SIAS-PRV-01 Personal information categories and security requirements
- Mandatory
- Yes
- Severity
- Medium
- Applies
- Conditional — the scope processes personal information
- SecurityInspect Verified profiles
- None
Control objective
The applicant knows what personal information the scope handles and has set security requirements for each category, so that protection matches sensitivity.
Testable requirement
- 1.The applicant shall maintain a record of the categories of personal information processed in the scope, recording for each: the individuals it concerns (for example customers, end users, patients or staff), the systems and data stores that hold it (linked to SIAS-DAT-02), its sources, the third parties that receive it and its retention period.
- 2.Each category shall be classified under SIAS-DAT-01, and the sensitive categories shall be classified as Confidential or Restricted.
- 3.For each classification applied to personal information, the applicant shall define minimum security requirements covering at least: encryption in transit and at rest; access restriction and logging; use in non-production environments (SIAS-DAT-04); retention and disposal (SIAS-DAT-03); and sharing with third parties.
- 4.The record shall be reviewed at least every 12 months and updated before a new category, system or recipient goes into use.
Applicability and scope
Conditional — the scope processes personal information. Marking it not applicable needs a quality-reviewer-approved rationale showing that no personal information, including account and log data, is processed in the scope. SecurityInspect Verified profiles: not part of VP-EXT, VP-APP or VP-CLD.
Pass criteria
- 1.The record exists with the fields in testable requirement 1 for every category (M1).
- 2.After investigation, A1 and A2 show no data store or collected field containing personal information that is absent from the record (M2).
- 3.Every sensitive category is classified as Confidential or Restricted (M3).
- 4.Security requirements covering every topic in testable requirement 3 exist for each classification, and the sampled categories' systems apply them (M4).
- 5.The record was reviewed within the 12 months before fieldwork (E4).
Severity
Medium. Mandatory escalation to Critical (§5.7): Restricted or sensitive personal information found exposed to unauthenticated parties during A1 or A2. The Critical finding is recorded against the control where the exposure occurs (for example SIAS-CLD-03 or SIAS-APP-04).
Informative framework mappings
- HIPAA Security Rule
- §164.306(a)
- PCI DSS v4.0.1
- No direct mapping
- Trust Services Criteria
- C1.1, P3 series
- ISO/IEC 27001:2022
- A.5.12, A.5.34
- Theme (SecurityInspect wording)
- known personal data with matched safeguards
SIAS-PRV-02 Restricted and logged access to personal information
- Mandatory
- Yes
- Severity
- High
- Applies
- Conditional — the scope processes personal information
- SecurityInspect Verified profiles
- None
Control objective
Only the people and services that need personal information can reach it, bulk access is controlled, and every workforce access to Restricted personal information can be traced to a person.
Testable requirement
- 1.Access to personal information in production shall be granted by role on a documented need and denied by default. Standing workforce access to Restricted personal information shall be limited to the roles listed in an approved access matrix.
- 2.Workforce access to Restricted personal information outside the normal application flow (for example direct database queries, data exports, or support tools that can display customer records) shall require an individual account, multi-factor authentication, and either time-limited approved access or a recorded business reason for each use.
- 3.Workforce and support-tool reads, exports, changes and deletions of Restricted personal information shall be logged with the user identity, time, the records or query scope and the action.
- 4.Exports or queries returning more records containing personal information than a documented threshold shall require prior approval or raise an alert that is reviewed within 1 business day.
- 5.Access logs for personal information shall be reviewed at least monthly for unusual access (for example access by departed users, access outside assigned customers or cases, and volume spikes), and each exception shall be investigated.
- 6.Access to personal information shall be included in the access reviews under SIAS-IAM-04.
Applicability and scope
Conditional — the scope processes personal information. Testable requirement 1 applies to all personal information; requirements 2 to 5 apply to Restricted personal information. SecurityInspect Verified profiles: not part of VP-EXT, VP-APP or VP-CLD.
Pass criteria
- 1.After review, A1 finds no access beyond the matrix, no shared account and no departed user with access.
- 2.Every sampled account has a documented need and approval (M2).
- 3.Every direct-access path requires multi-factor authentication and a time limit or recorded business reason (A4, M5).
- 4.Every access path tested in M3 logged the read and the export with the required fields.
- 5.Threshold controls on bulk exports work as documented (A3, E6).
- 6.A review is recorded for every month in the look-back period, with exceptions investigated (M4).
