Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

SIAS v1.0 · Domain 1 of 19

GOV: Governance and security ownership

This domain checks that someone specific owns security for the stated scope, that the rules are written down and current, that the scope itself is described accurately, that the applicant knows which security obligations apply to it, and that leadership reviews the program and fixes what it finds. It has 5 controls, 3 of them mandatory. SIAS-GOV-03 is in every SecurityInspect Verified profile and is a precondition for any decision (gate G0).

Controls in this domain

5 controls, 3 of them mandatory.

Controls in the GOV domain
ControlTitleMandatorySeverityApplies
SIAS-GOV-01Security ownership and accountabilityYesHighAll scopes
SIAS-GOV-02Information security policy setYesMediumAll scopes
SIAS-GOV-03System description and scope boundaryYesHighAll scopes
SIAS-GOV-04Security obligations registerNoMediumAll scopes (SIAS checks that obligations are identified; it does not determine legal compliance)
SIAS-GOV-05Management review and continual improvementNoMediumAll scopes

SIAS-GOV-01 Security ownership and accountability

Mandatory
Yes
Severity
High
Applies
All scopes
SecurityInspect Verified profiles
None

Control objective

One named person is accountable for the security of the stated scope, and an officer of the applicant has the authority and resources to act on what that person reports, so that security decisions have an owner and do not fall between roles.

Testable requirement

  • (a)The applicant shall designate in writing one named individual as security owner for the stated scope, with a role description that sets out responsibilities, the authority to escalate directly to the accountable executive, and a named deputy or documented backup arrangement for absences.
  • (b)The applicant shall designate in writing an accountable executive, who is an officer or member of senior management of the applicant legal entity, approves the security policy set and accepts residual risk.
  • (c)The applicant shall assign a named owner to each SIAS domain that applies to the scope. One person may own several domains.
  • (d)The security owner shall report security status to the accountable executive at least every six months. Each report shall cover open risks, significant incidents, remediation progress and control exceptions, and the report and any decisions taken shall be recorded.
  • (e)The applicant shall reconfirm these assignments at least every 12 months and within 30 days of a change in the security owner, the deputy or the accountable executive.
  • (f)Where the security owner function is outsourced, the applicant shall keep the accountable executive role in-house and shall define the provider's responsibilities and availability in a contract. The security owner shall not be an employee or contractor of SecurityInspect (see the SIAS independence and impartiality rules).

Applicability and scope

All scopes. It cannot be marked not applicable. SecurityInspect Verified profiles: not included. It applies to the legal entity named in the scope declaration. Where a parent company runs security governance, the applicant must show in writing how the parent's arrangements bind the in-scope entity.

Pass criteria

  • 1.A current written designation names one security owner, a deputy or documented backup arrangement, and an accountable executive who is an officer or senior manager of the applicant legal entity (E1).
  • 2.Each named person is active in the directory extract (A1) and confirmed the role in interview (I1, I2).
  • 3.Every applicable SIAS domain has a named owner (A3, M2).
  • 4.At least one status report covering all four required topics was made to the accountable executive in the last six months, and, for renewal, one in every six-month period of the look-back (E4, A2, M3).
  • 5.The assignments were reconfirmed within the last 12 months and after every change of role holder (A2).
  • 6.The security owner is not an employee or contractor of SecurityInspect.

Severity

High. Standard escalation triggers apply; none is specific to this control. A finding that no one holds the security owner role is recorded at High and cannot be lowered.

Informative framework mappings

HIPAA Security Rule
§164.308(a)(2)
PCI DSS v4.0.1
12.1, 12.4
Trust Services Criteria
CC1.3, CC1.5
ISO/IEC 27001:2022
5.3; A.5.2, A.5.4
Theme (SecurityInspect wording)
named security owner with executive accountability

SIAS-GOV-02 Information security policy set

Mandatory
Yes
Severity
Medium
Applies
All scopes
SecurityInspect Verified profiles
None

Control objective

The applicant's security rules are written, approved by leadership, kept current, known to the people who must follow them and supported by working procedures.

