Sekit CSF · Identity & Access Management · Technical
RCF-0087Access reviews (recertification)
Systems automatically generate access reports to support periodic reviews
Mapping at a glance
RCF-0087Access reviews (recertification)Identity & Access Management · Technical
RCF-0087 maps to 5 controls across the published frameworks. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.18Access rightssupportsPulling access listings directly from identity provider exports and per-application reports means the review checks what access exists, not what someone remembers granting.A.8.15LoggingrelatedGenerating access listings from system exports depends on the same identity data A.8.15's logs capture, but serves periodic review rather than event logging.A.8.16Monitoring activitiesrelatedGenerating access listings for periodic review depends on identity data rather than the real-time behavioral monitoring A.8.16 is primarily about.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
This topic through the other lenses
All Identity & Access Management controls
Ask Sekura: “What evidence proves RCF-0087?”
Also via MCP, free with account