Sekit CSF · Cloud Security · Process
RCF-0335Cloud IAM
Cloud access rights are consistently reviewed and aligned with the principle of least privilege
Mapping at a glance
RCF-0335Cloud IAMCloud Security · Process
RCF-0335 maps to 7 controls across the published frameworks. +2 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.18Access rightssupportsReviewing cloud access rights on a recurring cycle and trimming what exceeds a person's role is A.5.18's access review requirement carried into cloud platforms.A.8.2Privileged access rightssupportsReviewing cloud access rights on a recurring cycle and removing leavers' access the day they go extends A.8.2's privileged access discipline into cloud environments.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
PR.AA-01Identities and credentials managedPR.AA-03Users and devices authenticatedPR.AA-05Access permissions managed
Maps to Cyber Essentials
Curated mapping with the reasoning, not just the codes.
This topic through the other lenses
All Cloud Security controls
Ask Sekura: “What evidence proves RCF-0335?”
Also via MCP, free with account