SIG Lite
Control APP-02
Extractive Review Standard
How to answer 'Do you follow a secure software development lifecycle?' on a SIG Lite
Reviewer Guidance & Pitfalls
Mention specific control gates: mandatory peer code reviews, automated CI/CD static analysis (SAST/dependency checking), branch protection rules, and environment segregation (dev/staging/prod). Reviewers look for automated enforcement over voluntary guidelines.
Example Answer Passing Enterprise Audit
Compliant Response Template
Yes. All code changes require branch protection passing automated SAST and dependency scans, plus at least one peer approval, before deployment via automated CI/CD pipelines (SOC 2, CC8.1).
Filling out a CAIQ or SIG Lite right now?
QuietQuestionnaire automatically drafts answers with citations from your own SOC 2 report, catches contradictions reviewers reject, and locks exports behind cryptographic human sign-off.
Zero spam. 100% confidential. No credit card required.