SIAS-CRY-01 Encryption of data in transit
- Mandatory
- Yes
- Severity
- High
- Applies
- All scopes
- SecurityInspect Verified profiles
- VP-EXT, VP-APP
Control objective
Data moving to, from and within the in-scope environment is protected against interception and tampering, and no in-scope service falls back to cleartext for anything other than public content.
Testable requirement
- 1.Every in-scope service reachable from the internet that carries anything other than public content shall use TLS that conforms to the SIAS cryptographic baseline, and shall not accept any protocol or cipher suite the baseline lists as not acceptable.
- 2.Every in-scope HTTP service on the internet shall redirect cleartext HTTP to HTTPS or not listen for cleartext HTTP, and shall never serve an authenticated page, form, API response or credential over cleartext HTTP.
- 3.Every in-scope internet-facing website shall send a Strict-Transport-Security header with a max-age of at least 15552000 seconds (180 days) on its HTTPS responses.
- 4.Confidential or Restricted data (SIAS-DAT-01) crossing any network the applicant does not fully control (including links between cloud regions or providers, to third parties, and to or from workforce devices over the internet) shall be encrypted to the baseline. Where Restricted data crosses a network segment the applicant fully controls in cleartext, that link shall be recorded in the risk register with a treatment decision (SIAS-RSK-02).
- 5.Administrative and remote-access connections to in-scope systems (SSH, remote desktop, database clients, management interfaces and APIs) shall be encrypted. Telnet, FTP, SNMP v1 or v2c, and cleartext LDAP binds shall not be used for in-scope systems.
- 6.Production clients and services under the applicant's control shall validate TLS certificates and host names. Certificate validation shall not be disabled in production code or configuration.
Applicability and scope
All scopes; cannot be marked not applicable. SecurityInspect Verified profiles: VP-EXT (the declared internet-facing endpoints only: testable requirements 1 to 3 and the internet-reachable part of 5); VP-APP (the named application and its APIs, including its outbound connections to back-end services and third parties: testable requirements 1 to 4 and 6).
Pass criteria
- 1.A1 shows that every in-scope internet-facing endpoint carrying non-public content offers TLS 1.2 or 1.3 and no protocol or suite listed as not acceptable.
- 2.A2 shows no authenticated page, form, API response or credential served over cleartext HTTP, and every cleartext HTTP listener redirects to HTTPS.
- 3.A3 shows Strict-Transport-Security with a max-age of at least 15552000 seconds on every in-scope internet-facing website.
- 4.A4 shows no cleartext administrative or legacy protocol on an in-scope internet-facing address.
- 5.Every link crossing a network the applicant does not fully control is encrypted to the baseline (M2), and every sampled cleartext internal link carrying Restricted data has a recorded treatment decision (M3).
- 6.No production code or configuration disables certificate or host-name validation (M4), where source access is in scope.
Severity
High. Mandatory escalation to Critical (§5.7): credentials sent in cleartext over the internet; Restricted or sensitive data or credentials exposed to unauthenticated parties through a cleartext channel.
Informative framework mappings
- HIPAA Security Rule
- §164.312(e)(1), §164.312(e)(2)(ii)
- PCI DSS v4.0.1
- 4.2
- Trust Services Criteria
- CC6.7
- ISO/IEC 27001:2022
- A.5.14, A.8.24
- Theme (SecurityInspect wording)
- encryption for data moving between systems
SIAS-CRY-02 Encryption of sensitive data at rest
- Mandatory
- Yes
- Severity
- High
- Applies
- Conditional — the scope stores Confidential or Restricted data (as classified under SIAS-DAT-01)
- SecurityInspect Verified profiles
- VP-CLD
Control objective
Confidential and Restricted data stored in the scope stays unreadable if storage media, snapshots, backups, database files or devices are obtained without authorization.
Testable requirement
- 1.The applicant shall encrypt, to the SIAS cryptographic baseline, every in-scope data store that holds Confidential or Restricted data: databases, object storage, file shares, block volumes, snapshots, backups, message queues and search indexes.
- 2.Workforce laptops and removable media that may hold Confidential or Restricted data shall use full-disk or device encryption.
