Security

The SIG Lite Questionnaire

What enterprise customers are asking and how to respond accurately.

What the SIG Lite Is

The Standardized Information Gathering (SIG) questionnaire is a security assessment tool developed by the Shared Assessments Program. The SIG Lite is the abbreviated version — typically 140–200 questions — used by enterprise customers, financial institutions, and regulated organizations to assess the security posture of vendors and service providers.

If you serve enterprise clients, you will receive a SIG Lite.

A note before you start: If an enterprise customer is asking about your security posture, the best credential you can provide is a SOC 2 Type II report — an independent third-party audit of your controls. Most enterprise clients will accept a clean SOC 2 in lieu of a filled-out SIG Lite. But not all organizations have undergone a SOC 2 audit, and the SIG Lite remains a practical, widely-accepted alternative.

The 17 Sections

The questionnaire is organized into content areas labeled A through U (not all letters are used):

A — Risk Assessment and Treatment Risk management program, vendor oversight, subcontractor access, privacy risk assessments, compliance risk management.

B — Security Policy Information security policy existence, management approval, review cadence.

C — Organizational Security Information security function and ownership.

D — Asset and Information Management Asset management policy, data classification, removable media, encryption, data segmentation, retention programs.

E — Human Resource Security HR policy, background screening, employment agreements, security awareness training, termination process.

F — Physical and Environmental Security Physical security program, data center and office controls, visitor management.

G — Operations Management Change management, backup procedures, cloud service models provided, maintenance windows, incident status communication.

H — Access Control Individual user IDs, password policy, remote access, MFARequires more than a password to sign in — typically a password plus a code from your phone. A stolen password alone isn't enough., federated identity (SAMLThe protocol behind enterprise SSO — log into your identity provider once and gain access to connected apps without separate credentials./OIDCA modern SSO standard built on OAuth 2.0 — like SAML but uses JSON instead of XML, designed for both web and mobile apps.), access to client data.

I — Application Security Web application controls, HTTPSHTTP secured with TLS encryption. Protects web traffic from interception and verifies the server's identity via a certificate. Every public-facing site should be HTTPS-only. enforcement, patch management, log protection, software development lifecycle.

J — Incident Event and Communications Management Incident response program, breach notification procedures, communication methods.

K — Business Resiliency Business continuity and disaster recoveryDisaster recovery (DR) is the set of policies, procedures, and technologies that enable an organization to restore IT systems and data after a major failure — a ransomware attack, hardware failure, natural disaster, or facility loss. planning, RTO/RPO, testing cadence.

L — Compliance Regulatory compliance frameworks, audit history, certifications (SOC 2, ISO 27001, PCI, HIPAA).

M — End User Device Security EndpointAn endpoint is any user-facing device that connects to a network — laptops, desktops, smartphones, tablets, and workstations. In security contexts, endpoints are the primary targets of attacks and the focus of EDR and MDM solutions. protection, MDMCentrally manages and secures your device fleet — laptops, phones, tablets — enforcing policies and enabling remote wipe regardless of location./device management, encryption on endpoints.

N — Network Security Network segmentation, perimeter controls, wireless security, monitoring.

P — Privacy Privacy program, data subject rights, consent management, cross-border transfer controls.

T — Threat Management Threat intelligence, vulnerability scanningAutomatically probes systems for known security weaknesses — unpatched software, misconfigurations, default credentials — and reports them prioritized for remediation., penetration testing, red team exercises.

U — Server Security OS hardening, patch management on servers, privileged access controls.

How to Approach It

The SIG Lite is not a test you pass or fail. It's a baseline assessment that helps the requesting organization understand your risk profile. Overstating controls creates liability — if you represent controls you don't have and subsequently experience a breach, that representation becomes part of the incident.

Honest answers, with context where it helps, are better than inflated answers. "No, we don't have a formal written risk management program, but our risk discussions happen at the leadership level quarterly and are documented in board minutes" is a better answer than "Yes" when the honest answer is "No."

Common Problem Areas

Areas where organizations most often struggle:

Written security policies: controls that exist informally but aren't documented.

Formal risk management: many SMBs manage risk through experience and judgment rather than structured programs.

Vendor management: how do you assess the security posture of your own vendors?

DR/BCP documentation: backup procedures that haven't been formally documented or tested.

Encryption specifics: what algorithm, what key length, for what data — questions that require knowing the technical details of your own implementations.

Preparing Before You Receive One

Organizations that respond efficiently have already built their documentation library:

  1. Information Security Policy
  2. Access Control Policy
  3. Data Classification and Handling Policy
  4. Incident Response Plan
  5. Business Continuity / DR documentation
  6. Vendor Management Policy
  7. Patch Management Policy

If you don't have these, the SIG Lite is a forcing function to build them — which is actually the right outcome.

Download a Blank Copy

We've prepared a clean, fillable version of the SIG Lite — with all example answers removed — that you can use to respond to vendor assessment requests.

Download SIG Lite (PDF)

Free to use. No signup required.

Answer SIG Lite

Need to complete a SIG Lite questionnaire?

We help businesses gather the right evidence, close gaps, and respond to vendor security assessments without the scramble. Tell us about the questionnaire you've received.

Let's Talk

Related

If a client or partner has sent you a SIG Lite questionnaire, our Cybersecurity Assessment service can help you answer it with confidence:

More from the University: