Sekit CSF · Application Security · Technical
RCF-0132CI/CD hardening
Technical controls protect the build pipeline from tampering and enforce security gates at each stage
Mapping at a glance
RCF-0132CI/CD hardeningApplication Security · Technical
RCF-0132 maps to 6 controls across the published frameworks. +1 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.8.4Access to source codesupportsThe CI/CD hardening technical facet locks down build definitions, secrets and deployment steps against tampering, a practical mechanism for the source code access control A.8.4 requires.A.8.9Configuration managementsupportsLocking the pipeline down so build definitions and deployment steps cannot be tampered with is A.8.9's configuration integrity applied to the delivery system.A.8.25Secure development life cyclesupportsThe technical facet locks down the pipeline so build definitions, secrets and deployment steps cannot be tampered with, enforcing a security gate at each stage.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
PR.PS-01Configuration management appliedPR.PS-03Hardware maintainedPR.PS-04Logs generated for monitoring
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
CI/CD pipeline security
The security controls in the automated build-and-deploy process, including containers and infrastructure-as-code.
From the Sekit evidence catalog
This topic through the other lenses
All Application Security controls
Ask Sekura: “What evidence proves RCF-0132?”
Also via MCP, free with account