Sekit CSF · Privacy · Policy
RCF-0358Consent & preference mgmt
The company has a formal policy for capturing and managing individual consent for data processing
Mapping at a glance
RCF-0358Consent & preference mgmtPrivacy · Policy
A.5.31Legal, statutory, regulatory and contractual requirementsISO/IEC 27001:2022 · Annex A controlsA.5.34Privacy and protection of personal identifiable information (PII)ISO/IEC 27001:2022 · Annex A controlsGV.OC-03Legal and regulatory requirements understoodNIST CSF 2.0GV.PO-02Cybersecurity policy maintainedNIST CSF 2.0
RCF-0358 maps to 4 controls across the published frameworks. Open in the full graph →
Maps to ISO/IEC 27001:2022 · Annex A controls
Curated mapping with the reasoning, not just the codes.
A.5.31Legal, statutory, regulatory and contractual requirementsrelatedA policy on when consent is required and how it is withdrawn is one concrete legal obligation this control's register needs to include.A.5.34Privacy and protection of personal identifiable information (PII)supportsDefining in writing when consent is the legal basis, how it must be captured, and how withdrawal works as easily as giving it sets the policy A.5.34 needs for protecting personal data, though consent capture and enforcement still have to happen in practice.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Privacy notice and consent records
The privacy information the company shows people before collecting their data (privacy notice / policy) and how consent is captured and respected.
From the Sekit evidence catalog
This topic through the other lenses
All Privacy controls
Ask Sekura: “What evidence proves RCF-0358?”
Connect your AI · free MCP
https://sekit.ai/api/mcp/crosswalk- In Claude or ChatGPT, add a custom connector and paste this URL.
- Sign in with your email to finish. Free, read-only, no organization required.