Sekit CSF · Family
Governance & Risk
36 controls in 12 topics, each seen through the policy, process and technical lenses.
Policy
RCF-0031Control testing program8 mappingsSecurity controls are regularly tested to verify they work as intendedRCF-0013Exception management4 mappingsExceptions to security policies are formally documented and approvedRCF-0022Internal audit4 mappingsThe company conducts formal internal audits of its security controlsRCF-0034Issues management7 mappingsSecurity issues and findings are formally tracked until resolutionRCF-0019Metrics & reporting7 mappingsSecurity performance is measured using defined metricsRCF-0001Policy management4 mappingsThe company has a formal written security policy approved by leadershipRCF-0016Regulatory compliance7 mappingsThe company formally tracks applicable laws and regulationsRCF-0007Risk assessment7 mappingsThe company formally identifies and documents its security risksRCF-0010Risk treatment5 mappingsThe company has a formal plan to address identified security risksRCF-0004Roles & responsibilities6 mappingsSecurity roles and responsibilities are formally defined and assignedRCF-0028Security charter6 mappingsLeadership has formally approved and sponsored the security programmeRCF-0025Third-party risk management11 mappingsThird party suppliers and vendors are formally assessed for security risk
Process
RCF-0032Control testing program8 mappingsControl testing results are tracked and drive remediation actionsRCF-0014Exception management4 mappingsException approvals follow a consistent process with defined time limitsRCF-0023Internal audit6 mappingsInternal audit findings are tracked and remediated within agreed timelinesRCF-0035Issues management7 mappingsIssues are assigned owners and resolved within agreed timelinesRCF-0020Metrics & reporting7 mappingsSecurity metrics are regularly reviewed and reported to leadershipRCF-0002Policy management6 mappingsSecurity policies are consistently communicated and followed across the organisationRCF-0017Regulatory compliance8 mappingsRegulatory requirements are consistently implemented across the organisationRCF-0008Risk assessment8 mappingsRisk assessments are conducted regularly and drive security decisionsRCF-0011Risk treatment6 mappingsRisk treatment actions are tracked and completed within agreed timelinesRCF-0005Roles & responsibilities9 mappingsSecurity responsibilities are understood and consistently fulfilledRCF-0029Security charter4 mappingsThe security programme has visible leadership support and adequate resourcesRCF-0026Third-party risk management13 mappingsThird party security requirements are consistently enforced through contracts
Technical
RCF-0033Control testing program7 mappingsAutomated tools regularly test technical controlsRCF-0015Exception management4 mappingsTechnical controls flag or compensate for approved policy exceptionsRCF-0024Internal audit6 mappingsTechnical tools support automated audit evidence collectionRCF-0036Issues management6 mappingsTechnical tools track and escalate unresolved security issuesRCF-0021Metrics & reporting7 mappingsTechnical dashboards provide real-time visibility of security metricsRCF-0003Policy management7 mappingsTechnical controls enforce compliance with security policiesRCF-0018Regulatory compliance9 mappingsTechnical controls support compliance with regulatory requirementsRCF-0009Risk assessment8 mappingsRisk assessment processes are supported by technical tools and dataRCF-0012Risk treatment8 mappingsTechnical controls implement the agreed risk treatment measuresRCF-0006Roles & responsibilities8 mappingsSystems enforce role-based security responsibilitiesRCF-0030Security charter3 mappingsTechnical infrastructure reflects leadership commitment to security investmentRCF-0027Third-party risk management13 mappingsTechnical controls monitor third party access and activity
This family in ISO/IEC 27001:2022
Every framework item the family's controls map to, most-connected first — grouped by Sekit CSF family, never by the framework's own index.
This family in NIST CSF 2.0
This family in ISO/IEC 42001:2023 — Annex A
This family in Cyber Essentials
Ask Sekura: “What evidence proves Governance & Risk?”
Also via MCP, free with account