Skip to content

SIG (Standardised Information Gathering)

Definition

A vendor security questionnaire published by Shared Assessments. The SIG Core covers eighteen risk domains including access control, data security, and business continuity. The SIG Lite is a condensed version for lower-risk suppliers. Both versions map to ISO 27001, NIST CSF, and PCI-DSS, enabling cross-vendor comparison.

Publisher
Shared Assessments
SIG Core
Eighteen risk domains including access control, data security, business continuity
SIG Lite
Condensed version for lower-risk suppliers
Framework mapping
ISO 27001, NIST CSF, PCI-DSS

Common questions

Why would an organisation use SIG instead of writing its own vendor security questionnaire?+

A custom questionnaire forces every vendor to answer differently structured questions, making responses hard to compare across a supplier portfolio. SIG's standardised domain structure and framework mapping let a security team compare vendors consistently and let vendors reuse one completed SIG response across multiple customers, reducing assessment overhead on both sides.

When would an assessor choose SIG Lite over SIG Core?+

SIG Lite is used for lower-risk suppliers, such as those without access to sensitive data or critical systems, where the full eighteen-domain SIG Core would be disproportionate effort for both the assessor and the vendor relative to the actual risk being evaluated.

Related terms

Audit Rights Clause
A contractual provision giving the buying organisation the right to assess, inspect, or commission a third-party audit of the vendor's security controls....
CAIQ (Consensus Assessments Initiative Questionnaire)
A questionnaire published by the Cloud Security Alliance, designed specifically for cloud service providers. It maps to the CSA Cloud Controls Matrix...
Fourth-Party Risk
The risk arising from a vendor's own subcontractors and suppliers. If a critical vendor outsources key processes to a subcontractor, the organisation's...
Inherent Risk
The level of risk a vendor relationship carries before any controls are applied. Inherent risk determines how deep an assessment must be:...
SOC 2 Type II Report
An independent audit report on a service organisation's controls related to security, availability, processing integrity, confidentiality, and privacy. Type II reports cover...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.