- 3.For each Restricted data element named in its classification (SIAS-DAT-01), the applicant shall document whether storage-layer encryption alone is sufficient, and shall apply field-level encryption, tokenization or another technique that keeps the element unreadable to administrators without separate key access wherever that documentation says it is required.
- 4.Encryption shall be on by default for new data stores (for example through an account-level default or an enforced policy), so that new stores do not start unencrypted.
- 5.Keys shall be managed under SIAS-CRY-03 and shall not be stored in cleartext alongside the data they protect.
Applicability and scope
Conditional — the scope stores Confidential or Restricted data (as classified under SIAS-DAT-01). Marking it not applicable needs a written rationale, approved by the quality reviewer, supported by the SIAS-DAT-02 data map showing that no such data is stored in the scope. SecurityInspect Verified profiles: VP-CLD (data stores in the named tenants or accounts; testable requirement 2 is excluded).
Pass criteria
- 1.Every in-scope data store holding Confidential or Restricted data is encrypted to the baseline (A1, A2, M2).
- 2.A4 reports no active in-scope device without disk encryption, other than devices enrolled within the last 7 days that are pending encryption, and every sampled device is encrypted (M4).
- 3.Field-level decisions are documented for every Restricted data element, and every element that requires field-level protection is unreadable to the administrative role tested (M3).
- 4.Default encryption for new stores is enforced (A3, E5).
- 5.No key material is stored in cleartext with the data it protects (M5).
Severity
High. Mandatory escalation to Critical (§5.7): Restricted or sensitive data exposed to unauthenticated parties (for example an unencrypted, publicly readable snapshot or backup). Such exposure is also recorded under SIAS-CLD-03.
Informative framework mappings
- HIPAA Security Rule
- §164.312(a)(2)(iv)
- PCI DSS v4.0.1
- 3.5
- Trust Services Criteria
- CC6.1
- ISO/IEC 27001:2022
- A.8.24
- Theme (SecurityInspect wording)
- stored sensitive data unreadable without keys
SIAS-CRY-03 Cryptographic key and secret management
- Mandatory
- Yes
- Severity
- High
- Applies
- All scopes
- SecurityInspect Verified profiles
- VP-APP, VP-CLD
Control objective
Encryption keys, API keys, tokens, service passwords and other machine secrets are generated, stored, used, rotated and revoked so that obtaining source code, images, logs or backups does not give access to systems or data.
Testable requirement
- 1.The applicant shall hold production cryptographic keys and machine secrets in a dedicated key management service, hardware security module or secrets manager. They shall not be stored in source code, container images, infrastructure-as-code templates, client-side code, unencrypted configuration files, tickets, chat messages or logs.
- 2.Access to keys and secrets shall be limited to the named roles and workloads that need them. Where the platform allows, the ability to manage keys (create, change policy, disable, delete or export) shall be held separately from the ability to use them. Every key-management action shall be logged (SIAS-LOG-01).
- 3.The applicant shall keep an inventory of keys and machine secrets for the scope, recording purpose, owner, location, algorithm or type, creation date and rotation schedule.
- 4.Customer-managed encryption keys shall be rotated at least every 12 months, using automatic rotation where the service supports it. Machine secrets and API keys shall be rotated at least every 12 months or replaced by short-lived credentials issued at run time. A key or secret shall be rotated or revoked after a suspected exposure within 24 hours of discovery where it was in a location that is or was publicly accessible, and otherwise within 1 business day (the same in SIAS-SDC-06 and SIAS-IAM-06), and within 7 days after a person who could read it leaves or changes role.
- 5.Where the platform supports it, deleting or disabling a key that protects backups or Restricted data shall require a waiting period or the approval of a second authorized person.
- 6.The applicant shall scan source repositories and build pipelines for committed secrets (as in SIAS-SDC-06 requirement 3 and SIAS-IAM-06 requirement 6) and treat every confirmed exposed secret as compromised. Committed secrets are scored under SIAS-SDC-06 or SIAS-IAM-06 where either is assessed, and under this control only where neither is (§2.11).
Applicability and scope
All scopes; cannot be marked not applicable (every scope uses at least TLS keys or service credentials). SecurityInspect Verified profiles: VP-APP (secrets used by or embedded in the named application, its repositories and its deployment pipeline); VP-CLD (keys and secrets in the named tenants or accounts).
