SIG (Shared Assessments)
Evidence request list. 31 controls, 31 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Access Control
Per SIG: access control + identity. Vendor demonstrates strong authentication + privileged access + access reviews.
- SIG evidence for SHAREASSESS-2
- SIG questionnaire + 4th-party partial
Cloud
Per SIG: cloud + SaaS controls.
- SIG evidence for SHAREASSESS-8
- SIG questionnaire + 4th-party partial
Governance
Per SIG (Shared Assessments) Standardized Information Gathering: vendor risk assessment. Requirements include (a) governance + risk management of vendors + (b) information security policies + (c) risk identification + treatment + (d) maintain SIG questionnaire responses.
- SIG evidence for SHAREASSESS-1
- SIG questionnaire + 4th-party partial
Privacy
Per SIG: privacy + GDPR + compliance.
- SIG evidence for SHAREASSESS-7
- SIG questionnaire + 4th-party partial
Resilience
Per SIG: incident response + BCM + DR.
- SIG evidence for SHAREASSESS-5
- SIG questionnaire + 4th-party partial
SIG: Application, Network and Threat Management
Apply secure software development lifecycle practices including secure coding standards, code review, vulnerability testing, dependency management, and pre release security gates.
- Secure SDLC policy
- Static and dynamic analysis scan reports
- Software composition analysis results
- Pre release sign off records
- No dependency scanning for open source components
- Findings closed without retest
Implement network segmentation, perimeter and internal firewalling, intrusion detection and prevention, secure remote access, and continuous monitoring across the production environment.
- Network architecture diagrams
- Firewall ruleset reviews
- IDS and IPS deployment evidence
- VPN and zero trust configuration documentation
- Flat network with limited segmentation
- Firewall rules not reviewed at least annually
Maintain threat intelligence, vulnerability management, penetration testing, and red team capabilities to identify and remediate weaknesses in a timely manner.
- Threat intelligence sources and feeds
- Vulnerability scan reports with remediation timelines
- Annual external penetration test report
- Red team or purple team exercise reports
- Critical vulnerabilities open beyond SLA
- Penetration test scope omits new applications
SIG: Asset, People and Physical Security
Maintain a complete and current inventory of information assets, data classification, ownership, and handling requirements throughout the asset lifecycle.
- Asset inventory with owner and classification
- Data classification policy and labeling guide
- Onboarding and decommissioning records
- Data flow diagrams
- Inventory missing cloud assets
- Classification labels inconsistent across systems
Implement background screening, onboarding, training, awareness, sanctions, and termination procedures appropriate to data sensitivity and role risk.
- Background check policy and records
- Annual security awareness training completion logs
- Sanctions policy
- Termination checklists and access removal records
- Contractor screening not performed
- Awareness training completion below threshold
Protect facilities and equipment from unauthorized physical access, environmental hazards, and operational disruptions through layered controls including perimeter, access management, monitoring, and environmental safeguards.
- Badge access logs
- CCTV configuration and retention policy
- Environmental sensor readings and alarms
- Visitor management records
- Tailgating not addressed by controls
- Environmental alarm response not tested
SIG: Cloud, Mobile and Artificial Intelligence
Establish controls for cloud hosted services including shared responsibility, identity federation, configuration hardening, logging, and use of cloud security posture management.
- Shared responsibility model documentation per cloud provider
- Cloud configuration baselines and benchmarks
- CSPM tool reports
- Identity federation configuration evidence
- Default cloud account configurations left in place
- Logging not centralized across cloud accounts
Apply controls to mobile devices and applications used to access in scope data including device encryption, application containerization, jailbreak detection, and remote wipe capabilities.
- Mobile device management policy
- MDM and MAM configuration evidence
- Jailbreak or root detection reports
- Remote wipe logs
- BYOD devices outside MDM scope
- No jailbreak detection enforced
Govern the development, procurement, and use of artificial intelligence and machine learning systems including model risk management, data governance, transparency, bias and fairness testing, and human oversight.
- AI use case inventory
- AI risk assessment and approval records
- Bias and fairness testing reports
- Human oversight procedures and escalation paths
- Shadow AI tools used without approval
- No documented bias testing prior to production deployment
SIG: Incident Management and Resiliency
Maintain an incident response capability with defined plans, classifications, escalation paths, communications protocols, evidence handling, lessons learned, and regulatory and customer notification procedures.
- Incident response plan and playbooks
- Tabletop exercise reports
- Notification templates and contact lists
- Post incident review reports
- No tabletop exercises within 12 months
- Customer notification timelines not tracked
Maintain business continuity and disaster recovery programs including business impact analysis, recovery objectives, plans, periodic testing, and dependencies on third party providers.
