Glossary

SIG Questionnaire

The SIG — Standardized Information Gathering questionnaire, maintained by Shared Assessments — is one of the most widely used third-party risk questionnaires. Enterprises use it to evaluate vendors’ security, privacy, and business-continuity posture with a standardized question bank instead of writing their own.

SIG Core vs SIG Lite

SIG Core is the full instrument — hundreds of questions across eighteen risk domains, used for vendors handling sensitive data or critical operations. SIG Lite is the abbreviated version for lower-risk relationships, and is what most SaaS startups encounter first. Buyers often start with Lite and escalate to Core sections selectively.

How to handle a SIG efficiently

Answer it once, thoroughly, and maintain it as a living document — the worst version of this process is five people re-deriving answers under deal pressure every quarter. A current SOC 2 report, a completed CAIQ, and a well-maintained SIG Lite together pre-answer the overwhelming majority of any enterprise security review; many teams put them in a trust center for self-serve download.

Related Terms

CAIQ — The CAIQ is the Cloud Security Alliance's standard security questionnaire — a yes/no assessment cloud vendors complete once and reuse across customer reviews.

vCISO — A vCISO provides fractional executive security leadership — strategy, risk decisions, and buyer-facing credibility — without a full-time CISO salary.