Testable requirement

  • (a)The applicant shall maintain a written set of information security policies, approved by the accountable executive, that covers at least: acceptable use; access control and authentication; data classification and handling; encryption and key management; secure development and change management; vulnerability and patch management; logging and monitoring; incident response; backup and business continuity; supplier security; workforce security; physical security; and privacy-related security safeguards. The set may be one document or several. A topic that does not apply to the scope shall be marked with the reason.
  • (b)Each policy shall show an owner, a version, an approval date and a next review date.
  • (c)The applicant shall review each policy at least every 12 months and after any material change, and shall record the review even when nothing changes.
  • (d)The applicant shall make the policies available to every workforce member and contractor with access to in-scope systems or data, and shall obtain their acknowledgment at onboarding and after each material revision.
  • (e)The applicant shall maintain documented operating procedures for the recurring security tasks its policies rely on, including at least user provisioning and deprovisioning, patching, backup and incident handling.
  • (f)The applicant shall record each policy exception with its owner, rationale, approver and expiry date.
  • (g)The applicant shall retain superseded policy versions for at least 6 years.

Applicability and scope

All scopes. It cannot be marked not applicable. SecurityInspect Verified profiles: not included.

Pass criteria

  • 1.The policy set covers every minimum topic in requirement (a), or records a reason for each topic marked not applicable (A1, M1).
  • 2.Every policy has an owner, a version and approval by the accountable executive, and was approved or reviewed in the last 12 months (A2, M2).
  • 3.At least 95% of in-scope workforce members have a current acknowledgment (A3), every sampled member has one or joined within the last 30 days (M3), and every gap has a dated follow-up.
  • 4.Each procedure named in requirement (e) exists, and the sampled execution followed it (M4).
  • 5.No policy exception is open past its expiry date, and each has an approver (A4, M5).
  • 6.Each interviewed workforce member located the policy set (I2, E6).

Severity

Medium. Standard escalation triggers apply; none is specific to this control.

Informative framework mappings

HIPAA Security Rule
§164.316(a), §164.316(b)(2)(iii)
PCI DSS v4.0.1
12.1
Trust Services Criteria
CC2.2, CC5.3
ISO/IEC 27001:2022
5.2; A.5.1, A.5.37
Theme (SecurityInspect wording)
approved, reviewed and communicated security policies

SIAS-GOV-03 System description and scope boundary

Mandatory
Yes
Severity
High
Applies
All scopes
SecurityInspect Verified profiles
VP-EXT, VP-APP, VP-CLD

Control objective

The scope that appears on a certificate is exactly the scope that was assessed. Nothing that can affect its security is left out, and every exclusion is visible.

Testable requirement

  • (a)The applicant shall maintain a current written system description of the stated scope that names: the legal entity; each website, product or system; the system components (applications, databases, cloud accounts, subscriptions or projects, networks, endpoint categories and SaaS administrative tenants); the environments (production, plus any non-production environment that holds in-scope data or can change production); the locations and hosting regions; the data types processed; the interfaces and external connections; the third parties that operate in-scope components; and each exclusion with its reason.
  • (b)The applicant shall maintain a boundary diagram showing in-scope components, trust boundaries, internet entry points and connections to out-of-scope systems.
  • (c)The applicant shall list every internet-facing domain, subdomain, IP range and service in scope, and shall demonstrate control of each domain to be bound to the certificate using the DNS method in the SIAS verification system.
  • (d)The applicant shall bring into scope every supporting component that can administer, authenticate to, deploy to, back up or store data from the in-scope systems, including identity providers, build and deployment pipelines, administrative endpoints, backup systems and log platforms. An out-of-scope system connected to an in-scope system shall be either segmented, with the segmenting controls identified, or brought into scope.
  • (e)The applicant shall update the system description within 30 days of a material change and review it at least every 12 months.
  • (f)The authorized representative shall sign the scope declaration (the application and scope declaration), confirming that it is accurate and complete.

