Security Info FAQKlistalabs-test
Reference desk / 01
Security review, made legible

SIG questionnaire questions.

Browse common SIG review topics and the security practices each question is designed to address.

110 reference questions 5 question sets browse freely

About these answers. Most entries explain common industry practices, not Klistalabs-test controls. SIG entries marked “Company response” use approved Klistalabs-test wording supplied for this site.

40 results
01

Which organizational security practices are covered in a SIG response?

SIG / SIG · organization and management

A SIG response describes security governance, accountable roles, reporting lines, policy oversight, and risk oversight. It identifies the organizational, service, or system boundaries to which those practices apply.

02

How should SIG policy and governance questions be approached?

SIG / SIG · policy and governance

A SIG policy and governance response explains the relevant policies, their owners and approval processes, how they are communicated and reviewed, and how compliance is overseen. It states whether each policy applies organization-wide or to specified services, functions, or systems.

03

What should a SIG risk management response address?

SIG / SIG · risk management

A SIG risk management response explains how risks are identified, assessed for likelihood and impact, recorded, assigned to owners, and treated through mitigation, transfer, or acceptance. It also describes how treatment decisions are approved, monitored, and reviewed.

04

How should SIG compliance questions be scoped?

SIG / SIG · compliance

A SIG compliance response identifies the applicable laws, regulations, contractual obligations, and jurisdictions, along with the services and activities in scope. It distinguishes requirements that have been assessed or attested from those outside the stated scope and describes relevant evidence or exceptions.

05

What personnel security topics appear in SIG?

SIG / SIG · human resources

A SIG personnel security response describes screening where applicable, onboarding, role-based security responsibilities, awareness training, conduct and disciplinary processes, and offboarding. It notes distinctions based on role, location, or employment relationship when they affect the controls.

06

What physical security details may a SIG reviewer request?

SIG / SIG · physical security

A SIG physical security response describes how access to relevant facilities and equipment is authorized and monitored, how visitors are handled, and how environmental hazards are addressed. It clarifies the division of responsibility for infrastructure operated by the organization and by service providers.

07

How should SIG asset management questions be answered?

SIG / SIG · asset management

A SIG asset management response explains how technology and information assets are inventoried, assigned owners, classified, and protected through acquisition, use, maintenance, and secure disposal. It identifies the asset types and systems within scope.

08

What access control details does a SIG response need?

SIG / SIG · access control

A SIG access control response describes how identities are provisioned, authorized for specific systems and data, and updated or removed when roles change. It covers least privilege, privileged-access safeguards, access reviews, and the approval and tracking of exceptions.

09

How should SIG authentication questions be validated?

SIG / SIG · authentication

A SIG authentication response explains how the identity of users, devices, or services is verified, which authentication methods protect different types of access, and where multi-factor authentication is used. It also addresses account recovery and safeguards for sensitive access.

10

What operational security topics are commonly requested in SIG?

SIG / SIG · operations security

A SIG operations security response describes the procedures and controls used to operate systems securely, including job scheduling, capacity management, malware defenses, logging, and operational changes. It identifies the teams and providers responsible for these activities.

11

How should SIG vulnerability questions be documented?

SIG / SIG · vulnerability management

A SIG vulnerability management response explains how weaknesses are identified through testing, scanning, and security advisories; assessed and prioritized by risk; assigned to owners; and tracked through remediation. It also describes how exceptions and unresolved vulnerabilities are documented and reviewed.

12

What should a SIG change management answer include?

SIG / SIG · change management

A SIG change management response describes how proposed changes are documented, assessed for risk, approved, tested, and controlled through release. It explains rollback planning and the approval and review process for urgent changes.

13

How should SIG continuity and recovery questions be addressed?

SIG / SIG · business continuity

A SIG continuity and recovery response identifies critical services and dependencies, and explains the plans and capabilities for maintaining or restoring them during disruption. It states the scope of continuity and disaster recovery plans, exercise practices, recovery objectives, and known limitations.

14

What does a SIG incident management response need to cover?