Pass criteria
- 1.A3 finds no valid secret in public web assets or supplied mobile application packages, and every exposed secret found there has been revoked or rotated (M4). Secrets that A2 finds in repositories, images or build logs are scored here only where neither SIAS-SDC-06 nor SIAS-IAM-06 is assessed (§2.11); otherwise A2 results are used here only for M2 and M4.
- 2.Every sampled production key and secret is held in a managed store (M2).
- 3.A1 shows every customer-managed key and machine secret rotated within its schedule, or short-lived credentials in use.
- 4.No sampled key policy gives management and use to the same principal where the platform supports separation (other than a documented break-glass account), and none grants access to wildcard or unknown external principals (A1, M3).
- 5.Key-management actions are logged (E4).
- 6.Deletion protection is enabled for every key protecting backups or Restricted data, where the platform supports it (A1).
- 7.The inventory contains the required fields for every key in E1, and leaver rotations were completed on time (M5).
Severity
High. Mandatory escalation to Critical (§5.7): a valid secret that grants access to production systems, Restricted data or key management found in a place open to unauthenticated parties (for example a public repository, client-side code or a publicly readable storage location).
Informative framework mappings
- HIPAA Security Rule
- §164.312(a)(2)(iv)
- PCI DSS v4.0.1
- 3.6, 3.7
- Trust Services Criteria
- CC6.1
- ISO/IEC 27001:2022
- A.8.24
- Theme (SecurityInspect wording)
- controlled lifecycle for keys and secrets
SIAS-CRY-04 Certificate and algorithm lifecycle
- Mandatory
- No
- Severity
- Medium
- Applies
- All scopes
- SecurityInspect Verified profiles
- VP-EXT
Control objective
TLS certificates in the scope stay valid and trusted, and the applicant can find and replace weak or deprecated algorithms before they fail or become unsafe.
Testable requirement
- 1.The applicant shall keep an inventory of the TLS certificates used by in-scope services, recording host names, issuer, expiry date, key type and size, owner and renewal method.
- 2.Certificates on in-scope internet-facing services shall be issued by a publicly trusted certificate authority, match the host names served and present a complete chain.
- 3.Renewal shall be automated, or alerts shall notify a named owner at least 30 days before expiry.
- 4.No in-scope service shall present an expired certificate, a certificate signed with MD5 or SHA-1, or an RSA key shorter than 2048 bits.
- 5.In-scope domains should publish CAA records restricting issuance to the certificate authorities the applicant uses.
- 6.The applicant shall keep a cryptographic inventory of the algorithms and protocols used to protect in-scope data (transport, at rest, signing and hashing) and review it against the SIAS cryptographic baseline and current deprecation guidance at least every 12 months, recording planned replacements. The review should record the applicant's approach to post-quantum migration for Confidential or Restricted data that must stay confidential for many years.
Applicability and scope
All scopes; cannot be marked not applicable. SecurityInspect Verified profiles: VP-EXT (testable requirements 2 to 5 for the declared internet-facing endpoints; testable requirements 1 and 6 are checked only for those endpoints).
Pass criteria
- 1.A1 finds no expired, untrusted, host-name-mismatched or weak certificate on any in-scope service (testable requirements 2 and 4).
- 2.The inventory covers every certificate found by A1 and every current certificate for in-scope host names found by A3, or each missing one is explained (M2).
- 3.Automated renewal or 30-day expiry alerting is shown for every certificate (M3).
- 4.The cryptographic inventory was reviewed within the 12 months before fieldwork (M4).
Severity
Medium. Mandatory escalation to Critical (§5.7) where M2 shows that a certificate for an in-scope domain was obtained by an unauthorized party and indicates active compromise (for example a domain or subdomain takeover).
Informative framework mappings
- HIPAA Security Rule
- §164.312(e)(2)(ii)
- PCI DSS v4.0.1
- 4.2
- Trust Services Criteria
- CC6.7
- ISO/IEC 27001:2022
- A.8.24
- Theme (SecurityInspect wording)
- valid certificates and current algorithms maintained