SIG Lite
Control TVM-04
Extractive Review Standard
How to answer 'Do you perform Static and Dynamic Application Security Testing (SAST/DAST)?' on a SIG Lite
Reviewer Guidance & Pitfalls
Distinguish between continuous automated SAST in the CI/CD pipeline and periodic or release-gated DAST/external scanning.
Example Answer Passing Enterprise Audit
Compliant Response Template
Automated SAST runs on every commit in CI/CD pipelines. DAST and automated API security scans are executed weekly against pre-production staging environments (SOC 2, CC7.1).
Filling out a CAIQ or SIG Lite right now?
QuietQuestionnaire automatically drafts answers with citations from your own SOC 2 report, catches contradictions reviewers reject, and locks exports behind cryptographic human sign-off.
Zero spam. 100% confidential. No credit card required.