SIG (Shared Assessments)
Standardized Information Gathering questionnaire for third-party risk
SIG (Shared Assessments) is a compliance framework from International with 16 domains and 31 controls that map to 142 other frameworks. The largest domains are SIG: Operations, Access and Endpoint (4 controls), SIG: Risk, Policy and Organisation (4 controls), SIG: Application, Network and Threat Management (3 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (16)
Access Control
| Code | Title |
|---|---|
| SHAREASSESS-2 | Access Control, Identity, Authentication |
Cloud
| Code | Title |
|---|---|
| SHAREASSESS-8 | Cloud, SaaS, Infrastructure |
Governance
| Code | Title |
|---|---|
| SHAREASSESS-1 | Information Governance and Risk |
Privacy
| Code | Title |
|---|---|
| SHAREASSESS-7 | Privacy, Compliance, GDPR Alignment |
Resilience
| Code | Title |
|---|---|
| SHAREASSESS-5 | Incident Response, BCM, DR |
SIG: Application, Network and Threat Management
SIG: Asset, People and Physical Security
SIG: Cloud, Mobile and Artificial Intelligence
SIG: Incident Management and Resiliency
SIG: Operations, Access and Endpoint
SIG: Privacy and Supply Chain
SIG: Questionnaire Scope and Use
| Code | Title |
|---|---|
| SIG-CORE-01 | SIG Core Coverage and Use |
| SIG-LITE-01 | SIG Lite Coverage and Use |
SIG: Risk, Policy and Organisation
Technical Security
| Code | Title |
|---|---|
| SHAREASSESS-3 | Network Security, Endpoint, Data Protection |
Third-Party
| Code | Title |
|---|---|
| SHAREASSESS-6 | Third Party / Subcontractor Management |
Vulnerability and AppSec
| Code | Title |
|---|---|
| SHAREASSESS-4 | Vulnerability Management, Patching, Application Security |
Your Compliance Coverage
If you comply with SIG (Shared Assessments), you already cover:
ISO 27043
13%
4 controls mapped
Compare →ISO/IEC 27010:2015
13%
4 controls mapped
Compare →AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association)
13%
4 controls mapped
Compare →+ 139 more: ISO/SAE 21434 (13%), NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices (13%)
See all 142 mapped frameworks ↓Maps to 142 other frameworks
If I already comply with another framework, how much of SIG (Shared Assessments) do I already cover?
SIG (Shared Assessments) maps to 142 other compliance frameworks. The top mapping partners are ISO 27043 (13% coverage), ISO/IEC 27010:2015 (13% coverage), AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) (13% coverage). Use our comparison tool to explore control-level mappings between frameworks.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required