- 7.Access to personal information was included in the most recent SIAS-IAM-04 review.
Severity
High. Mandatory escalation to Critical (§5.7): personal information classified as Restricted, or credentials, exposed to unauthenticated parties.
Informative framework mappings
- HIPAA Security Rule
- §164.308(a)(4)(ii)(B), §164.312(a)(1), §164.312(b)
- PCI DSS v4.0.1
- 7.2, 10.2
- Trust Services Criteria
- CC6.1, CC6.3
- ISO/IEC 27001:2022
- A.5.34, A.8.3
- Theme (SecurityInspect wording)
- need-based, traceable access to personal data
SIAS-PRV-03 Tracking technologies and outbound data sharing match declared practices
- Mandatory
- No
- Severity
- Medium
- Applies
- Conditional — public websites or apps are in scope (tests technical behavior against the applicant's own published notice; not a legal-compliance determination)
- SecurityInspect Verified profiles
- None
Control objective
What in-scope websites and apps actually collect and send to third parties matches what the applicant says it does, and personal information does not leak to third parties through tags, pixels, URLs or recordings.
Testable requirement
- 1.The applicant shall keep an inventory of the tracking technologies used on in-scope public websites and apps (cookies, pixels, tags, software development kits, analytics and session-replay tools), recording the recipient, purpose, data sent and the consent or opt-out state under which each runs. This may be part of the SIAS-APP-05 script inventory.
- 2.The observed behavior of in-scope sites and apps shall match the applicant's published privacy notice and tracking disclosures: no recipient or category of tracking shall operate that the notice does not disclose.
- 3.Where the applicant's notice or consent tool states that users can refuse or opt out of certain tracking, or that browser opt-out preference signals (for example Global Privacy Control) are honored, the tags concerned shall not run, or shall run only in the stated restricted mode, once the user has refused, opted out or sent the signal.
- 4.Pages shall not send form-field values, search terms, email addresses, data from sensitive categories or health-related page context to third-party tracking recipients (in URLs, referrer headers, event parameters or session recordings) unless the notice discloses it and the applicant's own security requirements under SIAS-PRV-01 permit it.
- 5.Session-replay tools, where used, shall mask input fields by default and shall be excluded from pages that collect credentials, payment data or Restricted data.
- 6.New tracking technologies shall be authorized under SIAS-APP-05 and checked against the notice before they go live.
Applicability and scope
Conditional — public websites or apps are in scope (tests technical behavior against the applicant's own published notice; not a legal-compliance determination). SecurityInspect does not interpret legal requirements; it tests only the applicant's own statements. SecurityInspect Verified profiles: not part of VP-EXT, VP-APP or VP-CLD.
Pass criteria
- 1.The inventory covers every tracking technology observed in A1 (after M3).
- 2.No undisclosed recipient or tracking category is observed (A2, M2, M3).
- 3.In the refused, opted-out and signal states, no tag runs contrary to the notice (A1).
- 4.A3 finds no synthetic value from form fields or sensitive categories sent to a third-party tracking recipient, other than flows the notice discloses and SIAS-PRV-01 permits.
- 5.Session replay masks input fields and is excluded from sensitive pages (M4).
- 6.Every tracking technology added in the look-back period was authorized (M5).
Severity
Medium. Mandatory escalation to Critical (§5.7) where credentials, payment data or Restricted personal information are sent to a recipient that is not a disclosed, contracted recipient, which SIAS treats as exposure of sensitive data or credentials to unauthenticated parties.
Informative framework mappings
- HIPAA Security Rule
- No direct mapping
- PCI DSS v4.0.1
- 6.4, 11.6
- Trust Services Criteria
- P1 series, P6 series
- ISO/IEC 27001:2022
- A.5.14, A.5.34
- Theme (SecurityInspect wording)
- tracking behavior matches own disclosures
SIAS-PRV-04 Secure handling of privacy requests
- Mandatory
- No
- Severity
- Medium
- Applies
- Conditional — the applicant receives access, deletion or similar requests for in-scope personal information
- SecurityInspect Verified profiles
- None
Control objective
Requests from individuals to access, delete, correct or limit their personal information cannot be used to obtain or destroy someone else's data, and completed requests are carried out across every in-scope system concerned.
Testable requirement
- 1.The applicant shall document how it receives, verifies, fulfills and records privacy requests for in-scope personal information, including which systems each request type must reach.