SIG / SIG · incident management

A SIG incident management response explains how security events are detected, reported, classified, investigated, escalated, and contained, and identifies response roles and communication processes. It also covers recovery, evidence handling, and post-incident review and corrective actions.

15

How should SIG logging and monitoring questions be answered?

SIG / SIG · logging and monitoring

A SIG logging and monitoring response identifies the systems and events recorded, how logs and other signals are monitored, and how alerts are reviewed and escalated. It also describes access controls, retention, and protections for log integrity.

16

What network security topics may appear in SIG?

SIG / SIG · network security

A SIG network security response describes network segmentation, boundary protections, administrative access controls, monitoring, and change controls relevant to the service. It clarifies how network responsibilities and protections map to the service architecture and any infrastructure providers.

17

How should SIG encryption questions be scoped?

SIG / SIG · encryption

A SIG encryption response identifies which data is encrypted at rest and in transit, the systems and services covered, and the cryptographic standards in use. It also explains how encryption keys are generated, stored, accessed, rotated, and retired.

18

What data protection details should a SIG response include?

SIG / SIG · data protection

A SIG data protection response describes information classification, access restrictions, permitted handling, retention and deletion, and protections during transfer. It also explains how applicable customer or data subject requests are handled and identifies the data and services in scope.

19

How should third-party risk questions in SIG be answered?

SIG / SIG · third-party management

A SIG third-party risk response explains how relevant vendors and service providers are identified and assessed before engagement, how security and privacy expectations are established contractually, and how provider risks and changes are monitored. It also describes reassessment and termination or transition planning.

20

How can a SIG response stay accurate and reviewable?

SIG / SIG · evidence and response quality

A reviewable SIG response answers each control question directly, describes the relevant practice and evidence, and identifies the services, systems, and responsibilities in scope. It distinguishes verified facts from controls that do not apply, notes material exceptions, and avoids claims beyond the available evidence.

21

Is there a formalized risk governance policy approved by management that defines the Enterprise Risk Management program requirements?

SIG / Company response · risk governance

Yes. The organization maintains a documented risk management framework that defines requirements for identifying, assessing, treating, monitoring, and reporting enterprise and information security risks. The framework is reviewed periodically and approved by appropriate management.

22

Have any of the Information Security and IT processes been outsourced?

SIG / Company response · outsourced processes

Yes. Certain IT and security functions may be supported by qualified third-party service providers, including cloud infrastructure, security monitoring, and business applications. Third parties are subject to risk assessment, contractual security requirements, and ongoing oversight.

23

Is all media containing scoped data disposed of securely?

SIG / Company response · media disposal

Yes. Media containing sensitive or customer data is securely sanitized or destroyed using methods appropriate to the media type and aligned with recognized industry practices. Disposal activities are managed to prevent unauthorized recovery of data.

24

Are encryption keys generated in a manner consistent with key management industry standards?

SIG / Company response · key management

Yes. Encryption keys are generated, stored, accessed, rotated, and retired using industry-standard cryptographic and key-management practices. Access to encryption keys is restricted to authorized systems and personnel.

25

Does the service provider conduct user and privileged access reviews for remote access by its vendors with access to scoped systems and data?

SIG / Company response · vendor access

Yes. Access granted to vendors and other third parties is limited based on business need and least-privilege principles. User and privileged access is periodically reviewed, and access is removed when no longer required.

26

Does the password policy require system configuration to lock an account when five or more invalid login attempts are made?

SIG / Company response · account protection

The organization maintains account protection controls designed to mitigate brute-force and unauthorized login attempts. Depending on the system, controls may include account lockout, rate limiting, progressive delays, MFA, and automated threat detection rather than a fixed five-attempt threshold.

27

Is there an individual or group responsible for Application Security?

SIG / Company response · application security

Yes. Responsibility for application security is assigned to designated security and engineering personnel. Application security activities include secure development practices, code review, vulnerability management, dependency monitoring, and security testing.

28

Is there a formal, documented information technology disaster recovery exercise and testing program in place?

