SIG Lite
Control IAM-05
Extractive Review Standard
How to answer 'Is multi-factor authentication required for production access?' on a SIG Lite
Reviewer Guidance & Pitfalls
State the factor type (TOTP vs hardware key), the scope (production vs all internal tools — reviewers probe the difference), and where the requirement is enforced (SSO/IdP policy). A scope mismatch between two answers on the same form is a top-3 rejection cause.
Example Answer Passing Enterprise Audit
Compliant Response Template
Yes. Production access requires SSO with hardware-key MFA enforced at the IdP; access reviews run quarterly (SOC 2, CC6.2).
Filling out a CAIQ or SIG Lite right now?
QuietQuestionnaire automatically drafts answers with citations from your own SOC 2 report, catches contradictions reviewers reject, and locks exports behind cryptographic human sign-off.
Zero spam. 100% confidential. No credit card required.