SIAS-GOV-01 Security ownership and accountability
- Mandatory
- Yes
- Severity
- High
- Applies
- All scopes
- SecurityInspect Verified profiles
- None
Control objective
One named person is accountable for the security of the stated scope, and an officer of the applicant has the authority and resources to act on what that person reports, so that security decisions have an owner and do not fall between roles.
Testable requirement
- (a)The applicant shall designate in writing one named individual as security owner for the stated scope, with a role description that sets out responsibilities, the authority to escalate directly to the accountable executive, and a named deputy or documented backup arrangement for absences.
- (b)The applicant shall designate in writing an accountable executive, who is an officer or member of senior management of the applicant legal entity, approves the security policy set and accepts residual risk.
- (c)The applicant shall assign a named owner to each SIAS domain that applies to the scope. One person may own several domains.
- (d)The security owner shall report security status to the accountable executive at least every six months. Each report shall cover open risks, significant incidents, remediation progress and control exceptions, and the report and any decisions taken shall be recorded.
- (e)The applicant shall reconfirm these assignments at least every 12 months and within 30 days of a change in the security owner, the deputy or the accountable executive.
- (f)Where the security owner function is outsourced, the applicant shall keep the accountable executive role in-house and shall define the provider's responsibilities and availability in a contract. The security owner shall not be an employee or contractor of SecurityInspect (see the SIAS independence and impartiality rules).
Applicability and scope
All scopes. It cannot be marked not applicable. SecurityInspect Verified profiles: not included. It applies to the legal entity named in the scope declaration. Where a parent company runs security governance, the applicant must show in writing how the parent's arrangements bind the in-scope entity.
Pass criteria
- 1.A current written designation names one security owner, a deputy or documented backup arrangement, and an accountable executive who is an officer or senior manager of the applicant legal entity (E1).
- 2.Each named person is active in the directory extract (A1) and confirmed the role in interview (I1, I2).
- 3.Every applicable SIAS domain has a named owner (A3, M2).
- 4.At least one status report covering all four required topics was made to the accountable executive in the last six months, and, for renewal, one in every six-month period of the look-back (E4, A2, M3).
- 5.The assignments were reconfirmed within the last 12 months and after every change of role holder (A2).
- 6.The security owner is not an employee or contractor of SecurityInspect.
Severity
High. Standard escalation triggers apply; none is specific to this control. A finding that no one holds the security owner role is recorded at High and cannot be lowered.
Informative framework mappings
- HIPAA Security Rule
- §164.308(a)(2)
- PCI DSS v4.0.1
- 12.1, 12.4
- Trust Services Criteria
- CC1.3, CC1.5
- ISO/IEC 27001:2022
- 5.3; A.5.2, A.5.4
- Theme (SecurityInspect wording)
- named security owner with executive accountability
SIAS-GOV-02 Information security policy set
- Mandatory
- Yes
- Severity
- Medium
- Applies
- All scopes
- SecurityInspect Verified profiles
- None
Control objective
The applicant's security rules are written, approved by leadership, kept current, known to the people who must follow them and supported by working procedures.
Testable requirement
- (a)The applicant shall maintain a written set of information security policies, approved by the accountable executive, that covers at least: acceptable use; access control and authentication; data classification and handling; encryption and key management; secure development and change management; vulnerability and patch management; logging and monitoring; incident response; backup and business continuity; supplier security; workforce security; physical security; and privacy-related security safeguards. The set may be one document or several. A topic that does not apply to the scope shall be marked with the reason.
- (b)Each policy shall show an owner, a version, an approval date and a next review date.
- (c)The applicant shall review each policy at least every 12 months and after any material change, and shall record the review even when nothing changes.
- (d)The applicant shall make the policies available to every workforce member and contractor with access to in-scope systems or data, and shall obtain their acknowledgment at onboarding and after each material revision.
- (e)The applicant shall maintain documented operating procedures for the recurring security tasks its policies rely on, including at least user provisioning and deprovisioning, patching, backup and incident handling.
- (f)The applicant shall record each policy exception with its owner, rationale, approver and expiry date.
- (g)The applicant shall retain superseded policy versions for at least 6 years.
Applicability and scope
All scopes. It cannot be marked not applicable. SecurityInspect Verified profiles: not included.
Pass criteria
- 1.The policy set covers every minimum topic in requirement (a), or records a reason for each topic marked not applicable (A1, M1).
- 2.Every policy has an owner, a version and approval by the accountable executive, and was approved or reviewed in the last 12 months (A2, M2).
- 3.At least 95% of in-scope workforce members have a current acknowledgment (A3), every sampled member has one or joined within the last 30 days (M3), and every gap has a dated follow-up.