SIG / Company response · disaster recovery

Yes. The organization maintains documented business continuity and disaster recovery procedures. Recovery capabilities are tested periodically, and identified issues or improvement opportunities are tracked through remediation.

29

Is a website maintained or hosted for the purpose of advertising, offering, managing, or servicing accounts, products, or services to clients' customers?

SIG / Company response · web services

Yes. The organization maintains web-based services used to provide information about and/or deliver its products and services. Production systems are subject to applicable security, privacy, access-control, and monitoring requirements.

30

Are network or security technologies used to establish and enforce security requirements and block unauthorized traffic between segregated systems and other networks and systems?

SIG / Company response · network security

Yes. Network and cloud security controls are used to restrict unauthorized communications and enforce logical separation between systems and environments. Controls may include firewalls, security groups, access control policies, network segmentation, and monitoring technologies.

31

Does the organization's environmental policy have executive and board-level commitment, support, and endorsement?

SIG / Company response · environmental policy

Where applicable, environmental and sustainability responsibilities are overseen by organizational leadership and incorporated into relevant corporate policies and operational practices. Formal board-level oversight depends on the organization's size, regulatory requirements, and environmental risk profile.

32

Does the organization have material discharges to air as a direct result of its operations?

SIG / Company response · environmental impact

No. As a primarily software- and technology-based organization, the company does not conduct industrial or manufacturing activities that result in material direct discharges to air.

33

Does the organization have a policy for ensuring the diversity of board members and reporting this information as appropriate?

SIG / Company response · board governance

The organization considers appropriate experience, qualifications, backgrounds, and perspectives when establishing its leadership and governance structure. Formal board diversity reporting is performed where required by applicable law, regulation, or corporate governance requirements.

34

Is personal information collected directly from an individual by the organization on behalf of the client?

SIG / Company response · privacy

Where required to provide the service, limited personal information may be collected or processed on behalf of customers. Such information is handled in accordance with contractual obligations, applicable privacy laws, and the organization's privacy and security policies.

35

Is notice provided at or before the point of collection regarding the selling of personal information or sharing of data with third parties for marketing purposes?

SIG / Company response · privacy notices

Yes, where applicable. Privacy notices describe how personal information is collected, used, disclosed, and shared. The organization does not sell personal information unless explicitly disclosed and permitted under applicable law.

36

Do any other parties, such as affiliates, contractors, subcontractors, sub-processors, or sub-service organizations, have access to, receive, process, or retain client scoped data?

SIG / Company response · subprocessors

Yes. Authorized subprocessors and service providers may process customer data where necessary to deliver the service. Such providers are subject to security and privacy due diligence, contractual requirements, and appropriate confidentiality and data-protection obligations.

37

Is remote access restricted to employees and contractors during specific hours and locations and through secure VPN with multi-factor authentication, including sub-tier contractors when necessary?

SIG / Company response · remote access

Remote access is restricted to authorized users and protected through strong authentication and access-control measures, including MFA where supported. Access is granted based on business need and least privilege. The organization does not necessarily restrict remote access to predefined hours or physical locations where equivalent risk-based security controls are in place.

38

Do asset inventory and management processes include all physical objects with network connectivity (IoT Devices)?

SIG / Company response · asset management

Yes. Asset management processes are designed to identify and track applicable company-managed devices with network connectivity. Where IoT devices are used, they are included within the relevant inventory and security management processes.

39

Are Cloud Hosting services provided?

SIG / Company response · cloud hosting

Yes, where applicable. The organization's services are delivered using cloud infrastructure provided by established cloud service providers. The organization is responsible for securing its applications, configurations, identities, and data within the applicable shared-responsibility model.

40

Is the Cloud Service Provider responsible for deploying patches to the live guest Operating Systems?

SIG / Company response · cloud patching

Responsibility depends on the hosting model. For managed cloud services, the cloud provider maintains the underlying infrastructure and managed platform components. Where the organization manages guest operating systems or compute instances, the organization is responsible for applicable operating system patching under the shared-responsibility model.