SIAS-VPM-01 Vulnerability identification and scanning
- Mandatory
- Yes
- Severity
- High
- Applies
- All scopes
- SecurityInspect Verified profiles
- VP-EXT, VP-APP
Control objective
Vulnerabilities in in-scope assets are found soon after they appear, and no in-scope asset stays outside the applicant's view for long.
Testable requirement
- The applicant must:
- 1.scan every internet-facing in-scope asset from outside at least monthly, and after any significant change to it;
- 2.scan internal in-scope hosts, including cloud workloads, with authenticated (credentialed) scans at least monthly wherever the asset supports them;
- 3.scan the software dependencies and container images of in-scope applications at build time, and scan deployed images at least monthly;
- 4.keep scanner vulnerability content up to date, updated before each scheduled scan or automatically;
- 5.cover 100% of internet-facing in-scope assets and at least 95% of other in-scope assets in the inventory (SIAS-AST-01) in each cycle, reconciling scan targets with the inventory and recording why any asset was not scanned;
- 6.monitor supplier security advisories and the CISA KEV catalog for in-scope technologies that scanners cannot assess (for example network appliances and managed services);
- 7.record every identified vulnerability in a tracking system with the asset, an identifier (a CVE ID or another identifier), the rating, the first-detected date and an owner.
Applicability and scope
All scopes. SecurityInspect Verified profiles: VP-EXT (requirements 1 and 4–7 for the declared internet-facing domains, addresses and services); VP-APP (requirements 3, 4, 6 and 7 for the named application, its dependencies and its hosting, plus requirement 1 for its internet-facing endpoints).
Pass criteria
- 1.Every internet-facing in-scope asset was scanned externally at the required cadence throughout the look-back period, and after each significant change.
- 2.Authenticated internal scans ran at the required cadence on every asset that supports them.
- 3.Dependencies and images were scanned at build time, and deployed images at least monthly.
- 4.The most recent cycle met the coverage thresholds in requirement 5, and no internet-facing asset went unscanned for more than one cycle in the look-back period.
- 5.A3 found no High or Critical vulnerability missing from the applicant's records where both the vulnerability and the asset were known before the applicant's last scan.
- 6.Scanner content was current at each scan.
- 7.Every sampled tracker entry has the required fields.
Severity
High. A KEV-listed vulnerability on an internet-facing asset found during this testing is recorded as a Critical finding under SIAS-VPM-02.
Informative framework mappings
- HIPAA Security Rule
- No direct mapping
- PCI DSS v4.0.1
- 6.3, 11.3
- Trust Services Criteria
- CC7.1
- ISO/IEC 27001:2022
- A.8.8
- Theme (SecurityInspect wording)
- finding technical vulnerabilities regularly
SIAS-VPM-02 Risk-based remediation within defined timelines
- Mandatory
- Yes
- Severity
- Critical
- Applies
- All scopes
- SecurityInspect Verified profiles
- VP-EXT, VP-APP
Control objective
Known vulnerabilities are fixed or mitigated in order of risk, within time limits short enough to close likely attack paths.
Testable requirement
- The applicant must:
- 1.rate each vulnerability with a documented method that starts from the CVSS base score (version 3.1 or 4.0) or the supplier's rating and adjusts for exposure and known exploitation. Without a documented adjustment, the rating follows the CVSS bands: Critical 9.0–10.0, High 7.0–8.9, Medium 4.0–6.9, Low 0.1–3.9. Any rating lowered below its band needs a recorded rationale approved under SIAS-VPM-05;
- 2.remediate (patch, upgrade, reconfigure or remove) or mitigate so that the vulnerability can no longer be exploited, within these maximum times from first identification: KEV-listed on an internet-facing asset, 7 days; Critical, 15 days; High, 30 days; Medium, 90 days; Low, 180 days;
- 3.start the clock on the date the vulnerability is first identified on the asset by any source (scan, advisory, external report or SecurityInspect testing). For a vulnerability added to the KEV catalog later, the 7-day clock starts on the later of first identification and the KEV addition date;
- 4.where no fix exists, apply a documented mitigation within the same time limit and keep tracking the vulnerability until it is fixed;
- 5.confirm each remediation by rescanning or retesting, and close the tracker entry only after that confirmation;
- 6.handle any vulnerability that cannot be remediated or mitigated in time under SIAS-VPM-05, except KEV-listed vulnerabilities on internet-facing assets, which must be remediated, mitigated or removed from internet exposure;
- 7.report remediation performance (the share closed within time limits, by rating) to the security owner at least monthly.
Applicability and scope
All scopes. SecurityInspect Verified profiles: VP-EXT (vulnerabilities on the declared internet-facing assets); VP-APP (vulnerabilities in the named application, its dependencies and its hosting).
Pass criteria
- 1.The documented time limits are no longer than the maxima in requirement 2, and the rating method meets requirement 1.
- 2.At the time of testing, no in-scope vulnerability is past its deadline unless a SIAS-VPM-05 risk acceptance covers it. A risk acceptance keeps this criterion from failing; it does not stop SecurityInspect from recording the vulnerability itself as a finding under the SIAS severity scale.
