SIAS-WFS-01 Role-appropriate screening
- Mandatory
- No
- Severity
- Medium
- Applies
- All scopes (only as permitted by applicable law; SIAS never requires unlawful screening)
- SecurityInspect Verified profiles
- None
Control objective
People given privileged access or access to sensitive data have been checked to a level that matches the risk of their role, within the law.
Testable requirement
- The applicant must:
- 1.define screening levels by role risk, with a higher level for roles that hold privileged access or access to Restricted data;
- 2.complete the screening for a role's level before privileged access or access to Restricted data is granted, or record an interim restriction (for example supervised or limited access) until it is complete;
- 3.screen only as permitted by applicable law, recording any role for which the applicant has determined that screening is not permitted;
- 4.require, by contract, that suppliers of contractors and other third-party personnel who will hold such access screen them to the level the role requires, and obtain the supplier's confirmation for each person;
- 5.screen again when a person moves to a role with a higher screening level;
- 6.record completion (date and level) in a system of record, keeping screening results out of any records that SecurityInspect needs to see.
Applicability and scope
All scopes (only as permitted by applicable law; SIAS never requires unlawful screening). Where applicable law prohibits screening for a role, requirements 2 and 5 are met for that role by the recorded determination in requirement 3. Not part of any SecurityInspect Verified profile.
Pass criteria
- 1.The policy defines screening levels by role risk, including a higher level for privileged and Restricted-data roles.
- 2.Every holder of privileged or Restricted-data access completed screening before access, or was under an interim restriction or a recorded legal determination.
- 3.Supplier contracts require screening, and confirmations exist for every sampled contractor.
- 4.Every move to a higher-level role was followed by the required screening.
Severity
Medium. The global escalation rules apply.
Informative framework mappings
- HIPAA Security Rule
- §164.308(a)(3)(ii)(B)
- PCI DSS v4.0.1
- 12.7
- Trust Services Criteria
- CC1.4
- ISO/IEC 27001:2022
- A.6.1
- Theme (SecurityInspect wording)
- risk-based personnel screening
SIAS-WFS-02 Security terms, acceptable use and sanctions
- Mandatory
- Yes
- Severity
- Medium
- Applies
- All scopes
- SecurityInspect Verified profiles
- None
Control objective
Everyone with access knows their security obligations, has agreed to them, and knows that breaking them has consequences.
Testable requirement
- The applicant must:
- 1.include confidentiality and information-security obligations, including obligations that continue after the relationship ends, in employment terms, contractor agreements and agreements covering third-party personnel with access to in-scope systems or data;
- 2.maintain an acceptable use policy covering in-scope systems and devices, data handling, credentials, personal devices (where allowed) and reporting of suspected security incidents;
- 3.obtain each person's acknowledgment of the acceptable use policy before access is granted, again at least every 12 months, and after each material change to the policy;
- 4.maintain a documented sanction process for security-policy violations and apply it consistently. The applicant decides outcomes; SIAS checks that the process exists and runs;
- 5.track acknowledgments in a system of record.
Applicability and scope
All scopes. Covers all personnel. Not part of any SecurityInspect Verified profile.
Pass criteria
- 1.Agreement templates include security and confidentiality obligations, including obligations that continue after the relationship ends.
- 2.The acceptable use policy covers every topic in requirement 2.
- 3.At least 98% of active personnel hold a current acknowledgment, and every sampled new starter acknowledged before access.
- 4.The sanction process is documented and, where applied in the look-back period, was applied as written.
- 5.Contractors and third-party personnel are covered by requirements 1 and 3.
Severity
Medium. The global escalation rules apply.
Informative framework mappings
- HIPAA Security Rule
- §164.308(a)(1)(ii)(C), §164.310(b)
- PCI DSS v4.0.1
- 12.2
- Trust Services Criteria
- CC1.1, CC1.5
- ISO/IEC 27001:2022
- A.5.10, A.6.2, A.6.4, A.6.6
- Theme (SecurityInspect wording)
- security obligations, acceptable use and consequences
SIAS-WFS-03 Security awareness and phishing training
- Mandatory
- Yes
- Severity
- Medium
- Applies
- All scopes
- SecurityInspect Verified profiles
- None
Control objective
Everyone with access can recognize common attacks, handles data correctly, and knows how to report something suspicious.
Testable requirement
- The applicant must:
- 1.train all personnel within 30 days of starting, before any privileged access or access to Restricted data is granted, and at least every 12 months after that;
- 2.cover in the training: phishing and social engineering (including phone- and message-based pretexts and repeated MFA prompts), password and MFA practice, data handling under the classification scheme (SIAS-DAT-01), safe use of devices and remote work, and how and when to report a suspected incident;
- 3.run phishing simulations for personnel at least twice a year, and assign follow-up training to people who fail;
- 4.provide a simple way to report suspected phishing (for example a report button or a dedicated mailbox) that reaches the security function;
- 5.reach at least 95% completion among active personnel in each annual cycle, tracked in a system of record;
- 6.update the content at least every 12 months, and sooner when relevant threats change. SIAS does not use phishing click rates as a pass criterion, because that would reward easy simulations. It checks that simulations run, fit the organization, and lead to follow-up.
