SIG Lite
Control CEK-05
Extractive Review Standard
How to answer 'What cipher suites and TLS versions are supported for data in transit?' on a SIG Lite
Reviewer Guidance & Pitfalls
State TLS 1.2 and 1.3 enforcement with modern forward-secrecy ciphers (e.g. ECDHE-RSA-AES128-GCM-SHA256). Explicitly confirm SSLv3, TLS 1.0, and TLS 1.1 are disabled.
Example Answer Passing Enterprise Audit
Compliant Response Template
We enforce TLS 1.2 and TLS 1.3 with Perfect Forward Secrecy cipher suites across all public endpoints; legacy protocols (SSLv3, TLS 1.0, TLS 1.1) are permanently disabled at the load balancer (SOC 2, CC6.1).
Filling out a CAIQ or SIG Lite right now?
QuietQuestionnaire automatically drafts answers with citations from your own SOC 2 report, catches contradictions reviewers reject, and locks exports behind cryptographic human sign-off.
Zero spam. 100% confidential. No credit card required.