Standardized Information Gathering (SIG)
The Standardized Information Gathering (SIG) questionnaire is a standardized set of questions used to collect information from a third party, such as a vendor, in order to assess the risks of working with them. Organizations commonly use it to gather assessment documentation and support security risk reviews of their suppliers. Because the questions are standardized, it aims to make vendor information easier to request and compare.
SIG is a standardized questionnaire developed and maintained by Shared Assessments and used within third-party and vendor risk management programs to obtain assessment documentation and perform security risk assessments of third parties. According to the evidence, the questionnaire is designed to map to requirements of numerous cyber regulations and frameworks and is offered in more than one scope variant (for example, SIG Core and SIG Lite). As a data-collection instrument, it supports the assessment stage of third-party due diligence; it does not itself constitute a control, an audit, or a compliance determination, and interpreting responses and treating identified risks remain management activities within the assessing organization. This entry does not cover specific question content, version details, licensing terms, or implementation tooling, which vary and are not established by the evidence provided.
Why it matters
Third-party relationships expand an organization's attack surface and introduce risks that fall outside its direct control. A structured means of gathering information from vendors is therefore central to third-party risk management, and the SIG questionnaire is one widely referenced instrument for that purpose. Because its questions are standardized, it can help organizations request comparable information across multiple suppliers rather than relying on ad hoc, inconsistent inquiries, which in turn can make security risk reviews more repeatable.
Standardization also has value on the supplier side of the relationship. A vendor that receives similar questionnaires from many customers may be able to respond more efficiently to a common instrument, and assessing organizations may be able to interpret responses more consistently. According to the evidence, the SIG questionnaire is designed to map to the requirements of numerous cyber regulations and frameworks, which can help organizations relate the information collected to obligations they are already tracking.
It is important to keep the questionnaire's role in perspective. SIG is a data-collection tool that supports the assessment stage of due diligence; it is not itself a control, an audit, or a compliance determination. Collecting completed responses does not by itself establish that a vendor is secure or compliant. The work of evaluating responses, corroborating them where warranted, and deciding how to treat any identified risks remains a management responsibility within the assessing organization.
Who it's relevant to
Inside SIG
Common questions
Answers to the questions practitioners most commonly ask about SIG.
