SIG Lite Control IAM-05 Extractive Review Standard

How to answer 'Is multi-factor authentication required for production access?' on a SIG Lite

Reviewer Guidance & Pitfalls

State the factor type (TOTP vs hardware key), the scope (production vs all internal tools — reviewers probe the difference), and where the requirement is enforced (SSO/IdP policy). A scope mismatch between two answers on the same form is a top-3 rejection cause.

Example Answer Passing Enterprise Audit

Compliant Response Template
Yes. Production access requires SSO with hardware-key MFA enforced at the IdP; access reviews run quarterly (SOC 2, CC6.2).

Filling out a CAIQ or SIG Lite right now?

QuietQuestionnaire automatically drafts answers with citations from your own SOC 2 report, catches contradictions reviewers reject, and locks exports behind cryptographic human sign-off.

Zero spam. 100% confidential. No credit card required.