Applicability and scope

All scopes (also in every SecurityInspect Verified profile). It cannot be marked not applicable. SecurityInspect Verified profiles: VP-EXT, VP-APP, VP-CLD. In a SecurityInspect Verified assessment the description covers only the declared technical scope: the declared internet-facing assets (VP-EXT), the named application with its APIs, hosting and supporting components (VP-APP), or the named cloud tenants or accounts (VP-CLD). Requirement (d) applies to VP-APP and VP-CLD. For VP-EXT, the declared asset list must include every internet-facing asset under the bound domains and declared IP ranges.

Pass criteria

  • 1.The signed scope declaration and the system description contain every element in requirements (a) to (c) (M1).
  • 2.Every discrepancy from A1, A2 and A4 is classified with evidence, and no in-scope component remains undocumented at decision (M2).
  • 3.Every supporting component under requirement (d) is in scope, and every claimed segmentation boundary is confirmed (M3, M4).
  • 4.Every domain to be bound passed DNS verification (A3).
  • 5.The legal entity name matches the state business registry (M6).
  • 6.Each exclusion is specific and has a written reason (M5).
  • 7.The description was reviewed in the last 12 months and, for renewal, updated within 30 days of each material change in the look-back.

Severity

High. A deliberate or material misstatement of scope is an integrity failure under gate G0: it ends the assessment without an outcome and is not scored as a finding. An unintentional discrepancy is a finding against this control. If an undeclared asset exposes sensitive data or credentials to unauthenticated parties, that exposure is also recorded as a Critical finding against the most specific control (for example SIAS-CLD-03).

Informative framework mappings

HIPAA Security Rule
No direct mapping
PCI DSS v4.0.1
12.5
Trust Services Criteria
No direct mapping
ISO/IEC 27001:2022
4.3
Theme (SecurityInspect wording)
documented, confirmed scope boundary

SIAS-GOV-04 Security obligations register

Mandatory
No
Severity
Medium
Applies
All scopes (SIAS checks that obligations are identified; it does not determine legal compliance)
SecurityInspect Verified profiles
None

Control objective

The applicant knows which legal, regulatory and contractual security obligations apply to the stated scope, has given each one an owner, and does not make public security statements that its controls do not support.

Testable requirement

  • (a)The applicant shall maintain a register of the security and privacy-related security obligations that apply to the in-scope systems and data, such as U.S. federal and state laws, sector rules, customer contracts, business associate agreements, payment-card acquirer requirements and cyber insurance conditions. Each entry shall show the source, the obligation in the applicant's own summary, the owner, the controls that address it and the last review date.
  • (b)The applicant shall record who identified the obligations (for example its counsel, compliance function or an outside adviser) and when.
  • (c)The applicant shall review the register at least every 12 months, and also when it enters a new market or sector, adopts a new type of contractual security term, or learns of a relevant legal change.
  • (d)The applicant shall record the security statements it makes publicly about the in-scope systems (for example a website security page or trust page) and shall keep each statement consistent with its implemented controls.

Applicability and scope

All scopes (SIAS checks that obligations are identified; it does not determine legal compliance). It cannot be marked not applicable. SecurityInspect Verified profiles: not included. SecurityInspect does not review privileged legal advice. It needs the register and a record that it was reviewed, not the content of counsel's advice.

Pass criteria

  • 1.The register exists and every entry has the required fields (A1).
  • 2.The register was reviewed in the last 12 months and the source of identification is recorded (E2).
  • 3.For each data type and sector in the system description, the register lists the obligations identified or records who determined that none apply, and when (M1).
  • 4.The security obligations of every sampled contract appear in the register (M2).
  • 5.Every captured public security statement is supported by observed controls or was corrected before the decision (M3).