- 3.No KEV-listed vulnerability on an internet-facing asset is open and unmitigated at the time of testing, in either the applicant's records or SecurityInspect's testing.
- 4.Over the look-back period, at least 90% of Critical and High vulnerabilities combined were remediated or mitigated within their deadlines.
- 5.Every sampled closure was confirmed by rescan or retest, and A4 confirms each fix.
- 6.Every mitigation tested in M2 prevents exploitation.
Severity
Critical. Any KEV-listed vulnerability on an internet-facing in-scope asset that is open and unmitigated is a Critical finding regardless of age, and blocks certification until SecurityInspect retests it. A finding may be lowered to High only for a partial failure (for example no overdue items at the time of testing, but an on-time rate below the pass criterion over the look-back period), with written rationale, quality-reviewer concurrence and approval by the second independent reviewer.
Informative framework mappings
- HIPAA Security Rule
- §164.308(a)(1)(ii)(B)
- PCI DSS v4.0.1
- 6.3, 11.3
- Trust Services Criteria
- CC7.1
- ISO/IEC 27001:2022
- A.8.8
- Theme (SecurityInspect wording)
- fixing vulnerabilities in priority order, on time
SIAS-VPM-03 Patch and update management
- Mandatory
- Yes
- Severity
- High
- Applies
- All scopes
- SecurityInspect Verified profiles
- VP-EXT
Control objective
Operating systems, firmware, applications and libraries run versions that still receive security updates, and updates are applied through a controlled, timely process.
Testable requirement
- The applicant must:
- 1.run only operating systems, firmware, software and libraries that receive security updates from their supplier or from a contracted extended-support provider;
- 2.keep a register of end-of-support dates for in-scope technologies and plan each replacement before its end of support;
- 3.apply security updates through a defined process that includes testing proportionate to risk, a rollback method and an emergency path for urgent fixes (time limits under SIAS-VPM-02);
- 4.enable automatic security updates on in-scope endpoints;
- 5.rebuild container images on current base images at least monthly, and when a base-image vulnerability rated High or above is published;
- 6.measure patch coverage and keep at least 95% of in-scope endpoints and servers at their current security patch level, measured against the SIAS-VPM-02 time limits. The applicant should enable automatic security updates on servers and managed services wherever operationally safe, and record why it has not where it has not.
Applicability and scope
All scopes. SecurityInspect Verified profile: VP-EXT (software on the declared internet-facing services, whose versions and support status SecurityInspect identifies from outside and confirms with the applicant).
Pass criteria
- 1.No end-of-support technology is in scope unless a compensating control accepted under this control covers it.
- 2.Patch coverage is at least 95% in the most recent measurement, and A6 confirms it for the sample.
- 3.Sampled patches show testing, a rollback method and, where used, the emergency path.
- 4.Automatic security updates are enabled on in-scope endpoints.
- 5.Container images are within the age limit in requirement 5.
- 6.The end-of-support register lists every in-scope technology with its dates.
Severity
High. The global escalation rules apply; exploitable vulnerabilities in end-of-support software on internet-facing assets are handled as findings under SIAS-VPM-02.
Informative framework mappings
- HIPAA Security Rule
- §164.308(a)(1)(ii)(B)
- PCI DSS v4.0.1
- 6.3
- Trust Services Criteria
- CC7.1
- ISO/IEC 27001:2022
- A.8.8, A.8.19
- Theme (SecurityInspect wording)
- applying security updates to operational systems
SIAS-VPM-04 Periodic penetration testing
- Mandatory
- No
- Severity
- High
- Applies
- Conditional — internet-facing applications or services, or applicant-operated networks, are in scope
- SecurityInspect Verified profiles
- None
Control objective
Skilled people periodically try to break in, finding weaknesses that automated scanning misses, and what they find is fixed.
Testable requirement
- The applicant must:
- 1.commission or perform a penetration test of in-scope internet-facing applications and services, and of applicant-operated networks, at least every 12 months and after each significant change to them;
- 2.use testers who are qualified by documented experience or recognized professional credentials, and who are independent of the design, build and operation of the systems they test (internal or external);
- 3.define the scope and rules of engagement in writing, covering application-layer and network-layer testing, authenticated testing of applications, and checks of segmentation wherever segmentation is used to limit scope;
- 4.use a documented method that goes beyond automated scanning, including manual exploitation attempts and testing of business logic;
- 5.enter findings into the SIAS-VPM-02 process with its time limits, and retest remediated High and Critical findings;
- 6.keep the report, the scope and the retest evidence.
Applicability and scope
Conditional — internet-facing applications or services, or applicant-operated networks, are in scope. Marking it not applicable needs a written rationale approved by the quality reviewer. SecurityInspect's manual technical testing during a SIAS assessment does not fulfill this control, because the control tests the applicant's own ongoing program. A penetration test previously performed for the applicant by SecurityInspect may be accepted as evidence only if none of its testers or advisers serve on the SIAS assessment team, the quality review or the certification decision. Not part of any SecurityInspect Verified profile.
Pass criteria
- 1.A test completed within the last 12 months covered every in-scope internet-facing application and service and every applicant-operated network.