- 4.Each procedure named in requirement (e) exists, and the sampled execution followed it (M4).
- 5.No policy exception is open past its expiry date, and each has an approver (A4, M5).
- 6.Each interviewed workforce member located the policy set (I2, E6).
Severity
Medium. Standard escalation triggers apply; none is specific to this control.
Informative framework mappings
- HIPAA Security Rule
- §164.316(a), §164.316(b)(2)(iii)
- PCI DSS v4.0.1
- 12.1
- Trust Services Criteria
- CC2.2, CC5.3
- ISO/IEC 27001:2022
- 5.2; A.5.1, A.5.37
- Theme (SecurityInspect wording)
- approved, reviewed and communicated security policies
SIAS-GOV-03 System description and scope boundary
- Mandatory
- Yes
- Severity
- High
- Applies
- All scopes
- SecurityInspect Verified profiles
- VP-EXT, VP-APP, VP-CLD
Control objective
The scope that appears on a certificate is exactly the scope that was assessed. Nothing that can affect its security is left out, and every exclusion is visible.
Testable requirement
- (a)The applicant shall maintain a current written system description of the stated scope that names: the legal entity; each website, product or system; the system components (applications, databases, cloud accounts, subscriptions or projects, networks, endpoint categories and SaaS administrative tenants); the environments (production, plus any non-production environment that holds in-scope data or can change production); the locations and hosting regions; the data types processed; the interfaces and external connections; the third parties that operate in-scope components; and each exclusion with its reason.
- (b)The applicant shall maintain a boundary diagram showing in-scope components, trust boundaries, internet entry points and connections to out-of-scope systems.
- (c)The applicant shall list every internet-facing domain, subdomain, IP range and service in scope, and shall demonstrate control of each domain to be bound to the certificate using the DNS method in the SIAS verification system.
- (d)The applicant shall bring into scope every supporting component that can administer, authenticate to, deploy to, back up or store data from the in-scope systems, including identity providers, build and deployment pipelines, administrative endpoints, backup systems and log platforms. An out-of-scope system connected to an in-scope system shall be either segmented, with the segmenting controls identified, or brought into scope.
- (e)The applicant shall update the system description within 30 days of a material change and review it at least every 12 months.
- (f)The authorized representative shall sign the scope declaration (the application and scope declaration), confirming that it is accurate and complete.
Applicability and scope
All scopes (also in every SecurityInspect Verified profile). It cannot be marked not applicable. SecurityInspect Verified profiles: VP-EXT, VP-APP, VP-CLD. In a SecurityInspect Verified assessment the description covers only the declared technical scope: the declared internet-facing assets (VP-EXT), the named application with its APIs, hosting and supporting components (VP-APP), or the named cloud tenants or accounts (VP-CLD). Requirement (d) applies to VP-APP and VP-CLD. For VP-EXT, the declared asset list must include every internet-facing asset under the bound domains and declared IP ranges.
Pass criteria
- 1.The signed scope declaration and the system description contain every element in requirements (a) to (c) (M1).
- 2.Every discrepancy from A1, A2 and A4 is classified with evidence, and no in-scope component remains undocumented at decision (M2).
- 3.Every supporting component under requirement (d) is in scope, and every claimed segmentation boundary is confirmed (M3, M4).
- 4.Every domain to be bound passed DNS verification (A3).
- 5.The legal entity name matches the state business registry (M6).
- 6.Each exclusion is specific and has a written reason (M5).
- 7.The description was reviewed in the last 12 months and, for renewal, updated within 30 days of each material change in the look-back.
Severity
High. A deliberate or material misstatement of scope is an integrity failure under gate G0: it ends the assessment without an outcome and is not scored as a finding. An unintentional discrepancy is a finding against this control. If an undeclared asset exposes sensitive data or credentials to unauthenticated parties, that exposure is also recorded as a Critical finding against the most specific control (for example SIAS-CLD-03).
Informative framework mappings
- HIPAA Security Rule
- No direct mapping
- PCI DSS v4.0.1
- 12.5
- Trust Services Criteria
- No direct mapping
- ISO/IEC 27001:2022
- 4.3
- Theme (SecurityInspect wording)
- documented, confirmed scope boundary
SIAS-GOV-04 Security obligations register
- Mandatory
- No
- Severity
- Medium
- Applies
- All scopes (SIAS checks that obligations are identified; it does not determine legal compliance)
- SecurityInspect Verified profiles
- None
Control objective
The applicant knows which legal, regulatory and contractual security obligations apply to the stated scope, has given each one an owner, and does not make public security statements that its controls do not support.