- 2.Before disclosing, changing or deleting personal information, the applicant shall verify the requester's identity, or an authorized agent's authority, by a documented method for each request type and data category. Requests concerning Restricted personal information shall require either an authenticated account session with re-authentication, or a match on at least two items of information that are not publicly available.
- 3.Responses containing personal information shall be delivered through an encrypted channel limited to the verified requester (for example an authenticated download that expires within 7 days), not as unencrypted email attachments.
- 4.Deletion and correction shall be carried out in every system listed for the request type, including derived stores, and processors shall be notified where the applicant's contracts require it. Exceptions (for example legal holds, or backups that expire on schedule) shall be recorded.
- 5.Request records shall hold the request type, verification method, systems actioned, dates and outcome, and access to them shall be restricted in the same way as the personal information they concern.
- 6.Request intake forms and endpoints shall be protected against automated abuse (for example by rate limiting or a challenge) and shall not reveal whether an account exists.
Applicability and scope
Conditional — the applicant receives access, deletion or similar requests for in-scope personal information. SIAS assesses the security of the process only. It does not assess whether response times, exemptions or request types are legally sufficient. SecurityInspect Verified profiles: not part of VP-EXT, VP-APP or VP-CLD.
Pass criteria
- 1.The procedure documents every element in testable requirements 1 to 5 (M1).
- 2.The insufficiently verified test request was refused, and verification for Restricted personal information meets testable requirement 2 (M2).
- 3.Responses are delivered through an encrypted channel limited to the requester (M2, M4).
- 4.The test deletion removed the test identity's data from every listed system, with any exception recorded (M2).
- 5.Every sampled request record is complete (M3, A3).
- 6.Intake is protected against automated abuse and does not reveal account existence (A1).
Severity
Medium. Mandatory escalation to Critical (§5.7): a request process that discloses Restricted personal information to an unverified requester, which is exposure to an unauthenticated party.
Informative framework mappings
- HIPAA Security Rule
- No direct mapping
- PCI DSS v4.0.1
- No direct mapping
- Trust Services Criteria
- P5 series
- ISO/IEC 27001:2022
- A.5.34
- Theme (SecurityInspect wording)
- identity-checked, protected handling of individual requests
SIAS-PRV-05 Personal-information impact in incident handling
- Mandatory
- No
- Severity
- Medium
- Applies
- Conditional — the scope processes personal information
- SecurityInspect Verified profiles
- None
Control objective
When a security incident happens, the applicant can quickly establish whether personal information was involved, what kind and whose, and gets that information to the people who decide on notification.
Testable requirement
- 1.The incident response plan (SIAS-INC-01) shall include steps to establish whether personal information was accessed, acquired, changed, disclosed or made unavailable; which categories were involved (using the SIAS-PRV-01 record); how many individuals; and their states of residence where known.
- 2.The plan shall name who evaluates notification obligations (for example the applicant's counsel or privacy lead) and require escalation to that person within 24 hours of personal-information involvement being suspected.
- 3.The applicant shall be able to produce, from its logs and records, the list of affected individuals and records for a defined incident scenario, within 1 business day, and shall preserve the evidence used.
- 4.Incident records shall document the personal-information assessment, its conclusion and the date of escalation.
- 5.At least one incident response exercise every 12 months (SIAS-INC-02) shall include a scenario involving personal information.
Applicability and scope
Conditional — the scope processes personal information. SIAS checks that the capability and procedure exist and work. It does not decide whether any incident was notifiable or whether any notice met legal requirements (see SIAS-INC-04). SecurityInspect Verified profiles: not part of VP-EXT, VP-APP or VP-CLD.
Pass criteria
- 1.The plan includes the personal-information steps, a named evaluator and an escalation time (M1).
- 2.Every reviewed incident has a personal-information assessment, and every suspected involvement was escalated within 24 hours (M2, A1).
- 3.The scenario test produced an accurate list, including every SecurityInspect test event, within 1 business day (M3, A2).
- 4.An exercise with a personal-information scenario took place within the 12 months before fieldwork (M4).
Severity
Medium. No escalation trigger.
Informative framework mappings
- HIPAA Security Rule
- §164.308(a)(6)(ii)
- PCI DSS v4.0.1
- 12.10
- Trust Services Criteria
- CC7.4, P6 series
- ISO/IEC 27001:2022
- A.5.26, A.5.34
- Theme (SecurityInspect wording)
- incidents assessed for personal-data impact