI DSS v4.0.1
6.5, 12.5
Trust Services Criteria
CC3.4
ISO/IEC 27001:2022
6.3
Theme (SecurityInspect wording)
telling the assessor about significant change

SIAS-CMC-03 Serious security incident notification to SecurityInspect

Mandatory
Yes
Severity
High
Applies
All scopes for SecurityInspect Certified
SecurityInspect Verified profiles
None

Control objective

SecurityInspect learns promptly about serious security incidents that affect the certified scope, so that the certificate's status can be reviewed.

Testable requirement

  • 1.The applicant's incident response plan (SIAS-INC-01) must include a step to notify SecurityInspect of any serious security incident affecting the certified scope, and must name the person responsible for sending the notice.
  • 2.Definition of a serious security incident (if it differs from the definition in the SIAS renewal, suspension and revocation rules, the lifecycle document prevails): a confirmed incident affecting the certified scope that involves unauthorized access to or disclosure of Restricted data; unauthorized administrative or privileged access; ransomware or other destructive or extortion activity; loss of availability of an in-scope service beyond its recovery objective; or an incident that the applicant reports to a regulator, to law enforcement or to affected individuals.
  • 3.The notice must reach SecurityInspect within 72 hours of the applicant confirming that the certified scope is affected, through the channel named in the certification agreement. It must state what is known: the date, the nature of the incident, the scope elements affected and the containment status. Details that are legally privileged or restricted may be withheld if the notice says that they are; the fact that the incident occurred may not.
  • 4.The applicant must send an update when the incident is closed, stating the root cause and any corrective actions that affect SIAS controls.
  • 5.This notice serves certification purposes only. It does not replace any notification the applicant owes under law or contract, and SecurityInspect does not provide incident response under SIAS.
  • 6.At the initial assessment, the named person must prepare and send one test notice, marked as a test and containing no real incident details, through the channel named in the certification agreement, in a walkthrough that SecurityInspect observes.

Applicability and scope

All scopes for SecurityInspect Certified. Cannot be marked not applicable for a SecurityInspect Certified assessment. At the initial assessment it is tested as a documented step, a named person and an observed test notice received by SecurityInspect; at surveillance and renewal, as actual performance for incidents during the period. SecurityInspect Verified profiles: none.

Pass criteria

  • 1.At every assessment: the incident response plan contains the notification step, the definition, the named person and the channel.
  • 2.At every assessment: the named person can describe the step and the 72-hour window.
  • 3.At surveillance and renewal: every serious security incident in the period was notified within 72 hours of scope confirmation.
  • 4.At surveillance and renewal: every closed serious security incident has a closure update.
  • 5.At the initial assessment: the observed walkthrough (I3) produced a test notice that was received through the agreed channel with the content required by requirement 3 (E5).

Severity

High. Escalation to Critical applies only on the standard escalation triggers in the scoring model (§5.7). Concealing a serious security incident is an integrity failure, and a serious security incident is itself a suspension or revocation trigger under the SIAS renewal, suspension and revocation rules.

Informative framework mappings

HIPAA Security Rule
No direct mapping
PCI DSS v4.0.1
No direct mapping
Trust Services Criteria
CC2.3
ISO/IEC 27001:2022
No direct mapping
Theme (SecurityInspect wording)
telling the assessor about serious incidents

SIAS-CMC-04 Surveillance cooperation and evidence refresh

Mandatory
Yes
Severity
High
Applies
All scopes for SecurityInspect Certified
SecurityInspect Verified profiles
None

Control objective

SecurityInspect can keep checking the certified scope between reassessments, so that the public status stays accurate.

Testable requirement

  • 1.In the certification agreement, the applicant must authorize SecurityInspect's automated external surveillance of the declared internet-facing assets at least weekly for the validity period. The applicant must not selectively block SecurityInspect's declared testing sources in a way that stops SecurityInspect from seeing what any internet user can see. Protective controls that apply to all traffic, such as a web application firewall, are allowed.
  • 2.The applicant must take part in the formal surveillance review at month 6 (plus or minus 30 days) and in any special review SecurityInspect starts under the SIAS renewal, suspension and revocation rules, for example after a material change or a serious security incident.
  • 3.The applicant must supply evidence requested for surveillance within 10 business days of the request, unless SecurityInspect agrees an extension in writing, and must keep the read-only access arrangements agreed for surveillance working.
  • 4.The applicant must name a surveillance contact and keep the contact details current.
  • 5.The applicant must make personnel available for surveillance interviews and allow observation where the surveillance plan requires it.
  • 6.The applicant must keep the evidence that SIAS controls rely on for at least 12 months, so that renewal can use a 12-month look-back.

Applicability and scope

All scopes for SecurityInspect Certified. Cannot be marked not applicable for a SecurityInspect Certified assessment. At the initial assessment it is tested as a signed authorization, a named contact, agreed access arrangements and a baseline surveillance run; at surveillance and renewal, as actual cooperation. SecurityInspect Verified profiles: none.

