SIG Lite Control CEK-05 Extractive Review Standard

How to answer 'What cipher suites and TLS versions are supported for data in transit?' on a SIG Lite

Reviewer Guidance & Pitfalls

State TLS 1.2 and 1.3 enforcement with modern forward-secrecy ciphers (e.g. ECDHE-RSA-AES128-GCM-SHA256). Explicitly confirm SSLv3, TLS 1.0, and TLS 1.1 are disabled.

Example Answer Passing Enterprise Audit

Compliant Response Template
We enforce TLS 1.2 and TLS 1.3 with Perfect Forward Secrecy cipher suites across all public endpoints; legacy protocols (SSLv3, TLS 1.0, TLS 1.1) are permanently disabled at the load balancer (SOC 2, CC6.1).

Filling out a CAIQ or SIG Lite right now?

QuietQuestionnaire automatically drafts answers with citations from your own SOC 2 report, catches contradictions reviewers reject, and locks exports behind cryptographic human sign-off.

Zero spam. 100% confidential. No credit card required.