Applicability and scope
All scopes. Covers all personnel. Not part of any SecurityInspect Verified profile.
Pass criteria
- 1.Completion in the current annual cycle is at least 95%.
- 2.Every sampled new starter was trained within 30 days, and every holder of privileged or Restricted-data access was trained before the access grant.
- 3.The content covers every topic in requirement 2.
- 4.At least two simulations ran in the 12 months before the assessment or, for a program younger than 12 months, one ran and the next is scheduled within 6 months of it.
- 5.Follow-up training was assigned to, and completed by, people who failed a simulation.
- 6.The reporting mechanism worked in M3.
Severity
Medium. The global escalation rules apply.
Informative framework mappings
- HIPAA Security Rule
- §164.308(a)(5)(i), §164.308(a)(5)(ii)(A)
- PCI DSS v4.0.1
- 12.6
- Trust Services Criteria
- CC1.4, CC2.2
- ISO/IEC 27001:2022
- A.6.3
- Theme (SecurityInspect wording)
- general security awareness for all personnel
SIAS-WFS-04 Role-based security training for technical and privileged staff
- Mandatory
- No
- Severity
- Medium
- Applies
- All scopes
- SecurityInspect Verified profiles
- None
Control objective
People whose work directly shapes security, such as developers, administrators and incident responders, have the specific security skills their roles need.
Testable requirement
- The applicant must:
- 1.identify the security-relevant technical roles in scope, at least: developers of in-scope software, system and cloud administrators, other holders of privileged access, incident responders and people who triage security alerts;
- 2.define the security competencies each role needs;
- 3.provide role-based security training at least every 12 months: secure coding and common vulnerability classes for developers, in the languages and frameworks in use; secure administration, privileged access handling and configuration hardening for administrators; the applicant's incident response plan and handling procedures for responders;
- 4.provide that training before, or within 60 days of, a person taking on the role;
- 5.record completion and evidence of competence (for example training records, relevant professional credentials or exercise participation) against each role's competencies.
Applicability and scope
All scopes. Covers personnel in the roles identified under requirement 1. Not part of any SecurityInspect Verified profile.
Pass criteria
- 1.Technical roles and their competencies are defined.
- 2.At least 90% of role holders were trained within the last 12 months, and every sampled new role holder within 60 days.
- 3.The content is relevant to the technologies and procedures in use.
- 4.Completion and competence records exist for every sampled role holder.
Severity
Medium. The global escalation rules apply.
Informative framework mappings
- HIPAA Security Rule
- §164.308(a)(5)(i)
- PCI DSS v4.0.1
- 6.2, 12.6, 12.10
- Trust Services Criteria
- CC1.4
- ISO/IEC 27001:2022
- 7.2; A.6.3
- Theme (SecurityInspect wording)
- targeted training for technical roles
SIAS-WFS-05 Offboarding and role change
- Mandatory
- Yes
- Severity
- High
- Applies
- All scopes (HR-triggered process and asset return; technical deprovisioning is tested under SIAS-IAM-01)
- SecurityInspect Verified profiles
- None
Control objective
When someone leaves or changes role, the people who manage access find out in time, company assets and data come back, and continuing obligations are reinforced.
Testable requirement
- The applicant must:
- 1.have HR, or the owner of a contractor relationship, notify the access-management function of each separation no later than the separation date, and for an involuntary separation before or at the time the person is informed;
- 2.use an offboarding checklist covering: the access removal request (tested under SIAS-IAM-01); return of devices, security keys, access badges and tokens; retrieval or deletion of company data on personal devices where they are allowed; transfer of ownership of accounts, keys, scripts, scheduled jobs and cloud resources the person owned; rotation of shared secrets the person knew; and a reminder of continuing confidentiality obligations;
- 3.recover assets within 5 business days of separation, or remotely lock and wipe them;
- 4.notify the access-management function of each role change within 5 business days, so that access the new role does not need is removed;
- 5.record the completion of each checklist item with its date.
Applicability and scope
All scopes (HR-triggered process and asset return; technical deprovisioning is tested under SIAS-IAM-01). Covers all personnel. Not part of any SecurityInspect Verified profile.
Pass criteria
- 1.Every sampled separation was notified on time, and A1 shows at least 95% of all separations in the look-back period notified on time.
- 2.Every sampled involuntary separation was notified before or at the time the person was informed.
- 3.Every sampled separation's assets were recovered, or locked and wiped, within 5 business days.
- 4.Every sampled role change produced an access-change ticket within 5 business days.
- 5.Every sampled checklist is complete, including shared-secret rotation where it applied.
- 6.A4 found no in-scope resource still owned by a separated person.
Severity
High. The global escalation rules apply; for example, use of a separated person's access after separation that indicates compromise is a Critical finding, recorded under SIAS-IAM-01.
Informative framework mappings
- HIPAA Security Rule
- §164.308(a)(3)(ii)(C)
- PCI DSS v4.0.1
- 8.2
- Trust Services Criteria
- CC6.2
- ISO/IEC 27001:2022
- A.5.11, A.6.5
- Theme (SecurityInspect wording)
- access and asset handling at exit