SIG (Standardised Information Gathering)
Definition
A vendor security questionnaire published by Shared Assessments. The SIG Core covers eighteen risk domains including access control, data security, and business continuity. The SIG Lite is a condensed version for lower-risk suppliers. Both versions map to ISO 27001, NIST CSF, and PCI-DSS, enabling cross-vendor comparison.
- Publisher
- Shared Assessments
- SIG Core
- Eighteen risk domains including access control, data security, business continuity
- SIG Lite
- Condensed version for lower-risk suppliers
- Framework mapping
- ISO 27001, NIST CSF, PCI-DSS
Common questions
Why would an organisation use SIG instead of writing its own vendor security questionnaire?+
A custom questionnaire forces every vendor to answer differently structured questions, making responses hard to compare across a supplier portfolio. SIG's standardised domain structure and framework mapping let a security team compare vendors consistently and let vendors reuse one completed SIG response across multiple customers, reducing assessment overhead on both sides.
When would an assessor choose SIG Lite over SIG Core?+
SIG Lite is used for lower-risk suppliers, such as those without access to sensitive data or critical systems, where the full eighteen-domain SIG Core would be disproportionate effort for both the assessor and the vendor relative to the actual risk being evaluated.
Related terms
- Audit Rights Clause
- A contractual provision giving the buying organisation the right to assess, inspect, or commission a third-party audit of the vendor's security controls....
- CAIQ (Consensus Assessments Initiative Questionnaire)
- A questionnaire published by the Cloud Security Alliance, designed specifically for cloud service providers. It maps to the CSA Cloud Controls Matrix...
- Fourth-Party Risk
- The risk arising from a vendor's own subcontractors and suppliers. If a critical vendor outsources key processes to a subcontractor, the organisation's...
- Inherent Risk
- The level of risk a vendor relationship carries before any controls are applied. Inherent risk determines how deep an assessment must be:...
- SOC 2 Type II Report
- An independent audit report on a service organisation's controls related to security, availability, processing integrity, confidentiality, and privacy. Type II reports cover...