Pass criteria

  • 1.At every assessment: a signed authorization covers weekly external surveillance and the month-6 review.
  • 2.At every assessment: a surveillance contact is named and current.
  • 3.At every assessment: the agreed read-only access arrangements work.
  • 4.At surveillance and renewal: no surveillance run was prevented by selective blocking of SecurityInspect's declared sources.
  • 5.At surveillance and renewal: every evidence request was answered within 10 business days or within an agreed extension.
  • 6.At surveillance and renewal: the month-6 surveillance review was completed within its window.
  • 7.At renewal: 12 months of evidence is available for the controls that rely on it.

Severity

High. Escalation to Critical applies only on the standard escalation triggers in the scoring model (§5.7). Refusing to cooperate with reassessment is a revocation trigger under the SIAS renewal, suspension and revocation rules.

Informative framework mappings

HIPAA Security Rule
§164.308(a)(8)
PCI DSS v4.0.1
No direct mapping
Trust Services Criteria
CC4.1
ISO/IEC 27001:2022
A.5.35
Theme (SecurityInspect wording)
supporting independent checks between assessments

SIAS-CMC-05 Accurate representation of certification and badge use

Mandatory
Yes
Severity
High
Applies
All scopes
SecurityInspect Verified profiles
VP-EXT, VP-APP, VP-CLD

Control objective

What the holder says about its SIAS result matches the verification record, so that no one is misled about what was assessed.

Testable requirement

  • 1.The applicant must accept the badge license (the badge license) as part of the certification agreement and follow the badge and mark policy.
  • 2.The applicant must not state or imply that it holds any SIAS level before SecurityInspect issues it, or after the certificate becomes Suspended, Expired, Revoked or Withdrawn.
  • 3.Every display of a SIAS badge must link to the certificate's verification page (https://securityinspect.com/verify/<certificate-id>), use unaltered artwork, and carry the defined alternative text: "SecurityInspect Certified — independently assessed against SIAS v1.0. Select to verify current status." Badges may appear only on the bound domains or in materials that identify the certified scope.
  • 4.Public statements must match the level and scope on the verification record. A SecurityInspect Verified result must not be presented as organizational certification. A SecurityInspect Reviewed result must not be presented as a pass. The certified scope must not be presented as covering other products, systems or legal entities.
  • 5.Statements about SIAS must not claim or imply that SIAS is equivalent to, endorsed by, or a substitute for HIPAA, PCI DSS, SOC 2 or the AICPA Trust Services Criteria, or ISO/IEC 27001, and must not describe the holder as secure, compliant or protected against breaches on the basis of its SIAS result. The full wording rules are in the SIAS claims rules.
  • 6.The applicant must name a person responsible for public statements about SIAS, and must have a review step for marketing, sales and proposal materials that mention SecurityInspect or SIAS.
  • 7.Misuse found by the holder or notified by SecurityInspect must be corrected within 10 business days.

Applicability and scope

All scopes (also in every SecurityInspect Verified profile). Cannot be marked not applicable. At the initial assessment it is tested as accepted license terms, a named responsible person, a review step, and the absence of premature claims; at surveillance and renewal, as actual use. SecurityInspect Verified profiles: VP-EXT, VP-APP and VP-CLD.

Pass criteria

  • 1.At every assessment: the badge license terms are accepted, a responsible person is named and the review step is documented.
  • 2.At the initial assessment: no claim of a SIAS level made before issuance is found.
  • 3.At surveillance and renewal: every badge display links to the correct verification page, uses unaltered artwork and carries the defined alternative text.
  • 4.At surveillance and renewal: no statement misrepresents the level, the scope or the relationship between SIAS and any framework.
  • 5.At surveillance and renewal: every misuse notified during the period was corrected within 10 business days.

Severity

High. Escalation to Critical applies only on the standard escalation triggers in the scoring model (§5.7). Deliberate misrepresentation, and use of a badge after suspension, expiry, revocation or withdrawal, are badge misuse under the SIAS renewal, suspension and revocation rules (a suspension or revocation trigger), in addition to any finding under this control.

Informative framework mappings

HIPAA Security Rule
No direct mapping
PCI DSS v4.0.1
No direct mapping
Trust Services Criteria
CC2.3
ISO/IEC 27001:2022
No direct mapping. This is a SIAS program rule with no framework counterpart
Theme (SecurityInspect wording)
honest statements about the SIAS result

Framework mappings in this domain

The mappings above are informative cross-references by identifier only. They don’t reproduce any framework’s text, and meeting a SIAS control doesn’t mean any framework requirement is met.

What framework mappings mean

SecurityInspect certification is a proprietary, scope-limited assessment against the SecurityInspect Assurance Standard. Framework mappings indicate thematic alignment only. Certification does not constitute an HHS-recognized HIPAA certification, PCI DSS validation, a SOC 2 examination or report, or accredited ISO/IEC 27001 certification.

How SIAS relates to other security frameworks

Where our work stops

Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.

Talk to us about a SIAS assessment

Tell us what you want assessed, and we’ll start with the scope.