Sekit CSF · Compliance & Audit · Policy
RCF-0373Control evidence management
The company formally requires that evidence of security controls is collected and maintained for audit purposes
Mapping at a glance
RCF-0373Control evidence managementCompliance & Audit · Policy
A.5.33Protection of recordsISO/IEC 27001:2022A.5.36Compliance with policies, rules and standards for information securityISO/IEC 27001:2022GV.RM-05Lines of communication for risk establishedNIST CSF 2.0ID.IM-03Improvements from operationsNIST CSF 2.0ID.IM-04Response and recovery plans maintainedNIST CSF 2.0
RCF-0373 maps to 8 controls across the published frameworks. +3 more in the table below. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.5.33Protection of recordssupportsStating in writing which controls require retained evidence and how long it is kept extends this control's record-protection principle to the audit evidence itself.A.5.36Compliance with policies, rules and standards for information securityenablesThis policy control states in writing which controls require retained evidence, where it lives and how long it is kept, the evidence standard A.5.36's compliance checking is built on.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
GV.RM-05Lines of communication for risk establishedID.IM-03Improvements from operationsID.IM-04Response and recovery plans maintained
Maps to ISO/IEC 42001:2023 — Annex A
Curated mapping with the reasoning, not just the codes.
A.5.3Documentation of AI system impact assessmentssupportsRequiring retained evidence with an owner and location gives the documentation obligation its home, though it is written for general controls, not AI assessments specifically.A.6.2.3Documentation of AI system design and developmentsupportsRequiring retained evidence with a named owner and location gives AI design documentation a place to live, though it does not itself require technical design content.A.6.2.7AI system technical documentationsupportsRCF-0373 commits in writing to retaining control evidence, but it names no AI system; A.6.2.7 needs that policy extended to cover model versions, data and configuration decisions specifically.
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Audit evidence and corrective actions log
The file where proof that controls work is kept, plus the tracking of audit findings through to closure.
From the Sekit evidence catalog
This topic through the other lenses
All Compliance & Audit controls
Ask Sekura: “What evidence proves RCF-0373?”
Also via MCP, free with account