- 2.Each significant change since that test was followed by a test, or a documented reason why none was needed.
- 3.The testers were qualified and independent of the tested systems.
- 4.The method included manual testing beyond automated scanning.
- 5.High and Critical findings were remediated within the SIAS-VPM-02 time limits and retested.
- 6.SecurityInspect's sample retest confirms the fixes.
Severity
High. A previously reported test finding that SecurityInspect confirms is still exploitable, and that meets a global escalation trigger (for example an authentication bypass on an internet-facing system), is a Critical finding.
Informative framework mappings
- HIPAA Security Rule
- §164.308(a)(8)
- PCI DSS v4.0.1
- 11.4
- Trust Services Criteria
- CC4.1
- ISO/IEC 27001:2022
- A.8.8
- Theme (SecurityInspect wording)
- periodic independent attack simulation
SIAS-VPM-05 Vulnerability exceptions and risk acceptance
- Mandatory
- No
- Severity
- Medium
- Applies
- All scopes
- SecurityInspect Verified profiles
- None
Control objective
A vulnerability that is not fixed on time is knowingly accepted by someone with authority, for a limited time, with interim safeguards in place.
Testable requirement
- The applicant must:
- 1.record a risk acceptance, before the deadline passes, for every vulnerability not remediated within its SIAS-VPM-02 time limit and for every rating lowered below its CVSS band;
- 2.state in each acceptance the vulnerability, the affected assets, the reason, the risk, the interim safeguards, the owner, the approver, the approval date and the expiry date;
- 3.for vulnerabilities rated Critical or High, have the acceptance approved by a person with authority for that level of risk under the applicant's risk process (SIAS-RSK-02) who is not the asset owner requesting it;
- 4.set an expiry no later than 12 months after approval, with a fresh review for any renewal;
- 5.never accept the risk of a KEV-listed vulnerability on an internet-facing asset;
- 6.review open acceptances at least every 3 months.
Applicability and scope
All scopes. An applicant's risk acceptance never resolves a SIAS finding, and it is separate from a SIAS exception. Not part of any SecurityInspect Verified profile.
Pass criteria
- 1.Every overdue or re-rated item has an acceptance approved before its deadline.
- 2.Every acceptance has all the required fields.
- 3.Approvers of Critical and High acceptances had the required authority and were not the requester.
- 4.No expired acceptance is still relied on.
- 5.No acceptance covers a KEV-listed vulnerability on an internet-facing asset.
- 6.Open acceptances were reviewed at the required interval.
- 7.The interim safeguards in the sample are in place.
Severity
Medium. The global escalation rules apply. An overdue vulnerability without an acceptance is also a finding under SIAS-VPM-02.
Informative framework mappings
- HIPAA Security Rule
- §164.308(a)(1)(ii)(B)
- PCI DSS v4.0.1
- 6.3, 12.3
- Trust Services Criteria
- CC3.2
- ISO/IEC 27001:2022
- 6.1.3; A.8.8
- Theme (SecurityInspect wording)
- documented, time-limited treatment of residual risk
SIAS-VPM-06 Coordinated vulnerability disclosure intake
- Mandatory
- No
- Severity
- Low
- Applies
- Conditional — public-facing websites, applications or APIs are in scope
- SecurityInspect Verified profiles
- VP-EXT
Control objective
People outside the organization who find a vulnerability can report it easily, and each report reaches someone who acts on it.
Testable requirement
- The applicant must:
- 1.publish a way to report security vulnerabilities for each public-facing in-scope domain: a security.txt file at /.well-known/security.txt in the format defined by RFC 9116, a vulnerability disclosure policy page linked from the site, or both;
- 2.monitor the published contact and acknowledge each report within 5 business days;
- 3.route valid reports into the vulnerability tracker (SIAS-VPM-01) and the remediation process (SIAS-VPM-02);
- 4.keep the reporting route current: a security.txt expiry date in the future, and a contact that works;
- 5.tell reporters what to expect: how to send details, which systems are covered and when they will hear back. The applicant should publish security.txt even where a policy page exists. SIAS does not require a bug bounty or payments to reporters. Any legal assurance offered to reporters is a matter for the applicant's own counsel; SIAS does not assess it.
Applicability and scope
Conditional — public-facing websites, applications or APIs are in scope. Marking it not applicable needs a written rationale approved by the quality reviewer. SecurityInspect Verified profile: VP-EXT (the declared public-facing domains).
Pass criteria
- 1.Every public-facing in-scope domain publishes a reporting route.
- 2.Where security.txt is used, it is valid and unexpired.
- 3.The A3 test report was acknowledged within 5 business days.
- 4.Every sampled real report was acknowledged within 5 business days and entered into the tracker where valid.
Severity
Low. The global escalation rules apply.
Informative framework mappings
- HIPAA Security Rule
- No direct mapping
- PCI DSS v4.0.1
- 6.3
- Trust Services Criteria
- CC2.3
- ISO/IEC 27001:2022
- A.8.8
- Theme (SecurityInspect wording)
- receiving vulnerability reports from outside parties