Testable requirement
- (a)The applicant shall maintain a register of the security and privacy-related security obligations that apply to the in-scope systems and data, such as U.S. federal and state laws, sector rules, customer contracts, business associate agreements, payment-card acquirer requirements and cyber insurance conditions. Each entry shall show the source, the obligation in the applicant's own summary, the owner, the controls that address it and the last review date.
- (b)The applicant shall record who identified the obligations (for example its counsel, compliance function or an outside adviser) and when.
- (c)The applicant shall review the register at least every 12 months, and also when it enters a new market or sector, adopts a new type of contractual security term, or learns of a relevant legal change.
- (d)The applicant shall record the security statements it makes publicly about the in-scope systems (for example a website security page or trust page) and shall keep each statement consistent with its implemented controls.
Applicability and scope
All scopes (SIAS checks that obligations are identified; it does not determine legal compliance). It cannot be marked not applicable. SecurityInspect Verified profiles: not included. SecurityInspect does not review privileged legal advice. It needs the register and a record that it was reviewed, not the content of counsel's advice.
Pass criteria
- 1.The register exists and every entry has the required fields (A1).
- 2.The register was reviewed in the last 12 months and the source of identification is recorded (E2).
- 3.For each data type and sector in the system description, the register lists the obligations identified or records who determined that none apply, and when (M1).
- 4.The security obligations of every sampled contract appear in the register (M2).
- 5.Every captured public security statement is supported by observed controls or was corrected before the decision (M3).
Severity
Medium. Standard escalation triggers apply; none is specific to this control.
Informative framework mappings
- HIPAA Security Rule
- No direct mapping
- PCI DSS v4.0.1
- No direct mapping
- Trust Services Criteria
- No direct mapping
- ISO/IEC 27001:2022
- 4.1, 4.2 (incl. Amd 1:2024); A.5.31
- Theme (SecurityInspect wording)
- obligations identified, owned and kept current. SIAS does not assess the climate-change considerations that Amendment 1:2024 added to clauses 4.1 and 4.2
SIAS-GOV-05 Management review and continual improvement
- Mandatory
- No
- Severity
- Medium
- Applies
- All scopes
- SecurityInspect Verified profiles
- None
Control objective
Leadership looks at how the security program is performing at planned intervals, and problems found from any source are corrected and checked, not just recorded.
Testable requirement
- (a)The applicant shall hold a documented management review of the security program for the stated scope at least every 12 months, attended by the accountable executive. It shall cover: the status of actions from earlier reviews; changes in obligations, threats and the environment; security measures (at least incidents, vulnerabilities past their deadline, open exceptions, access-review completion, backup-test results and training completion); results of internal and external assessments, including any SIAS findings; the status of the risk register; resource needs; and improvement opportunities.
- (b)The applicant shall record the decisions and actions from each review, each with an owner and a due date.
- (c)The applicant shall keep a corrective-action log for problems found from any source (internal reviews, incidents, exercises, customer assessments and SIAS assessments). Each item shall have an action, an owner, a due date and a record of how its effectiveness was checked, and items that arise from High or Critical issues shall also record the root cause.
- (d)The applicant shall have its compliance with its own security policies reviewed at least every 12 months by a person who does not operate the controls under review. That person may be a member of staff or an outside party. The SIAS assessment itself does not count as this review.
- (e)Actions more than 90 days overdue shall be escalated to the accountable executive, and the escalation recorded.
Applicability and scope
All scopes. It cannot be marked not applicable. SecurityInspect Verified profiles: not included. An initial applicant must hold at least one management review and one policy-compliance review before fieldwork starts.
Pass criteria
- 1.A management review attended by the accountable executive took place in the last 12 months and covered every required input, or recorded why one was unavailable (M1).
- 2.The review's decisions and actions are recorded with owners and due dates.
- 3.The corrective-action log exists, every High- or Critical-derived item has a root cause, and no action is more than 90 days overdue without a recorded escalation (A1, A3).
- 4.Each sampled action from the previous review is closed with its effectiveness checked, or is open with a current due date (M2).
- 5.A policy-compliance review was completed in the last 12 months by a person who does not operate the controls reviewed (M4).
- 6.The sampled measures match their source data, or each difference is explained (A2, M5).
Severity
Medium. Standard escalation triggers apply; none is specific to this control.
Informative framework mappings
- HIPAA Security Rule
- §164.308(a)(8)
- PCI DSS v4.0.1
- 12.4
- Trust Services Criteria
- CC4.1, CC4.2
- ISO/IEC 27001:2022
- 9.3, 10.1, 10.2; A.5.35, A.5.36
- Theme (SecurityInspect wording)
- periodic leadership review with tracked corrective action