Sekit CSF · Application Security · Technical
RCF-0144DevSecOps governance
Technical dashboards provide visibility of security posture across all development pipelines
Mapping at a glance
RCF-0144DevSecOps governanceApplication Security · Technical
RCF-0144 maps to 5 controls across the published frameworks. Open in the full graph →
Maps to ISO/IEC 27001:2022
Curated mapping with the reasoning, not just the codes.
A.8.15LoggingrelatedAggregating pipeline security findings into one dashboard depends on logged pipeline events, extending A.8.15's logging into the development environment.A.8.16Monitoring activitiesrelatedAggregating pipeline security findings into one view reports on development-time monitoring, adjacent to but not the same as the system monitoring A.8.16 covers.
Maps to NIST CSF 2.0
Curated mapping with the reasoning, not just the codes.
GV.PO-01Cybersecurity policy establishedPR.PS-01Configuration management appliedPR.PS-03Hardware maintained
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
CI/CD pipeline security
The security controls in the automated build-and-deploy process, including containers and infrastructure-as-code.
From the Sekit evidence catalog
This topic through the other lenses
All Application Security controls
Ask Sekura: “What evidence proves RCF-0144?”
Also via MCP, free with account