- Business impact analysis with RTO and RPO
- Approved BCP and DR plans
- Annual test reports
- Supplier dependency map
- RTO and RPO not validated against tested recovery
- Critical supplier failover untested
SIG: Operations, Access and Endpoint
Document and follow operational procedures for change management, capacity management, system hardening, backup, and operational monitoring for production systems.
- Operations procedure manual
- Change advisory board minutes and tickets
- Backup completion and restore test logs
- Capacity reports
- Backup restore not tested
- Emergency changes routinely used to bypass CAB
Implement formal access provisioning, periodic recertification, least privilege, separation of duties, and privileged access management across systems hosting in scope data.
- Access management policy
- User access review reports
- Privileged access management tool logs
- Joiner mover leaver workflows
- Privileged accounts shared
- User reviews completed without manager attestation
Protect end user devices through configuration baselines, endpoint detection and response, encryption, mobile device management, and patch management.
- Hardening baseline documents
- EDR console coverage report
- MDM enrollment report
- Patch compliance reports
- Personal devices accessing data without MDM controls
- EDR coverage below 95 percent
Apply hardened build standards, configuration management, integrity monitoring, antimalware, and logging on servers hosting in scope data and applications.
- Server hardening standards aligned to CIS Benchmarks
- Configuration management tool reports
- File integrity monitoring alerts
- Antimalware coverage reports
- Servers built outside golden image process
- Integrity monitoring exclusions undocumented
SIG: Privacy and Supply Chain
Manage personal data in accordance with applicable privacy laws and contractual obligations, including data subject rights, lawful basis, cross border transfers, and breach notification.
- Privacy program policy
- Data subject request handling procedure and metrics
- Records of processing activities
- Transfer impact assessments and standard contractual clauses
- No transfer impact assessment for non adequacy jurisdictions
- DSR metrics not tracked against statutory deadlines
Manage risk across the supply chain including subservice organizations, fourth parties, hardware and software providers, and concentration risk, with appropriate due diligence and continuous monitoring.
- Supplier inventory with risk tiering
- Due diligence questionnaires and reports
- Continuous monitoring tool outputs
- Concentration risk analysis
- No fourth party visibility
- Continuous monitoring not actioned
SIG: Questionnaire Scope and Use
Use SIG Core for comprehensive due diligence covering all SIG questions across all domains, suitable for higher risk relationships and assurance level requirements.
- Completed SIG Core questionnaire
- Linked evidence library
- Internal quality review report
- Subject matter expert sign offs by domain
- Domain experts not engaged in response review
- Evidence library out of sync with current state
Use SIG Lite for high level due diligence covering essential controls across all SIG domains where a lower assurance tier is appropriate, ensuring responses are reviewed and approved by accountable owners.
- Completed SIG Lite questionnaire
- Reviewer and approver sign off
- Evidence attachments where requested
- Annual refresh log
- Responses not refreshed annually
- No evidence attachments supporting yes responses
SIG: Risk, Policy and Organisation
Maintain a documented risk assessment and treatment program covering information security, operational, third party, and compliance risks, with defined ownership, frequency, and integration into business decision making.
- Risk management policy and procedure
- Current risk register with owners
- Treatment plans with target dates and approvals
- Risk committee minutes
- Risk register stale beyond annual cycle
- No documented risk acceptance approvals at appropriate level
Establish, approve, communicate, and periodically review a suite of information security policies that cover access control, acceptable use, data classification, encryption, vulnerability management, incident response, and supplier management.
- Approved policy library with version control
- Executive or board approval records
- Distribution and acknowledgement logs
- Annual review evidence
- Policies not reviewed annually
- Acknowledgement coverage below 95 percent of workforce
Define the security organization, governance structure, roles, segregation of duties, and reporting lines for the chief information security function and related committees.
- Security org chart with reporting lines
- Documented security roles and responsibilities
- Information security committee charter and minutes
- Segregation of duties matrix
- CISO reports into role that controls budget for security
- No segregation of duties evidence
Identify, track, and demonstrate compliance with applicable laws, regulations, contractual obligations, and industry standards relevant to the services delivered to the client.
- Compliance obligation register
- Recent independent audit and assessment reports
- Contract obligation tracker
- Regulatory change monitoring procedure
- No central register of contractual security commitments
- Audit findings not remediated within agreed dates
Technical Security
Per SIG: technical security including network + endpoint + data protection + encryption + DLP.
- SIG evidence for SHAREASSESS-3
- SIG questionnaire + 4th-party partial
Third-Party
Per SIG: subcontractor + 4th-party management.
- SIG evidence for SHAREASSESS-6
- SIG questionnaire + 4th-party partial
Vulnerability and AppSec
Per SIG: vulnerability management + patching + app security + secure SDLC.
- SIG evidence for SHAREASSESS-4
- SIG questionnaire + 4th-party partial
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the SIG (Shared Assessments) framework page.