Severity

Medium. Standard escalation triggers apply; none is specific to this control.

Informative framework mappings

HIPAA Security Rule
No direct mapping
PCI DSS v4.0.1
No direct mapping
Trust Services Criteria
No direct mapping
ISO/IEC 27001:2022
4.1, 4.2 (incl. Amd 1:2024); A.5.31
Theme (SecurityInspect wording)
obligations identified, owned and kept current. SIAS does not assess the climate-change considerations that Amendment 1:2024 added to clauses 4.1 and 4.2

SIAS-GOV-05 Management review and continual improvement

Mandatory
No
Severity
Medium
Applies
All scopes
SecurityInspect Verified profiles
None

Control objective

Leadership looks at how the security program is performing at planned intervals, and problems found from any source are corrected and checked, not just recorded.

Testable requirement

  • (a)The applicant shall hold a documented management review of the security program for the stated scope at least every 12 months, attended by the accountable executive. It shall cover: the status of actions from earlier reviews; changes in obligations, threats and the environment; security measures (at least incidents, vulnerabilities past their deadline, open exceptions, access-review completion, backup-test results and training completion); results of internal and external assessments, including any SIAS findings; the status of the risk register; resource needs; and improvement opportunities.
  • (b)The applicant shall record the decisions and actions from each review, each with an owner and a due date.
  • (c)The applicant shall keep a corrective-action log for problems found from any source (internal reviews, incidents, exercises, customer assessments and SIAS assessments). Each item shall have an action, an owner, a due date and a record of how its effectiveness was checked, and items that arise from High or Critical issues shall also record the root cause.
  • (d)The applicant shall have its compliance with its own security policies reviewed at least every 12 months by a person who does not operate the controls under review. That person may be a member of staff or an outside party. The SIAS assessment itself does not count as this review.
  • (e)Actions more than 90 days overdue shall be escalated to the accountable executive, and the escalation recorded.

Applicability and scope

All scopes. It cannot be marked not applicable. SecurityInspect Verified profiles: not included. An initial applicant must hold at least one management review and one policy-compliance review before fieldwork starts.

Pass criteria

  • 1.A management review attended by the accountable executive took place in the last 12 months and covered every required input, or recorded why one was unavailable (M1).
  • 2.The review's decisions and actions are recorded with owners and due dates.
  • 3.The corrective-action log exists, every High- or Critical-derived item has a root cause, and no action is more than 90 days overdue without a recorded escalation (A1, A3).
  • 4.Each sampled action from the previous review is closed with its effectiveness checked, or is open with a current due date (M2).
  • 5.A policy-compliance review was completed in the last 12 months by a person who does not operate the controls reviewed (M4).
  • 6.The sampled measures match their source data, or each difference is explained (A2, M5).

Severity

Medium. Standard escalation triggers apply; none is specific to this control.

Informative framework mappings

HIPAA Security Rule
§164.308(a)(8)
PCI DSS v4.0.1
12.4
Trust Services Criteria
CC4.1, CC4.2
ISO/IEC 27001:2022
9.3, 10.1, 10.2; A.5.35, A.5.36
Theme (SecurityInspect wording)
periodic leadership review with tracked corrective action

Framework mappings in this domain

The mappings above are informative cross-references by identifier only. They don’t reproduce any framework’s text, and meeting a SIAS control doesn’t mean any framework requirement is met.

What framework mappings mean

SecurityInspect certification is a proprietary, scope-limited assessment against the SecurityInspect Assurance Standard. Framework mappings indicate thematic alignment only. Certification does not constitute an HHS-recognized HIPAA certification, PCI DSS validation, a SOC 2 examination or report, or accredited ISO/IEC 27001 certification.

How SIAS relates to other security frameworks

Where our work stops

Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.

Talk to us about a SIAS assessment

Tell us what you want assessed, and we’ll start with the scope.